Story Atlas AI Studio

Privacy

How Story Atlas AI Studio handles your information. Last updated 9 October 2026.

This notice covers accounts in Story Atlas AI Studio, the work in them, payments, and product news you ask for. The public pages of our site count visits with analytics of their own; that, and the production company's project form, are covered by the website privacy notice, where you can also turn that measurement off.

Who we are

Story Atlas LLC runs Story Atlas AI Studio and decides how your personal information is used. Write to andrew@storyatlasstudio.com about anything on this page. Our representatives for people in the EU and the UK are being appointed; their details will be added here.

Your organization's work (scripts, boards, pictures, renders) belongs to your organization. For that work we act on the organization's behalf.

What we collect

Your account. Your name, email address, sign-in method, and two-factor setting. If you tell us how you found us, or arrive from a link that says, we keep that too.

What you agreed to. The words you agreed to, their version and the time: the Terms of Service, the confirmation that you have the rights to what you upload, the confirmation that people in a picture agreed to their likeness being used, and an authorization to charge a saved card automatically, with its amounts.

Your work. What you and your organization put in or make: scripts, boards, prompts, reference images, stills, renders, notes.

What the jobs were. For every paid job: which model ran it, what it cost, how it ended, and how long it took.

How the planner is used. Counted in our own database, never by an outside analytics company: which tools are opened, when a take is kept, page speed, errors. These records carry no content (no prompt, script, file name or search), only short codes and numbers, and your country (never your city).

Security records. Sign-ins and security events, with the address and the city they came from. An organization's record also notes what happened to its work and who did it: a project made, archived or deleted, a script brought in, an LLM connected, and the email address an invitation was sent to. Its owner and managers can read it.

Payments. What you added and spent, and any refund you asked for. Full card numbers and security codes go directly to Stripe. We receive limited card information from Stripe: the card's brand and its last four digits.

Reports and safety. A report or a removal request you send us, with the contact details you give. A request our automated check stopped (below), with the account, name, email and IP address it came from. A copyright notice about something in your organization, and what we did.

Product news you ask for on our site. If you type your email address into the product news form on our site: the address, when and on which page you gave it, the words you were shown, and the IP address the request came from. The IP address is kept only as proof that the request was made. You do not need an account, and we ask for nothing else.

AI that reads your work

The engines you choose. A still, a render or an upscale sends its prompt and the pictures or clips it uses to the engine you picked, listed below. Each sees only what that job needs.

Your script. Three things read it. When a project's first script arrives, Claude (Anthropic) reads its title and opening pages to fill in the project's name, format, look and cover idea. When you run a breakdown, the script's text is sent to Claude to find the cast, places and props. When you ask for a shot list or a review of a sequence, the scene and the compiled prompt are sent to Claude or to OpenAI. Claude also names downloaded files from their prompts.

A check before anything is made. Before a picture or a video is made, its prompt is read by an automated check (Jev, by TypeSafe). It looks for one thing it must stop, sexual content involving anyone under 18, and, for video, for what a video model is likely to refuse, such as someone else's character or a real, well-known person. That second kind is only a warning, and the choice to send it is yours. If the check cannot be reached, the request goes ahead without it, and the AI companies' own filters still apply. A flag by the check is not a finding that anyone broke the law; a person decides, and you can write to us if you think a request was stopped by mistake.

Faces. A video model may refuse a picture because it takes the face in it for a real person. So that the render can be made, that picture is then registered with the video model's maker (BytePlus): a picture made here from words is registered as it is; an uploaded one, or one made from an upload, only after you confirm that the person agreed. It is removed from there when the last organization that uses it is deleted.

An assistant you connect. If you connect an AI assistant such as Claude or ChatGPT to the planner, it can read and change the projects you let it reach, and anything it does is done for you, under its maker's own terms. What it reads is then with that company, under your agreement with it, not ours. It can never make a paid job without your approval. Its messages in the project chat are kept with the project, and the organization's security record notes when it was used and what it wrote. Disconnect it any time under Organizations, MCP.

Training. Story Atlas does not train AI models on your content. We reach each AI company below through its paid business service, set so that what we send is not used to train its generative models. Each may keep what it is sent for a time to check for abuse, and longer where its own safety checks flag something or the law requires it. As each one published it on 8 October 2026:

OpenAIUp to 30 days, to check for abuse. Longer only where the law requires it.
AnthropicUp to 30 days. What its safety checks flag: up to 2 years, and the scores those checks give up to 7 years.
Google55 days, to check for abuse. It may use what it logs for those checks to improve the checks themselves.
BytePlusWhat its safety filter flags: 180 days. A face registered with it stays until it is removed (we remove it when the organization or the person is deleted).
TypeSafeAs long as it needs to run its service. It says it does not train on what it is sent.
Tencent CloudThe clip, while it is upscaled.

