Governance
Privacy Policy
How StoryHelm collects, uses, and protects your data, including the honest path your manuscript takes when you ask us to analyze it. You keep your copyright; we never train on or sell your work.
Effective: · Last updated: This document's own dates. No other paper moves them.
Contents
16 sections · about 8 min read
Privacy at a glance
A courtesy, not the contract
StoryHelm is an AI manuscript-intelligence platform for indie series authors. It reads and analyzes your work; it never writes your prose. Here is the short version, with the detail in the sections below.
- You keep 100% of the copyright in your manuscripts. We never sell your work, and neither we nor our AI provider trains any model on it.
- When you run an analysis or a translation, your manuscript text is sent to our servers (hosted on DigitalOcean) and onward to Anthropic's Claude API to produce the read you asked for. We are transparent about this because it is how the product works.
- We collect the data needed to run your account, deliver analysis, keep the service secure, and handle billing. Non-essential cookies and marketing are off until you opt in.
- You can access, export, correct, or delete your data by emailing privacy@storyhelm.com.
Where this note and the sections below disagree, the sections govern.
Who we are and what we collect
StoryHelm ("StoryHelm", "we", "us") provides the StoryHelm manuscript-intelligence service and is the controller of the personal data described in this policy.
You can reach our privacy team at privacy@storyhelm.com. Our registered mailing address is available on request.
We collect the following categories of information.
- Account and authentication. Your Google sign-in identifier and the authentication metadata that comes with it (such as the timestamps and tokens that keep you signed in securely).
- Profile. The name, email address, and any optional details you add to your StoryHelm profile.
- Manuscript content and derived insight. The prose, notes, and project files you upload or write in the built-in editor, together with the findings, canon, scene data, and other analysis StoryHelm derives from them.
- Collaboration data. The email addresses of collaborators you invite and the shared canon and comments produced when you work together.
- Usage and analytics. Information about how you use the product, such as pages visited, features used, and device and browser details. Product analytics and session replay are consent-gated and off by default.
- Billing. Your Stripe customer and subscription identifiers and the credit and LLM-spend ledger that tracks the analysis you run. Card numbers are handled by Stripe; we do not store full card numbers.
- Translation jobs. When you use Translation Studio, the source text, the language pairs you select, and the resulting translation records.
- Support communications. The messages, attachments, and context you send when you contact us for help.
- Cookies and device data. Identifiers and settings stored on your device. See our Cookie Policy for the full list.
We use your information for the purposes below. Where the GDPR or UK GDPR applies, the lawful basis for each purpose is shown.
- Performance of our contract with you. Creating and securing your account, delivering the analysis, findings, canon, and translations you request, enabling collaboration, and processing your subscription. We cannot provide the service without this.
- Our legitimate interests. Keeping the service safe and reliable (fraud prevention, abuse detection, security monitoring) and improving the product. We balance these interests against your rights, use de-identified or aggregated signals wherever we can, and never use your manuscript prose to train models. You can object to processing based on legitimate interests at any time.
- Your consent. Non-essential cookies, product analytics and session replay, and marketing communications. These are off until you opt in, and you can withdraw consent at any time without affecting the lawfulness of earlier processing.
- Legal obligations. Meeting tax, accounting, and other legal requirements, for example retaining billing records.
Where your words go
We believe authors deserve a clear answer about what happens to their words, so here it is in plain language.
When you run an analysis or a translation, the relevant manuscript text and the context derived from it are sent from your browser to our servers, which are hosted on DigitalOcean, and from there to Anthropic, PBC's Claude API. StoryHelm is the multi-agent system that produces your read: a 41-pass analysis across 7 workflows, powered by Claude. Your prose does not stay only on your device, and we will never tell you that it does.
Training. Neither StoryHelm nor Anthropic, PBC trains any model on your manuscripts. Under Anthropic's commercial terms, the Claude API does not train on inputs or outputs by default.
Retention at the provider. Training and retention are different things. By default, Anthropic retains API inputs and outputs for a limited window for safety and abuse-prevention purposes before deletion. We do not currently operate under a Zero-Data-Retention agreement, so we describe this honestly rather than claiming your text is never stored.
See our Subprocessors page for the full list of providers and the role each one plays.
You retain 100% of the copyright and all other rights in your manuscripts. To provide the service, you grant us a limited license to host, process, and transmit your content to the subprocessors that make analysis, collaboration, and translation work. That license exists only to run StoryHelm for you and ends when you delete the content or close your account.
