Legal
Privacy Policy
Effective 23 September 2026
The short version
Your writing never leaves your device unless you send it, and when you send it, it goes to Anthropic under your own key rather than to us. We hold an email address, the times you have signed in with it, and a license status, so the app knows who you are and what you have paid for — and, if you press Report a problem, whatever that sheet showed you before you sent it. While you are signed in with an active license, the app also keeps a copy of your own beats and your practice on our server, so the devices you use stay in step; the Sync section below says exactly what that copy holds, what it never holds, and the button that removes it. There is no analytics, no tracking, no advertising and no third-party scripts on this website.
What stays on your device
Storydrills is an offline-first application. The following are held in your browser’s local storage on your own device. The last two are never sent to us; the first three stay on your device unless you are signed in with an active license, in which case a copy travels as the Sync section describes:
- The beat bank, including any beats you write or import
- Your progress, accuracy history and spaced-repetition scheduling
- Game scores and sessions
- Your settings and chosen theme — never sent
- Your Anthropic API key — never sent
You can export all of it at any time from Settings, and you can delete all of it at any time from Settings → Advanced → Delete everything on this device. The export deliberately leaves your API key out, so you re-enter it after a restore.
What we hold, and why
Two short records — what you signed in with, and what you are entitled to — and, while a license is active, the sync copy described in its own section below.
- Your email address — what you sign in with, and the identifier a license is issued against
- When you signed in — the date and time of your sign-ins, which the authentication service records as a matter of course. There is no password, so there is none to store
- License status and expiry date
- When the app last checked in — a licensed copy renews its offline pass when you open it, and only if more than a fortnight has passed since the last time, so opening it twice in a week reaches us once. We keep the date that happened. It is a time and nothing else: what you were doing when it happened is not sent and is not stored. It exists so that a license granted to somebody who never came back can be told apart from one in daily use
- A payment reference from the payment processor, so a renewal or refund can be matched to the right license. Nothing is on sale yet, so no such reference exists for anybody.
That is the whole of it. We do not store payment details at all, and we never receive your content or your progress except as the sync copy, which exists only while a license is active and only to keep your own devices in step. The only other things we ever hold are the two you send us on purpose — a request for access, and a bug report — and both are described below. Your name is stored only if you typed it into one of them.
The legal basis, where that framing applies to you, is performance of a contract: without an email address there is no way to tell you apart from anyone else and no way to give you what you bought.
Both records, and the sync copy, are held on Supabase infrastructure, on servers in the United States: Supabase Auth holds the email address and the sign-in times, a license table holds the rest, and the sync copy sits in a table of its own beside it. The sign-in code itself is delivered by Resend, which handles your email address at the moment a code is sent and is given nothing else. They are kept while your license is active and for a reasonable period afterwards so a lapsed license can be renewed without losing your history, and deleted on request.
If you ask for access
Storydrills is in private beta, and the form on the front page is how you ask for a way in. What you type is written down before it is emailed, for the same reason a bug report is:
- Your name and email address
- Which kind of access you are after — for yourself, for a school or program, for a writers’ room, or something else
- Anything else you chose to tell us in the last box
- A shortened form of your IP address — the same coarsened shape described below, and there for the same reason: it stops the form being used to flood the inbox, and nothing else reads it
The record is kept on the same Supabase infrastructure, alongside whether we have answered you, and the request is then mailed to [email protected]. If you are given access, that address becomes the address your license is issued against. If you are not, the request is marked answered rather than deleted, so that writing to us again is not treated as a first approach. Requests are deleted on request.
If you report a problem
The app has a Report a problem button. Pressing it sends only what the sheet shows you before you press send:
- The note you type
- The app’s own state — version, browser, screen size, which framework and mode were open, how much is in storage, and the last few answers as step identifiers and right-or-wrong flags
- Your email address, only if you are signed in
- A shortened form of your IP address — the first three parts only (a /24 for an IPv4 address, a /48 for IPv6), which groups a sender without locating one. It exists to stop the button being used to flood our inbox, and nothing else reads it
No beats, no notes, no works, no display name and no API key. The answer log this draws on has never held a word of anything you wrote — only which step was asked and whether the answer was right — which is what makes it safe to send at all.
A report is written down before it is emailed. Those four things are stored as a row — on the same Supabase infrastructure, alongside the time it arrived and whether the notification mail succeeded — and only then mailed to [email protected], with your address as the reply-to if you were signed in. That order is deliberate: a report that existed only as a mail attempt is a report lost the moment mail breaks. Reports are deleted on request.
Sync
While you are signed in with an active license, the app keeps one copy of your own work on our server so that the devices you use — a phone on the train, a laptop at the desk — hold the same beats and the same practice history. The copy is a single record, one per license, and our server never reads inside it: the app on your device merges it with what it already holds, using the same rules as Merge a backup, and sends the result back.
What leaves the device, in that copy:
- the beats you wrote, and when each was last changed
- the bundled beats you have edited — an unedited bundled beat is not sent, because every device already has it
- your list of works
- your mastery and drill counters, and your practice log
- your game and analysis history — for each analysis, its verdict, your own notes, the title and a word count, and nothing of the text itself
- the identifiers of beats you have deleted, so a deletion made on one device holds on the others
What never leaves the device, sync or no sync:
- the text of any script or draft you analyze — not the text, not the excerpt the app keeps for you on the device
- your Anthropic API key
- your settings, your chosen theme, your display name and picture
When. When you open the app, and a few seconds after you change something — only while you are signed in with an active license and online. A device that is offline, or signed out, or whose license has lapsed, changes nothing on the server and keeps working exactly as it was. Because two devices can disagree about the time, the app uses our server’s clock to decide which of two edits to the same beat is the newer one; that is why every reply from the sync service carries the time, and why the app learns the time from it.