Why, and on what basis

To provide the planner (our contract with you): your account, your work, generating what you ask for, billing.

To keep it safe and working (our legitimate interest): security records, error reports, abuse prevention, the usage counts that tell us what to fix.

Because the law requires it: payment records for tax, acting on reports and legal notices, and answering lawful requests.

Because you asked (your consent): product news by email, about new models, price changes and what is new. It is sent only if you tick the box when you start or switch it on in Your account, and you can switch it off there at any time. Sign-in codes, receipts and invitations are sent either way, because the service does not work without them.

You can also ask for product news on our site, without an account. We then keep your email address, when and where you gave it, and the IP address of the request as proof that it was made. We send one email to that address asking you to confirm, and you are on the list only after you confirm from your own inbox. A request that is not confirmed is deleted after 30 days. Every news email has an unsubscribe link that works in one press, without signing in; if you have an account you can also switch product news off in Your account. Either way it stops at once. We keep an unsubscribed address, marked as unsubscribed, so that we never write to it again by mistake.

Cookies and analytics

The planner uses no advertising cookies and no third-party analytics scripts. When you open a payment form, Stripe loads its payment components to take the payment, and they set Stripe's own cookies. This is everything the planner keeps in your browser:

NameForYour browser keeps itOur server honours itKind
__Host-planner_sessionKeeps you signed in12 hours. On a device you asked us to remember: up to 400 days12 hours. On a remembered device: 30 days after you last used itNeeded
planner_pendingCarries a second sign-in step (your two-factor code) through Google's sign-in5 minutes5 minutesNeeded
planner_pkceProves that the answer from Google's sign-in belongs to the request you made10 minutesUsed onceNeeded
pl-themeRemembers light or dark1 yearNot kept by the serverPreference
Browser storage (names beginning pl-)How you left the screen: a list or a grid, the size of a window, notices you closed. Kept in your browser and never sent to usUntil you clear itNever sentPreference
Stripe's own cookiesSet by Stripe when you open a payment form, to take the payment and prevent fraudAs Stripe's notice saysStripe's, not oursStripe's

Turning analytics off. In Your account, switch off product analytics: we stop counting what you do from that moment, and delete what was already counted. If that deletion cannot be done at once, the page tells you, and it is tried again each night until it is done. If your browser sends a Global Privacy Control signal, we count nothing new from that browser; to have earlier counts deleted too, use the switch. Security records and the record of paid jobs are kept either way: they are needed to run and bill the service. We do not answer the older Do Not Track signal, and we do not sell your information or share it for advertising.

Who else processes it

These companies process information for us, only to do their part:

CompanyForWhat it getsWhere we send itWhere it may also go
VercelHosting the plannerRequests, addresses in short-lived logsUSAIts network worldwide, to deliver pages
SupabaseDatabase and sign-inAccounts, projects, logsUSA
Cloudflare (R2)File storageStills, renders, uploadsCloudflare's networkNot held to one country
ResendSign-in codes, notices and product news by emailEmail addressUSA
SentryServer error reportsError details, no request bodies or cookiesUSA
StripePayments (US customers)Payment and billing detailsUSAOther countries where Stripe operates
BytePlusVideo (Seedance) and images (Seedream)Prompts, reference images and clips, registered facesSingaporeMalaysia, Indonesia and the EU; what its safety filter flags is kept in Malaysia
OpenAIImage generation, prompt reviewPrompts, reference imagesUSA
GoogleImage and video generation; Drive export when switched onPrompts, reference images, exported filesUSABriefly, other countries where Google has facilities
AnthropicA script's first read and its breakdown, shot lists, file names, and a check of a video prompt when the main check is unavailableScript text, promptsUSA
TypeSafeA check of a prompt before a picture or a video is madePromptsUSA
Tencent CloudVideo upscalingClips sent for upscalingUSA
AtlasCloudOlder renders only, kept playablePrompts, reference images and clipsTo be confirmed
MuApiOlder renders only, kept playablePrompts, reference imagesTo be confirmed

The AI providers receive your prompts and reference images only to make the still, render or text you asked for. “Where we send it” is the region of the service we call. “Where it may also go” is what that company's own terms say about other places it may process it; empty means it names none that we know of. Most of this processing happens in the United States; transfers from the EU and UK rely on the providers' data processing terms and standard contractual clauses.

Who in your organization can see what

Owners and managers can open every project in the organization. Members and viewers can open the projects they are given, and their own loose work. A role decides what each person may change, generate or spend.

Who at Story Atlas can see what

The people who run the platform see who is in an organization, counts, money, timings and error codes. They do not see your scripts, boards, prompts or files, with three exceptions, below. If you need help with something only visible inside your organization, its owner can let support in for 24 hours from the organization's settings, and take it back at any time. Support then also sees the names of your projects and how many sequences each has, not what is in them.

