Legal
What we collect, where it goes, how long we keep it, and what we do not do with it.
Effective · operated by SMADA WORKS LLC
This policy describes how StoryDirector handles information when you visit our site, create an account, and use the product to turn written stories into cinematic direction and generated video. It applies to the StoryDirector web application and marketing site.
When you create an account we collect:
We ask for an email address so we can verify your account and send you password resets and service messages. We do not run marketing email campaigns.
Using the product means putting creative material into it. That includes:
Uploading a photograph of a person or an image you did not create requires you to confirm that you hold the necessary rights. We record that confirmation with the upload: the version of the confirmation text you agreed to, the time, your IP address at the moment of upload, and the original filename. We keep that record so there is a durable answer to who affirmed what, and when. Removing or replacing an image later does not erase the historical confirmation record.
StoryDirector is built on third-party AI providers. To give you the product at all, we send your material to them:
We name categories rather than individual models here on purpose: which model runs a given shot is configurable and changes as models improve, and a list of names on this page would be wrong within weeks. What does not change is the shape of it — your creative material leaves our systems and is processed by AI providers under their own terms.
Where a provider's API supports it, we ask that the exchange not be retained on their side: our story-analysis and direction requests are sent with server-side storage switched off. We want to be precise rather than flattering about this — that flag is set on those requests, and it is not set on every model call the engine makes. We do not have a zero-retention or no-training contract in place with our providers, and we do not claim one.
Every render writes a receipt: which provider and model ran, the exact prompt text we sent, the request we made, the provider's response, and any error it returned, along with identifiers linking it to your story and shot. This is the provenance ledger that makes the engine auditable — it is how a result can be traced back to the inputs that produced it, and how we investigate a bad or failed generation.
We keep these records for as long as the account exists. No automatic expiry is applied to them today.
Uploaded and generated images and video are stored in cloud object storage and served through a content delivery network.
Please read this part carefully. Those files are stored as publicly readable objects at long, randomly generated URLs. The URL is not guessable and is not listed or indexed anywhere by us, but anyone who has the URL can open the file without signing in. That is true of generated shots, of set images, of uploaded final cuts, and of identity reference photographs. If you are uploading a photograph of another person, this is the fact to weigh before you do.
Payments are handled by Stripe. Checkout and billing management happen on Stripe's own pages, not ours.
Card details never reach our servers. What we store is an identifier that lets us recognise your Stripe customer record, plus the subscription and credit events Stripe reports back to us so your plan and balance are correct.
Nothing you make is public unless you make it public. There are two ways to do that, and both are off by default:
Visitors can rate published films. When someone rates a film we store a salted, irreversible hash of their IP address as an abuse signal — we do not store the raw IP address for ratings — along with an anonymous token in a cookie so the same visitor is not counted twice.
Our staff can review content submitted to the Creator Showcase, because moderating a public gallery requires looking at what is in it. Staff can also access account and story records through internal consoles when operating the service — investigating a failed render, resolving a billing problem, or responding to a support request.
We set the following cookies:
We also use Google Analytics on our site to understand how pages are used and which parts of the product people reach. Google Analytics sets its own cookies and receives usage data, including your IP address, under Google's terms. Our pages also load fonts from Google's font service, which likewise sees the request.
That is the whole list. To be specific about what we do not do: we do not run advertising on this product, we do not use advertising or retargeting networks, we do not work with data brokers, and we do not sell your personal information.
Our servers keep operational logs so we can run and debug the service. These record events such as sign-ins, renders dispatched, credits debited and refunded, moderation actions, and errors, together with the account and story identifiers involved. Passwords are stored only as hashes and are never logged.
While your account is active, we keep your account, your stories, your uploads and your generation records so the product works.
If a subscription lapses, your account moves through a defined sequence rather than disappearing. It first enters a grace period, and then a retention period, each of which runs for thirty days. After those windows pass without the account returning to good standing, an automated nightly process archives your content: your stories, scenes, characters, cast permissions, style boards, projects and story image records are copied to cold storage and removed from the live tables. Archived content is not lost — it can be restored if your account becomes active again.
When content is archived we record a date after which it becomes eligible for permanent deletion. We want to be straightforward that eligibility is not the same as deletion: we mark the date, and we have not built an automated process that erases archived data when it arrives. If you want your archived content actually deleted, ask us and we will do it.
Export. You can export a story's assets from the product as a zip file containing its storyboard and images, and you can export its video prompts. These are per-story tools for your creative work; we do not currently offer a single download of everything associated with your account. Ask us and we will put it together for you.
Deletion. You can delete your account from your profile settings. It requires your password, and it is immediate and permanent — there is no undo and no recovery window. Deleting your account removes your account record and the associated records that hang off it, including your stories, cast permissions, projects, credit history and purchase history.
Two honest limits on that. Files already written to object storage are not removed by the account-deletion process, and content that was previously archived to cold storage is not covered by it either. If you want those deleted as well, email us and we will handle it directly. We would rather tell you this plainly than let you assume a delete button reaches further than it does.
StoryDirector is not intended for children under 13, and you may not create an account if you are under 13. We do not knowingly collect information from children under 13. If you believe a child under 13 has created an account, contact us and we will remove it.
Separately, and regardless of your own age: you may not upload a photograph of a minor as an identity reference, or use the product to generate a recognisable minor.
We may update this document as the product changes. When we do, we revise the effective date shown above. If a change materially affects how we handle your information or what you agree to, we will give notice through the service or by email before it takes effect. Continuing to use StoryDirector after a change takes effect means the updated version applies to you.
StoryDirector is operated by SMADA WORKS LLC. Questions about this document, requests about your information, and reports of misuse all go to support@storydirector.ai.
Your use of StoryDirector is also governed by our Terms of Service.