Privacy policy
Operator and support contact must be configured before public launch.
Data collected
Account email, password hashes, session records, preferences, project text, submitted recordings, generated assets, consent evidence and usage/payment references are processed to deliver the workspace. Full payment card information is handled by the payment provider and is not stored by StoryWeave.
Purpose and legal basis
Data supports authentication, voice creation, authorization review, credit accounting, payments, abuse prevention and service reliability. Region-specific legal bases, required separate consent and biometric classification must be approved before launch.
Processors and transfers
Speech providers, private storage, email and payment processors receive only necessary data. The configured deployment region controls processing routes; recordings are not automatically routed to another region. Publish a verified processor list, processing locations and any approved transfer safeguards before launch.
Retention and deletion
Private assets use expiring access links. User deletion disables voice use while provider/storage deletion completes. Financial and security records may need separate retention. Specific retention schedules, backup deletion timelines and legal exceptions remain pending review.
Your choices and rights
Request access, correction, export, deletion or applicable consent withdrawal through the operator support channel, which must be configured. Identity verification and statutory response timelines must be implemented before public launch. Do not submit recordings you cannot lawfully share.