Who We Are
StoryXI ("StoryXI", "we", "us", "our") provides tools to create and manage stories, images, audio, and video (the "Services"). This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the Services.
Scope
This Policy applies to visitors and registered users of our Services, including story creation, image/audio/video generation, and galleries.
Third-party services you access via our Services are governed by their own policies.
Beta Status
The Service is currently in beta. Bugs, interruptions, and unexpected behavior may occur, and features may change or be removed without notice. Do not rely on the Service for mission‑critical needs and keep your own backups of important content.
Information We Collect
Account & Profile
- Email address for account creation and authentication
- Optional profile info you provide
- From Facebook Ads: If you arrive at our website by clicking a Facebook advertisement, Facebook may provide us with additional information about you, including name, email, date of birth, gender, and location data, subject to your Facebook privacy settings
Billing & Subscription
- Subscription plan, status, invoices, charges, refunds, proration, and related identifiers from our payment processor
- Token balances and usage associated with your account
- We do not store full payment card numbers
User Content & Media
- Prompts, scripts, stories, shotlists, character data you create
- Images, audio, and video you upload
- Generated outputs and related metadata (e.g., model used, parameters, timestamps)
Usage & Device
- IP address, device/browser type, and diagnostic logs (e.g., status codes, error messages)
- Feature usage events (e.g., model selections, durations)
- Analytics data: Through Google Analytics, we collect page views, user interactions, session duration, and conversion events
- Advertising data: Through Facebook Pixel, we collect website visits, actions taken, and conversion events to measure ad effectiveness
Cookies & Tracking
- Essential cookies for authentication/session and preferences
- Google Analytics cookies: To understand website usage and improve user experience
- Facebook Pixel tracking: To measure advertising effectiveness and enable retargeting
Sensitive Content Caution
Please avoid uploading sensitive personal data unless it is necessary for your use of the Service and you have the appropriate rights or permissions. Content you submit may be transmitted to third‑party providers when you use related features.
How We Use Information
- Provide and operate the Services (authentication, storage, galleries, generation workflows)
- Process your image, audio, and video generation requests
- Manage subscriptions, proration, refunds, and send transactional emails
- Security, fraud prevention, and abuse detection
- Troubleshoot issues, improve quality, and develop features
- Comply with legal obligations and enforce terms
We transmit only the data needed to complete the features you choose (e.g., when you run a specific model).
Third‑Party Services We Use
When you use related features, we send the minimum necessary information so providers can perform the requested operation.
- Supabase (authentication, database, storage)
- Stripe (payments, subscriptions, invoicing, proration)
- Replicate (orchestration/hosting of certain image/video models, including models from Runway, Google, Topaz)
- ElevenLabs (audio/dialogue, music generation)
- Pixaverse (video lip sync)
- Our FFmpeg server (video/audio combination and scene compilation)
- Google Analytics (website analytics and performance tracking)
- Meta/Facebook Pixel (advertising measurement and retargeting)
These providers process data under their own terms and privacy policies. We do not control their internal retention or processing beyond the API options we use.
What We Send to Providers
- Text prompts and parameters (e.g., aspect ratio, output format, duration)
- Reference media you supply (image/audio/video URLs or uploads, as required by the model/API)
- Minimal metadata required by the provider API
Billing information is handled by our payment processor and is not sent to model providers.
Storage and Backups
Storage of your content is provided to enable the Service and is not a separate paid storage service. You are responsible for keeping your own backups and copies of any content you upload or generate. We do not guarantee availability or recoverability of any content.
Google Analytics
We use Google Analytics to understand aggregate usage of the Services. Google Analytics may collect your IP address, device/browser information, and interactions with our pages.
You can manage cookies in your browser, and Google provides an opt‑out add‑on: https://tools.google.com/dlpage/gaoptout.
Data Retention
- Your content (stories, prompts, media, outputs) remains until you delete it or delete your account, subject to backup/restore cycles.
- Billing/transactional records are retained as required by applicable laws.
- Operational logs are retained for security and troubleshooting, then deleted or aggregated.
Security
- Role‑based access and row‑level security where configured
- Transport security (HTTPS)
- Minimal logging of sensitive data
No method of transmission or storage is 100% secure.
Your Choices & Rights
- Access, export, correct, or delete your data
- Delete your account
- Opt out of non‑essential communications
- Request information about how your data is processed
- Object to certain processing where applicable
To make a request, contact support@storyxi.com. We may verify your identity before fulfilling requests. Some rights may be limited by applicable law or our legitimate interests.
