Back home

Trust & Privacy

This page is maintained by the Storya team to answer common security and privacy questions about Storya. It describes the controls we have in place today and how responsibility is shared between Storya, our hosting platform, and you. It is editable project content — not an independent certification or audit.

Shared responsibility

Storya runs on the Lovable platform, which provides hosting, the database, authentication, file storage, and the AI gateway. We configure those services and write the application code. You are responsible for the content you upload and for keeping your account credentials private.

Lovable's platform capabilities described below are factual statements about features we have enabled. They are not certifications issued by Lovable or by any third party.

Accounts & authentication

Accounts use email/password and Google sign-in. Passwords are handled by the platform's authentication service and are never stored in plain text by Storya. We do not see your password.

Session tokens are issued by the authentication service and stored in your browser. Signing out from the app revokes the local session.

Your data

Stories, characters, world entries, screenplays, codex entries, franchises and other content you create are stored in the project database and scoped to your account through row-level access rules so other users cannot read or modify them.

Generation requests are sent to the AI gateway to produce the requested text or images and return the result to your project. We do not sell your content.

Third-party services we rely on

Storya uses the Lovable platform for hosting, database, authentication, file storage, the AI gateway, and email delivery for account messages. Payments, when enabled, are processed by our payment provider; Storya does not store full card numbers.

We do not enable additional advertising or analytics SDKs unless we say so on this page.

Retention & deletion

You can delete a project at any time from inside the app. When you delete a project, the associated rows are removed from the database. Account deletion requests can be made through the contact below; deleting your account removes the projects associated with it.

Contact

For security reports, privacy questions, or data requests, please contact the Storya team through the in-app feedback button. We will respond to verified requests as quickly as we can.

This page does not grant or imply any legal warranty, certification, or regulatory compliance statement. For binding terms, see your account agreement.