Skip to content
Storskarvia.by Aristocratix
Pricing Guides About Manual Sign in Start free

Privacy Policy

Last updated 1 October 2026

Storskarvia is a writing studio built on a simple promise: your manuscript lives in your storage, not ours. This policy explains what we collect, what we don't, who else touches it, and what you can ask us to do. It is written to be read, and it applies to everyone who uses Storskarvia, wherever they live.

Who we are

Storskarvia is a product of Aristocratix, LLC ("Storskarvia", "we", "us"), 2108 N St, Ste N, Sacramento, CA 95816, United States, operating the website and application at storskarvia.com. We are the data controller for the personal data described here. You can reach us about anything in this policy at .

Where your writing lives

When you create a document, you choose where its canonical copy is stored: your Google Drive, your Dropbox, or a folder on your own computer. That copy is yours. Storskarvia keeps a working copy on our servers only so the app can function: to render the editor, run fact-checks, produce insights, and let you browse version history. If you delete a document, we remove its working copy. Disconnecting a storage provider revokes our access to that provider and discards its tokens; the working copies stay until you delete the documents or your account.

Information we collect

  • Account information. Your email address, a securely hashed password, your plan, your settings, and whether you ticked the box to hear from us. We never store your password in readable form.
  • Your documents. The text and structure of documents you write, plus document metadata (titles, settings, comments, story-bible entries, timelines, research notes and files, and version snapshots), held as the working copy described above.
  • Fact-check data. When you run a fact-check, the document being checked is sent to our AI provider, and search queries built from it go to web-search sources, so claims can be verified; the resulting findings are stored with your document. We do not use passages to train anything. Our AI provider, DeepSeek, reserves the right in its own terms to use what it receives, after de-identification, to improve its services and models, and offers no way for us to switch that off for API traffic; see Service providers and International transfers below. Text is sent only when you press a button that asks for it: a fact-check sends the document being checked, plus a few short dated excerpts from the documents before it in the project, so it knows when the story is set; a continuity pass sends the document, the names in your story bible and the details it compares; "Populate from draft" sends up to the first 16,000 characters of the document you choose; a Research question sends your question and up to 400 characters you had selected; a lookbook image sends a description built from one story-bible entry and the house style you typed. Agent access keys, below, are the one route that does not need a button press.
  • Agent access keys. If you create a key under MCP access on your Account page, the AI assistant you connect with it can read the full text of your documents, ask us to look up sources on Wikipedia and web search for claims it picks, and save findings back to a document, depending on the permissions you gave the key. You choose that assistant, and its maker's terms govern what it does with your text. We store only a hash of each key, with its label, permissions and dates. Revoke a key on the Account page to close the route.
  • The free anachronism checker. A passage pasted into /anachronism-checker is sent to DeepSeek and to web-search sources exactly as a fact-check is, but it is never written to our database: it is held in memory while the check runs. The findings, which quote the lines they flag, are kept for 24 hours and then deleted. The daily allowance is counted against a keyed hash of your network address, and repeated refusals from one address are logged as abuse signals. We also count checks per day by where the visitor came from (the label in the link we tagged, or the name of the website that linked here), as totals that hold nothing about you or your passage. No account and no cookie are needed.
  • Storage connection tokens. If you connect Google Drive or Dropbox, we store the access and refresh tokens needed to save your files there, encrypted at rest.
  • Billing information. If you subscribe or buy a top-up, Stripe handles the payment and holds your card details. We keep your Stripe customer reference, what you bought, and the state of your subscription. We never see or store a full card number.
  • How you found us. Where you consent, or where consent is not required, the first page you view here is remembered in a cookie and recorded against your account if you sign up: the labels in the link if we tagged it (labels we wrote ourselves, such as the name of a campaign), the name of the website that linked to us (its domain only, never the page), the page you landed on (its path only, with any private link shortened to its section), and a referral code if the link carried one. Nothing else. It is also passed to our email provider with your address, so we can tell which campaigns and sites bring writers in.
  • Your measurement answer. Whether you said yes or no on the cookie banner.
  • Support correspondence. What you send us by email, and our replies.
  • Operational logs. Standard server logs (IP address, timestamps, request paths, browser type, error traces) used to keep the service running and secure, kept for 14 days. Sign-in attempts and rate-limit counters are kept briefly for abuse prevention.

