The promises below are not policy aspirations. Each one is enforced by the product itself, and the legal pages that back them are published, not buried.
Every page a client or crew member opens is built from a separate, deny-by-default list of fields. Your private notes, your team's discussion, your other boards and your library are not hidden behind a setting on those pages: the data simply never leaves the building. A new field stays internal until someone deliberately adds it to what guests receive.
A share link can carry a password, an expiry date, or both. Turning one off works instantly, and even the images inside are re-checked against the link on every single request, so a revoked link cannot keep serving pictures from a cache. A link that has been turned off can never be brought back: you make a new one, on your terms.
A lapsed subscription makes the workspace read-only: everything you made stays visible, existing share links keep working, clients can still comment, and you can still export a PDF of any board. Nothing is deleted and nothing is watermarked. Editing resumes the moment the subscription does.
Deleting your account removes projects, boards and pictures permanently, confirmed by an emailed link so a stolen laptop session cannot destroy an account by itself. Deleted items wait 30 days before they are gone for good, and our rolling backups age out within days after that. Erasure requests are honoured and the process is rehearsed, not just written down.
Your data is stored in the UK and Europe. Payments are handled by Stripe; card numbers never touch Storybrdr. Uploads are scanned for illegal material, with a human review behind every automated decision. The full detail lives where it should:
When a client approves a board, the approval records the name they gave, the time, and a fingerprint of the board exactly as it stood. If the board changes afterwards, the approval says so. Six months later, nobody argues about which version was signed off.