Governance
Cookie Policy
How StoryHelm uses cookies, localStorage, and session replay, what loads only after you consent, and how to control every non-essential tracker. Your prose is masked and never captured.
Effective: · Last updated: This document's own dates. No other paper moves them.
Contents
8 sections · about 3 min read
How we use cookies and similar technologies
A courtesy, not the contract
StoryHelm uses cookies, browser localStorage, and similar technologies to keep you signed in, secure your account, remember your preferences, and, with your consent, to understand and improve how the product works. We group these into the categories described below.
Non-essential trackers are opt-out by default. Analytics, session replay, and any other non-essential technology load only after you consent to the relevant category in the cookie banner. Until you give consent, only the essential cookies and storage needed to run StoryHelm are active. You can change your choices at any time using the controls described in "Managing your preferences" below.
Where this note and the sections below disagree, the sections govern.
Cookies and trackers we use
The table below lists the cookies and storage technologies active on StoryHelm, the category each belongs to, what it does, whether it is a cookie or localStorage, whether it is set by us or a third party, and how long it persists.
| Name / Provider | Category | Purpose | Type | Party | Duration |
|---|---|---|---|---|---|
| sh_session (StoryHelm) | Essential | Keeps you signed in and maintains your authenticated session. | Cookie | First-party | Session / up to 30 days |
| sh_csrf (StoryHelm) | Essential | Protects forms and account actions against cross-site request forgery. | Cookie | First-party | Session |
| sh_prefs (StoryHelm) | Essential | Remembers interface preferences such as theme and layout. | localStorage | First-party | Until cleared |
| sh_consent (StoryHelm) | Essential | Records your cookie consent choices so we can honor them on every visit. | localStorage | First-party | Up to 12 months |
| PostHog (analytics + session replay) | Analytics | Product analytics and session replay to diagnose issues and improve the product. Routed through our first-party /ingest proxy to a US-hosted PostHog instance. Loads only after you consent to analytics. | localStorage + cookie | Third-party | Up to 12 months |
When you first visit StoryHelm, you choose which categories to allow. Essential is always on because the product cannot function without it. Every other category is off until you turn it on.
- EssentialAlways on
Required for sign-in, security, and core functionality. Always on; exempt from consent. - Analytics
Product analytics and session replay (PostHog) to understand and improve the product. - Marketing
Measuring marketing campaigns and reach. - Third-party
Third-party services and integrations you opt into. - Product improvement
Use of de-identified product signals to improve StoryHelm. Never includes your manuscript prose.
Consent and controls
When you consent to analytics, PostHog records sessions so we can see how interface flows behave, reproduce bugs, and improve usability. This is not anonymous, aggregate data. Recorded events are tied to your account so we can support you and resolve issues.
Your writing is protected. Your manuscript, the editor, and the reading surfaces are masked in recordings, so your prose is never captured in a session replay. We record how the surrounding interface is used, not the words you write.
You control non-essential cookies in several ways:
- The consent banner shown on your first visit, where you accept, reject, or customize each non-essential category.
- The "Manage cookie preferences" control in the footer of every page, which reopens the same choices at any time.
- Your browser settings, which let you block or delete cookies and clear localStorage.
Clearing your cookies or site storage removes your session, so you will be signed out of StoryHelm and will need to sign in again. It also resets your saved consent choices, and the banner will appear again on your next visit.
StoryHelm does not sell your personal information, and we do not share it for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal and treat it as a valid opt-out request under the California Consumer Privacy Act. If your browser or an extension sends a GPC signal, we apply it automatically to your visit.
For more detail on your privacy rights and how to exercise them, see our Privacy Policy.
Transfers, retention, and changes
Related policies
StoryHelm
Privacy & data requests: privacy@storyhelm.com · Legal: legal@storyhelm.com · Registered mailing address available on request.
Effective July 5, 2026 · Last updated July 6, 2026. We notify you of material changes in-app and by email; continued use after an update constitutes acceptance.