Where. The same Supabase database that holds your license, on servers in
the United States. The record has six columns: licence_id (which license it
belongs to), payload (the copy itself), hash (a short fingerprint
of the copy, so a device that already has it is told so without downloading it again),
version (a counter that stops two devices saving over each other),
bytes (its size) and updated_at (when it was last saved).
How long. As long as the license row exists, and not a day longer. The sync record is tied to the license record in the database in such a way that deleting the license deletes the copy with it — a cascade, in the database’s own word — so there is no way for the copy to outlive the license it belongs to.
How to remove it. Settings → Your data → Sync → Delete cloud copy. It deletes the record on our server and nothing else: the copies on your devices are untouched, and your license is untouched. That device then stops syncing until you press Sync now; another device you are signed in on will upload its own copy again the next time it opens the app, so to stop syncing altogether, sign out on each device.
Analyze and Walk Through
These features send text you choose — a scene, an outline, a draft — to Anthropic’s API, directly from your browser, using an API key you supply.
That text does not pass through our servers and we never see it. It is also deliberately excluded from every export the app produces and from the sync copy. Your agreement with Anthropic governs what happens to it after that.
This is a design decision rather than an oversight: screenwriters should not have to send unproduced work through a stranger’s server, and the cost of that decision is that you have to bring your own key.
Payments
Nothing is on sale yet, so no payment has ever been taken and no payment record of any kind exists. When licenses go on sale, a third-party merchant of record will collect and process your payment details and billing information under its own privacy notice, and will pass us your email address and the status of your purchase and nothing else we need. We never see or store card numbers. That processor will be named on this page before anything is sold.
This website
- No analytics. No Google Analytics, no pixels, no tag manager, no cookie banner, because there is nothing to consent to.
- Hosting. storydrills.com and the app are served by Cloudflare, which processes standard request logs (IP address, user agent, requested URL) for security and delivery.
- The access form posts to our own function on Supabase, which writes the request down and then emails it to us. What you type in it is what we receive, and what it keeps is listed above.
- Signing in. The app has its own sign-in wall: you type your email
address and it emails you a six-digit code. There is no password. The sign-in is
handled by Supabase Auth and the code is delivered by
Resend, sending from
send.storydrills.com. Cloudflare Access, which guarded the app earlier in the beta, was removed on 31 August 2026 and is no longer in the path. - Fonts are self-hosted. The app and this site load no external font, script or stylesheet, so opening either does not announce you to a third party.
Your rights
You can ask us to show you what we hold, correct it, or delete it. Because what we hold is an email address, a set of sign-in times and a license status, that is a short conversation. Deleting your sign-in and license records ends the license and your access to the app; it does not touch anything on your device.
If you are in the UK, EU or a US state with a comprehensive privacy law, you have the rights that law gives you — access, correction, deletion, portability and objection among them — and we will honour them without asking which one applies. We do not sell personal information and never have.
To exercise any of this, email [email protected] from the address on the license.
Children
Storydrills is not directed at children under 13 and we do not knowingly collect their personal information. Where a school or program licenses Storydrills for students, the institution is responsible for obtaining any consent its own rules require.
Changes
If this policy changes, the effective date above changes with it. If a change means we start collecting something we did not collect before, we will say so plainly rather than edit a sentence and hope.
17 September 2026. This page now describes the app’s own sign-in wall — the email address and sign-in times held by Supabase Auth, and the code delivered by Resend — which replaced the Cloudflare Access gate on 31 August 2026. It also says plainly that a bug report is stored as a row before it is emailed. Nothing is collected now that was not being collected before this date; what changed is that this page says so.
19 September 2026. The form on the front page now writes your request down as a record of its own before it emails it, where before it was relayed to us as an email and nothing else. That is a new thing held about you, and this is the plain statement promised in the paragraph above rather than a quietly edited sentence. What the record holds is listed under If you ask for access.
21 September 2026. This page no longer names a specific payment processor. None is live, nothing is on sale, and the company named here before this date was never engaged. Nothing about what is held has changed — there has never been a payment record of any kind — and the processor that does handle payments will be named on this page before anything is sold.
21 September 2026, later the same day. A licensed copy of the app renews its offline pass when you open it, rather than only when you sign in — and only if more than a fortnight has passed since the last time — and we now keep the date of the most recent one. That is a new thing held about you and this is the plain statement promised above. It is a timestamp: no progress, no scores, nothing about what you drilled or how it went — all of that stays in your browser, as the rest of this page describes. The renewal is also what lets an ended license actually end on a device that is already installed, rather than a month later.
23 September 2026. The app can now keep a copy of your own beats and your practice history on our server, one per license, so the devices you sign in on stay in step. That is a new thing held about you, and this is the plain statement promised above. What the copy holds, what it never holds — no script text, no API key, no settings — how long it lives, and the button that removes it are all under Sync. Nothing else on this page changed in what it describes; the sentences that said your content never reaches us now say “except the sync copy”, because that is the truth.
Contact
Joseph Hood, trading as Hoodworks Media Group — [email protected].
Storydrills™ is a trademark of Hoodworks Media Group.
