Privacy Policy
Effective Date: September 9, 2026 Version: 1.0
This Privacy Policy explains how StoryGen (storygen.xyz) collects, uses, and protects personal information during its pilot: a service that writes a personalized Italian graded reader for the words you already know.
Who We Are
Eyal Lapid, an individual based in Israel, is the sole operator and data controller responsible for StoryGen.
- Operator: Eyal Lapid, sole operator, Israel
- Privacy contact: privacy@storygen.xyz
You can reach us at that address for any question about this policy or to exercise the rights described below.
Information We Collect
Browsing, the quiz, and the free editions
You can read the landing page, take the vocabulary quiz, and read the three free (A1/A2/B1) editions without an account. We do not track you across these pages with any third-party analytics or advertising tool — see “Cookies” below.
Accounts
Generating a personalized story requires signing in. You can sign in with a one-time magic link sent to your email, or with your Google account.
- Magic link: you provide your email address; we email you a one-time sign-in link. No password is set or stored.
- Google sign-in: Google acts only as an identity provider. It shares your email address, whether Google has verified it, and Google’s own identifier for your account (used only to link future sign-ins to the same account) — nothing else.
- What an account stores: your email address, whether you consented to be contacted (and when), when you last signed in, and your active sign-in sessions.
- Consent to be contacted is a separate checkbox at sign-up, changeable later on the
/accountpage.
Your word list, quiz answers, and generated story
To write a story for exactly the words you know, we collect and store the word list or quiz answers you submit, and we send that list to our AI providers (see “Who We Share Data With”) as part of generating your story. We store the generated story itself so you can read it and, in this pilot, we do not offer a way to opt out of that storage while the story exists.
Usage events
We record a small set of first-party events tied to your session or reader — for example that a page was visited, a story reached a particular generation step, or a chapter was opened — so we can measure whether this pilot is working. These events do not carry your IP address (see “The Session Cookie and Rate Limiting” below) and are described further in “How Long We Keep Information.”
Reporting a problem
If you use the “report a problem” option while reading, the note you type — up to 280 characters — is stored together with the chapter and location it refers to. We use it only to find and fix problems with that story or the reader. The note is tied to that reader’s own token, not shared with anyone beyond us, and is deleted along with that reader 60 days after creation, the same as the rest of that reader’s data.
“Email me the next story”
At the end of a story you can choose to give a separate email address, together with a checkbox agreeing to be contacted, so we can send you the next chapter or story when it is ready. That address is stored only if you tick the checkbox, tied to that reader’s own token, and used only for that purpose. It is deleted along with that reader 60 days after creation, the same as the rest of that reader’s data.
The session cookie
Signing in sets one cookie, _storyengine_key, so the site recognizes you as signed in between requests. It is:
- First-party only — set by storygen.xyz and read by no one else;
- Signed — its contents cannot be tampered with, only read;
HttpOnly— invisible to page scripts, which limits what a malicious script could steal;- Sent only over HTTPS in production (
Secure) and only with same-site requests (SameSite=Lax); - A session cookie — it carries no separate expiry of its own and is cleared when you close your browser, or immediately when you sign out.
It carries no advertising or analytics identifier and is not shared with or read by any third party.
Rate limiting
To keep the pilot’s generation budget available to everyone, we temporarily rate-limit how often one visitor can sign in or submit a word list. This check runs in memory and does not write your IP address to any log or database — a rejected request is refused with no identifying record kept.
How We Use Information
We use the information above to:
- create and maintain your account and keep you signed in;
- generate your personalized story from the word list or quiz answers you provide;
- deliver your story and email you when it’s ready;
- measure whether the pilot is working, using the anonymized events described above;
- prevent abuse and keep the service available to every visitor;
- diagnose errors and keep the service reliable and secure;
- respond to your questions and rights requests.
Legal Bases (GDPR)
For visitors in the EU/EEA, we rely on the following legal bases under the GDPR:
- Contract (Art. 6(1)(b)) — to create your account, generate your story, and deliver the service you asked for;
- Legitimate interests (Art. 6(1)(f)) — to secure the service, prevent abuse via rate limiting, and measure aggregate pilot events, none of which are used for advertising;
- Consent (Art. 6(1)(a)) — for the optional “you may email me” checkbox, which you can withdraw at any time on the
/accountpage; - Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with the law.
Providing Your Information; Automated Decisions
An email address is required to create an account and generate a story; without one, we cannot create your account, generate a story, or deliver it to you. You do not need to provide any personal information at all to read the landing page, the vocabulary quiz, or the three free editions.
StoryGen makes no automated decision about you — including profiling — that produces a legal effect or similarly significantly affects you (GDPR Art. 22). Story generation decides only what text to write for the word list you gave it; it makes no decision about you, your rights, or your access to the service.
