STORAIVERSE™
HomeKids’ StoraisAdult StoraisGiftsAboutPricingFAQ
Create Your StoraiLogin

Your privacy, clearly explained

Privacy Policy

Storaiverse™ / StoraiBook™ · Version 4.0

Effective August 4, 2026Last updated August 4, 2026
Privacy PolicyTerms of Service

On this page

1. Scope and Who We Are2. Definitions and Relationship to the Terms3. Information We Collect4. How We Use Information5. Artificial Intelligence, Model Development, and Product Improvement6. Platform Data, Derived Insights, Aggregation, and De-identification7. Cookies, Analytics, Advertising, and Similar Technologies8. How We Disclose Information9. Public Features, Marketplace Activity, and User-Directed Disclosure10. Sensitive Data11. Children’s Privacy and Parental Controls12. Biometric, Facial, Voice, and Digital-Replica Information13. Retention and Deletion14. Security15. Your Choices and Privacy Rights16. United States State Privacy Disclosures17. International Users and Cross-Border Transfers18. Automated Processing and Profiling19. Third-Party Services and Links20. Business Transfers and Organizational Changes21. Changes to This Policy22. Contact UsAPPENDIX A — ILLUSTRATIVE DATA-PROCESSING MATRIX
PRIVACY AT A GLANCE

This Policy explains how Storaiverse Inc. collects, uses, derives, retains, shares, and otherwise processes information through Storaiverse™, StoraiBook™, and related services. The Services are adult-directed. Personalized Storais are private by default. We use information broadly to operate, personalize, secure, analyze, develop, market, and improve our business and technologies, subject to applicable law, required consent, and the specific restrictions stated in this Policy. Additional notices or consents may apply to children’s information, biometrics, digital replicas, Marketplace participation, subscriptions, and other specialized features.

Privacy contact: privacy@storaiverse.com

1. Scope and Who We Are

This Privacy Policy (“Policy”) describes how Storaiverse Inc., a corporation duly organized and existing under the laws of the State of Wyoming (“Storaiverse,” “Company,” “we,” “us,” or “our”), collects, uses, discloses, retains, derives, and otherwise processes Personal Information in connection with Storaiverse™, StoraiBook™, and all Company websites, applications, AI-assisted creation tools, personalization systems, ordering and subscription services, digital products, physical products, Marketplace features, customer support, communications, and related services (collectively, the “Services”).

This Policy applies when Company acts as a business, controller, or comparable decision-maker for Personal Information. It does not apply to information processed solely on behalf of an enterprise customer under a separate data-processing agreement, to independent third-party services, or to employment and applicant information covered by a separate notice.

The Services are owned and operated by Storaiverse Inc. Our registered office and registered agent address is 30 N. Gould Street, Suite R, Sheridan, Wyoming 82801, USA. Privacy requests may be submitted to privacy@storaiverse.com. General support inquiries may be sent to support@storaiverse.com.

This Policy should be read with the Terms of Service, applicable checkout disclosures, Marketplace Terms, cookie notices, biometric notices and releases, parental-consent materials, likeness releases, and other just-in-time notices. A more specific notice, consent, election, or agreement controls for the processing it expressly addresses. For collection, use, disclosure, retention, derivation, model development, service-provider processing, and other handling of Personal Information, this Policy and any more specific privacy notice or consent control over inconsistent general language in the Terms of Service, except that the Terms of Service continue to govern ownership, licensing, intellectual-property, payment, dispute, and other contractual matters.

2. Definitions and Relationship to the Terms

Capitalized terms not defined here have the meanings given in the Terms of Service. For consistency:

“Customer Content” includes photographs, video, audio, voice recordings, artwork, original text, names, biographical or family information, preferences, prompts, and other materials submitted, selected, uploaded, or provided by or for a customer.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, household, or device, as defined by applicable law.

