Junior Modesomeone is using Storyus

What we know, and why

Privacy Policy

Current version · effective 26 July 2026 · The data controller is See More Potential Ltd, trading as Storyus

The short version

  • We collect what running a family archive needs: your email, your username, and the stories and photos you upload - and very little else.
  • No advertising, no selling data, no tracking cookies. The only cookies are the ones that keep you signed in.
  • Your photos keep their embedded details (dates, sometimes places) - that's what powers timelines, albums and journey maps.
  • A small set of outside services store and deliver your content - the principal ones are listed below.
  • You can ask for a copy of your data, or ask us to delete it: [email protected].

1. Who's responsible

The data controller for Storyus (storyus.life) is See More Potential Ltd, trading as Storyus, registered in England and Wales, company number 06669823, registered office: The Old Counting House, 82e High Street, Wallingford, Oxfordshire, OX10 0BS, United Kingdom. Storyus is operated from the United Kingdom, is aimed primarily at people in the UK, and this policy is written to UK data-protection law. Anything in this policy you want to ask about, or any of your rights you want to use: [email protected].

2. What we collect

  • Your account: your email address, your chosen username, and your password - stored only as a secure hash, which means we can't read it.
  • Your content: the stories, photographs and videos you upload, including the metadata embedded in photos (capture dates, camera details and sometimes location). We keep that metadata because Storyus's features - timelines, albums that build themselves, journeys drawn on maps - run on it.
  • Memberships and roles: which collectives you belong to and your role in each, plus an audit trail of membership changes - kept so a family archive's history of who-could-see-what is answerable.
  • Things your family adds about you: Storyus can hold information about you that someone else put there - photographs you appear in, stories that mention you, or your email address, entered by a family member to invite you. The person sharing chooses to add it; this policy covers how we look after it, and you can contact us about it whether or not you have an account. Invitations that are never accepted expire (currently after 14 days).
  • Technical logs: standard server logs (IP address, request, time), kept briefly for security and debugging.
  • The waiting list: if you joined it, your email address lives in Mailchimp and is used only for Storyus news, until you unsubscribe.
  • Reports, help and ideas: if you report content we hold the report (the link, what you told us, and your email address if you left one) and what we decided about it. If you write to us through Help & ideas we hold the conversation, its status, and a note of which collectives you belonged to and your role in each at the time you wrote - that context is how we understand what you could and couldn't see. Ideas you send are kept on record with their status. If you email us instead, we keep the correspondence.
  • Junior authors: if a guardian sets up junior authoring for a child, we hold what the guardian provides: the child's display name (typically just a first name), an optional birth year, which collective the byline belongs to, who the child's guardians are, and - where one is reserved - the child's future username, kept in a reservation register together with a record of which guardians approved what, and when. The guardian's Junior Mode PIN is stored only as a secure hash. That is the whole record: no email address, no date of birth, no profile. Section 8 says more.
  • Records that keep things answerable: which terms version you accepted and when; sign-in and security events; follow and access requests (including the relationship note you write with a request); and export requests.

Of all this, only the account basics are required - without an email address, a username and a password we can't provide an account. Everything else is there because you or your family chose to add it.

3. Why we use it

We process personal data to run the service you asked for (our contract with you): storing and showing your stories to the people you chose, and sending the emails an account needs - password resets, invitations, membership changes. We also process some data in our legitimate interest of keeping Storyus secure and free of abuse. News and marketing go only to people who consented by joining the waiting list - and that consent can be withdrawn at any time: every email has an unsubscribe link, or just tell us.

We do not use your data for advertising, we do not profile you, we do not sell data to anyone, and we do not use your content to train AI models.

Activity by activity, the legal bases look like this:

What we're doingLegal basis
Your account and the service you asked forContract
Security, abuse prevention and protecting the serviceLegitimate interests
Handling reports, and reports the law requires us to makeLegal obligation (and legitimate interests)
Family content that includes people without accountsLegitimate interests, carefully weighed
Junior authoring, set up and controlled by a guardianContract with the guardian, and legitimate interests, weighed with the child's best interests first
Waiting-list newsConsent
Records of acceptance, decisions and disputesLegitimate interests / legal claims

One more honesty: family stories are intimate. What you write can reveal things like health, faith or heritage - about you and about your family. We don't ask for any of that and we don't mine your stories for it; it simply lives inside your content, governed by the privacy level you chose. Where data-protection law asks more of us for this kind of information, meeting that is our job, not yours.