Legal Basis for Processing (EEA/UK)
If you are in the European Economic Area or UK, we process your personal data based on:
- Contract: To provide the Services you request
- Legitimate Interests: Service improvement, security, fraud prevention, and analytics compatible with user expectations
- Consent: For non‑essential cookies, marketing communications, or any processing beyond what's necessary to provide the Services
- Legal Obligations: Tax, accounting, and regulatory requirements
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete personal information (subject to exceptions)
- Right to correct inaccurate personal information
- Right to opt‑out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information (we do not use it for inferring characteristics)
- Right to non‑discrimination for exercising these rights
To exercise these rights, contact support@storyxi.com. Authorized agents may make requests on your behalf where permitted by law.
Cookies & Tracking Technologies
We use cookies and similar tracking technologies to provide and improve our Services:
Essential Cookies
- Authentication cookies: To keep you logged in and secure your account
- Preference cookies: To remember your settings and preferences
Analytics & Performance Cookies
- Google Analytics: We use Google Analytics to understand how visitors use our website, which pages are most popular, and how we can improve the user experience. This includes tracking page views, user interactions, and conversion events.
- Facebook Pixel: We use Facebook Pixel to measure the effectiveness of our advertising campaigns, track conversions from Facebook ads, and create custom audiences for retargeting. This helps us show relevant ads to people who have visited our website.
Third-Party Data Sharing
When you visit our website, the following third parties may collect information about you:
- Google: Through Google Analytics, Google may collect your IP address, browser information, pages visited, and user interactions. See Google's Privacy Policy.
- Meta (Facebook): Through Facebook Pixel, Meta may collect your IP address, browser information, pages visited, and actions taken on our website. See Meta's Privacy Policy.
Facebook Integration & Data Sharing
We have a two-way data relationship with Facebook/Meta for advertising and analytics purposes:
Data We Receive from Facebook
When you click on our Facebook advertisements, Facebook may share the following information with us (subject to your Facebook privacy settings and consent):
- Basic profile information: Name, email address
- Demographic information: Date of birth, gender
- Location information: Country, state/province, city, postal code
- Ad interaction data: Which ad you clicked, when you clicked it
Data We Send to Facebook (Advanced Matching)
We use Facebook's Advanced Matching feature to improve ad attribution and measurement. When you create an account or interact with our website, we may share the following information with Facebook (hashed for privacy protection):
- Email address: Your account email address
- Name: Your first and last name (when provided)
- Location data: Country, state, city, and postal code (automatically detected from your IP address)
- Demographic data: Date of birth and gender (when available from Facebook ad clicks)
How We Use This Information
Information received from Facebook and shared with Facebook is used to:
- Personalize your experience: Customize content and features based on your demographics and interests
- Improve ad targeting: Show you more relevant advertisements
- Measure ad effectiveness: Track which ads lead to sign-ups and conversions
- Prevent fraud: Verify legitimate users and prevent abuse
- Analytics: Understand our user demographics and improve our services
- Retargeting: Show relevant ads to people who have visited our website
Privacy Protection: All data shared with Facebook is hashed (encrypted) before transmission to protect your privacy. We only use this data in accordance with Facebook's terms and your privacy settings.
You can opt out of this data sharing by:
- Adjusting your Facebook Ad Preferences
- Declining cookies when prompted on our website
- Using browser settings to block tracking cookies
Your Cookie Choices
You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our Services. You can also:
International Transfers
Our providers may process data in multiple countries. Your use of the Service may involve transfers of information to countries that may have data protection laws different from those in your jurisdiction.
Data Sharing & Transfers
We do not sell your personal information. We disclose data to providers listed above when needed to perform a feature you use, to comply with law or legal process, or in connection with a corporate transaction as permitted by law.
Children’s Privacy
We recommend that only individuals age 18+ use the Services. We do not verify user age and the Services are not designed for children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, please contact support@storyxi.com so we can delete it.
Data Breaches and Incident Response
In the event of a data breach that may affect your personal information, we will notify you and relevant authorities as required by applicable law. We maintain incident response procedures to address security events promptly.
Automated Decision‑Making
We do not engage in solely automated decision‑making that has legal or similarly significant effects on individuals. Our AI‑assisted features respond to your prompts and settings and are user‑initiated.
Data Protection Officer and Supervisory Authority
For data protection inquiries or complaints in the EEA/UK, you may contact your local supervisory authority. We do not currently have a designated Data Protection Officer but handle privacy matters through support@storyxi.com.
Changes & Contact
We may update this Policy. We will update the “Last updated” date when changes are made. Material changes may be communicated in‑product or by email.
Questions or requests: support@storyxi.com