StoryWorld — Privacy Policy
Version: 2026-09-17 · Last updated / Effective date: 2026-09-17 · Change log: /privacy/history
This Privacy Policy explains how Storyworld AI Private Limited (UEN 202626500W), a company incorporated in Singapore ("StoryWorld", "we", "us"), collects, uses, discloses, and protects personal data when you use the StoryWorld platform and the Mali generation engine (the "Service"). It is incorporated into our Terms of Service.
We serve users globally, including in the United States and the European Union, and comply with the Singapore Personal Data Protection Act ("PDPA") and, where they apply, the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended ("CCPA/CPRA"), and US state biometric-privacy laws.
One contact for everything in this Policy: support@storyworld.ai (this reaches our Data Protection Officer).
1. Controller & Data Protection Officer
1.1 Data controller: Storyworld AI Private Limited, 410 Ang Mo Kio Avenue 10, #01-851, Singapore 560410 (UEN 202626500W).
1.2 Data Protection Officer (DPO). As required by the PDPA, we have appointed a DPO. You can contact our DPO about this Policy, your personal data, or any privacy concern at: - DPO: Khok Hong Jing - Email: support@storyworld.ai (subject line: "Privacy")
2. Scope & Definitions
"Personal data" means data about an identifiable individual. "Inputs", "Outputs", "Your Content", "Likeness Data", "Provenance Marks", and "Third-Party AI Models" have the meanings given in the Terms of Service. "Biometric data" means personal data resulting from specific technical processing of a person's face, voice, or other physical characteristics which allows or confirms their unique identification, including facial-geometry templates and voiceprints; it is a form of Likeness Data and is described in Section 11.
3. Data We Collect
- Account data: name, email address, password (hashed), and profile details you provide.
- Acceptance records: the version of the Terms and this Policy you accepted, the timestamp, your IP address, and device information at the time of acceptance, and records of any consents you give (including biometric consent under Section 11).
- Billing data: subscription/plan, transaction records, and limited payment metadata. Card details are handled by our payment processor, not stored by us.
- Your Inputs: prompts, text, scripts, reference images, reference audio/video, characters, camera/scene parameters, and other creative material you submit.
- Likeness Data, including biometric data: facial-geometry templates, voiceprints, or similar identifiers Mali derives from reference material to keep a character consistent across scenes (Section 11).
- Your Outputs: the video, image, and audio content generated for you, including Provenance Marks.
- Usage, device & log data: IP address, device/browser information, actions in the Service, timestamps, and diagnostic logs.
- Support and report data: messages you send us, and information in copyright, removal, or abuse reports.
- Cookies & similar technologies: see Section 10.
We do not intentionally collect special-category / sensitive data other than Likeness Data you choose to submit (Section 11).
4. How We Use Data & Legal Bases
We use personal data to:
| Purpose | GDPR lawful basis |
|---|---|
| Create and manage your Account; provide the Service; generate and deliver your Outputs | Performance of a contract |
| Create and store Likeness Data to keep your characters consistent | Explicit consent (GDPR Art 9(2)(a)) — see Section 11 |
| Process payments, prevent payment fraud | Contract; legal obligation |
| Provide support and communicate about the Service, including notices of changes to our Terms or this Policy | Contract; legitimate interests |
| Secure the Service; detect and prevent abuse, fraud, and AUP violations | Legitimate interests; legal obligation |
| Content safety and legal compliance — applying Provenance Marks to Outputs, handling removal requests for non-consensual intimate content, responding to Online Safety Commission and other lawful directions | Legal obligation; legitimate interests |
| Maintain and improve the reliability of the Service using aggregated, de-identified operational data | Legitimate interests |
| Improve the quality and safety of Mali using text prompts, scripts, and generation parameters (never reference media or Likeness Data) — see Terms, Section 7.2 | Consent (EU/UK: opt-in); legitimate interests elsewhere, with opt-out |
| Comply with law and respond to lawful requests | Legal obligation |
| Send marketing (where permitted) | Consent (opt-in where required) |
Under the PDPA, we collect, use, and disclose personal data for purposes a reasonable person would consider appropriate in the circumstances, with your consent (including deemed consent) or as otherwise permitted by law. Where we rely on deemed consent by notification for a new purpose, we first assess the likely adverse effect on you, notify you of the purpose, and give you a reasonable period to opt out.
We do not use your Outputs to train, fine-tune, or improve StoryWorld's own AI models. We never use reference images, audio, video, or Likeness Data to train any model. (See Section 5 for how Third-Party AI Models process your Inputs.)
5. AI Processing & Third-Party AI Model Providers (Please Read)
5.1 Your Inputs are sent to third-party AI providers. To generate your Outputs, the Mali engine transmits your Inputs to Third-Party AI Models operated by other companies — currently ByteDance / Seedance (video generation, via ByteDance's Volcano Engine (Volcengine) Ark API, Beijing region), MiniMax (video generation), OpenAI (image generation), and Google (Gemini image generation). Likeness Data itself (templates and voiceprints) is not created by either product today — we hold your reference material as you uploaded it and send it to the providers above only to generate your Outputs.
