Skip to content
Storgy
← Help centre

Privacy, data & security

What we collect, what we don't, where it lives, and how to get it back or delete it.

  • What personal data does Storgy collect?

    Four things, and we don't run advertising on any of them:

    • Your email address, if you make an account — plus a handle, and a display name and bio if you add them.
    • Analytics about page visits.
    • What you submit to a tool: the text, the result, a hashed form of your IP address for rate limiting, and a short ID for the result URL.
    • Billing references if you subscribe. Card details are held by the payment provider, never by us.

    Your IP address is never stored in the clear against a submission — only a salted one-way hash of it, which exists purely to enforce rate limits.

    See alsoThe full privacy notice

  • What cookies and trackers do you use?

    Two third-party analytics tools run on the public site:

    • Google Analytics 4, for page and traffic measurement.
    • The Meta pixel, used to measure advertising we've run.

    Storgy's own cookies are functional rather than advertising ones:

    • Your session, if you're signed in.
    • A marker for your one free anonymous AI run, and another for the free anonymous study-sheet download.
    • A first-touch record of how you arrived, so we know which pages bring readers in.
    • A referral code, if you followed someone's referral link.

    You can block all of the analytics — with a tracker-blocking extension, by blocking analytics cookies, or with Google's own opt-out add-on. Storgy works fine without them.

    Both analytics loaders are switched off entirely on pages reached by a secret link, such as a shared draft — on those pages the URL itself is the credential, and it should not be reported to anyone.

    See alsoThe full privacy notice

  • Do you sell my data or train AI on what I write?

    No to both. We don't sell or share analytics data, and we don't sell your text, publish it elsewhere, or use it to train AI models — ours or anyone else's.

    Text you submit goes to Anthropic's Claude to produce the result you asked for. Under their API terms that input is excluded from training by default, and we don't reuse it for training on our side either.

    What you write stays yours. We take only the narrow licence needed to store it, process that one request, and show you the result.

    See alsoTrust & AI policy

  • Which companies process data on your behalf?

    Seven, each listed at /trust/ with what it does and a link to its own privacy policy: Anthropic and OpenAI (AI processing), Resend (transactional email), Stripe and Paddle (payments), Hetzner (hosting), and Cloudflare (DNS).

    Cloudflare is authoritative DNS only. No request, cookie, or customer record passes through it.

    See alsoThe sub-processor list

  • Where is my data stored, and how is it protected?

    In Germany. Postgres on a Hetzner server in Falkenstein, on an encrypted filesystem, with backups encrypted before they leave the machine. Traffic is TLS 1.3, terminated once at that origin — there's no CDN edge and no third-party firewall in the path.

    See alsoSecurity disclosures

  • Do you hold SOC 2 or ISO 27001?

    No — and we'd rather say so plainly than let a procurement process discover it. There is no SOC 2 Type I or Type II, no ISO 27001, and no commissioned third-party penetration test. If your district requires SOC 2 as a hard prerequisite, we are not yet a fit.

    What we do have: EU data residency under GDPR, an SDPC National Data Privacy Agreement we'll counter-sign on request, a published sub-processor list, a vulnerability-disclosure policy with stated timelines, and OWASP ASVS Level 1 controls followed internally without external attestation.

    See alsoSecurity disclosuresTrust & compliance

  • How do I export or delete my data?

    Export: /settings/ → Your data → "Download my data (JSON)". One export per hour. It contains your account fields and every saved tool run.

    Delete everything: /settings/ → Danger zone. Your account enters a deletion-pending state immediately and is permanently erased fourteen days later, along with every saved tool run. There's no self-serve undo — email us inside those fourteen days if you change your mind.

    Delete one thing: to take down a single tool result, email hello@storgy.com with its URL. Analyzer submissions are otherwise kept so their permalinks keep working.

    See alsoAccount settingsMore on deleting an account

  • Who do I contact about privacy, GDPR, or a security issue?

    • Privacy questions and GDPR access requests — hello@storgy.com.
    • A counter-signed SDPC National DPA for a school or district — privacy@storgy.com.
    • A security vulnerability — security@storgy.com. An encryption key for the report is available on request.

    For security reports we commit to acknowledging within five business days, and to a fix or coordinated public disclosure within ninety. Good-faith research has safe harbour: don't exfiltrate user data, don't pivot to other systems, don't extort, and we won't come after you.

    A confirmed personal-data breach is reported to the lead supervisory authority within 72 hours, with affected schools and users emailed in the same window where the risk is material.

    See alsoAll contact addressesFull disclosure policy

  • Is Storgy suitable for under-16s?

    The corpus is classic literature and the tools are study instruments, so the content is classroom-appropriate — but an account needs a working email address the holder controls, and we don't provide student-account provisioning or parental-consent flows.

    In practice, classes use Storgy without accounts: reading, the deterministic tools, and the published question sets require none. That's the route we'd recommend for younger pupils.

    See alsoCompliance for schools

Still stuck

Didn't find it?

The help centre covers what we get asked most. Anything else — a billing problem, a bug, a poem we've got wrong — goes to a person, who answers within a day.

Privacy, data & security — Storgy Help · Storgy