Legal & data

Privacy Policy

How StoryMind handles waitlist, account, workspace, source, usage, support, and billing information.

Document version: Version 1.0 — effective 6 March 2025

Controller and contact

Aumivi AG, Lerchenfeldstrasse 3, 9014 St. Gallen, Switzerland, UID CHE-359.168.454, is the controller for personal data processed through StoryMind. StoryMind is developed in collaboration with Jyoti Guptara. Contact the controller at hello@storymind.net or +41 71 589 67 00.

Aumivi AG is established in Switzerland. StoryMind is currently a limited early-access service and does not intentionally conduct large-scale, regular monitoring of people in the EU. We have not appointed a separate EU representative under GDPR Article 27 at this time. If an Article 27 appointment becomes applicable to a processing activity, we will appoint the representative before that activity begins and publish its name and contact details here. EU residents may send requests directly to Aumivi AG using the contact details above in all cases.

Data categories

We collect only what is needed for the purposes below. Waitlist data includes name, email, optional company and reason, confirmation token metadata, confirmation time, invitation status, consent version, and timestamps. Account data includes name, email, authentication records, verification state, labels, and security events. Workspace data includes workspace identity, membership, company details, onboarding answers, sources, uploaded files, approved context, stories, generated assets, ratings, comments, and visibility choices. Usage data includes routes, feature events, device and browser information supplied by the application, and security logs. Support data includes feedback, requests, contact permission, and responses. Billing data includes plan, payment-provider customer and subscription identifiers, billing email, invoice state, and verified webhook events; StoryMind does not store full payment-card numbers.

Purposes and legal bases

Waitlist registration, email confirmation, and invitation delivery use the steps you request before a contract and, where required, your consent under Swiss data-protection law and GDPR Article 6(1)(a) and (b). Account, workspace, source hosting, generation, support, and requested exports are processed to perform the contract under Article 6(1)(b). Security, fraud prevention, service reliability, debugging, and limited service measurement rely on our legitimate interests under Article 6(1)(f), balanced against your rights. Tax, accounting, legal requests, and records required by law rely on Article 6(1)(c). Optional analytics and any optional Alpha improvement use are processed only after the separate consent you provide under Article 6(1)(a). You may withdraw consent at any time for future processing.

Service providers and roles

Self-hosted Appwrite provides authentication, database, storage, and future server functions. Resend provides transactional email. Stripe provides checkout, subscriptions, and billing administration when enabled. Self-hosted Matomo provides optional page analytics after consent. No AI or content-extraction provider is currently configured to receive StoryMind customer content; any such provider will be disclosed in the Subprocessors page before use.

International transfers

Aumivi AG prefers operator-controlled Swiss hosting for StoryMind. Some service providers may process data in the United States or another country. Where the destination is not recognised as providing adequate protection, Aumivi AG uses the European Commission’s Standard Contractual Clauses, as adapted or supplemented for Swiss law, together with a transfer-impact assessment and supplementary technical or organisational measures where appropriate. Provider-specific details are listed on the Subprocessors page.

Retention periods

Unconfirmed waitlist requests are deleted 30 days after the 48-hour confirmation link expires. Confirmed waitlist records are deleted 24 months after the last meaningful waitlist activity unless an invitation, dispute, or legal obligation requires longer retention. Account records are kept while the account exists and deleted within 30 days after verified account deletion, subject to backups retained for up to 90 days. Workspace sources, generated material, and membership records are deleted within 30 days after the relevant workspace or account deletion request, subject to backups retained for up to 90 days. Usage and security logs are retained for 12 months. Support and feedback records are retained for 24 months after closure. Billing and accounting records are retained for 10 years where required by Swiss accounting or tax law. Consent and withdrawal records are retained for 3 years after the relevant relationship ends to demonstrate compliance.

Security

We use tenant-scoped access, Appwrite permissions, short-lived authentication tokens, transport security, restricted administrative access, and operational safeguards. No online service can promise absolute security. Please do not send passwords, API keys, payment-card data, or unnecessary sensitive personal data to StoryMind.

Your rights

Subject to legal limits, you may request access, correction, deletion, restriction of processing, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time. To exercise a right, email hello@storymind.net with the request, the account or waitlist email involved, and enough information for us to verify identity. We acknowledge requests within 5 business days and respond within 30 days; complex requests may take an additional 60 days where GDPR permits, and we will explain the reason. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3005 Bern, Switzerland, edoeb.admin.ch, or to the data-protection authority in your EU or EEA country of residence, work, or alleged infringement.

Cookies and analytics

Essential technology supports security, navigation, the Appwrite session, the sidebar preference, and saved cookie choices. Optional Matomo analytics does not load until you consent. You can change your choice at any time on the Cookie Settings page.

Updates

We may update this Policy as StoryMind develops. The version above identifies the current publication. Material changes will be communicated where appropriate.