Privacy Policy
Salt & Gorse Ltd ("we", "us"), company 15581747, registered at Bosnoweth, Higher Argal, Budock Water, Cornwall TR11 5PE, operates Storybrdr at storybrdr.com. This policy explains what we collect, why, and your rights under UK GDPR.
Which hat we are wearing matters, so we say it plainly.
- For your account, your name, email, sign-in, billing, and the technical records that keep the Service running and secure, we are the data controller. This policy is our notice to you about that data.
- For the work you put in, your boards, your images, your notes, and any person who appears in a photograph you upload, you are the data controller and we are your processor. That covers everything we do with it on your instructions: storing it, showing it to you, making thumbnails, producing the exports you ask for, and showing shared boards to the people you send links to. We do none of that for any purpose of our own, and our obligations to you in that role are set out in the Data Processing Addendum, which forms part of your contract with us.
- There is one exception and it is deliberate. The safety check is ours. We scan every uploaded image to make sure this Service is not hosting unlawful material. We decided to do it, we decided what it looks for, we decide what happens when it finds something, and you cannot switch it off. That makes it processing for a purpose of our own, so for the safety check, and only for the safety check, we are the controller.
- Descriptive tagging sits on your side of the line. It runs on your material, for your benefit, as a feature you subscribed to, and you can ask us to remove the words at any time.
- If someone in one of your reference photographs asks who holds their picture and why, the answer for the picture is you, and we will help you answer them. The answer for the safety check is us, and section 8 tells them so directly.
1. What we collect and why
| Data | Examples | Why (lawful basis) |
|---|---|---|
| Account data | Name, email address, password (stored only as an irreversible hash), avatar, Google account identifier if you sign in with Google | To provide your account (contract) |
| Content you create | Projects, storyboards, notes and uploaded images | To provide the Service (contract). Your content is private to you and the people you share it with; we access it only for support at your request or as required by law |
| Billing data | Subscription plan and status, country for VAT. Card details go directly to Stripe; we never see or store them | Payment and legal obligations (contract; legal obligation) |
| Guest data | Name a guest provides when commenting or approving via a share link, and the comment or approval itself | This is your content and you are its controller; we hold it as your processor |
| Technical data | IP address, browser type, error reports, security logs | Security, fraud prevention and fixing faults (legitimate interest). Error reports are scrubbed of content and passwords |
| Usage data | Not collected today. If we ever add first-party product analytics we will update this policy first | It will never include advertising or cross-site trackers |
| Support correspondence | Emails you send us | Handling your request (legitimate interest) |
We do not sell personal data, run third-party advertising trackers, or use your content to train AI models.
Automated image tagging and the safety check
When you upload an image, it is sent to Anthropic's API, which returns descriptive words so the picture can be found by searching your library, together with a safety assessment under our Acceptable Use Policy. Tagging and script import are the only circumstances in which your material leaves our own hosting and storage.
What is sent. The picture, or a smaller rendition of it where one exists, with an instruction to describe it. No customer identifiers travel with it: no name, no email, no project title, no client name, no workspace.
How often. Once per picture. We record the attempt before the picture is sent, so the same picture cannot be sent twice, even by two parts of the software racing each other. If a call fails after that point, the picture is marked as unscanned and waits for a person to retry it rather than being resent automatically.
The words can describe people. The tags say what is in the frame, which includes the people in it. A picture may come back tagged "crew", "woman", "two men". These words are stored against the picture in your library so you can search for them. They are not names, we do not attempt to identify anybody, and nothing is matched against any other image or database. But a written description of a person is still information about that person, and you should know it is being created and kept.
What we tell it not to describe. A photograph can show things about a person that are nobody's business: their health, their religion, their ethnicity, who they love, what they believe. The model is instructed not to describe any of it, and separately we filter the words before they are stored, so that even if it does, we do not keep it. The safety check is the one exception, and only in one direction: to know whether an image is unlawful, it has to consider what is in it. That reading is kept only where there is a concern, only long enough to act on it, and nowhere near your search index.
The safety assessment records a flag, a category and a one-line note. Where an image is flagged, that note is an allegation about the content and we treat it as sensitive.
Our lawful basis. For making your own library searchable, tagging is part of the Service you signed up for, so our basis is performance of our contract with you. For anyone who happens to appear in a photograph you upload, and for the safety check that keeps unlawful material off the Service, our basis is legitimate interest: ours in running a lawful service, and every other customer's in not having their work sit alongside illegal material. We have assessed that interest against the rights of the people involved and recorded the assessment.