“Sensitive Data” includes information subject to heightened legal protection, such as precise geolocation, government identifiers, account credentials, health information, biometric identifiers or information, and identifiable information concerning a child.

“Platform Data” means data generated or derived from operation of the Services, including usage metrics, performance data, classifications, error reports, quality signals, recommendation signals, statistics, metadata, embeddings, vectors, and aggregated or de-identified datasets. Platform Data may include Personal Information and remains subject to this Policy and applicable law.

“De-identified Data” means information processed so that it cannot reasonably be linked to an identified or identifiable individual, household, or device, considering technical safeguards, contractual restrictions, and information reasonably available to Company.

Characterizing information as Platform Data, inferred data, pseudonymous data, or derived data does not remove statutory privacy rights when the information remains Personal Information. Customer ownership of Customer Content does not create ownership of Company-created analytics, models, classifications, embeddings, vectors, metrics, de-identified datasets, or other Platform Data.

This Policy describes information-processing practices and does not limit, modify, transfer, or supersede ownership, licensing, intellectual-property, commercialization, operational, or contractual rights established by the Terms of Service, Marketplace Terms, releases, consents, or another applicable agreement. To the extent permitted by law, those documents and this Policy are intended to be read together and to provide Company the broadest lawful authority consistent with the applicable transaction, notice, consent, and Customer choice.

3. Information We Collect

A. Information You or Others Provide

Account and contact information, such as name, email address, postal address, telephone number, account credentials, language, age confirmation, and communication preferences.

Customer Content, including photographs, video, audio, voice recordings, artwork, text, names, family details, character traits, relationships, settings, preferences, prompts, exclusions, story instructions, and information about depicted persons.

Order, payment, subscription, tax, shipping, gifting, and transaction information. Payment-card information may be collected directly by payment processors rather than stored by Company.

Identity, age, parental-authority, rights-clearance, consent, release, tax, Marketplace, fraud-prevention, or compliance documentation.

Customer-service messages, feedback, survey responses, reviews, testimonials, complaints, dispute materials, and communications with Company.

Marketplace submissions, rights elections, creator profiles, payment instructions, tax forms, listings, promotional assets, and commercialization information.

Information supplied by another person on your behalf or about you, subject to the submitting user’s authority and applicable law.

B. Information Collected Automatically

Device, browser, application, network, operating-system, IP address, language, approximate location, time-zone, identifier, and configuration information.

Usage and interaction information, including pages or features viewed, clicks, searches, prompts, selections, generation events, edits, downloads, reading or listening activity, session duration, referrals, campaign attribution, and feature engagement.

Cookie, pixel, SDK, local-storage, advertising, analytics, and similar technology data.

Log, diagnostic, security, fraud, error, performance, quality, moderation, and audit information.

Uploaded File Metadata. Photographs, video, audio, documents, and other files may contain embedded metadata, including creation date, device information, camera settings, file characteristics, approximate or precise location, editing history, and technical identifiers. Company may process such metadata for personalization, chronology, organization, security, rights verification, quality assurance, troubleshooting, fraud prevention, service development, and other purposes described in this Policy. Users may remove metadata before upload where supported by their device or software.

Inferences, profiles, classifications, recommendations, similarity measures, embeddings, vectors, preference patterns, predicted interests, quality scores, and other data derived from information described in this Policy.

C. Information From Third Parties

Payment processors, carriers, printers, manufacturers, fulfillment providers, retailers, distributors, and Marketplace partners.

Authentication, identity-verification, age-assurance, parental-consent, fraud-prevention, sanctions-screening, and security providers.

Analytics, advertising, social-media, affiliate, referral, and marketing partners.

AI, hosting, cloud, storage, communications, moderation, translation, voice, image, and technology providers.

Public sources, rights databases, government records, professional advisers, claimants, law-enforcement agencies, and counterparties.

Corporate affiliates and parties involved in financing, investment, diligence, merger, acquisition, restructuring, bankruptcy, or asset transactions.

