Privacy Policy

Last updated: 8 October 2026

Storyvote is built to need as little personal data as possible: there are no accounts, and you only give a display name. This policy explains what we process, why, and the rights you have.

In short: we store only what you type into a room (your display name, the room's stories and votes) and delete it as soon as the host ends the session, or automatically 7 days after the room was last used.

1. Who is responsible for your data

Storyvote ("we", "us") is the controller of your personal data. For any privacy question or request, write to storyvoteapp@gmail.com.

Storyvote is a non-commercial project run by Daniel Grynyk, a private individual in Poland.

2. What we collect

What you enter in a room

  • Your display name and a random participant ID created by your browser. Use a nickname if you prefer; it doesn't have to be your real name.
  • Room content: the room name, stories (titles and ticket keys), votes, saved estimates, the chosen deck and disciplines, and who is the host or a facilitator.
  • Room password, if the host sets one. We store only a salted scrypt hash, never the password itself.

A single cookie

Your browser keeps your participant ID and display name in one strictly necessary cookie that is deleted when you close the browser. See our Cookie Policy.

Technical data

Like every website, Storyvote receives your IP address, browser type (user agent), the address of the page you request and the time of the request. Our hosting provider's servers record these in access logs, which are kept for 7 days. Our application also holds your IP address in memory for about one minute to limit the number of requests (rate limiting). We don't use any of this to profile you.

Messages you send us

If you email us, we receive your email address and whatever you choose to write.

What we don't collect

No email address or password for an account (there are no accounts), no payment details (Storyvote is free), and no access to your chats, calendars, files, Jira or Azure DevOps. Storyvote currently uses no analytics or advertising tools.

3. Who can see what you enter

Anyone with a room's invitation link (and its password, if one is set) can join and see the room name, the stories, the participants' names and, once a story is revealed, each person's vote. In an anonymous room, nobody sees who voted what, only how many people picked each card. Treat the invitation link like a meeting link and share it only with your team.

4. Why we process your data and on what legal basis

PurposeDataLegal basis (GDPR)
Providing planning poker rooms you create or joinDisplay name, participant ID, room content, cookie Art. 6(1)(b): performing our agreement with you (the Terms)
Keeping Storyvote secure and preventing abuseIP address, user agent, request detailsArt. 6(1)(f): our legitimate interest in a secure, available service
Answering your messages and complaintsEmail address, message contentArt. 6(1)(f): our legitimate interest in responding to you
Meeting legal obligationsData required by the specific obligationArt. 6(1)(c): compliance with a legal obligation

Giving us your name is voluntary, but you need some name to take part in a room. We don't make any decisions about you by automated means and don't profile you.

5. How long we keep it

  • Room data (names, stories, votes, password hash): deleted immediately when the host ends the session, and otherwise automatically 7 days after the room was last used. Email us the room code if you want it deleted sooner.
  • Cookie: until you close your browser.
  • Access logs: 7 days. Rate-limiting data: about one minute.
  • Emails: as long as needed to handle your request, and no longer than 12 months after it is resolved, unless the law requires longer.

6. Who we share it with

We share data only with these service providers, which process it on our instructions:

  • Railway Corporation (USA) hosts the application and its database in its US West (California) region. Railway is SOC 2 Type II certified.
  • Google (Gmail) hosts our mailbox, storyvoteapp@gmail.com, so it receives the messages you send us.

We disclose data to public authorities only when the law requires us to.

7. Transfers outside the EEA

Because our servers are in the United States, your data is transferred outside the European Economic Area. These transfers are protected by the European Commission's Standard Contractual Clauses (Art. 46 GDPR), which are part of Railway's Data Processing Agreement. You can ask us for a copy. Emails you send us may be stored by Google in the United States; Google is certified under the EU-U.S. Data Privacy Framework.

8. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy of it;
  • have inaccurate data corrected (you can also rename yourself in any room);
  • have your data erased;
  • restrict how we process it;
  • receive it in a portable format;
  • object to processing based on our legitimate interests;
  • lodge a complaint with a supervisory authority: in Poland, the President of the Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority where you live or work.

To exercise a right, email storyvoteapp@gmail.com. Since there are no accounts, please include the room code and the display name you used so we can find your data. We reply within one month.

9. Children

Storyvote is a tool for work teams and is not intended for children under 16. We don't knowingly collect their data.

10. Security

We protect your data with encryption in transit, a hardened application and minimal data collection. Read more on our Security page.

11. Changes to this policy

If we change this policy, we'll update the date at the top of this page. We'll announce significant changes on the site before they take effect. If we start using new services that process personal data, such as analytics or advertising, we'll update this policy first and ask for your consent where the law requires it.