Privacy policy
Last updated: August 9, 2026
This page describes what Narratomi actually collects and stores: no more, no less. It is written against the code, not against a template.
What we collect
- Account data. Your name, email address, and a hashed password, managed by our authentication layer. That is the whole profile.
- Project and story content. Scripts, scene graphs, assets, and published story bundles. Stored in our Postgres database, S3-compatible object storage, and the real-time collaboration backend that syncs edits between collaborators.
- Billing data. If you buy a paid plan or pack: your plan, a Stripe customer id, and invoice history. Payments are handled by Stripe — your card number never reaches our servers.
We send email for one reason: operating your account. Verification links when you sign up, password-reset links, and project invites. No newsletters, no marketing.
Published stories are public
Publishing a story serves it at a public link to anyone holding the slug, with no sign-in. Do not put anything in a published story you would not hand a stranger. Unpublishing stops the link from serving.
Player saves stay in the browser
People playing a published story get no account and send us nothing. Their progress and saves live in their own browser’s localStorage (the player says so in its UI) and never reach our servers.
No tracking
Our CDN, Cloudflare, injects its Web Analytics beacon into pages. It is cookieless, counts page views in aggregate only, and does not identify or follow you across sites. Beyond that there are no analytics or tracking scripts on Narratomi: no Google Analytics, no PostHog, no Plausible. The only cookie we set is the session cookie that keeps you signed in.
Who processes your data
A small number of service providers process data on our behalf, and data-processing agreements are in place with each:
- Stripe — payments. Receives your name, email, and card details; card numbers are handled entirely by Stripe and we never see them.
- AI provider — the AI co-writer sends your prompts and relevant project context, as described in the terms of service.
- Hosting and storage providers — run the servers, database, and object storage where everything above lives.
Privacy officer
For privacy questions or complaints, email [email protected] — it reaches the person accountable for Narratomi’s handling of personal information.
If a breach of our security safeguards creates a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as the law requires, and we keep records of all such breaches.
Deleting your data
You can delete your account from Settings in the app, which removes your account data. For anything else (questions, deletion requests, or reporting abuse), email [email protected].
Changes
If what the app does changes, this page changes with it. Material changes will be announced in the app or by email.