Third-Party Sign-In Services. If you use a third-party sign-in or authentication service, the provider may share your name, email address, profile image, account identifier, authentication token, and other information authorized through your provider settings. Company may use that information for authentication, account linking, fraud prevention, personalization, analytics, customer support, security, service development, and other purposes described in this Policy.

4. How We Use Information

To the extent permitted by applicable law, and subject to required notice, consent, choice, and purpose limitations, Company may collect, combine, organize, store, access, use, disclose, analyze, model, infer from, transform, pseudonymize, aggregate, de-identify, and otherwise process information for the following purposes:

Provide, operate, host, maintain, administer, authenticate, and support the Services.

Create, personalize, edit, illustrate, translate, narrate, format, manufacture, fulfill, ship, replace, reorder, and support Storais and related products.

Maintain Story Bibles, character profiles, continuity, relationships, preferences, prior assets, order history, sequel and series consistency, recommendations, and future-format compatibility.

Story Bible and continuity information may include Personal Information and Customer Content as well as Company-owned structures, schemas, metadata, classifications, continuity logic, derived data, generated assets, and Platform Data. Processing of such information does not alter the ownership and licensing allocation established by the Terms of Service.

Process payments, subscriptions, refunds, taxes, chargebacks, royalties, Marketplace payouts, accounting, auditing, and financial reporting.

Communicate about accounts, transactions, subscriptions, production, shipping, support, security, legal matters, policy changes, and customer requests.

Personalize content, interfaces, recommendations, search, prompts, offers, products, timing, messaging, and user experiences.

Conduct analytics, measurement, attribution, customer research, segmentation, forecasting, business intelligence, strategic planning, pricing, inventory planning, and operational optimization.

Develop, test, evaluate, validate, secure, improve, and troubleshoot products, workflows, Company AI Systems, recommendation systems, classifiers, moderation systems, safety tools, and other technologies, as further described below.

Protect users, depicted persons, Company, vendors, and the public; verify rights and consent; moderate content; detect fraud, abuse, infringement, security threats, unlawful conduct, and violations of the Terms.

Advertise and market Company products and services; measure campaigns; manage referrals, promotions, surveys, loyalty programs, and communications; and conduct targeted advertising where permitted and subject to applicable opt-out rights.

Review, publish, promote, distribute, license, sell, and otherwise administer Marketplace content only where the applicable Storai has been affirmatively submitted and accepted and the necessary Marketplace Terms, releases, and consents apply.

Establish, exercise, defend, investigate, or resolve legal claims; enforce agreements; respond to lawful requests; comply with law; and preserve evidence.

Support financing, investment, insurance, audit, diligence, merger, acquisition, reorganization, bankruptcy, asset sale, affiliate transfer, or other corporate transaction.

Create and commercialize aggregated, statistical, synthetic, or De-identified Data, derived insights, benchmarks, taxonomies, analytics, and other information that is not Personal Information under applicable law.

Carry out any other purpose disclosed at collection, reasonably compatible with the context in which the information was collected, authorized by the individual, or otherwise permitted by law.

Company may combine information collected through different Services, devices, accounts, brands, affiliates, and lawful sources. Company may use automation and human review together. Where applicable law requires separate consent for a materially different purpose, Sensitive Data, targeted advertising, sale, profiling, model training, or other processing, Company will seek that consent or provide the required choice before the processing occurs.

5. Artificial Intelligence, Model Development, and Product Improvement

The Services use AI Systems, automation, and human-assisted processes for generation, editing, illustration, translation, narration, personalization, recommendations, moderation, fraud prevention, safety review, quality assurance, and operations.

Company AI Systems

Company may use Company IP, Company-created content, synthetic data, De-identified Data, aggregated data, quality metrics, error labels, safety signals, workflow data, prompts or outputs that do not identify an individual, and other lawfully usable information to train, fine-tune, evaluate, test, validate, secure, and improve Company AI Systems and related technologies.

