Privacy Policy
Last updated: 7 октября 2026 г.
Story Checker (story-checker.com) checks e-learning courses and produces a bug report. This page states exactly what the service collects, where it is stored, for how long and who touches it. When the system changes, this page changes with it.
1. What we collect
- Account details: your email address and display name.
- Workspaces: the workspace name, its members and their roles, and the email addresses of people invited.
- Course files uploaded for a scan: the published package (ZIP), the .story file and a script, whichever you upload.
- Scan results: the findings, including the course title, slide numbers and short quotes of on-slide text, plus "intentional" marks and any notes written on them.
- Screenshots of slides, shown next to each finding, and the full HTML report.
- Usage counters (scans, bytes uploaded) and a workspace activity log, for quotas, security and support.
Your IP address is used for rate limiting, in server memory only; it is not stored in the database.
2. Where it is stored
- Account, sign-in, workspaces and findings: Supabase, in the EU (Frankfurt, eu-central-1).
- Course files, screenshots and reports: the disk of a Google Cloud virtual machine in Frankfurt (europe-west3).
Files are not kept in any other third-party file storage.
3. How long
- Uploaded course files are deleted when each scan ends, whether it succeeded or failed. A nightly cleanup removes anything left behind for any reason.
- Screenshots and HTML reports are kept for 30 days, then deleted.
- Findings and scan details are kept until the workspace or the account is deleted.
- Account details are kept until the account is deleted.
4. During a scan
The course runs in an isolated browser on our server. Every attempt by the course to reach an address on the internet is blocked and measured, and the report ends with an evidence line listing what was attempted and blocked (net_audit).
The isolation is at the browser level: the scanning server itself has an internet connection, like any server. We say so plainly instead of claiming an air gap we do not have.
5. Subprocessors
These providers process data on our behalf, each only for the purpose listed:
- Supabase: database, sign-in and account management (EU, Frankfurt).
- Google Cloud: the server that runs the site and the scans and stores the files (Frankfurt).
- Resend: sending email, such as workspace invitations.
- Let's Encrypt: the site's TLS certificate (the encrypted connection). Receives no personal data.
If you choose to sign in with Google, Google takes part in that sign-in under its own privacy policy.
7. Your rights
Under the GDPR and applicable privacy law you have these rights over your data:
- Access: get a copy of the data we hold about you.
- Correction: fix data that is wrong.
- Deletion: delete your account and your data. Workspace owners can also delete a workspace from its settings.
- Export: receive your data in a machine-readable format. You can export the findings of any scan yourself as CSV or JSON.
For any request: privacy@story-checker.com. We answer within 30 days. You may also complain to your data protection authority.
8. Changes to this policy
When this policy changes, the date at the top changes. For a material change we will notify you by email or on the site before it takes effect.