Overview
StoryNest™ (the “Platform,” “we,” “us”) provides a global storytelling service for readers, writers, creators and publishers. This Privacy Policy explains how we handle information when you use our website, apps, APIs and related services (collectively, the “Services”).
We designed the Services to collect the minimum information necessary to run a safe and reliable platform. Where we can offer a feature without collecting data, we do.
Information we collect
Information you provide
- Account details — name or display handle, email address, password hash, preferred languages.
- Profile content — biography, profile photo, social links, and any content you publish.
- Support & ticket messages — the contents of your communications with us.
- Payment details — processed by our payment providers; we store only tokens and receipts.
Information collected automatically
- Device & log data — IP address, browser type, OS, referring pages, timestamps.
- Usage data — pages visited, chapters read, listening time, search queries (aggregated for analytics).
- Cookies & similar technologies — see the Cookies section.
How we use information
- To provide the Services — deliver stories, save progress, sync across devices.
- To personalise your experience — recommendations, reading lists, language defaults.
- To keep the Platform safe — abuse detection, moderation, fraud prevention.
- To communicate — service notices, safety alerts, and (only with consent) product updates.
- To improve — aggregated analytics on feature performance and content discovery.
- To comply with law — respond to lawful requests and enforce our Terms.
Storage & security
Data is stored in access-controlled, encrypted-at-rest data stores. Traffic is encrypted in transit with TLS 1.2+. Access to production systems is restricted to a small on-call team, logged in a chained audit trail, and reviewed periodically.
No system is perfectly secure, but we work continuously to reduce risk — with independent penetration tests, dependency scans, secret-scanning, RLS-first database policies and BYOK-first AI integrations.
Your rights
- Access & portability — download a copy of your data from Account Settings.
- Correction — update profile fields any time.
- Deletion — request account deletion; we honour it within 30 days, subject to lawful holds.
- Restriction & objection — opt out of non-essential processing.
- Consent withdrawal — from the Consent Center at any time.
- Complaint — file with your local data-protection authority.
Data retention
We keep account data while your account is active and for a limited period after deletion for security, billing reconciliation and legal compliance. Aggregated, non-identifying analytics may be retained longer.
Analytics
We use privacy-respecting analytics to understand which stories, features and languages help readers most. Analytics data is aggregated and does not include the contents of stories you read.
Third-party services
We use vetted providers for hosting, email delivery, payments, error monitoring and (optional) AI. We share the minimum data needed to provide the specific service. A current sub-processor list is available on request from privacy@storynest.com.
International compliance
We honour the principles of the GDPR (EU/UK), India's DPDP Act 2023, CCPA/CPRA (California) and similar frameworks. Where a stricter local rule applies to you, we apply it.
Children's privacy
StoryNest™ offers a dedicated Kids experience with age-gated content, restricted community features and parental controls. Accounts for children under the local age of digital consent require a linked parent account and follow COPPA / DPDP-compliant handling.
Changes to this policy
We may update this policy from time to time. Material changes are notified in-app and by email at least 30 days before they take effect, and past versions are preserved in the Consent Center.
Contact
Privacy questions? privacy@storynest.com. Data-protection officer requests may be sent to the same address.