The safety check cannot be turned off. It is a condition of using the Service. We do not ask your consent for it, and nothing in this policy should be read as asking. It exists so that unlawful material is not hosted here, and a switch that let it be bypassed would be a switch for exactly the person we are checking for.
The descriptive tags are a different matter and you are in charge of them. They are a search feature, nothing more. You can ask us to delete the words we already hold, for one image, one project or your whole library, free and within one month. Removing tags does not remove the safety check: your images are still checked, and what goes is the searchable description. Tagged images removed of their tags are afterwards findable by filename and project name.
Decisions our software makes on its own
The safety check is made by software, and two of its outcomes take effect before a person is involved.
Where an image is flagged for review, it stays visible to you but is left out of share links and exports until someone has looked at it. Where an image is blocked, which happens only for suspected child sexual abuse material and only where the model expresses no doubt, it is withheld from everyone including you, immediately. We do that because we will not host such material while waiting for a person to be free, and because being able to say that is what lets us offer this Service at all.
A person always follows. Use the appeal button on the image, or email us. Someone reads every appeal, normally within one working day, and can clear the hold. You can tell us why you think we are wrong, and you can challenge what we decide.
Occasionally an image cannot be read by the check at all: an unusual file format, or a failure at our end. Those images stay visible to you, are marked in your library so you know, and are left out of share links and exports until we can read them. You can appeal those too.
Nothing here deletes your work. The machine can hide a picture; only a person can remove one.
Objecting
Objecting to the safety check. You can object, and so can anyone who appears in an image. We will consider every objection on its own facts, and we will tell you what we decided and why.
We should be straight with you about what we expect that answer to be. Preventing this Service from holding images that are unlawful to hold is, in our view, a compelling reason that outweighs the interests engaged in almost every case, so we expect to refuse most objections to the safety check. We would rather say that here than have you discover it. What we will not do is refuse without looking. If we do refuse, we will explain why in writing, and we will tell you that you can complain to the Information Commissioner at ico.org.uk or take the matter to court.
Objecting to the descriptive tags is different, and here we simply do what you ask: see the paragraph above on tag removal.
Requests should be sent to support@storybrdr.com. Where a person appearing in an image asks us directly, we will act on it in the same way and, where necessary, contact the customer in whose library the image sits.
Script import
If you paste a script into the import tool, the text goes once to Anthropic so it can be broken into scenes and shots. The suggestion comes back, becomes editable board content, and the paste is not kept as a separate copy. This happens only when you click the button; nothing is sent unless you ask for it. Scripts name people: characters, and often real cast and crew. Our lawful basis is performance of our contract with you, because you asked for the breakdown; for any real person named in a script, our basis is legitimate interest, assessed the same way as for photographs.
Anthropic's role. Anthropic is our sub-processor for descriptive tagging and script import, which we do on your instructions, and our processor for the safety check, which we do on our own. Either way it is bound by a data processing agreement and may use your material for nothing else. If we ever add or change a sub-processor we will update the table below and email account holders at least 30 days before the change takes effect, so you have time to object. If you object and we cannot resolve it, you may cancel and we will refund the unused part of what you have paid.
2. Who processes data for us
| Provider | Purpose | Location and notes |
|---|---|---|
| Vercel | Application hosting | EU/US (standard contractual clauses) |
| Neon | Database hosting | UK (London); your database never leaves the country |
| Cloudflare | File storage and delivery | EU jurisdiction, enforced; delivered via its global network |
| Stripe | Payments, invoices, VAT | Global; PCI-DSS certified; sees card data so we don't |
| Resend | Sending email (verification, resets, notices) | EU/US (SCCs) |
| Sentry | Error monitoring (content-scrubbed) | EU region |
| Anthropic | Image tagging, script import and the safety check | US; UK Addendum to the standard contractual clauses; not used for training |
The current sub-processor list is always the one on this page.
What leaves the UK, and what does not
We are a Cornish company and we have kept the important part close to home, so it is worth being specific rather than waving at "international transfers".
Your work is held in the UK and the EU. The database holding your projects, boards, notes and account lives in London and does not leave the country, backups included. Your uploaded image files are held on Cloudflare storage under an enforced EU jurisdiction restriction, not merely a regional preference, so they cannot be moved outside the EU; they are delivered to you from whichever Cloudflare location is nearest when you open them.
