Privacy Policy
Effective: June 15, 2026
Who we are
Storypole (“we”, “us”) is the operator of the website storypole.app and the Storypole application. Contact: hello@storypole.app.
What data the app handles — and where it lives
Everything you enter in Storypole — budgets, payments, schedules, decisions, risks, supplier contacts, photos and receipts — is stored locally on your device, in your browser's storage (IndexedDB and localStorage). It is not transmitted to us. We have no database, no server-side storage, and no way to access it.
Files you create (JSON backups, the full backup .zip that also bundles your photos, Excel exports, the optional linked auto-save file) are ordinary files saved where you choose. They are under your control, like any document on your computer.
Optional Google Drive sync
If you connect Google Drive, the app syncs your project data and photos directly from your browser to your own Google Drive account using Google's API. This traffic goes between your device and Google — it never passes through us.
- The app requests the narrowest available permission (
drive.file): it can only see files it created itself, nothing else in your Drive. - The sign-in token is stored locally in your browser and expires within about an hour.
- You can disconnect at any time in Settings, delete the sync file from your Drive, and revoke the app's access at myaccount.google.com/permissions.
- Your use of Google Drive is governed by Google's privacy policy.
Storypole's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What our infrastructure can see
Honesty requires mentioning the ordinary plumbing of the web:
- Hosting (Cloudflare). The website and app are served by Cloudflare. Like any web host, Cloudflare processes standard connection data (such as IP addresses) to deliver pages and defend against attacks. We have not enabled analytics; we do not receive or review visitor logs.
- Excel converter (SheetJS). Only when you use Excel import/export, the app loads the SheetJS library from a public CDN. That CDN sees a standard file request from your browser. None of your project data is sent to it.
- Google sign-in script. Only when you connect Drive sync, Google's sign-in script is loaded from Google. Until you click Connect, no Google code runs.
- License service. Only if you buy Premium: activating your key (and a roughly weekly background re-check while online) contacts the payment provider's license API with the key and a short device label — never your project data. See Purchases below.
- Fonts. Self-hosted inside the app. No fonts CDN is contacted.
Cookies and tracking
The website and app set no cookies and contain no analytics, advertising, fingerprinting or tracking of any kind. The app uses browser storage solely to store your project data and preferences on your device.
Purchases
If you purchase a premium license, the payment is processed by an independent payment provider acting as the merchant of record — currently Lemon Squeezy (lemonsqueezy.com). They handle your payment details under their own privacy policy; we never receive your card information. What we can see in their seller dashboard is the standard order record: your name, the email you used at checkout, your country, what you bought, and your license key with its activation count. We use it solely to provide support, process refunds, and manage licenses.
To be precise about where purchase data lives: the purchase record (your checkout email, what you bought, the license key) is held by the payment provider; your license key is stored locally on your device to keep premium features active; and we keep any correspondence you have with us about your purchase. This is the only personal data connected to us anywhere in Storypole.
When you activate a license key (and roughly once a week afterwards while online), the app contacts the payment provider's license service directly from your browser to confirm the key is valid. That request carries the key and a short device label (e.g. "Storypole on Android") — no project data, ever. If you're offline, premium features keep working; validation simply waits.
If you email us, we receive your address and message and use them only to reply. We do not run newsletters or marketing emails.
Your rights (GDPR and similar laws)
Privacy laws give you rights of access, correction, deletion and portability over personal data a company holds about you. For your project data and app usage, Storypole's design satisfies these inherently — we hold none of it: it is already in your possession, exportable at any time (JSON or Excel), and deletable by you (in-app reset, clearing browser data, or deleting your files).
The only personal data that can exist on our side is what's described above: purchase and license records (held with the payment provider) and emails you send us. Your rights apply to those in full — write to us and we will access, correct or delete them, and you can also exercise rights directly with the payment provider under their policy.
Security
Storypole stores your data using the storage mechanisms your browser and device provide, and the app is designed to minimize attack surface (no accounts, no server, no third-party code beyond what's listed above). But “local” is not the same as “secure”: no storage is immune to a compromised or stolen device, malware, browser vulnerabilities, or someone with access to your computer or phone. Protect the device like you would any device that holds your financial documents — lock screen, OS updates, and care with browser extensions, which can read any page they're granted access to.
Children
Storypole is not directed at children under 16. Since we collect no personal data, no child's data is processed by us either.
Changes
If we ever change how Storypole handles data — for example, if a future feature involves a server — we will update this policy and clearly flag the change on this page before it takes effect. The effective date above always reflects the current version.