We never sell your work, and we never use it to train AI models. StoryHelm reads and analyzes; it does not write your prose. Every word of your story remains yours and human-authored.
We rely on a small set of trusted service providers to host the platform, run analysis, process payments, authenticate sign-in, and measure consent-gated analytics. Each one acts on our instructions under a written agreement and is bound by appropriate data-protection terms.
The complete, current list, including each provider's purpose, the data it handles, and its processing location, is maintained on our Subprocessors page.
Sharing, retention, and security
We do not sell your personal information. We share it only in these limited circumstances.
- Subprocessors. The service providers described above, acting on our behalf to deliver the service.
- Legal process. When we are required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, safety, and security of our users, the public, or StoryHelm.
- Business transfer. In connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy and will notify you of any change in control of your data.
StoryHelm is operated from, and your data is hosted in, the United States. If you access the service from the European Economic Area, the United Kingdom, or another region, your information is transferred to the United States and to our subprocessors there.
Where required, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with appropriate technical and organizational safeguards, to protect those transfers.
We keep personal data only as long as we need it for the purposes described in this policy, then delete or anonymize it. Our standard retention periods are below; we may keep data longer where the law requires it or to resolve disputes and enforce our agreements.
| Category | Retention period |
|---|---|
| Account & identity | For the life of your account, then deleted within 3 years of account deletion |
| Manuscript content & generated findings | Until you delete it, then within 3 years of account deletion |
| Preferences & settings | Up to 3 years after account deletion |
| Collaboration data (collaborator emails, shared canon) | Until removed, then within 3 years of account deletion |
| Usage & analytics | 1 year |
| Payment & billing records | 7 years (tax and accounting obligations) |
| Consent records | Kept as evidence of consent for the applicable limitation period |
We protect your data with encryption in transit (TLS 1.2 or higher) and at rest, role-based access controls, and the principle of least privilege for access to production systems. We monitor for abuse and review our controls regularly.
We are working toward SOC 2 Type II as our security program matures. No method of transmission or storage is perfectly secure, so we encourage you to use a strong, unique sign-in and to report any concern to security@storyhelm.com. You can learn more on our Security page.
Your rights and choices
Depending on where you live, you have rights over your personal data. We honor these rights regardless of where you are based.
If you are in the EEA or the UK (GDPR / UK GDPR), you have the right to:
- be informed about how we process your data;
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- erase your data (the right to be forgotten);
- restrict processing in certain circumstances;
- data portability, to receive your data in a portable format;
- object to processing based on our legitimate interests or to direct marketing; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
You can exercise most of these rights yourself from the in-product Privacy Controls, including exporting and deleting your data, or by emailing privacy@storyhelm.com. We may need to verify your identity before acting, and we aim to respond within about 30 days. You also have the right to lodge a complaint with your local supervisory authority, though we ask that you contact us first so we can try to resolve the issue. For more detail, see our GDPR & UK GDPR page.
If you are a California resident (CCPA / CPRA), you have the right to:
- know what personal information we collect and how we use and share it;
- delete the personal information we hold about you;
- correct inaccurate personal information; and
- opt out of any sale or sharing of personal information. We do not sell or share your personal information in this sense.
We will not discriminate against you for exercising any of your privacy rights.
Changes and contact
Privacy questions, answered
No. Neither StoryHelm nor its AI provider trains any model on your work. StoryHelm does not train on your prose, and Anthropic's commercial Claude API does not train on inputs or outputs by default. You keep 100% of the copyright in your work.
No. StoryHelm does not sell your personal information or your manuscript. Your data is used to run your account, deliver the analysis you request, keep the service secure, and handle billing.
When you run an analysis or a translation, your manuscript is sent to StoryHelm's servers and to Anthropic's Claude API to produce your findings. It is processed only to generate your results, is not used to train models, and is not sold.
StoryHelm supports GDPR and UK GDPR rights (access, rectification, erasure, restriction, portability, objection, and the right to complain to a supervisory authority) and California CCPA/CPRA rights, with no discrimination for exercising them. See the GDPR page for details.
To access, export, correct, or delete your data, email privacy@storyhelm.com and we'll handle your request. Identity verification may be required, and we respond within about 30 days.
Related policies
StoryHelm
Privacy & data requests: privacy@storyhelm.com · Legal: legal@storyhelm.com · Registered mailing address available on request.
Effective July 5, 2026 · Last updated July 6, 2026. We notify you of material changes in-app and by email; continued use after an update constitutes acceptance.