Two things cross the Atlantic, and only two. Anthropic (United States) receives customer content in two circumstances: images, when they are tagged and checked, and script text, if you use script import. A script is more directly identifying than most photographs, because it names characters and often cast and crew, so it is worth stating separately. If you do not use script import, no script of yours is ever sent. In neither case does Anthropic receive your name, your email, your account, or the name of your project or client, and in neither case is it told whose material it is. It does not use commercial API content to train its models, which is its stated default rather than a commitment we have extracted. Vercel and Resend (US/EU) run the application itself and send its email, so they handle the ordinary traffic of using a website: an email address on a verification message, an IP address in a server log.
The legal mechanism for both is the UK Addendum to the standard contractual clauses, the transfer agreement issued by the Information Commissioner. It is incorporated into our agreement with each provider, and it obliges them to protect your data to a UK standard and to resist requests for it that do not meet one.
What that mechanism does not do is make US law go away. A US company can, in principle, face a legal demand no UK company would. We think the risk to a storyboard is low, and the design limits it further: the only thing that ever crosses is a single picture or a pasted script with nothing attached to say whose it is. But you are entitled to know that the exposure is not zero rather than to be reassured that it is.
3. Cookies
We use only essential cookies: keeping you signed in and keeping the Service secure. We do not use advertising or cross-site tracking cookies, so no consent banner is required. If this ever changes, we will ask for consent first.
4. How long we keep data
- Account and content: while your account is active. When you close your account, it is deactivated immediately and permanently deleted within one month, including your content and personal data, except minimal records we must keep (for example invoices for tax law, kept 6 years).
- Deleted content: recoverable for 30 days, then permanently deleted, including removal of a deleted image from any boards it appeared on.
- Backups: our database keeps a rolling seven-day history, held in London with the database itself. Deleted data ages out of that history within seven days of deletion, after which no copy remains.
- Guest comments: retained with the project they belong to; a guest may ask us or the project owner to remove their name.
- Logs and error reports: up to 90 days.
5. Your rights
Under UK GDPR you can: access a copy of your data; correct it; delete it; restrict or object to processing; and port your data. The Service exports any board as a PDF and any shot list as a CSV at any time, including after a subscription has lapsed. A full export of your account, including original image files, and account deletion are both handled by us on request rather than self-service today; email us and we will complete either within one month. Contact support@storybrdr.com; we respond within one month. You can complain to the Information Commissioner's Office (ico.org.uk); we would appreciate the chance to resolve any issue first.
6. Security
Data is encrypted in transit (HTTPS) and at rest. Passwords are hashed, never stored or logged in readable form. Access to customer data is limited to the operator of the Service, only for support or legal reasons, and every such access is logged. Payment pages are hosted by Stripe. We will notify you and the ICO of any breach as required by law.
7. Children
The Service is not directed at children and requires users to be at least 16.
8. If you appear in a photograph on Storybrdr
You may be reading this because you were photographed on a location recce, at a casting session or on a shoot, and that photograph was uploaded here by the production.
We do not know who you are. We hold no name, no contact details, and nothing that could match a face to a person. We do not use facial recognition and we never have. That is also why we could not write to you to tell you we hold your picture: we have no way to reach you. The law allows us to publish this instead, which is what this section is.
Two things happen to a photograph you may be in. It is described in broad words so the production can find it again, words like "harbour", "two men", "golden hour". And it is checked automatically to make sure it is not unlawful material. The description is stored so it can be searched. Nothing else about you is stored, and nothing is used to work out who you are.
The production is in charge of the picture. We are in charge of the check. The photograph belongs to the company that uploaded it, and they decide what happens to it. The safety check is ours: we decided to do it and it cannot be turned off.
What you can ask for. Write to support@storybrdr.com. We will remove the descriptive words held against a photograph on request, free of charge and within one month. We will pass a request about the photograph itself to the customer whose library it sits in, and help them answer you. You can object to what we do, and section 1 explains how we handle that. You can complain to the Information Commissioner at ico.org.uk, or go to court.
One honest limitation. Because we hold nothing that identifies you, we may not be able to find a particular photograph from a description alone. If you can tell us the production, the date or the place, we have a much better chance.
9. Changes
We will notify account holders by email or in-product notice of material changes to this policy at least 30 days before they take effect.
Contact:Salt & Gorse Ltd, Bosnoweth, Higher Argal, Budock Water, Cornwall, England, TR11 5PE. Email support@storybrdr.com.