Last updated: December 4, 2024
Summary
We collect only what we need to operate an 18+ interactive-story platform, run analytics, process payments, and send you updates if you opt in. Prompts you type are not stored on our servers, and generated stories become public only when you choose to publish them.
XStory.io
We do not currently have an EU/UK GDPR representative because we do not actively target EU/UK users. If this changes, we will update this section.
The Service is intended only for individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18 or permit under-18 registration. If you believe a minor has provided us personal data, contact us and we will delete it.
| Category | Examples | Collected? | Purpose |
|---|---|---|---|
| Account Identifiers | Email, username, social-login ID | ✔ | Account creation, login, security |
| Payment Information | Tokenized card data via Stripe | ✔ (via Stripe) | Subscription billing |
| Device & Usage Data | IP address, browser type, session data | ✔ (via Analytics) | Service analytics, security |
| Marketing Data | Email preferences, newsletter sign-ups | ✔ (future) | Send updates with consent |
| Cookies / Similar IDs | Session cookies, Google Analytics | ✔ | Remember login, measure traffic |
| Prompt Text | Text you type to instruct AI | ✖ (not stored) | Generate content |
| AI-Generated Content | Stories or images from our model | ✔ (if published) | Display to readers |
| Sensitive Data | Biometric, health, precise location | ✖ | N/A |
We use personal data only when we have a lawful basis (typically contract or consent) and to:
No model training: We do not feed your prompts, usage data, or AI outputs back into model fine-tuning.
We use:
We do not use behavioral advertising or retargeting cookies.
You can manage cookies in your browser settings or via our in-app cookie banner.
We share data only with trusted service providers who process it on our behalf and under confidentiality agreements:
We do not sell or rent your personal data.
| Data type | Retention period |
|---|---|
| Account & billing records | While active + 1 year for compliance |
| Server logs (IP, user-agent) | 30 days rolling |
| Published AI stories & comments | Until deleted by user |
| Backups | Encrypted backups for 6 months |
You may delete your account at any time; deletion is instant in production databases.
We respond to all verified requests within 30 days.
No system is perfect, but we take commercially reasonable measures to protect your data.
We may update this Privacy Policy from time to time. If changes are material, we will notify you by email or in-app banner 30 days before they take effect.
Questions?
Contact Support