Storyline

Storyline Studio Privacy Policy

Last updated July 21, 2026


Introduction

Storyline Studio (“the Platform,” available at storylinestudio.app) is Storyline Strategies, LLC’s secure platform for delivering research deliverables to our clients. This policy explains what information the Platform processes, how we use and protect it, and the choices you have.

This policy covers the Platform only. Our general website has its own privacy policy at storylinestrategies.com/privacy.

Who we are

The Platform is operated by Storyline Strategies, LLC (“Storyline,” “we,” “us”). Contact: info@storylinestrategies.com · PO Box 74, Union Hall, VA 24176.

For research content our clients entrust to the Platform, we generally act as a service provider/processor on the client’s behalf under our engagement agreement with that client; for the account and usage information described below, we act as the controller.

Information we process

Account information (from Google Sign-In). Access to the Platform is by individual invitation or approved organization membership only — there is no self-registration and there are no passwords. When you sign in with your Google account, we receive your basic Google profile information: your name, email address, and profile photo. Section 4 describes exactly how this Google user data is used.

Access and activity records. For security and accountability, the Platform keeps an audit log of security-relevant activity — sign-ins, invitations, access changes, and content publication and delivery events. Audit records identify the account and action involved; they do not contain research content, files, or credentials. Our hosting providers also generate routine technical logs (such as IP address, browser type, and timestamps) needed to operate and secure the service.

Research content. The heart of the Platform is confidential research material prepared under client engagements — today, aggregate research data and interactive deliverables; over time this may include additional deliverable types and related materials (for example analyses, reports, transcripts, or multimedia content). Research content is processed on the instructions of the client engagement it belongs to and is accessible only to individually authorized users (Section 6). Where research content ever includes personal data, its collection and use are governed by the applicable engagement agreement and research consents, and we process it only to provide the contracted services.

Communications. If you contact us for support, we keep the correspondence.

Google user data

This section describes our use of information received from Google APIs, as required by the Google API Services User Data Policy.

  • What we access: your basic profile information only — name, email address, and profile photo — through Google Sign-In (OAuth). We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google service data.
  • How we use it: solely to authenticate you, to match your verified email address against your invitation or approved organization, to display who is signed in, and to attribute actions in the audit log.
  • What we never do with it: we do not sell it; we do not use it for advertising; we do not transfer it to third parties except the subprocessors that host the Platform (Section 7), as required by law, or as part of a merger or acquisition with equivalent protections; we do not use it to train machine-learning models; and humans do not read it except for security, compliance, or support with your permission.

Storyline Studio’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

We use the information above to: operate the Platform and deliver research content to authorized users; decide and enforce who may access what (invitations, organization membership, per-project permissions); secure the service and investigate suspicious activity; maintain the audit trail our clients rely on; provide support; and comply with legal obligations. We do not sell personal information and we do not use Platform information for advertising.

How access to research content works

  • Access is by named, individual invitation or approved organization membership, matched to your exact email address.
  • Every request is authorized on our servers against current permissions — possession of a link is never enough — and the database enforces access rules independently as a second layer.
  • Client separation is engineered and tested: users of one client organization cannot reach another organization’s content.
  • Access can be revoked at any time and takes effect on the next request. When someone leaves their organization, their ability to sign in ends with their Google account, and Storyline additionally suspends platform access as part of offboarding.

Sharing and subprocessors

We share information only with the service providers that host and operate the Platform, each bound by appropriate agreements:

ProviderRole
SupabaseDatabase, file storage, and authentication infrastructure (SOC 2 Type II, ISO 27001)
VercelApplication hosting and delivery (SOC 2 Type II, ISO 27001)
GoogleSign-in (authentication)
CloudflareDomain name services (DNS only; Cloudflare does not proxy or process Platform traffic)

Beyond these: we may disclose information if required by law or to protect rights, safety, or the integrity of the service; and if Storyline is involved in a merger, acquisition, or sale of assets, information may transfer with protections consistent with this policy. We do not sell personal information.

International transfers

The Platform is operated from the United States and information is processed in the United States. Where users access the Platform from other jurisdictions, we rely on appropriate safeguards consistent with applicable law.

Security

Security is foundational to the Platform’s design: every request is authorized server-side against current permissions; the database independently enforces access rules; data is encrypted in transit and at rest; research content is versioned so published material cannot be silently altered; security-relevant activity is recorded in an append-only audit log that application users cannot alter; and access reviews and operational security controls (including administrator multi-factor authentication and offboarding) follow a written internal runbook. A plain-language overview is available to clients on request.

No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify affected parties consistent with applicable law and our incident procedures.

Retention

  • Account information: kept while your account is active. On offboarding or engagement end, accounts are suspended promptly; account records may be retained thereafter for audit and legal purposes.
  • Audit records: retained for the life of the platform relationship to preserve accountability, and per our internal retention decisions.
  • Research content: retained and deleted according to the applicable client engagement agreement and our data-lifecycle procedures; clients may request deletion of their engagement’s content.
  • Backups: the production database is backed up on a rolling short-term cycle; deleted data ages out of backups on that cycle.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to non-discrimination for exercising these rights (including under the GDPR and the CCPA/CPRA). Contact us at info@storylinestrategies.com and we will respond consistent with applicable law. Where your request concerns research content processed on a client’s behalf, we may route the request to that client, as they control that content.

You can stop using the Platform at any time; because sign-in uses your Google account, you may also revoke Storyline Studio’s access in your Google account settings (myaccount.google.com/permissions).

Children

The Platform is a business service for invited professional users and is not directed to children under 16. We do not knowingly collect information from children.

Changes to this policy

We will post any changes here and update the date above. For material changes, we will notify active users through the Platform or by email.

Contact

Questions about this policy or our privacy practices: info@storylinestrategies.com · Storyline Strategies, LLC, PO Box 74, Union Hall, VA 24176.