LEGAL
Privacy Policy
Last updated: May 2026
Welcome to The Storly. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://thestorly.com/ and use our AI-powered carousel creation platform (collectively, the "Service").
Please read this policy carefully. If you disagree with its terms, please discontinue use of our Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account registration data: name, email address, and password when you sign up via email or Google OAuth.
- Profile information: niche/industry, preferred social platforms, and onboarding preferences.
- Brand kit assets: logo files, colors, and font preferences you upload.
- Content you create: carousel topics, voice recordings, slide text, and generated carousels.
- Payment information: billing details processed via Paddle (international). We do not store full card numbers — these are handled by our payment processors.
- Communications: messages you send us via email or support channels.
1.2 Information Collected Automatically
- Usage data: pages visited, features used, time spent, clicks, and navigation paths.
- Device and browser data: IP address, browser type, operating system, device identifiers.
- Log data: server logs including timestamps, errors, and referring URLs.
- Cookies and similar technologies: session cookies, persistent cookies, and local storage identifiers (see Section 7).
1.3 Voice Input Data
If you use our voice-to-carousel feature, we process audio recordings you provide. Audio is transmitted to OpenAI's Whisper API for transcription and is not stored by us beyond the duration of your session unless you explicitly save the transcript.
1.4 Information from Third Parties
- Google OAuth: if you sign in with Google, we receive your name, email address, and profile picture from Google, subject to your Google account privacy settings.
- Analytics providers: aggregated and anonymized usage data from analytics services.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide and operate the Service, including generating carousels and applying your brand kit.
- To process your voice recordings and convert them to carousel content via third-party transcription APIs.
- To manage your account, authenticate you, and maintain security.
- To process payments and manage your subscription.
- To send transactional emails (account confirmation, password reset, billing receipts) via Resend.
- To send service-related notifications and, with your consent, promotional communications.
- To analyze usage patterns and improve the Service, fix bugs, and develop new features.
- To comply with legal obligations.
- To enforce our Terms of Service and protect against fraud or abuse.
We do not sell your personal data. We do not use your carousel content to train our AI models or third-party AI models without your explicit consent.
3. Legal Basis for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, our legal bases for processing your personal data under the General Data Protection Regulation (GDPR) and equivalent laws are:
- Contract performance: processing necessary to provide the Service you have signed up for.
- Legitimate interests: improving our Service, maintaining security, and preventing fraud, where these do not override your rights.
- Consent: for optional features such as marketing emails and voice recording processing. You may withdraw consent at any time.
- Legal obligation: where we are required by law to process your data.
5. International Data Transfers
The Storly operates globally. Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our service providers are located.
If you are located in the EEA, UK, or Switzerland, we ensure that any transfers of personal data to countries outside these regions are protected by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
- Other legally approved transfer mechanisms.
By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: retained for the duration of your account plus 30 days after deletion to allow account recovery.
- Carousel content: retained until you delete it or close your account.
- Voice recordings: not retained beyond the current session unless saved as transcript.
- Billing records: retained for up to 7 years to comply with financial regulations.
- Log data: retained for up to 12 months.
You may request deletion of your account and associated data at any time (see Section 8).
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
8.1 Rights for All Users
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data ("right to be forgotten").
- Data portability: request your data in a structured, machine-readable format.
- Opt-out of marketing: unsubscribe from promotional emails at any time via the unsubscribe link or by contacting us.
8.2 Additional Rights for EEA/UK Users (GDPR)
- Restriction: request that we restrict processing of your data.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: you have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or your national DPA in the EU).
8.3 Rights for California Residents (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and sell.
- Delete personal information we have collected (subject to certain exceptions).
- Opt-out of the sale of personal information. We do not sell personal information.
- Non-discrimination for exercising your privacy rights.
To exercise your California rights, contact us using the details in Section 13.
8.4 How to Exercise Your Rights
To exercise any of the above rights, please contact us at support@thestorly.com. We will respond to your request within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
9. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information.
10. Security
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS.
- Access controls and authentication requirements for our team.
- Regular security reviews.
However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
11. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party platforms (such as Instagram, LinkedIn, or VK) for direct publishing features. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before connecting your accounts.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page and, for material changes, notify you by email or by a prominent notice within the Service. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- The Storly
- Email: support@thestorly.com
- Website: https://thestorly.com/
- Registered address: Isani-Samgori / Dvali St.