Who We Share Data With
We do not sell your personal information. We share information only with the service providers (“sub-processors”) that help us run StoryGen:
| Sub-processor | Purpose | Location | What it receives |
|---|---|---|---|
| Anthropic | Story generation | United States | Your word list or quiz answers, sent as part of the prompt used to write your story |
| OpenAI | Story generation | United States | Your word list or quiz answers, sent as part of the prompt used to write your story |
| Postmark | Transactional email | United States | Your email address, to send your sign-in link and story-ready notification |
| DigitalOcean | Hosting (application and database) | Amsterdam, Netherlands (EU) | The application and its database, including everything described in this policy |
| Grafana Cloud | Logs, metrics, and traces | EU/US (provider-managed) | Operational logs, metrics, and traces used to keep the service reliable — not your word list or story text |
| Sentry | Error reporting | EU/US (provider-managed) | Details of application errors, to help us fix bugs. This excludes your word lists, quiz answers, problem-report notes, and email addresses — request data carrying those fields is scrubbed before it is sent (see “Security” below) |
| Sign-in, only if you choose it | United States | Your email address, its verification status, and Google’s account identifier | |
| Google Fonts (Google LLC) | Web fonts, loaded on every page | United States | Your IP address and standard request details (browser, requested file), disclosed to Google as an ordinary consequence of your browser fetching the font files — this happens on every page, whether or not you sign in |
International Transfers
StoryGen is operated from Israel and uses service providers in the United States and the European Union (see the table above). Where personal information leaves Israel or the EU/EEA, we rely on the sub-processor’s own standard contractual clauses, data processing agreement, or equivalent safeguard, consistent with both the GDPR’s Chapter V transfer rules and the Israeli Privacy Protection (Transfer of Data to Databases Abroad) Regulations. Israel itself holds an EU adequacy decision, so transfers between Israel and the EU/EEA do not require an additional safeguard.
How Long We Keep Information
- Readers — including the word list, quiz answers, generated story, any problem-report note, and any next-story email address, plus every event tied to that reader’s own token — are deleted 60 days after creation. This runs automatically, every day, inside the service itself; nobody has to remember to trigger it.
- Events that are not tied to any reader (for example an anonymous page visit) are handled differently: instead of being deleted, the fields that could identify you are cleared after 60 days and the event row itself is kept without them, so we can still measure whether the pilot worked without holding your personal data.
- Accounts are not part of this 60-day sweep. An account is removed only when you delete it yourself (see “Deleting Your Account” below) or when the pilot is closed out at the end of its run.
- Rate-limit checks are held only in memory for the duration of the limit’s own window and are never written to disk.
Your Rights
Depending on your location, you have some or all of the following rights over your personal information:
- Access — to obtain a copy of the personal data we hold about you (GDPR Art. 15; Israel PPL);
- Rectification — to correct inaccurate data (GDPR Art. 16; Israel PPL);
- Erasure — to have your data deleted, subject to the exceptions in GDPR Art. 17 (for example, where we must keep anonymized events to measure the pilot, or where the law requires retention);
- Restriction of processing (GDPR Art. 18);
- Data portability — to receive your data in a structured, commonly used format (GDPR Art. 20);
- Objection — to object to processing based on our legitimate interests (GDPR Art. 21);
- Withdrawal of consent — for anything based on consent, such as the contact checkbox, at any time and without affecting past processing;
- Complaint — to lodge a complaint with your local data protection authority (in the EU/EEA) or the Israeli Privacy Protection Authority.
How to exercise these rights: email privacy@storygen.xyz, or delete your account directly from the /account page. We respond to email requests within 30 days, as required by GDPR Art. 12(3). We may ask you to verify your identity before acting on a request.
Deleting Your Account
The /account page has a “Delete account” action. When you delete your account, we:
- replace your email address with an unreadable placeholder and remove any linked Google identity, so the account can no longer identify you;
- revoke every active sign-in session immediately;
- delete your readers and word lists — the generated stories and the word lists or quiz answers behind them are removed, not just anonymized;
- keep the anonymized events described above (with
user_idcleared), so the pilot’s results remain measurable without holding any data that identifies you.
This is separate from, and faster than, the 60-day reader retention described above: deleting your account deletes your readers immediately rather than waiting for the sweep.
Cookies
StoryGen sets exactly one cookie: the first-party session cookie described above, used only to keep you signed in. We do not use third-party analytics, tracking, or advertising cookies, and we run no third-party advertising. Because we set no non-essential or third-party cookie, this site shows no cookie consent banner.
Every page also loads two files directly from Google’s servers to display our fonts (Google Fonts, fonts.googleapis.com and fonts.gstatic.com). Google does not set a cookie for this, but your browser’s request for those files discloses your IP address and basic request details to Google as an ordinary consequence of loading them — see “Google Fonts” in the sub-processors table above.
Security
We use technical and organizational measures intended to protect your information, including HTTPS, a signed and HttpOnly session cookie, and access controls on our infrastructure. No service can guarantee perfect security. If you believe you have found a vulnerability, contact privacy@storygen.xyz.
Children
StoryGen is not directed at children under 16. We do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, contact privacy@storygen.xyz and we will delete it.
Pricing Note
€9 per story after the pilot. Free during the pilot; nothing is charged. This policy governs personal data regardless of whether a story is paid for.
Changes to This Policy
We may update this Privacy Policy as the pilot evolves. Material changes will be posted on this page with an updated version number and effective date.
Contact
For privacy questions or to exercise your rights, contact privacy@storygen.xyz.