4. Who helps us run Storyus

Storyus runs on a small set of outside services. Most are processors: they handle data for us under contract, only on our instructions:

ServiceWhat it does for Storyus
RailwayRuns the application
MongoDB AtlasHosts the database
Amazon Web Services (S3)Stores your original photos and videos
CloudinaryResizes and delivers images
MuxProcesses and streams video
ResendSends account emails
CloudflareContent delivery, security and DNS
MailchimpWaiting-list emails only

A few others don't process data on our behalf: they're services your browser fetches directly when a page needs them, so they see the standard technical data any web request carries (such as your IP address):

ServiceWhy a page loads it
Google FontsThe site's typefaces
jsDelivrThe video player used on our marketing and guide pages
Google Cast (gstatic.com)Loaded by that video player so videos can be cast to a TV

These are our principal providers. If the set changes in a way that matters, this policy changes with it.

5. Where your data lives

Some of these providers process data in the United States and other countries outside the UK. Where they do, the transfers are protected by UK-approved safeguards - the UK International Data Transfer Agreement or Addendum, or the UK–US Data Bridge where the provider is certified. If you'd like a copy of the safeguard that applies to a particular provider, email [email protected].

6. How long we keep things

Account data lasts as long as your account does. Your content stays until you (or your collective's admins, within their role) delete it, or you ask for it to go - plus a short period while backups cycle out. Server logs are kept only as long as security and debugging need them. The membership audit trail is kept for the life of the collective it describes - it's the archive's record of who could see what. Reports and safety records are kept as long as the law and the fair handling of complaints require. The record of which terms version you accepted lasts as long as your account, and afterwards for as long as legal claims could arise. Signups that are never confirmed are removed after 14 days.

To close your account, email [email protected]. We'll delete your account and profile data, except anything the law requires us to keep. Stories you authored in a shared collective remain part of that family's archive by default - tell us if you'd rather they were removed, when you close your account or at any time (see the Terms, section 11).

7. Your rights

UK data-protection law gives you rights over your personal data: to access a copy of it, to correct it, to have it deleted, to restrict or object to how it's used, and to take it with you (portability). Email [email protected] and we'll help.

Two of those deserve their own line. You can object at any time to processing we base on legitimate interests, and we'll stop unless we have compelling grounds that override yours. And portability is built in: your settings page includes a full export of your stories and media, no email needed.

You can also complain to the Information Commissioner's Office (ico.org.uk) - though we'd ask you to talk to us first, so we can try to put it right.

8. Children

Storyus accounts are for people aged 13 and over. Children younger than that appear in Storyus the way they appear in any family album - in stories and photographs uploaded by the adults in their family, who are responsible for what they share about their children. The privacy levels mean most family content is never public at all: a new story defaults to collective visibility, and public is always a deliberate choice. Photographs can carry location details; those are governed by the same privacy level as the story they're in.

Younger children can also tell stories, through guardian-managed junior authoring. The design is data-minimising from the ground up:

  • A junior author is a byline, not an account. The child holds no credentials; a guardian hands over a device in a supervised, PIN-locked Junior Mode, and everything done there happens under the guardian's account.
  • The record is what the guardian provides - a display name, an optional birth year, and optionally a reserved future username - and it exists only to show the byline and run Junior Mode (see section 2).
  • Stories made in Junior Mode are visible to the family collective or kept private. A guardian can widen one later as far as guest level; junior-bylined stories cannot be made public, so a child's name does not appear as an author on the open, indexable internet.
  • In Junior Mode the child's view is narrowed too: only their own collectives, no private stories, no settings or administrative pages.
  • Story forms built on location data are excluded from Junior Mode: a child can't make a journey (a story told on a map from photo locations), so Junior Mode never assembles a map of a child's whereabouts. Externally hosted video is excluded too.
  • The future-username reservation register exists only to keep a reserved name safe and its history answerable. It is never a directory, is never public, and is only ever touched through guardian-controlled actions.
  • Guardians manage the record from their settings - renaming, adding a co-guardian, or removing the junior author - and can contact [email protected] about the child's data at any time.

9. Cookies

Storyus sets only essential cookies: the signed cookie that keeps you logged in (it lasts 30 days), a session cookie if an admin uses the "view as" preview, a signed cookie while a device is in Junior Mode, and - for developer accounts only - a one-minute cookie that shows a newly created API token once. No analytics cookies, no advertising cookies, no third-party trackers - which is why there's no cookie banner to click.

10. Security

Storyus runs over HTTPS everywhere; passwords are stored only as secure hashes; access to content is governed by each story's privacy level and each member's role; membership changes are audited; and we build on reputable infrastructure providers. No system on earth is perfect - if a breach ever affects your personal data, we'll tell you, and the ICO, as the law requires.

11. Changes to this policy

When this policy materially changes we'll publish the new version here and update the version and date at the top. Significant changes will be flagged in the product.

See More Potential Ltd, trading as Storyus · registered in England and Wales, company no. 06669823 · The Old Counting House, 82e High Street, Wallingford, Oxfordshire, OX10 0BS, United Kingdom
Terms & Conditions · Report content · [email protected]