Only for a legal obligation or a safety case (such as a report of abuse) can the owner of the platform give itself that same view without being asked, for four hours. It is written in the organization's security record as emergency access by Story Atlas, where the organization's owner and managers can see it.

The first exception. When the check stops a request as sexual content involving someone under 18, nothing is made. The words of that request, the account that sent it and the time are kept, and the owner of the platform reads them to decide what it was. If it breaks the law or our terms, we can suspend or close the account and report it to law enforcement or to the National Center for Missing & Exploited Children. Nothing else you write is read this way.

The second exception. When someone reports a file, asks us to remove an intimate picture of them, or sends a copyright notice, the person who decides may open that one file to see whether it must be removed. Each time is written in the organization's security record.

The third exception. When you ask us for a copy of your data, the person who prepares the file can see what is in it, and it lists the prompts of your stills and renders.

How long we keep it

Boards, scripts, assets, stills, rendersWhile the organization exists
Prompts on each generationWhile the organization exists
Sign-in sessions (address, browser)90 days after they end
Security log12 months with address and city, then without. The entries can still be tied to an account by its number
Product analytics events13 months, then daily totals only
Money ledger, receipts and refund requests7 years (tax and accounting), name removed on account deletion. Stripe keeps its own payment records under its own notice
What you agreed to (the Terms, upload rights, likeness rights, an auto top-up authorization): the words, the version and the timeWhile the account exists, and after it is deleted, as proof of the agreement
Operators' log3 years
Product news asked for on our site, not confirmed (the email address, when and where it was given, the IP address of the request)30 days, then deleted
Product news asked for on our site, confirmed (the same, and when it was confirmed)While you are on the list
An unsubscribed address, with the record of the request and when it was unsubscribedKept so we never write to it again by mistake, until you ask us to delete it
A request blocked as sexual content involving a minor (its words, the account, the name, email and IP address, the time)While it is reviewed. One cleared as a mistake is deleted with the account. Otherwise for as long as the law requires or we need it to act on it, and it is kept if the account is deleted
A report or a removal request (what was reported, what we did, and the contact details you gave)Kept as the record of what we did. Ask us to delete the contact details you gave
A file removed after a report or a copyright noticeHeld where nothing can open it for 30 days (90 for a copyright notice, and longer while a counter-notice is open), then deleted. One that may show a minor is kept for as long as the law requires
Server error reports (Sentry)30 days
Backups30 days. Something you delete leaves our backups within 30 days more, and a restored backup has it deleted again

Your rights

A copy of your data. Your account, Download my data: a file of the records we hold about you. It has your account and what you agreed to, your sign-ins and activity, what you added and spent, the jobs you ran with their prompts, and your reports and requests. If any part could not be read, the file says which. Your original pictures and clips are not in it: download those from the planner. Records about other people are left out. For anything you think is missing, write to andrew@storyatlasstudio.com.

Deleting your account. Your account, Delete my account. We do it within 30 days, and the request is not closed until every part is done: your files, your records, your sign-in, your place on the news list, and faces registered for you with a video model's maker. An organization only you are in is deleted with everything in it. An organization you own together with others needs a new owner first. Work you made in an organization that belongs to others stays with them, without your name. We email you when it is done. Download what you want to keep first: deletion cannot be undone.

What stays after deletion. Money records and refund requests, for tax, without your name. What you agreed to, as proof of the agreement. The security log, without addresses. A request stopped as sexual content involving a minor that is open or was upheld, a report, or a file held because of a report or a legal notice. Copies in backups: something deleted may stay in our restricted backups for up to 30 more days. We do not put it back into use, and if we ever restore a backup we delete it again.

Refunds. If you own the organization, ask in Billing for a refund of the unused funds it paid for before you delete it. A request that is still open is kept, and settled, if the organization is deleted. Where the law gives you a right to a refund, you have it.

Product news asked for on our site. Unsubscribe with the link in any news email. To have the address and everything kept with it deleted, write to andrew@storyatlasstudio.com.

Correcting it, objecting, or asking what we hold: write to andrew@storyatlasstudio.com. We answer within a month.

You may also complain to your data protection authority.

AI-generated pictures and video

What the planner makes is generated by AI. We keep the provenance marks that the AI companies put in the original files they give us, and we add a machine-readable mark of AI origin to the composite sheets we build ourselves. Smaller copies made for preview, and upscaled copies, may not carry those marks. Labelling rules depend on how and where you publish the work.

Age

Story Atlas AI Studio is for people 18 and over.

Reporting content

To report content made or shared with the planner (including intimate images shared without consent), use the report form or write to andrew@storyatlasstudio.com. If you ask us to remove an intimate picture of you that was made or shared without your consent, we remove it as soon as we can, and within 48 hours of a valid request, together with identical copies of it that we know we hold. Copyright notices go to the agent named in our Copyright Policy.