Privacy Policy
Last updated: 8 October 2026
Storyvote is built to need as little personal data as possible: there are no accounts, and you only give a display name. This policy explains what we process, why, and the rights you have.
In short: we store only what you type into a room (your display name, the room's stories and votes) and delete it as soon as the host ends the session, or automatically 7 days after the room was last used.
1. Who is responsible for your data
Storyvote ("we", "us") is the controller of your personal data. For any privacy question or request, write to storyvoteapp@gmail.com.
Storyvote is a non-commercial project run by Daniel Grynyk, a private individual in Poland.
2. What we collect
What you enter in a room
- Your display name and a random participant ID created by your browser. Use a nickname if you prefer; it doesn't have to be your real name.
- Room content: the room name, stories (titles and ticket keys), votes, saved estimates, the chosen deck and disciplines, and who is the host or a facilitator.
- Room password, if the host sets one. We store only a salted scrypt hash, never the password itself.
A single cookie
Your browser keeps your participant ID and display name in one strictly necessary cookie that is deleted when you close the browser. See our Cookie Policy.
Technical data
Like every website, Storyvote receives your IP address, browser type (user agent), the address of the page you request and the time of the request. Our hosting provider's servers record these in access logs, which are kept for 7 days. Our application also holds your IP address in memory for about one minute to limit the number of requests (rate limiting). We don't use any of this to profile you.
Messages you send us
If you email us, we receive your email address and whatever you choose to write.
What we don't collect
No email address or password for an account (there are no accounts), no payment details (Storyvote is free), and no access to your chats, calendars, files, Jira or Azure DevOps. Storyvote currently uses no analytics or advertising tools.
3. Who can see what you enter
Anyone with a room's invitation link (and its password, if one is set) can join and see the room name, the stories, the participants' names and, once a story is revealed, each person's vote. In an anonymous room, nobody sees who voted what, only how many people picked each card. Treat the invitation link like a meeting link and share it only with your team.
4. Why we process your data and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing planning poker rooms you create or join | Display name, participant ID, room content, cookie | Art. 6(1)(b): performing our agreement with you (the Terms) |
| Keeping Storyvote secure and preventing abuse | IP address, user agent, request details | Art. 6(1)(f): our legitimate interest in a secure, available service |
| Answering your messages and complaints | Email address, message content | Art. 6(1)(f): our legitimate interest in responding to you |
| Meeting legal obligations | Data required by the specific obligation | Art. 6(1)(c): compliance with a legal obligation |
Giving us your name is voluntary, but you need some name to take part in a room. We don't make any decisions about you by automated means and don't profile you.
5. How long we keep it
- Room data (names, stories, votes, password hash): deleted immediately when the host ends the session, and otherwise automatically 7 days after the room was last used. Email us the room code if you want it deleted sooner.
- Cookie: until you close your browser.
- Access logs: 7 days. Rate-limiting data: about one minute.
- Emails: as long as needed to handle your request, and no longer than 12 months after it is resolved, unless the law requires longer.
6. Who we share it with
We share data only with these service providers, which process it on our instructions:
- Railway Corporation (USA) hosts the application and its database in its US West (California) region. Railway is SOC 2 Type II certified.
- Google (Gmail) hosts our mailbox, storyvoteapp@gmail.com, so it receives the messages you send us.
We disclose data to public authorities only when the law requires us to.
7. Transfers outside the EEA
Because our servers are in the United States, your data is transferred outside the European Economic Area. These transfers are protected by the European Commission's Standard Contractual Clauses (Art. 46 GDPR), which are part of Railway's Data Processing Agreement. You can ask us for a copy. Emails you send us may be stored by Google in the United States; Google is certified under the EU-U.S. Data Privacy Framework.
8. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- have inaccurate data corrected (you can also rename yourself in any room);
- have your data erased;
- restrict how we process it;
- receive it in a portable format;
- object to processing based on our legitimate interests;
- lodge a complaint with a supervisory authority: in Poland, the President of the Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority where you live or work.
To exercise a right, email storyvoteapp@gmail.com. Since there are no accounts, please include the room code and the display name you used so we can find your data. We reply within one month.
9. Children
Storyvote is a tool for work teams and is not intended for children under 16. We don't knowingly collect their data.
10. Security
We protect your data with encryption in transit, a hardened application and minimal data collection. Read more on our Security page.
11. Changes to this policy
If we change this policy, we'll update the date at the top of this page. We'll announce significant changes on the site before they take effect. If we start using new services that process personal data, such as analytics or advertising, we'll update this policy first and ask for your consent where the law requires it.