Privacy — last updated 2026-08-31
How Storgy handles your data
Storgy doesn’t run advertising. The personal data the site touches is the email address you give us if you sign up, what Google Analytics records on every page, what gets stored when you submit a poem to the Analyzer, and billing references when you subscribe. The sections below cover each in plain terms, and the sub-processor list below names every third party that ever sees that data.
Sub-processors
Eight external services process Storgy customer data. Each is listed below with its specific purpose. The same list with direct privacy-policy links lives on the Trust & compliance page. If we add or remove a sub-processor, this list is updated and the date band above is bumped.
- Anthropic — AI model inference for editorial drafts
- OpenAI — Editorial phrasing pass — no customer-submitted text
- Resend — Transactional email and the member email sequence (address, first name, marketing state)
- Paddle — Payment processing (merchant of record, pre-Stripe subscriptions)
- Stripe — Payment processing and tax calculation (current subscriptions)
- Trustpilot — Review invitations for new subscribers (email address, first name, plan tier)
- Hetzner — Application + database hosting (EU)
- Cloudflare — Authoritative DNS + object storage for generated files
Analytics — Google Analytics 4
Storgy runs Google Analytics 4 (GA4). GA4 sets cookies, records the pages you view, and reports an IP-derived approximate location to us in aggregate. Google also processes your IP address as a transit-only signal — they truncate it before it reaches our reports. We use this only to see which pages people read and where readers come from; we don’t sell or share this data.
You can opt out by installing the Google Analytics Opt-out Browser Add-on, by blocking analytics cookies in your browser, or by using any standard tracker-blocking extension. Storgy works fine without GA4.
The Poem Analyzer — what we store
When you submit a poem to the Poem Analyzer, we store four things in our database:
- The poem text you pasted (plus the title and author you optionally provided), so the analysis lives at a permanent shareable URL.
- The Claude-generated analysis, so we don’t pay to regenerate it every time the URL is opened.
- A salted SHA-256 hash of your IP address, kept only for rate-limiting. We never store your raw IP, and the salt means the hash can’t be reversed against a precomputed table.
- A short ID (the part in the URL after
/tools/poem-analyzer/) so the result is reachable.
If you are signed in, the submission is also linked to your account id, so it appears in your own archive and in the data export at /settings/. A submission made while signed out carries no account identifier at all.
Result pages are public — anyone with the URL can see them — so don’t paste anything into a tool that you wouldn’t want read. Saved runs stay private to your profile unless you tick “Share on profile”.
We also use stored submissions internally to test and improve the tools (added 5 August 2026, and it applies to submissions stored before that date). In practice that means re-running a past submission against a changed prompt to check the new version is actually better, and looking at inputs that made a tool fail so we can fix them. It is done by us, on our own systems, and nothing is shown to other users. We do not sell your writing, publish it, or let anyone train models on it — see terms section 04. To opt out, email hello@storgy.com; no account needed, and you don’t have to say why.
Rate limits
The AI tools enforce four limits, all keyed off the salted IP hash described above: a burst limit of ten runs per five minutes, your plan’s credit allowance, a per-IP daily ceiling that applies to anonymous and free accounts only, and a site-wide daily cap that protects us from runaway model costs. The IP hash is held in our cache for the rate-limit window only.
Reading is never rate-limited, and the deterministic tools — the syllable counter, rhyme-scheme finder, citation generator and the rest — carry only a flood guard, since they make no model call.
Third parties that see your data
One external service reads the text you submit to a tool: Anthropic, which runs Claude, the model that produces the analysis. Their privacy policy applies, and their API terms state they don’t train on inputs from API customers by default.
We also use OpenAI, but not on anything you write. It runs a phrasing pass over our own editorial content before we publish it — poem-page study scaffolds, reading guides, and similar. Nothing you paste into a tool, and nothing you write at the Writing Desk, is sent to it.
Anthropic receives the text of that one request — never your IP, your hash, your email, or any other metadata. In a conversation, “that one request” is wider than a single message: if you have switched Remember me across tools on, it also carries the short note we keep about you and a list of your recent results, both described in section 07. With the switch off, neither is sent, and each conversation sees only the page it is on and what you type into it.
One more service stores what you make, without reading it: Cloudflare. When a tool produces a file — a Writing Desk read-aloud recording, or an image or worksheet from the poem tools — the file is kept in Cloudflare R2 object storage. Those files sit in a private bucket, are reachable only through a signed link that expires, are never indexed, and you can delete them. Files made without an account are removed automatically after thirty days. Cloudflare is also our authoritative DNS; no page request, cookie, or account record passes through it.
Resend sends our email, and — since 31 August 2026 — also decides when some of it goes out. When you verify your address, a contact record is created there holding your email address and first name, together with a few markers we write: which version of our welcome sequence you are in, whether you are on a paid plan, and whether you have already been sent the one message in it that mentions price. Those markers exist so the sequence stops at the right moment and never asks you twice. Every one of those emails carries an unsubscribe link, and unsubscribing stops all of them at once.
One thing happens when you subscribe, and only then. The email confirming your subscription is active is blind-copied to Trustpilot, through their Automatic Feedback Service, so that Trustpilot can invite you to review Storgy a few days later. A blind copy is the whole message, so what they receive is your email address, your first name and which plan you bought — nothing you have written, and nothing else from your account. The invitation comes from Trustpilot, not from us, and their privacy terms apply to it. If you have unsubscribed from Storgy emails, your address is not passed on.
Retention and deletion
Submissions to the analyzer are kept indefinitely so the permalinks keep working. If you want a specific submission deleted, email hello@storgy.com with the URL — we’ll remove it. GA4 data is retained per Google’s defaults; you can request its deletion at the same address.
Deleting a submission also removes it from the internal testing described in section 03. You can object to that use on its own, without deleting anything, by emailing the same address — the submission stays, its permalink keeps working, and we stop using it to test the tools. Either way we act on the request rather than asking you to justify it.
Conversations. Every message you send to a reader — on a result page, a study guide, a chapter or scene page, or at the Writing Desk — is stored with its reply, so the conversation is still there when you come back. They are kept until you delete the run they belong to, clear the conversation from its own page, or delete your account. A study guide conversation is cleared from the guide itself.
The note about you. If you switch Remember me across tools on, a model writes one short note about you — up to 1,500 characters of facts drawn from what you have said in your own messages: what you write, what you are studying, what you keep asking about. It is rewritten at most once an hour, it replaces itself rather than accumulating, and it is read by every conversation you have while the switch is on. It never holds an instruction, and it is not allowed to record health, religion, politics, sexuality, ethnicity, immigration status or money, even if you mention them. You can read it, switch it off and delete it at any time on your account page, and it is deleted with your account. One thing worth knowing: a fact already folded into the note stays there when you delete the conversation it came from — “Forget everything” on the account page is what removes it.
Deleting your account. A deletion request marks the account immediately and the records themselves — including your conversations and the note above — are erased at the purge that runs fourteen days later, which is the window in which a deletion can still be undone if you ask us.
One deletion we cannot make for you: once your address has been passed to Trustpilot with a subscription welcome (section 05), it sits in their system and is erased through their own process, set out in their privacy terms. Deleting your Storgy account does not reach it. Email us anyway and we’ll tell you exactly what was sent and when.
Contact
For any privacy or data-protection question — including GDPR access requests from EU readers — email hello@storgy.com. The site is operated by the Storgy editorial team.
Privacy contact
Questions?
hello@storgy.com →