Why we process it, and on what legal basis

For readers in the EEA, the UK and Switzerland, this is the legal basis for each use:

  • Providing the service you signed up for (the account, the editor, storage sync, fact-checks, exports, billing) rests on our contract with you.
  • Security and abuse prevention (logs, rate limits, fraud checks, keeping backups so your working copy survives a failure) rests on our legitimate interest in running a reliable, safe service.
  • Service messages (verification, password resets, receipts, payment problems, changes to these terms) rest on our contract with you and cannot be opted out of while you hold an account.
  • Marketing email is sent only with your consent, given by the checkbox at signup, and every such message has an unsubscribe link.
  • The campaign cookie and Meta's advertising pixel rest on your consent where the law requires it, as described under Cookies below.
  • Tax and accounting records of payments are kept because the law obliges us to.

How Storskarvia uses Google user data

If you connect Google Drive, Storskarvia requests a single, narrowly-scoped permission: drive.file: "See, edit, create, and delete only the specific Google Drive files that you use with this app." Concretely, this means Storskarvia can only touch the folders and files it creates for your Storskarvia documents. It cannot see, list, or access any other file in your Google Drive.

We use this access solely to save your documents (as .skarvia.json and .txt files), to write version snapshots, and to read a document back when you open it. Storskarvia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell or transfer it to third parties except as needed to provide the storage feature you asked for or as required by law, we do not allow humans to read it except with your consent, for security, or as required by law, and we do not use it to train generalized or artificial-intelligence models. Dropbox connections work the same way, limited to the Storskarvia files they create.

You can review or revoke Storskarvia's access to your Google Account at any time from Storskarvia's Account page, or directly at myaccount.google.com/permissions. Revoking access removes the stored tokens; files already saved to your Drive remain yours.

What we do not do

  • We do not sell your data or your writing, to anyone, ever.
  • We do not use your manuscripts to train AI models.
  • We do not read your connected cloud storage beyond the Storskarvia files it holds.
  • We do not show advertising on Storskarvia.
  • We make no decisions about you by automated means that have legal or similarly significant effects. Fact-check findings are suggestions about your text, and you decide what to do with them.

Cookies and measurement

Storskarvia sets a small number of cookies. None of them is used to build a profile of you, and none of them ever contains anything you have written. You can see and change your answer at any time on the Cookie preferences page, linked from every footer.

  • skarvia_session keeps you signed in. It lasts 7 days from your last visit and never more than 14 days from signing in, after which you are asked for your password again. Without it the site cannot work at all, so it is not optional.
  • sk_consent remembers your yes or no on the banner for six months, so we do not ask on every page.
  • sk_src remembers how you first arrived, for 30 days: the labels from a link we tagged, the domain of the site that linked to us, the page you landed on and any referral code. It is read once if you sign up. It is our own cookie on our own domain, and it holds nothing else.
  • _ga and _ga_… are set by Google Analytics, only after you have allowed measurement, so that a later page view can be counted as the same browser. They last up to two years and are removed when you answer no.
  • sk_new lives for two minutes after you create an account and tells the very next page to report one signup to the pixel, if you allowed it. Then it is gone.
  • Your theme (light or dark) is remembered in your browser's own storage and never reaches our server.

Our aggregate page-view counting (Cloudflare Web Analytics, described under Service providers) sets no cookie and stores nothing in your browser. Google Analytics, where you have allowed it, counts visits and the pages read; the IP address is truncated and nothing you write is ever part of it. Stripe sets its own cookies on its own checkout and billing pages; those are governed by Stripe's privacy policy, not ours.

Advertising measurement

We advertise Storskarvia in other places, and we would like to know which advertisement led to a signup. Where we run advertising we may load Meta's advertising pixel, which tells Meta that a browser visited a page here or created an account. That is a transfer to a third party, and under California law it counts as "sharing" for cross-context advertising, so:

  • In the EEA, the UK and Switzerland neither the pixel nor the campaign cookie is set unless you say yes to the banner. If we cannot tell where you are, we treat you as though you are in one of those places and ask anyway.
  • Everywhere, a no is honoured, and you can give it or change it on the Cookie preferences page. Saying no also removes the campaign cookie.
  • If your browser sends the Global Privacy Control signal, we treat it as a standing no: no pixel, no campaign cookie, and no banner.
  • Declining changes nothing about how Storskarvia works for you.
  • Your manuscripts, documents, research and fact-checks are never part of this. The pixel sees a page address and that an account was created.

Meta's own handling of that data is described in its privacy policy.

Service providers we rely on

To run the service we use these providers. Each receives only what its function needs, and each has its own privacy terms, which we link to or name so you can read them.

