Privacy Policy

Last updated: September 15, 2026

This Privacy Policy explains what information StoryFolder collects, how we use it, who we share it with, and the choices and rights you have. It covers the StoryFolder website, the StoryFolder desktop application, and our related services (together, the "Service").

StoryFolder is operated by Reflx, LLC ("StoryFolder", "we", "us", or "our"), 794 30th Ave N, #1, St. Petersburg, FL 33704, United States. If you have questions, contact us at [email protected].

The short version

A few things we think are worth stating plainly, because they are easy to get wrong:

  • Your video files stay on your computer during import. Importing a video, detecting shots, and transcribing audio all run locally on your device. We do not upload your source video to our servers to import it.
  • We do not sell your content, and we do not train AI models on it.
  • Unpublishing a share link disables it immediately. The URL stops working right away, and re-publishing later creates a brand-new link.
  • Share pages never expose your email address or billing details.
  • Desktop telemetry is content-free. We collect how the app is used, not what is in your projects. The one exception is the names of custom fields you create (never their values).

The rest of this policy is the detail behind those statements.

Information we collect

Information you provide

  • Account details — your name and email address when you create an account.
  • Billing details — when you subscribe, our payment processor (Stripe) collects your name, email, billing address, and payment-card details. We do not store full card numbers on our servers; Stripe handles card data directly.
  • Project content — the storyboards, shot lists, notes, custom fields, titles, and thumbnails you create. Most of this lives in your local app data by default; content you publish or process with cloud features is described below.
  • Support communications — messages you send us, including through our in-app chat.

Information collected automatically

  • Usage and analytics data — pages visited, features used, approximate location derived from IP, device and browser type, and similar diagnostic data.
  • Desktop app telemetry — an install identifier and hardware-derived identifiers, along with app version, operating system, and feature-usage events. This telemetry is content-free (it does not include your video, notes, or project content) but it is linked to your account so we can understand how signed-in users use the app.
  • Custom field names — when you use AI autofill, we record the names and types of the custom fields you have set up (for example, "Location" or "Shot Type"), linked to your account, so we can understand what people use StoryFolder to track. We do not record field options, the values in your fields, your notes, or your images for this purpose. Field names are kept for 2 years.
  • Crash reports — when the desktop app crashes, we collect diagnostic crash data (via Sentry) to fix bugs.
  • Log files — server and application logs, which may include file paths and URLs you imported from (for example a YouTube URL), for debugging and abuse prevention.

Education program applications

If you apply for a student or educator rate, we collect your institution, course, role, and an optional proof document (for example a student or staff ID, an enrolment letter, or a class roster) to verify eligibility. The proof document is stored in a private, encrypted cloud storage bucket that is not publicly accessible, is used only for that verification, and is deleted once a decision is made — approved or rejected — which is at most 30 days after you submit it.

How we use your information

  • To provide, operate, and maintain the Service, including your account and subscription.
  • To process payments and manage billing.
  • To send transactional email (receipts, password resets, account and security notices).
  • To power features you choose to use, including the AI features described below.
  • To understand how the Service is used and to improve it (analytics).
  • To provide customer support.
  • To detect, prevent, and address fraud, abuse, security, and technical issues.
  • To comply with legal obligations and enforce our terms.

Third-party processors and services

We use a number of trusted third parties ("processors") to run the Service. These providers process data on our behalf under their own security and privacy commitments. The main ones are:

Infrastructure, billing, and communications

  • Stripe — payment processing and subscription billing. Receives your name, email, billing address, and payment details. Billing details sync two ways between StoryFolder and Stripe.
  • Amazon Web Services (AWS S3) — cloud storage for shared storyboard images, published audio, backups, and logs.
  • SendGrid — sending transactional email on our behalf.
  • DeepSeek — powers the AI support assistant on our Support page. When you use it, your messages, the help pages it reads, and a summary of your plan, subscription status and activated devices are sent to DeepSeek to generate a reply. Conversations are stored with your account so you can return to them; you can delete them at any time from the Support page.

Analytics and advertising

  • Google Analytics 4 — usage analytics across the web, our servers, and the desktop app. On the web it is keyed to your internal user id when signed in; on our servers events are sent with your user id as the client id; on desktop it is keyed to an install / hardware-derived identifier.
  • Meta Pixel — conversion and advertising measurement on our website, including purchase events and their values.

