Privacy Policy
Last updated 8 September 2026
Who we are
StoryRoom is operated by WisGen AI, Sydney, Australia. Privacy questions and requests go to info@wisgen.ai. This page says what we collect, who else touches it, and what you can ask us to do about it.
What we collect
- Sign-in details. Your name, your email address and a unique id from your sign-in provider. Early accounts use a username and a password, which we store only as a hash.
- The content you upload. Photographs of pages, recordings, typed text, and the corrections you make to a reading.
- Usage records. Which readings ran, when they ran, and what each one cost.
- Payment records from Stripe. The amount, the card brand and the last four digits. We never see or store the full card number.
- Technical logs. IP address, browser and timestamps, kept for 30 days.
Why we use it
To provide the service, to bill for it accurately, to keep it secure, and to fix it when it breaks — and to improve the reader, only if you have said we may. We do not sell your data, we do not pass it to data brokers, and there is no advertising on StoryRoom.
Who processes it
Four companies handle part of it. Each receives what it needs and nothing else.
- Amazon Web Services. Stores your pages, recordings and text, runs the database, and provides Amazon Bedrock — the AI inference that reads your pages.
- Deepgram. Transcribes your recordings; it receives the audio.
- Google. Sign-in. It tells us your name, your email address and a unique id. Your Google password is never sent to us and we could not read it.
- Stripe. Card payment. Your card details go straight to Stripe; we receive the amount, the card brand and the last four digits, never the full number.
Where it is stored
Your content is stored and processed on Amazon Web Services and may be processed in more than one AWS region. We do not promise a fixed country or region: there is no requirement for one here, and naming a place would turn an operational choice into a promise we would then have to keep.
How accounts are kept apart
We would rather be exact than reassuring, so this section says where the separation between accounts has got to, rather than describing a finished thing.
StoryRoom is in private beta and invitation only. Every account in it today is one of ours, so nobody else's writing is yet held under any promise on this page. All three of the layers we wanted are now built and tested.
- Every row of writing records the account it belongs to, and the database refuses to file one account's work under another.
- The application filters every request by the account you signed in as. A request for another account's writing is answered as though that writing were not there — the same answer a request for something that genuinely does not exist receives, because any other answer would itself disclose that it exists.
- And now the database enforces this itself, underneath the application. If our own code ever asked for a row without saying which account it was acting for, the database does not hand back somebody else's writing and does not quietly return nothing: the request fails outright and we get an error we can find. That is the point of doing it this way round — a mistake of ours becomes a fault we have to fix, rather than a disclosure you would never hear about.
Every release is checked by tests that try each of those doors as the wrong account and require all of them to be shut, and that check the database's own rules are still switched on. We said we would state each layer here when it was finished and tested and not before; this is the last of the three. The site stays invitation-only in the meantime, because separation between accounts was never the only thing that has to be right before strangers are let in.
What we can already tell you is the intent, and it is a design commitment rather than a policy: there will be no application back door and no staff screen for reading your pages. It is a weaker claim than saying no human being could ever reach what is stored — an engineer holding the database owner credential could, and that is precisely why that credential is used for migrations and for nothing else, and why the running application is no longer able to read that credential at all.
Training the reader
Two boxes are shown when an account is created. Both start unticked, and if you leave them that way we do not train anything on your content.
- Improve my own reader. Your corrections are used to train a reader for your own hand, and for nothing else.
- Contribute to the shared reader. Your pages and corrections may be used to improve the reader that everyone uses.
You can change either choice at any time. Withdrawing consent is forward-looking: it stops any further use of your content from that moment. It cannot remove what a model has already learned, and we will not pretend otherwise.
How long we keep it
- Your content: until you delete it or close your account.
- Every version of a reading: kept for as long as the page it belongs to — that is what makes correcting a page safe.
- Technical logs: 30 days.
- Payment records: as long as financial and tax law requires us to keep them.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask for an export, or ask us to delete it. Write to info@wisgen.ai from the account's email address and we will act within a reasonable time — usually days, not weeks.
The Australian Privacy Act 1988 applies to us. If you are in the United Kingdom or the European Economic Area, the GDPR rights of access, rectification, erasure, portability and objection apply to you as well. If we get something wrong, tell us first; if we do not put it right, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Cookies
One cookie, and it is essential: the session cookie that keeps you signed in. No analytics, no advertising, no third-party trackers.
Children
StoryRoom is not directed at children under 16 and we do not knowingly collect their details. A page written by a child may of course be photographed by the adult whose account it is.
Changes to this policy
We post changes here with the date at the top, and we tell account holders directly about any change to how their content is used.