Policies

Privacy Policy

This policy explains what Storyframe collects, why, who we share it with and the choices you have. It covers UK GDPR, EU GDPR and the CCPA.

Last updated July 25, 2026 · Governed by the laws of England and Wales

Who is responsible

Storyframe is operated by HEEHAW LIMITED(“we”, “us”), the data controller for personal data described here. You can reach us at:

Storyframe is an online-only digital service (software as a service). There are no physical goods, no shipping and no delivery of any physical product, and we provide no on-site services.

What we collect

You give us

  • Account data — name, email and password credentials when you register.
  • Pitch and project inputs — the one-line pitches, choices (platform, length, format, tone) and any project notes you enter.
  • Support and enquiry data — messages you send through the contact form, the series briefing form or by email.
  • Billing details — the billing name, address and email you enter at checkout (card data is handled by our payment processor, not by us — see the payments section).

We collect automatically

  • Usage and device data — pages viewed, actions in the studio, approximate region, browser and device type, and diagnostic logs.
  • Cookies and similar technologies — see the Cookie Policy.

Collection sources

Our collection sources are limited and transparent. We collect personal data from the following sources:

  • Directly from you — when you register, type a pitch or project notes in the studio, contact us, or enter billing details at checkout.
  • Automatically from your use of the service — usage, device and diagnostic data gathered as you interact with the site, and cookies as described in the Cookie Policy.
  • From our processors — for example, our payment processor confirms that a subscription is active, and our hosting provider generates security logs.

We do not buy personal data from data brokers and we do not enrich your profile with third-party datasets.

Why we use it and our legal bases

  • To provide the studio and your account — generating scripts, storyboards, shot lists and previews, and saving your projects. Legal basis: performance of a contract.
  • To take payment and manage subscriptions — billing, receipts, renewals and cancellations. Legal basis: performance of a contract; legal obligation for tax records.
  • To support you — answering messages and resolving issues. Legal basis: legitimate interests and contract.
  • To keep the service secure and improve it — preventing abuse, fixing faults and understanding aggregate usage. Legal basis: legitimate interests.
  • To send service messages — essential notices about your account or plan. Legal basis: contract and legitimate interests. Marketing email, if any, is sent only with your consent and you can opt out anytime.

AI data handling: your input, generated output and uploads

Because Storyframe is an AI-assisted tool, this section explains exactly how your AI data is handled — the user input you provide, the generated output we return, and any files or example data involved.

User input

  • User input means the one-line pitch and the platform, duration, format and tone choices you enter, plus any project notes. We process this user input only to produce the plan you asked for.
  • Your input is stored with your saved projects so you can return to and edit them. You can delete any project, which removes its input from active storage.
  • Transient copies of your input may be cached briefly for performance and are cleared on a rolling basis.

Generated output

  • Generated output means the script, storyboard panels, shot list, schedule and animatic preview the tool produces. Storyboard sketches are drawn procedurally in your browser; any optional AI enhancement runs on the server.
  • Generated output is stored with your project so you can revisit and export it, and is deleted when you delete the project or close your account.
  • You own your generated output as set out in the Content License.

File uploads and example data

  • If we add file uploads or example datasets, they are used only to produce your requested output, are retained only as long as needed for that purpose, and are deletable by you.
No training on your data

We do notuse your user input, generated output, uploaded files or example data to train machine-learning models, and we do not sell or share them for others’ training. Where optional AI enhancement is enabled, your prompt is sent to the provider only to return your result.

Payments boundary

Payments are processed by Stripe. Card numbers, CVC and full card details are entered on Stripe’s secure checkout and are never seen or stored by Storyframe. We receive only limited confirmation data — such as the last four digits, card brand, billing country and subscription status — needed to service your account. Stripe acts as an independent controller for the payment data it collects; see Stripe’s own privacy notice for details.

Who we share it with

We share personal data only with processors and partners that help us run the service, under contract and only as needed:

  • Hosting & infrastructure — our cloud hosting and content-delivery provider.
  • Payments — Stripe, for checkout, subscriptions and the customer portal.
  • Email & support — our email/transactional messaging provider.
  • Database & storage — our managed database and file storage provider for accounts and projects.
  • AI provider — where optional AI enhancement is enabled, the provider processes the specific prompt to return a result and does not receive your account credentials.
  • Analytics — privacy-conscious, aggregate analytics as described in the Cookie Policy.

We may also disclose data to comply with the law, enforce our terms, or in connection with a business transfer. We do not sell your personal data.

International transfers

We are based in the United Kingdom and serve users worldwide. Some processors are located outside the UK or EEA. Where data is transferred internationally, we rely on appropriate safeguards such as UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or adequacy decisions, so your data receives an equivalent level of protection.

How long we keep it

  • Account & projects — kept while your account is open; deleted on request or after account closure (subject to short backup cycles).
  • Billing records — retained for the period required by tax and accounting law (typically up to seven years).
  • Support messages — kept for up to 24 months after resolution.
  • Diagnostic logs — kept for a short rolling window, then deleted or aggregated.

Security

We use encryption in transit, access controls, least-privilege practices and secret management for API keys. Payment keys and provider credentials are held server-side and are never exposed to the browser. No system is perfectly secure, but we work to protect your data and to notify you and regulators of a qualifying breach as required by law.

Your rights

Depending on where you live, you have rights over your personal data:

  • UK & EU (GDPR) — access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent.
  • California (CCPA/CPRA) — to know, access, delete and correct personal information, and to opt out of “sale” or “sharing” (we do neither).

To exercise any right, email support@heehawuk.shop. We will not discriminate against you for exercising your rights.

Do Not Sell or Share

We do not sell your personal information and we do not share it for cross-context behavioural advertising. There is nothing to opt out of on that basis; if this ever changes, we will provide a clear opt-out and update this policy first.

Cookies and analytics

We use strictly necessary cookies to run the site and keep you signed in, and limited, aggregate analytics to understand usage. You control non-essential cookies through your browser and our cookie controls. Full detail is in the Cookie Policy.

Automated decisions and children

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Storyframeis not directed at children under 13, who may not use it. Users aged 13–17 must have consent from a parent or guardian. If we learn we have collected data from a child under 13, we will delete it.

Complaints and contact

Questions or requests: support@heehawuk.shop. If you are in the UK you may also complain to the Information Commissioner’s Office (ICO); in the EEA, to your national data protection authority; in California, you may contact the California Privacy Protection Agency. We ask that you contact us first so we can help.

This policy was last updated on July 25, 2026.