GDPR Compliance Statement
Storyraise and the GDPR
Storyraise Technology Inc. is a United States company. All customer data is processed and stored in the United States on Google Cloud Platform. Storyraise does not market to or target individuals in the European Economic Area, and our customers are primarily US-based organizations.
We recognize that our customers' constituents may include EEA residents, and we support our customers, who act as data controllers, in meeting their own obligations. Storyraise acts as a data processor for the personal data our customers upload, and we apply GDPR-aligned principles across the platform.
Purpose limitation
We process personal data only to provide the service, on the customer's instructions. We do not sell personal data, and we do not share it with advertising networks or data brokers.
Data minimization
Personalized report delivery returns only the individual recipient's own record. Reporting and analytics are aggregate. AI-assisted features are optional and user-initiated, and send only the content in scope for the request.
Security of processing
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256), provided by Google Cloud.
- Access rules scoped to each customer organization, and role-based access control within it.
- Platform audit logs retained in Google Cloud Logging.
- An active security assessment and remediation program, including formal penetration testing against the OWASP Top 10 with findings tracked to closure.
Data subject rights
We support access, correction, export and deletion of personal data at the customer's direction. Constituent records export to CSV and reports export to PDF, so a customer can retrieve their data in a portable form at any time. On a customer's instruction we will delete personal data and certify that processing has stopped, including at our subprocessors.
Retention
We retain personal data for as long as the customer maintains it in the service. Retention is directed by the customer as data controller; we do not impose a separate retention period, and we delete data on the customer's instruction.
Subprocessors
We use the following subprocessors, and hold each to data processing terms:
| Subprocessor | Purpose |
|---|---|
| Google Cloud Platform / Firebase | Hosting, database, storage, authentication |
| Google BigQuery | Analytics processing |
| OpenAI | AI-assisted content features |
| Anthropic | AI assistant for Data Mapping, when an organization has allowed it |
| SendGrid | Transactional email |
| Resend | Transactional email (invitations and notifications) |
| Mailjet | Transactional email |
| Unsplash | Stock imagery |
| Cloudinary | Image transformation and delivery for report imagery |
| WorkOS | Single sign-on identity brokering (user email and identity assertion only) |
AI-assisted features are optional and user-initiated. Where they are used, the content submitted may include personal data contained in the customer's own material, and it is processed under the provider's commercial API terms. We will update this list before adding a subprocessor that processes personal data.
Breach notification
We comply with applicable breach notification laws and will notify affected customers without undue delay after becoming aware of a personal data breach.
Data processing agreements
Storyraise will enter into data processing agreements, including EU Standard Contractual Clauses where required, with customers whose compliance programs require them.
Contact
Questions about this statement or our privacy practices: privacy@storyraise.com
Last updated: October 2, 2026