Privacy Policy

Last updated: September 28, 2026

Intostory (“we”, “us”) makes an app for iPhone and Android that turns your prompts into narrated, illustrated stories, and this website. This policy explains what personal information we collect, why, who helps us process it, how long we keep it, and the choices you have. If anything is unclear, email support@intostory.app.

The short version

What we collect

Information you give us

Information created when you use Intostory

On this website

The website does not use advertising or tracking cookies. Our host records standard request logs (IP address, browser, pages requested). When you report a shared story, we receive the reason and any details you type, plus your IP address to prevent abuse.

How we use it

Where the GDPR or UK GDPR applies, our legal bases are: performing our contract with you (making and delivering your stories, purchases), our legitimate interests (safety, security, fraud prevention, improving the service), your consent where we ask for it (push notifications, analytics where required), and legal obligations.

AI processing

Intostory stories, narration and illustrations are generated by artificial intelligence. To make a story, your prompt and settings are sent to an AI text provider that writes the script, the script is sent to a text-to-speech provider, and scene descriptions (and, for saved characters, their reference pictures) are sent to an image provider. Prompts and stories also pass through automated safety checks. If one provider is unavailable we may use another from the list below for the same step.

We do not use your stories to train AI models ourselves. We use these providers under their paid business API terms, and where a provider offers a setting that keeps API content out of model training, we turn it on. Each provider handles your content under its own terms, which may let it keep inputs for a limited time for abuse monitoring.

Please don’t put sensitive personal information (such as health details or information about other real people) in prompts.

Who we share it with

We share personal information only with service providers who process it for us under contract, as described here, and when the law requires it. We don’t sell or rent personal information, and we don’t share it for cross-context behavioural advertising.

ProviderWhat forData involved
SupabaseAccounts and sign-in, database, file storage, realtime updates, API functionsAccount data, your stories and files, purchases status, support tickets
RailwayRuns the service that writes, narrates and illustrates storiesPrompts, story settings and generated content while a story is made
VercelHosts this website and public share pagesPage requests (IP address, browser), shared stories
Google (Gemini API)Writes story scripts; safety classification; illustrations (backup)Prompts, character and series descriptions, scripts, image prompts
OpenAISafety checks on prompts and stories; backup script writingPrompts, scripts
Groq, OpenRouterBackup script writing when the main provider is unavailablePrompts, scripts
Inworld, ElevenLabsNarration (text to speech)Story text to be read aloud
fal, ReplicateIllustrationsImage prompts; reference pictures of saved characters
RevenueCatIn-app purchases and subscription statusYour account ID, purchase and subscription events (no card details)
Apple, Google (App Store, Google Play)Payments, refunds; device checks (App Attest, DeviceCheck, Play Integrity)Purchase records; device attestation results
Firebase (Google)Push notifications (Cloud Messaging) and App CheckDevice push token, app instance attestation
ResendSign-in codes and service emails, support repliesEmail address, email content
SentryCrash and error reportsDevice and app details, error traces (no prompts, no email)
PostHogProduct analyticsPseudonymous account ID, in-app events, device and app details

Share pages. When you share a story, anyone with its link can listen to it and see its title, summary and illustrations. The page doesn’t show your name or email. You can stop sharing at any time.

If Intostory is ever sold or merged, personal information may transfer to the new owner under this policy. We may disclose information when required by law or to protect people’s safety.

How long we keep it

When you delete your account, see Delete your account for exactly what is removed and what is kept.

Your choices and rights

Depending on where you live (for example the EEA, the UK or California), you may have further rights, such as to restrict processing, to data portability, to know what we collect, and not to be discriminated against for using these rights. You can also complain to your local data protection authority. We will verify requests using the email address on your account.

International transfers

Intostory runs on servers in the United States, and some providers process data in other countries. Where data leaves the EEA or the UK, we rely on safeguards such as the European Commission’s Standard Contractual Clauses.

Age limit

Intostory is for people aged 16 and over, and is not directed at children. We don’t knowingly collect information from anyone under 16; if we learn that we have, we delete the account. If you believe a child is using Intostory, email us.

Security

We protect data in transit with encryption, restrict access to it inside our systems, and keep payment details out of our systems entirely. No service is perfectly secure; if a breach affects you we will tell you as the law requires.

Changes

We will update this page when our practices change and change the date above. For significant changes we will tell you in the app or by email.

Contact

Questions or requests: support@intostory.app.