Governance
Subprocessors
The third-party providers StoryHelm relies on to host, secure, analyze, translate, and bill for the service. We require each to protect your data, and we give you advance notice before adding a new one.
Effective: · Last updated: This document's own dates. No other paper moves them.
Contents
5 sections · about 4 min read
Subprocessors at a glance
A courtesy, not the contract
To run StoryHelm we rely on a small set of vetted third-party vendors, called subprocessors, that process data or manuscript content on our behalf under contract and our instructions. They cover hosting, AI analysis and translation, payments, consent-gated analytics, and sign-in. You keep your copyright, and neither StoryHelm nor our AI provider trains any model on your work. The current list, with what each vendor handles and where, is below.
Where this note and the sections below disagree, the sections govern.
StoryHelm is an AI manuscript-intelligence platform. To deliver the service, we engage the third-party companies listed below as subprocessors. A subprocessor is a vendor that processes personal data or your manuscript content on our behalf, under our instructions and contract, so that we can host, secure, analyze, translate, and bill for StoryHelm.
We require every subprocessor to protect your data under written terms that are at least as protective as our own commitments to you. Before we add a new subprocessor or change the role of an existing one, we give you at least 30 days notice in advance, and you may object. If you have a reasonable, data-protection-based objection, you can raise it with us and we will work with you in good faith. If we cannot resolve it, you may terminate the affected service as set out in our agreement.
To receive advance notice of subprocessor changes, contact privacy@storyhelm.com and ask to be added to our subprocessor notification list.
The following subprocessors are engaged to provide the StoryHelm service. Processing locations and transfer mechanisms are listed for each. Where personal data leaves the United Kingdom or the European Economic Area, transfers are governed by the European Commission Standard Contractual Clauses (EU SCCs) and the UK International Data Transfer Addendum (UK IDTA), together with supplementary safeguards.
| Subprocessor | Purpose | Data processed | Location | Transfer mechanism | Notes |
|---|---|---|---|---|---|
| Anthropic, PBC | AI manuscript-intelligence analysis and translation (Claude API) | Manuscript prose and derived analysis context (canon, scene, findings) | United States | EU SCCs / UK IDTA | Does not train models on inputs or outputs by default (Anthropic Commercial Terms). |
| DigitalOcean, LLC | Cloud hosting, storage, and managed database | All account, manuscript, and operational data at rest | United States | EU SCCs / UK IDTA | |
| Stripe, Inc. | Payment processing and subscription billing | Billing contact, payment-method tokens, transaction and subscription records | United States | EU SCCs / UK IDTA | Card data is handled by Stripe; StoryHelm does not store full card numbers. |
| PostHog, Inc. | Product analytics and session replay (consent-gated) | Usage events, pseudonymized identifiers; manuscript/editor surfaces are masked from recordings | United States | EU SCCs / UK IDTA | Loads only after you consent to analytics; opt-out by default. |
| Google LLC | Authentication (Google sign-in / OAuth) | Google account identifier, email, and basic profile | United States | EU SCCs / UK IDTA | |
| Email delivery (SMTP) provider | Transactional and account email delivery | Email address and message content | United States | EU SCCs / UK IDTA | Configured via SMTP; the specific provider depends on deployment. |
StoryHelm reads and analyzes your work. It never writes your prose. When you run an analysis or a translation, your manuscript text is sent from your browser to StoryHelm's servers and then on to our AI provider, Anthropic, PBC, which operates the Claude API that powers our 41-pass analysis, a multi-agent system. Your prose is processed only to generate your findings, canon, and translations, and to return them to you.
Your manuscript is not used to train any model. Neither StoryHelm nor Anthropic, PBC trains models on your inputs or outputs. Under the Anthropic Commercial Terms, the Claude API does not train on customer inputs or outputs by default. Training and retention are different things: by default the API provider may retain API data for a limited window for safety and abuse-prevention purposes. We disclose this flow plainly so you can make an informed choice, and we treat it as a trust commitment rather than fine print.
Before engaging a subprocessor, we assess whether the vendor is necessary to deliver the service and review its security and privacy posture. We look for encryption in transit and at rest, access controls, breach-notification commitments, and a data-protection agreement with appropriate transfer mechanisms for data that leaves the UK or EEA.
- We sign a data processing agreement, or rely on the vendor's equivalent terms, that binds the subprocessor to confidentiality, security, and purpose-limited processing.
- We limit each subprocessor to the specific data it needs for its stated purpose, and nothing more.
- We require EU SCCs and the UK IDTA, with supplementary safeguards, for transfers outside the UK and EEA.
- We periodically review whether each subprocessor is still required and still meeting our standards, and we remove vendors we no longer use.
This page is incorporated by reference into our Data Processing Addendum and our Privacy Policy. Together they describe how StoryHelm processes your data, the roles of our subprocessors, and the rights available to you and to your readers.
Questions about a specific subprocessor, or requests for a copy of the relevant transfer terms, can be sent to privacy@storyhelm.com. Legal notices can be sent to legal@storyhelm.com.
Related policies
StoryHelm
Privacy & data requests: privacy@storyhelm.com · Legal: legal@storyhelm.com · Registered mailing address available on request.
Effective July 5, 2026 · Last updated July 6, 2026. We notify you of material changes in-app and by email; continued use after an update constitutes acceptance.