AI features (when you use them, your footage leaves your device)

StoryFolder's core import — shot detection and transcription — runs locally and does not send your video to us or to any AI provider. Some optional AI features do send content to third-party AI providers to work. When you use them:

  • DeepSeek — AI shot analysis / autofill sends frame images from your video, along with video metadata and your instructions, to generate suggested field values.
  • Azure OpenAI — when you publish, we may send a frame image and the transcript to generate storyboard content.
  • OpenAI — AI field discovery sends your prompt and a schema to propose fields.

These providers process the content to return a result. We do not use your content to train our own models, and we rely on these providers' commitments regarding their handling of API data.

Embedded third-party content

Some pages embed third-party content. When such content loads, the third party may receive the viewer's IP address and similar request data:

  • YouTube and Vimeo — embedded video players on share pages.
  • Google Fonts — web fonts used on our site.

Sharing and publishing storyboards

Unless you publish a share link, only you can see your projects — other users, including people on the same plan or company, cannot. StoryFolder staff do not routinely view your project content; we can technically access data stored on our servers and do so only when needed for support, security, or operating the Service.

When you publish a share link, the content you see in the editor (your display name, storyboard title, notes, custom fields, thumbnails, and any published transcript) is uploaded so viewers with the link can see it. Hidden shots and toggled-off fields are not included.

  • Your email address and billing details are never exposed on a share page.
  • Unpublishing disables the link immediately. Re-publishing later generates a new URL; the old one stays dead.
  • All share pages (paths under /b/) are disallowed to search-engine crawlers in our robots.txt, so compliant crawlers do not index them regardless of the privacy level you choose. Privacy levels (public, private link-only, password-protected) control access expectations, not whether a well-behaved crawler is asked to index the page.

Cookies and similar technologies

Our website uses cookies and similar technologies for essential functionality (keeping you signed in), analytics (Google Analytics 4), and advertising measurement (Meta Pixel). A cookie banner appears on your first visit and lets you accept or decline non-essential cookies. Google Analytics runs in a cookieless mode until you accept analytics cookies; advertising cookies are not set unless you accept them either. We also honour Global Privacy Control: if your browser sends that signal, non-essential cookies stay off without your having to do anything. You can also control cookies through your browser settings. We also set a first-party cookie named sf_attr (and, briefly, sf_attr_raw on our help site) that records which website or campaign referred you; it is kept for 90 days, used only to attribute signups to a marketing channel, and never shared with a third party.

How long we keep your data (retention)

  • Account and project data — kept while your account is active, and deleted when you delete your account (see below).
  • Billing records — retained for approximately 7 years to meet tax and financial-records obligations, even after account deletion.
  • AI usage records — retained on a rolling basis and automatically expired after roughly 400 days.
  • Custom field names — retained on a rolling basis and automatically expired after roughly 2 years.
  • Sessions — kept for the life of the session and expired thereafter.
  • Logs and diagnostics — retained for a limited period for debugging, security, and abuse prevention.

Your rights and choices

Deleting your account

You can request deletion of your account and associated data. We are building a self-serve deletion flow; in the meantime you can request deletion through support. When you delete your account, your account record, projects, notes, and published share links are removed and share URLs stop working immediately. Certain records (notably billing and tax records) are retained for the period described above. See Delete your account for the current process.

If you are in the EEA or UK (GDPR)

You have rights to access, correct, delete, restrict, and port your personal data, and to object to certain processing. Our legal bases for processing are:

  • Performance of a contract — to provide the Service you signed up for (account, projects, billing).
  • Legitimate interests — for product analytics, security, abuse prevention, and licensing/entitlement enforcement, balanced against your rights.
  • Consent — for non-essential web cookies and similar technologies, which you can withdraw at any time.
  • Legal obligation — for retaining billing and tax records.

To exercise any of these rights, contact [email protected]. You also have the right to lodge a complaint with your local data protection authority.

If you are in California (CCPA/CPRA)

You have the right to know what personal information we collect and how we use it, to request access and deletion, to correct inaccurate information, and to be free from discrimination for exercising these rights. We do not sell your content, and we do not sell or "share" your personal information for cross-context behavioral advertising in exchange for money. We honor Global Privacy Control (GPC) signals as an opt-out where applicable.

International data transfers

We are based in the United States, and our processors may be located in the United States and other countries. Where your information is transferred internationally, we rely on appropriate safeguards and the protections offered by our processors.

Security

We use commercially reasonable technical and organizational measures to protect your data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Passwords you set on password-protected share links are stored on our servers so we can check what viewers enter, and are not stored with a one-way hash — a database compromise could expose them. Do not reuse an important password for a share link.

Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will remove it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

Questions about this policy or your data? Contact us:

  • By email: [email protected]
  • By mail: Reflx, LLC, 794 30th Ave N, #1, St. Petersburg, FL 33704, United States