  • OVHcloud (France): the server the application and database run on.
  • Cloudflare (United States): network, DNS and attack protection. Cloudflare tells us which country a request comes from, which is how we know whether to show the banner. Cloudflare also provides our page-view counts (Cloudflare Web Analytics): a small script on each page reports the page address, the referring page, and the browser and device type. It sets no cookie, does not fingerprint the browser, and we see only aggregate numbers such as how many visits a page had. It never sees anything you write.
  • Stripe (United States): payments, subscriptions, invoices and the billing portal.
  • SentientMail, running on Amazon Web Services (United States): delivery of verification, reset, receipt and other service emails, and of marketing email you consented to.
  • DeepSeek (People's Republic of China): the AI model behind fact-checks, continuity passes, "Populate from draft" and Research questions. It receives the text each of those sends, as listed above, with any evidence gathered for it, and nothing about who you are. DeepSeek's Terms of Use (27 March 2026) say it may, "to a minimal extent", use inputs and outputs after de-identification to develop or improve its services; its Open Platform terms make no promise not to train on API data, and its privacy policy states that data is stored in the People's Republic of China. We checked these documents on 5 September 2026 and will change this paragraph if they change.
  • Brave Search and Exa (United States), plus public sources such as Wikipedia, and a search service we run ourselves that passes queries on to public search engines: web evidence for claim verification. They receive search queries derived from your passage, or a Research question as you typed it.
  • xAI (United States): image generation for lookbook portraits, when you ask for one. It receives a description built from one story-bible entry and the house style you typed, up to 1,000 characters, and not your manuscript.
  • Google and Dropbox: only if you connect them, and only for the files Storskarvia creates there. Our own database backups are also held, encrypted at rest by Dropbox, in a Dropbox account we control.
  • Meta (United States): advertising measurement, only with your consent as described above.

International transfers

We are a United States company and our providers are in the United States, France and, for the AI features, the People's Republic of China. If you are in the EEA, the UK or Switzerland, your data therefore leaves your region. Where a provider offers them, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) in that provider's data processing terms; and we send the minimum needed, so the AI step receives the text listed above (for a fact-check, that includes the short dated excerpts from earlier documents) and never your name, email or account. If you would rather no passage travel that way, do not run fact-checks, continuity passes, "Populate from draft", Research questions or lookbook images; the editor and everything else work without them. Nothing else you write leaves our servers for an AI provider, except what an AI assistant you connect with an agent access key reads, under that assistant's own terms.

Your choices and rights

  • Disconnect Google Drive or Dropbox at any time from your Account page; this revokes the stored tokens.
  • Export any project as a .zip, or your documents as DOCX, EPUB, PDF, Fountain, FDX, or plain text, whenever you like.
  • Delete a document to remove its working copy, or delete your whole account from the Account page. Deletion removes your account, your working copies, your findings and your stored tokens at once, cancels any subscription, and the last backup copies roll off within about two weeks. Files already in your own storage stay yours.
  • Change your measurement answer on the Cookie preferences page, and unsubscribe from marketing email with the link in any such message.

If you are in the EEA, the UK or Switzerland, you also have the right to access the personal data we hold about you, to have it corrected or erased, to receive it in a portable form, to restrict or object to certain processing, and to withdraw consent at any time without affecting what was done before. Write to and we will answer within one month. You may also complain to your local data protection authority.

If you are a California resident, you have the right to know what personal information we collect and how we use it (this policy), to delete it, to correct it, to opt out of sale or sharing, and not to be discriminated against for exercising these rights. We do not sell personal information. The only "sharing" we do is the Meta pixel described above, and you opt out on the Cookie preferences page or by sending the Global Privacy Control signal, which we honour. Requests to ; we will confirm receipt within 10 days and answer within 45. Residents of other US states with similar laws have the same rights and the same route.

Children

Storskarvia is not directed to children. You must be at least 13 to use it, and at least 16 if you are in the EEA or the UK unless a parent or guardian has agreed. If we learn we hold data from someone under those ages without that agreement, we will delete it. Write to if you think that has happened.

Data retention & security

We keep your working copy and account data for as long as your account is active, and remove them when you delete the account. Backup copies are kept for about two weeks and then removed. Web server logs are kept for 14 days. Records of payments are kept for as long as tax law requires. Passwords are hashed with bcrypt; storage tokens are encrypted at rest; traffic is served over HTTPS only and browsers are told to insist on it; sign-in is rate-limited; the application runs without administrative privileges. No system is perfectly secure, but keeping the canonical copy in your own storage means the most valuable thing, your finished words, is never solely in our hands. If a breach ever affects your data, we will tell you and the relevant authorities as the law requires.

Changes to this policy

If we make material changes we will update the date above and notify you by email or by a notice in the app before they take effect. Continuing to use Storskarvia after that date means you accept the updated policy.

Questions?

Field notes from the staff — occasional, worth reading.
Storskarvia · storskarvia.comAbout · Anachronism checker · Manual · Help · Terms · Privacy · Cookie preferences · SupportEvery writer deserves a staff
An Aristocratix project