Storydrills

Legal

Privacy Policy

The short version

Your writing never leaves your device unless you send it, and when you send it, it goes to Anthropic under your own key rather than to us. We hold an email address, the times you have signed in with it, and a license status, so the app knows who you are and what you have paid for — and, if you press Report a problem, whatever that sheet showed you before you sent it. While you are signed in with an active license, the app also keeps a copy of your own beats and your practice on our server, so the devices you use stay in step; the Sync section below says exactly what that copy holds, what it never holds, and the button that removes it. There is no analytics, no tracking, no advertising and no third-party scripts on this website.

What stays on your device

Storydrills is an offline-first application. The following are held in your browser’s local storage on your own device. The last two are never sent to us; the first three stay on your device unless you are signed in with an active license, in which case a copy travels as the Sync section describes:

You can export all of it at any time from Settings, and you can delete all of it at any time from Settings → Advanced → Delete everything on this device. The export deliberately leaves your API key out, so you re-enter it after a restore.

What we hold, and why

Two short records — what you signed in with, and what you are entitled to — and, while a license is active, the sync copy described in its own section below.

That is the whole of it. We do not store payment details at all, and we never receive your content or your progress except as the sync copy, which exists only while a license is active and only to keep your own devices in step. The only other things we ever hold are the two you send us on purpose — a request for access, and a bug report — and both are described below. Your name is stored only if you typed it into one of them.

The legal basis, where that framing applies to you, is performance of a contract: without an email address there is no way to tell you apart from anyone else and no way to give you what you bought.

Both records, and the sync copy, are held on Supabase infrastructure, on servers in the United States: Supabase Auth holds the email address and the sign-in times, a license table holds the rest, and the sync copy sits in a table of its own beside it. The sign-in code itself is delivered by Resend, which handles your email address at the moment a code is sent and is given nothing else. They are kept while your license is active and for a reasonable period afterwards so a lapsed license can be renewed without losing your history, and deleted on request.

If you ask for access

Storydrills is in private beta, and the form on the front page is how you ask for a way in. What you type is written down before it is emailed, for the same reason a bug report is:

The record is kept on the same Supabase infrastructure, alongside whether we have answered you, and the request is then mailed to [email protected]. If you are given access, that address becomes the address your license is issued against. If you are not, the request is marked answered rather than deleted, so that writing to us again is not treated as a first approach. Requests are deleted on request.

If you report a problem

The app has a Report a problem button. Pressing it sends only what the sheet shows you before you press send:

No beats, no notes, no works, no display name and no API key. The answer log this draws on has never held a word of anything you wrote — only which step was asked and whether the answer was right — which is what makes it safe to send at all.

A report is written down before it is emailed. Those four things are stored as a row — on the same Supabase infrastructure, alongside the time it arrived and whether the notification mail succeeded — and only then mailed to [email protected], with your address as the reply-to if you were signed in. That order is deliberate: a report that existed only as a mail attempt is a report lost the moment mail breaks. Reports are deleted on request.

Sync

While you are signed in with an active license, the app keeps one copy of your own work on our server so that the devices you use — a phone on the train, a laptop at the desk — hold the same beats and the same practice history. The copy is a single record, one per license, and our server never reads inside it: the app on your device merges it with what it already holds, using the same rules as Merge a backup, and sends the result back.

What leaves the device, in that copy:

What never leaves the device, sync or no sync:

When. When you open the app, and a few seconds after you change something — only while you are signed in with an active license and online. A device that is offline, or signed out, or whose license has lapsed, changes nothing on the server and keeps working exactly as it was. Because two devices can disagree about the time, the app uses our server’s clock to decide which of two edits to the same beat is the newer one; that is why every reply from the sync service carries the time, and why the app learns the time from it.

Where. The same Supabase database that holds your license, on servers in the United States. The record has six columns: licence_id (which license it belongs to), payload (the copy itself), hash (a short fingerprint of the copy, so a device that already has it is told so without downloading it again), version (a counter that stops two devices saving over each other), bytes (its size) and updated_at (when it was last saved).

