Your client's work, treated
like your client's work.

The promises below are not policy aspirations. Each one is enforced by the product itself, and the legal pages that back them are published, not buried.

What a guest can never see

Hidden means absent, not disguised

Every page a client or crew member opens is built from a separate, deny-by-default list of fields. Your private notes, your team's discussion, your other boards and your library are not hidden behind a setting on those pages: the data simply never leaves the building. A new field stays internal until someone deliberately adds it to what guests receive.

  • Your production notes never reach a share link of any kind
  • The client's page carries no director's note. The editor's bible does, deliberately: that is the one link made for the edit
  • The crew's day link carries the plan and progress, and cannot carry commentary
  • One client's email address is never shown to another
Links you stay in charge of

Turned off means off

A share link can carry a password, an expiry date, or both. Turning one off works instantly, and every picture inside is re-checked against the link on every single request rather than handed out on a signed address that outlives it. The one thing no server can reach is a frame already sitting in somebody's own browser cache, which can hold for up to an hour. A link that has been turned off can never be brought back: you make a new one, on your terms.

  • Links are stored scrambled. Even we cannot read one back
  • Crew day links expire by themselves a day after they are made
  • Every link shows how often it has been opened
Restricted members

Restricted projects are restricted at the server

If a member is limited to named projects, the projects, images and people outside those jobs are not sent to them. They are not simply hidden in the interface. Owners and admins can also see who was invited, removed or changed, and when.

How Teams and project access work →

Approvals that hold up

A record, not a screenshot

When a client approves a board, the approval records the name they gave, the time, and a fingerprint of the board exactly as it stood. If the board changes afterwards, the approval says so. Six months later, nobody argues about which version was signed off.

If you stop paying

Read-only, never ransom

A lapsed subscription makes the workspace read-only: everything you made stays visible and you can always take a PDF of any board. Nothing is deleted, ever, and nothing is watermarked. Share links stop working and comments pause until you subscribe again, and then everything, including your links, comes back exactly as it was.

Deleting and leaving

Your work leaves when you do

Deleting your account removes projects, boards and pictures straight away, confirmed by an emailed link so a stolen laptop session cannot destroy an account by itself. Things you throw away inside the product work the other way round: they sit in the trash for 30 days so you can change your mind, then go for good, and the database's rolling recovery window ages out days after that. Erasure requests are honoured and the process is rehearsed, not just written down.

The unglamorous parts

Where things live

Your boards and your pictures are stored in the UK and Europe. Three suppliers can process data in the United States under standard contractual clauses, and the privacy policy names all three and says exactly what each one sees. Payments are handled by Stripe; card numbers never touch Storybrdr. Every picture you add to a board, a moodboard or your library is checked for illegal material: a hold takes the picture off share links and exports straight away, only a person can lift one, and you can ask us to look again. The full detail lives where it should:

Questions we haven't answered?

Ask before you trust us with a job. We'd do the same, and a person reads every email.

support@storybrdr.com