Privacy Policy
Last updated: February 2026 · Version 2026-02
1. Controller
Story Forge (operated by Woodside Ventures — see Impressum for full contact details) is the controller responsible for processing your personal data under the EU General Data Protection Regulation (GDPR / DSGVO).
2. Data we collect
Account data: email address, display name, and a bcrypt-hashed password (we never store plaintext passwords). Content data: feature descriptions you submit and the user stories generated from them. Payment data: order ID, payment ID, plan, and amount — processed by Razorpay; we never see or store your card details. Contact inquiries: name, email, and message when you use the contact form. Technical data: IP address in short-lived rate-limiting and brute-force protection records (auto-deleted after 30 minutes).
3. Purposes & legal bases
Providing the service, generating stories, and managing your subscription — Art. 6(1)(b) GDPR (contract). Sending verification, password-reset, and payment-receipt emails — Art. 6(1)(b). Security measures such as login lockouts and rate limiting — Art. 6(1)(f) (legitimate interest). Marketing consent, where given, is based on Art. 6(1)(a) and can be withdrawn at any time.
4. AI processing
Feature descriptions you submit are transmitted to AI model providers (OpenAI, Anthropic) to generate user stories. Do not include personal data of third parties in your feature descriptions. Generated stories are stored in your account until you delete them or your account.
5. Processors & third parties
Razorpay (payment processing), Hostinger (transactional email delivery), OpenAI / Anthropic (AI story generation), Atlassian Jira (only when you actively connect your own Jira workspace — your Jira API token is encrypted at rest with AES-128 Fernet encryption). Data may be processed outside the EEA; where this occurs, it is safeguarded by EU Standard Contractual Clauses of the respective providers.
6. Cookies & local storage
We do not use tracking or advertising cookies. We use only technically necessary storage (§25(2) TTDSG): a session login token (sessionStorage, deleted when the tab closes) and your dismissal of the storage notice (localStorage). No consent is legally required for strictly necessary storage; we display a notice for transparency.
7. Security
TLS encryption in transit (HSTS enforced), bcrypt password hashing, encryption at rest for connected API tokens, brute-force login lockouts, rate limiting, single-use time-limited email tokens, and OWASP-recommended security headers (CSP, X-Frame-Options, and others).
8. Retention
Account and content data are stored until you delete them or your account. Payment records are retained in anonymized form for up to 10 years to satisfy statutory bookkeeping obligations (§147 AO, GoBD). Security logs (login attempts) auto-delete after 30 minutes.
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17 — use "Delete account" in your Profile), restriction (Art. 18), data portability (Art. 20 — use "Download my data" in your Profile), and objection (Art. 21). You may lodge a complaint with a supervisory authority, e.g. the data protection authority of your German federal state (Landesdatenschutzbeauftragte).
10. Contact
For privacy requests, contact us via the contact form or the address in the Impressum. We respond within one month as required by Art. 12(3) GDPR.