Privacy Policy
Last updated: 2026-09-26 · alpha-grade content; reviewed before public launch.
What we collect
- Account data: email address, display name (if you set one), and authentication tokens.
- Content you create: requirements you submit, generated user stories, INVEST validation results, task breakdowns, effort estimations, and any edits you make.
- MCP API keys (only if you create one): the key’s name, a short display prefix, when it was created, last used and revoked. We store only a one-way hash of the key itself, never the key.
- Jira connection (only if you connect Jira): your Jira site address, the permissions you granted, and the OAuth access and refresh tokens, which we store encrypted (AES-256-GCM). Disconnecting Jira deletes them.
- Document sources (only if you start from documents): each file’s name and character count, saved with the session the draft becomes. We never receive your files, and we don’t store their text — only the requirement you generate from, like requirements you type.
- Usage telemetry (only with your consent — see Cookies below): page views, generation events, export events, and aggregate Core Web Vitals via Vercel Analytics and Speed Insights.
- Error reports (only with your consent): anonymised stack traces via Sentry to help us fix bugs.
- Product analytics (only with your consent): funnel-shape event counts via PostHog. Autocapture is disabled — only named events fire.
Where it’s stored
Account data and content are stored in Supabase (Postgres) in the EU (Frankfurt) region. The application itself is hosted on Vercel, served from EU edge locations. Telemetry is routed through PostHog EU (Frankfurt) and Sentry EU (Frankfurt). If you use an MCP API key, per-minute rate-limit counters keyed by your user ID are kept in Upstash Redis in the EU (Frankfurt) region.
AI-residency disclosure
Generation, validation, task breakdown, estimation, and drafting from documents are powered by Google’s Gemini 2.5 Flash and (as a fallback) GPT-OSS 120B hosted by Groq (an open-weight model; requests go to Groq, not OpenAI). Both providers’ APIs are US-region at the time of writing. When you submit a generation request, the requirement text and the returned stories transit US infrastructure on both providers. Text you import from a Jira epic, which may include your colleagues’ names or other personal data, becomes part of your requirement: it is sent to these providers and stored like requirements you type.
When you start from documents, your files are read in your browser and are never uploaded to us. If their text fits in 10,000 characters, it goes into your requirement as is, under “Document 1”, “Document 2” headings (not the file names). If it is longer, the extracted text — not the files, and not their names — is sent to these providers to condense it into a draft; we don’t store that text. Documents such as meeting transcripts may contain other people’s names or personal data, so only use documents you are allowed to share.
We’re tracking EU-region availability for both providers (e.g., Vertex AI for Gemini) and will migrate when it becomes viable without quality regression. This is documented as ADR-015 in our architecture decisions.
Free-tier Gemini API traffic may be retained by Google for model improvement, per their published policy. The same applies to free-tier Groq. We will move to paid tiers (which exempt this) before opening alpha to non-invited users.
How long we keep it
Account and content data: for the lifetime of your account. When you delete your account (see Your rights), everything cascades — sessions, stories, validations, tasks, estimations, and generation logs.
Sentry traces: 7-day retention on the free tier. PostHog events: 7-day retention on the free tier. Vercel Analytics: 30 days. If you reject analytics, no data flows to these processors in the first place. Upstash rate-limit counters expire automatically within 60 seconds.
Third-party processors
- Supabase (auth + database + storage) — EU Frankfurt
- Vercel (hosting + Analytics + Speed Insights) — EU edge
- Sentry (error tracking, opt-in) — EU Frankfurt
- PostHog (product analytics, opt-in) — EU Frankfurt
- Upstash (MCP API rate limiting; only if you use an API key) — EU Frankfurt
- Atlassian (Jira) (only if you connect Jira) — reads the projects and issues you choose and creates issues when you export; region follows your Jira site. Your Jira site is hosted by Atlassian under your organisation’s own agreement; we access it on your behalf.
- Google (Gemini) — US-region; AI inference only
- Groq (GPT-OSS 120B) — US-region; AI inference fallback only
Your rights
Under GDPR, you have the right to access, export, and delete your data. From your account page, you can:
- Export all your data as a single JSON file
- Delete your account and all associated data — this is irreversible and cascades to every row tied to your user id
Data captured before you accepted the consent banner (if any — alpha invitees prior to 2026-06-21) may persist in third-party processor logs until their retention window expires. We do not have the ability to retroactively remove it from vendor systems.
Cookies
We use a single first-party browser storage entry (storycraft.consent.v1, in localStorage) to remember your consent choice. This is a strictly-necessary item, exempt from consent rules. All other cookies / storage entries — set by Sentry, PostHog, and Vercel Analytics — fire only after you click Accept. If you click Reject or have not chosen, no third-party tracker is loaded.
Contact
Questions or requests: email privacy@storycraft.example (alpha placeholder — to be replaced with a real contact before public launch).