Back to Story Arc

Privacy Policy

Last updated: 4 October 2026

EXPERIMENTAL PRODUCT NOTICE

Story Arc is currently an experimental product in early release. During this phase, the service is designed for experimental use only. Features, functionality, and service availability may change as we develop and refine the platform.

1. Who we are

Story Arc is run by Everyday Magic Limited, a New Zealand company ("we", "us"). This policy explains what we collect when you use Story Arc (app.thestoryarc.ai, account addresses such as yourcompany.thestoryarc.ai, custom domains that customers set up, and our AI assistant connector), how we use it, and your choices. Questions go to team@thestoryarc.ai.

2. Information we collect

  • Account information: your name, email address and profile photo. Passwords and sign-in are handled by our sign-in provider, Clerk; we never see your password. If you sign in with Google, we receive your name, email and photo from Google.
  • What you set up in Story Arc: workspace and account details, brand and competitor names, website addresses, the prompts you track, tasks, notes, assignments and team members.
  • Results we generate: the answers AI assistants give to your prompts, the sources they cite, and our analysis of them.
  • Website audits: we fetch publicly available pages of the websites you (or your competitors) publish, to check how ready they are for AI assistants.
  • Google Analytics data: only if you connect it (see section 5).
  • Usage information: pages you visit and features you use in Story Arc, device and browser details, and IP address, collected through our product analytics and logs.
  • Communications: messages you send us by email.
  • Payment information: handled by Stripe. We don't store card numbers.

3. How we use it

  • To provide Story Arc: run your prompts, audit websites, show results and trends, and suggest what to fix
  • To keep your account secure and your data separated from other customers
  • To send emails you need, such as invitations and task assignments
  • To understand how Story Arc is used so we can improve it, and to find and fix problems
  • To bill for paid plans
  • To meet legal obligations and to prevent fraud and abuse

We don't sell your personal information, and we don't use it for advertising.

4. AI providers

Story Arc works by asking AI assistants the prompts you track. Those prompts are sent to OpenAI, Anthropic, Google and Perplexity through the Vercel AI Gateway, and their answers are stored in your workspace. We also use TypeSafe to make structured judgements about AI answers and web pages, for example whether an answer recommends your brand or whether a page answers a prompt.

We send these providers the prompt text, brand and competitor names, and public web page text they need. We don't include your account details such as your name or email. The providers process this under their API terms.

5. Google Analytics

If a workspace manager connects Google Analytics:

  • We ask Google for read-only access to your Analytics data and for the email address of the Google account you connect, so we can show which account is linked
  • We read traffic figures (for example sessions, users and engaged sessions by week, channel and referring AI site) and store those totals in your workspace. We store the access tokens encrypted
  • We use this data only to show your AI referral traffic in Story Arc. We don’t use it for advertising, sell it, or share it except with the service providers who host Story Arc
  • Disconnecting Google Analytics deletes the stored Analytics data and revokes our access with Google. You can also remove access at any time in your Google account settings

Story Arc's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Connected AI assistants

You can connect an AI assistant (such as Claude or ChatGPT) to Story Arc through our connector (details). When you do:

  • You sign in to Story Arc and approve the connection; the assistant receives an access token, never your password
  • The assistant can read the same workspace data you can see in Story Arc, and take the same actions your role allows there (such as creating or running prompts, which uses credits, and updating tasks)
  • We receive only the tool requests the assistant makes (for example, which workspace to read). We don’t receive or store your conversations with the assistant
  • We record which tools are used, with ids, options and timings, in our product analytics to improve the connector; we don’t record the text you enter or the data the tools return
  • Data the assistant reads is then handled under that assistant provider’s own terms and privacy policy
  • You can disconnect at any time from the assistant’s settings, which stops its access

7. Service providers

We use these providers to run Story Arc. They process information only to provide their service to us:

ProviderWhat for
VercelHosting, and the AI Gateway that routes prompts to AI providers
OpenAI, Anthropic, Google and PerplexityAnswering the prompts you track (through the Vercel AI Gateway)
TypeSafeStructured judgements about AI answers and web pages (for example, how an answer presents your brand)
NeonDatabase
ClerkSign-in and account security
CloudflareSending emails such as invitations and task notifications
PostHogProduct analytics
LangfuseMonitoring the cost and reliability of AI requests
StripePayments and billing
GoogleGoogle Analytics data, only if you connect it (see below)

We also share information when you ask us to, when the law requires it, to protect our rights or others' safety, or as part of a sale or merger of our business (in which case this policy continues to apply).

8. Where your information is processed

We are based in New Zealand. Our database and hosting run mainly in Australia, and some of our providers, including the AI providers, process information in the United States and elsewhere. We use providers that protect personal information to a standard comparable to New Zealand's Privacy Act 2020.

9. Cookies

  • Sign-in cookies that keep you signed in (from Clerk, and our own session cookie on custom domains)
  • Product analytics (PostHog), to understand how Story Arc is used

Blocking sign-in cookies stops Story Arc working; the others are optional and you can block them in your browser.

10. Security

We keep each customer's data separate and check access on every request, encrypt data in transit, and encrypt sensitive credentials such as Google tokens. However, during this experimental release you should expect that the service may experience disruptions. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

11. How long we keep it

We keep your information while your account is active and as needed to provide Story Arc. If you close your account or ask us to delete your information, we delete it, except where we need to keep some of it for legal, accounting or fraud-prevention reasons. Backups are overwritten on their normal schedule.

12. Your rights

You can ask to see the personal information we hold about you and to have it corrected. Depending on where you live, you may also have the right to have it deleted, to receive a copy in a portable format, or to object to or restrict how we use it. Email team@thestoryarc.ai and we'll respond within 20 working days. If you're not happy with our response, you can complain to the New Zealand Privacy Commissioner (privacy.org.nz) or your local data protection authority.

13. Changes to this policy

We may update this policy as Story Arc changes. We'll change the date at the top, and tell you about significant changes by email or in the app.

14. Contact us

Questions about this policy or your information: team@thestoryarc.ai.