5.2 Their role and terms. These providers process your Inputs under their own terms and privacy policies. Depending on the provider and configuration, they may act as our processors or as independent controllers. StoryWorld does not control their independent practices.
5.3 What we can and cannot commit to. As at the effective date: - OpenAI (API): under OpenAI's business terms, API data is not used to train OpenAI's models; retention is up to 30 days for abuse monitoring; processing is in the United States. - ByteDance / Seedance: we have not authorised the provider to use Your Content for training; content flagged by the provider's safety filters may be retained for up to 180 days; processing location depends on the provider channel and may include mainland China (see Section 7.2).
We operate on these providers' standard commercial terms. Beyond the commitments above, we cannot guarantee how a provider processes, retains, or uses Your Content, including where processing occurs. We review provider terms at least quarterly, keep a current summary at /trust, and will notify you under Section 16 if a change materially affects you. If we move backends onto enterprise no-training or data-residency tiers, we will update this Policy.
6. Sharing & Disclosure
We share personal data with:
- Third-Party AI Model providers (Section 5) to generate your Outputs.
- Service providers / processors — cloud hosting and storage (including Alibaba Cloud Object Storage where StoryWorld assets are stored — Alibaba Cloud, Singapore region), payment processing, analytics, email/communications, and customer support — acting on our instructions.
- Legal and safety disclosures — where required by law, legal process, or a direction of a competent authority (including the Singapore Online Safety Commission), or to protect the rights, safety, and security of StoryWorld, our users, or the public (including reporting CSAM). This may include disclosing user identity information where lawfully required.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell your personal data and do not "share" it for cross-context behavioural advertising as those terms are defined under CCPA/CPRA. We never sell, lease, trade, or otherwise profit from biometric data.
7. International / Overseas Transfers
7.1 Your data may be processed outside Singapore. Because our infrastructure and the Third-Party AI Models operate in multiple countries, your personal data (including your Inputs) may be transferred to, processed, and stored outside Singapore and outside your own country, including in the United States and other jurisdictions listed in Section 5.3.
7.2 Honest note on data location. On our current provider tiers, we cannot guarantee the specific country in which a Third-Party AI Model processes your Inputs. Processing may occur in jurisdictions whose data-protection laws differ from your own, and — on current tiers — the infrastructure of certain providers may include processing in mainland China. Data processed on infrastructure in mainland China may be subject to access by PRC authorities under PRC law, and the provider may be restricted from disclosing such requests. We do not currently make a "your data never leaves China" or "processed only outside China" guarantee. If we adopt data-residency-guaranteed tiers, we will update this Policy.
7.3 PDPA (s.26). Where we transfer personal data overseas, we take reasonable steps so the recipient provides a standard of protection comparable to the PDPA, through contractual measures with our processors or another lawful mechanism.
7.4 GDPR transfers. For transfers of EU/UK personal data to countries without an adequacy decision (Singapore does not have an EU adequacy decision), we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where relevant, transfer-impact assessments.
8. Data Retention
8.1 We keep personal data only as long as needed for the purposes in this Policy or as required by law.
8.2 Account data is kept while your Account is active. Inputs and Outputs are kept to provide the Service to you and are deleted or de-identified when you delete them or your Account, subject to (a) routine backups cycled out in the ordinary course (target: purged within 30 days), (b) records we must retain by law (e.g., transaction records), and (c) copies retained under an active abuse investigation or legal hold.
8.3 Likeness Data / biometric data follows the destruction schedule in Section 11.4.
8.4 Acceptance and consent records are kept for as long as your Account exists and for 7 years after, as evidence of the terms and consents that applied.
8.5 Retention of any content-safety or abuse logs by Third-Party AI Model providers follows their own schedules: content flagged by a provider's safety filter may be retained by that provider for up to 30 days (OpenAI) or 180 days (ByteDance).
9. Your Rights
Subject to applicable law, you have the following rights. To exercise them, contact support@storyworld.ai (subject line: "Privacy request"); we will verify your identity and respond within the time required by law.
- PDPA (Singapore): request access to and correction of your personal data, and withdraw consent for future processing (which may limit our ability to provide the Service). You may complain to the Personal Data Protection Commission (PDPC).
- GDPR (EU/UK): access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests, and the right to withdraw consent (including biometric consent under Section 11) at any time without affecting prior processing. You may also lodge a complaint with your supervisory authority.
- CCPA/CPRA (California): the right to know what we collect and how we use/disclose it, to delete, to correct, to opt out of sale/sharing (note: we do not sell or share as defined), to limit the use of sensitive personal information (including biometric data), and to non-discrimination for exercising your rights. We honour recognised opt-out preference signals (e.g., Global Privacy Control) where applicable.
