Security

Last updated: 8 October 2026

Your team's estimates deserve care. Here is how Storyvote protects them, and how to report a problem if you find one.

Collect less, keep less

The safest data is data we never have. Storyvote has no accounts, so there are no passwords or email addresses to steal, and no payment details because it's free. A room holds only display names, stories and votes, and it is deleted as soon as the host ends the session, or automatically 7 days after it was last used.

Encryption in transit

Everything between your browser and Storyvote, including the live connection that carries votes, is encrypted with HTTPS (TLS). Browsers are told to always use HTTPS for Storyvote (HSTS).

Votes stay secret until the reveal

Votes are kept on our server and are not sent to other participants' browsers until the cards are revealed, so they can't be read early, even with developer tools. In anonymous rooms, individual votes are never sent to anyone; everyone receives only the totals per card.

Room access

  • Room codes are generated with a cryptographically secure random generator, from about 28 million possible codes.
  • For extra protection, hosts can set a room password. We store it only as a salted scrypt hash, and a connection that enters a wrong password five times is blocked.
  • Permissions are enforced on the server: only the host can change the room's settings or end it, and only the host and facilitators can manage stories and reveal votes.

Infrastructure

Storyvote runs on Railway, a cloud platform that is SOC 2 Type II certified, in its US West region. The application reaches its database over Railway's private network, and credentials are kept in Railway's environment settings, never in source code. Access to the production environment is limited to the operator.

Application safeguards

  • A strict Content Security Policy: the site loads only its own scripts, with no third-party code.
  • Security headers on every response, and rate limiting against abuse.
  • Input length limits on everything you can type.
  • Error messages that never reveal internal details.
  • Automated tests and a dependency vulnerability check run on every change to the code.

What you can do

  • Share invitation links only with your team, as you would a meeting link.
  • Set a room password for sensitive sessions.
  • Don't enter confidential information in story titles; a ticket key such as PROJ-123 is usually enough.

Reporting a vulnerability

If you believe you've found a security issue, email storyvoteapp@gmail.com with "Security" in the subject, a description of the issue and steps to reproduce it. We'll acknowledge your report within 3 business days, keep you updated, and credit you once it's fixed if you'd like.

Please act in good faith: don't access or change other people's data, don't run denial of service or social engineering attacks, and give us reasonable time to fix the issue before disclosing it. We won't take legal action against research done this way.

How we handle personal data is described in our Privacy Policy.