How long. As long as the license row exists, and not a day longer. The sync record is tied to the license record in the database in such a way that deleting the license deletes the copy with it — a cascade, in the database’s own word — so there is no way for the copy to outlive the license it belongs to.

How to remove it. Settings → Your data → Sync → Delete cloud copy. It deletes the record on our server and nothing else: the copies on your devices are untouched, and your license is untouched. That device then stops syncing until you press Sync now; another device you are signed in on will upload its own copy again the next time it opens the app, so to stop syncing altogether, sign out on each device.

Analyze and Walk Through

These features send text you choose — a scene, an outline, a draft — to Anthropic’s API, directly from your browser, using an API key you supply.

That text does not pass through our servers and we never see it. It is also deliberately excluded from every export the app produces and from the sync copy. Your agreement with Anthropic governs what happens to it after that.

This is a design decision rather than an oversight: screenwriters should not have to send unproduced work through a stranger’s server, and the cost of that decision is that you have to bring your own key.

Payments

Nothing is on sale yet, so no payment has ever been taken and no payment record of any kind exists. When licenses go on sale, a third-party merchant of record will collect and process your payment details and billing information under its own privacy notice, and will pass us your email address and the status of your purchase and nothing else we need. We never see or store card numbers. That processor will be named on this page before anything is sold.

This website

Your rights

You can ask us to show you what we hold, correct it, or delete it. Because what we hold is an email address, a set of sign-in times and a license status, that is a short conversation. Deleting your sign-in and license records ends the license and your access to the app; it does not touch anything on your device.

If you are in the UK, EU or a US state with a comprehensive privacy law, you have the rights that law gives you — access, correction, deletion, portability and objection among them — and we will honour them without asking which one applies. We do not sell personal information and never have.

To exercise any of this, email [email protected] from the address on the license.

Children

Storydrills is not directed at children under 13 and we do not knowingly collect their personal information. Where a school or program licenses Storydrills for students, the institution is responsible for obtaining any consent its own rules require.

Changes

If this policy changes, the effective date above changes with it. If a change means we start collecting something we did not collect before, we will say so plainly rather than edit a sentence and hope.

17 September 2026. This page now describes the app’s own sign-in wall — the email address and sign-in times held by Supabase Auth, and the code delivered by Resend — which replaced the Cloudflare Access gate on 31 August 2026. It also says plainly that a bug report is stored as a row before it is emailed. Nothing is collected now that was not being collected before this date; what changed is that this page says so.

19 September 2026. The form on the front page now writes your request down as a record of its own before it emails it, where before it was relayed to us as an email and nothing else. That is a new thing held about you, and this is the plain statement promised in the paragraph above rather than a quietly edited sentence. What the record holds is listed under If you ask for access.

21 September 2026. This page no longer names a specific payment processor. None is live, nothing is on sale, and the company named here before this date was never engaged. Nothing about what is held has changed — there has never been a payment record of any kind — and the processor that does handle payments will be named on this page before anything is sold.

21 September 2026, later the same day. A licensed copy of the app renews its offline pass when you open it, rather than only when you sign in — and only if more than a fortnight has passed since the last time — and we now keep the date of the most recent one. That is a new thing held about you and this is the plain statement promised above. It is a timestamp: no progress, no scores, nothing about what you drilled or how it went — all of that stays in your browser, as the rest of this page describes. The renewal is also what lets an ended license actually end on a device that is already installed, rather than a month later.

23 September 2026. The app can now keep a copy of your own beats and your practice history on our server, one per license, so the devices you sign in on stay in step. That is a new thing held about you, and this is the plain statement promised above. What the copy holds, what it never holds — no script text, no API key, no settings — how long it lives, and the button that removes it are all under Sync. Nothing else on this page changed in what it describes; the sentences that said your content never reaches us now say “except the sync copy”, because that is the truth.

Contact

Joseph Hood, trading as Hoodworks Media Group — [email protected].

Storydrills™ is a trademark of Hoodworks Media Group.