- Illinois, Texas, Washington, and other US states with biometric-privacy laws: the rights described in Section 11, including to withdraw consent and request destruction of biometric data.
You will not be discriminated against for exercising any of these rights.
10. Cookies & Tracking
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality. Where required by law, we obtain consent for non-essential cookies through a consent banner.
11. Likeness & Biometric Data (Please Read)
11.1 Consent-first rule. The Service lets you submit reference images, audio, or video, which may depict a real person. You must not upload or generate the face, voice, or likeness of a real, identifiable person without that person's consent. By submitting such material, you represent and warrant that you have that consent (see the Terms of Service, Sections 9.1 and 10).
11.2 What we create and why. To keep characters consistent across scenes, Mali extracts and stores biometric identifiers and biometric information — such as facial-geometry templates and voiceprints — derived from reference material you submit. The sole purpose is to generate and maintain consistent AI characters at your request. We do not use biometric data to identify or track any person, to make decisions about you, or to train or improve any AI model.
11.3 Notice and written consent. We create and store biometric data only after providing this notice and obtaining written consent (an electronic signature or affirmative click on a dedicated consent screen counts as written consent) from: - you, at the moment you first upload reference material of a real person; and - the person depicted, where that person is not you — you must confirm you hold their written consent and, on request, provide it to us.
The consent screen states the specific purpose, the retention period in Section 11.4, and how to withdraw consent. Consent is separate from your acceptance of the Terms and this Policy and cannot be bundled into it. For EU/UK users, this is explicit consent under GDPR Article 9(2)(a).
11.4 Retention and destruction schedule. We retain biometric data only for as long as needed to maintain the characters you have created. We permanently destroy biometric data at the earliest of: (a) when you delete the associated character or reference material; (b) when you withdraw consent or delete your Account; (c) when the purpose for which it was collected is satisfied; or (d) 3 years after your last interaction with the Service (never longer than the maximum permitted under Illinois BIPA). Destruction includes copies held by processors, subject only to backups cycled out within the window in Section 8.2.
11.5 No sale, no profit. We do not sell, lease, trade, or otherwise profit from biometric data.
11.6 Disclosure. We disclose biometric data only (a) to processors strictly necessary to provide the Service, under confidentiality and comparable-protection obligations; (b) with your consent; or (c) where required by law or a valid court order or subpoena.
11.7 Security. Biometric data is stored using at least the same standard of care we apply to other confidential and sensitive information, including encryption at rest and in transit and access controls (Section 12).
11.8 Withdrawing consent. You may withdraw consent at any time by contacting support@storyworld.ai (subject line: "Privacy"). Withdrawal triggers destruction under Section 11.4 and means the affected characters can no longer be generated consistently.
12. Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Data Breach Notification
13.1 Singapore PDPA. If a data breach is likely to result in significant harm to affected individuals or affects 500 or more individuals, we will notify the Personal Data Protection Commission (PDPC) no later than 3 calendar days after we assess the breach is notifiable, and notify affected individuals where required.
13.2 GDPR. Where GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of a notifiable breach, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights.
13.3 US state laws. Where US state breach-notification laws apply (including to biometric data), we will notify affected individuals and regulators within the timeframes those laws require.
14. Children / 18+
The Service is for individuals 18 and older. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. If you believe a minor has provided us data, contact support@storyworld.ai.
15. Complaints & Contact
For any privacy question, request, or complaint, contact our DPO at support@storyworld.ai (subject line: "Privacy"). If you are in the EU/UK, you may also complain to your local supervisory authority; in Singapore, to the PDPC; in California, to the California Privacy Protection Agency or Attorney General.
16. Changes to This Policy
16.1 Each version of this Policy shows its effective date. Prior versions are archived at /privacy/history.
16.2 Minor changes (clarifications, corrections, formatting, contact details) take effect when posted.
16.3 Material changes — any new purpose for which we use your data; any new category of recipient or new AI model provider; any new country to which your data is transferred; changes to your rights or how to exercise them; or any use of your Inputs, Outputs, or Likeness Data to train or improve AI models — are published as a new version of this Policy that shows its effective date and a summary of the change, and apply from that date. The next time you use the Service on or after the effective date, you will be asked to review and accept the updated Policy.
16.4 Fresh consent. Where a material change introduces a purpose that requires consent, new processing of biometric or other sensitive data, or training on Your Content, we will not process your data for that purpose until you opt in through a separate, un-ticked affirmative action. Declining will not affect features that do not depend on that processing.
16.5 No retroactive effect. A revised Policy will not be applied to personal data collected under an earlier version in a way that expands its use, sharing, or transfer beyond what that version disclosed, unless you have consented under Section 16.4.
16.6 If you do not accept a material change, you may stop using the Service and delete your Account and data (see Section 9).
Storyworld AI Private Limited (UEN 202626500W). This Privacy Policy (version 2026-09-17) is effective as of 2026-09-17. Previous versions: /privacy/history.