Subject to applicable law and the choices described in this Policy, Company may also use eligible Customer Content and associated interaction data for internal evaluation, quality assurance, error correction, abuse prevention, safety review, personalization, and improvement of the specific Services used by the customer. Company may use identifiable Customer Content for generalized AI-model training only where Company has provided clear notice and obtained any separate affirmative consent required by applicable law, the Terms of Service, Company policy, or the context in which the information was collected.

Sensitive and Child-Related Training Restrictions

Company will not use identifiable child Customer Content, biometric identifiers, biometric information, precise geolocation, authentication credentials, government identifiers, or other Sensitive Data for generalized AI-model training without separate, affirmative, informed opt-in consent specifically covering that use where required by law or Company policy. Refusal of optional training consent will not prevent use of core paid Services unless the relevant optional feature cannot technically be provided without that processing and the condition is clearly disclosed in advance.

Service Providers and Third-Party Models

Service providers may process Customer Content and Personal Information on Company’s behalf for documented, contracted, operational, developmental, safety, security, support, analytics, or other lawful purposes authorized by Company. Subject to applicable law, applicable customer choices, Company’s contractual commitments, and any restrictions Company elects to impose, providers may use such information to operate, support, secure, evaluate, test, improve, or develop services, models, systems, or technologies used for or made available to Company. Providers may use Customer Content or Personal Information for their own independent general-purpose models, products, or services only where the use is permitted by applicable law, consistent with applicable disclosures and consents, not prohibited by Company’s contract with the provider, and expressly authorized by Company. Company may impose additional contractual, technical, organizational, retention, deletion, confidentiality, security, audit, and use restrictions based on the information, provider, feature, jurisdiction, and business purpose.

Human Review

Authorized personnel and contractors may review limited content or related data when reasonably necessary for customer support, rights verification, safety, moderation, fraud prevention, quality assurance, debugging, evaluation, legal compliance, or improvement. Access is subject to role-based controls, confidentiality obligations, and other safeguards appropriate to the information and purpose.

6. Platform Data, Derived Insights, Aggregation, and De-identification

Company may generate Platform Data from operation of the Services. Subject to applicable law, Company may use, reproduce, analyze, combine, disclose, license, commercialize, and otherwise exploit Platform Data for lawful business purposes, including analytics, benchmarking, product development, quality measurement, recommendations, research, strategic planning, and development of Company IP.

Company may convert Personal Information into aggregated or De-identified Data and may use or disclose that data for any lawful purpose. Where required by law, Company will maintain and use De-identified Data without attempting to re-identify it and will require recipients to do the same. Where permitted by law, Company may conduct controlled testing designed to validate de-identification safeguards or may temporarily reconnect information to source records where reasonably necessary for security, fraud prevention, rights verification, legal compliance, correction of a material data-quality problem, or another lawful purpose consistent with this Policy. Any reconnected information will be treated as Personal Information and subject to appropriate access restrictions and applicable law.

Company will not represent data as de-identified where it remains reasonably linkable to an individual, household, or device. Company may license, disclose, commercialize, and otherwise use aggregated, statistical, synthetic, or De-identified Data to the fullest extent permitted by law, provided such use is not prohibited by applicable law, a binding consent, or a contractual commitment applicable to Company.

Company does not treat Customer Content in its original identifiable form as De-identified Data merely because it is indexed, encoded, embedded, classified, or transformed. Privacy rights continue to apply whenever information remains reasonably linkable to an individual, household, or device.

7. Cookies, Analytics, Advertising, and Similar Technologies

Company and its partners may use cookies, pixels, tags, SDKs, local storage, device identifiers, session-replay or interaction tools, and similar technologies to operate the Services; remember preferences; authenticate users; prevent fraud; measure performance; understand usage; improve features; conduct attribution; personalize content; and deliver or measure advertising.

Depending on the technology, partner, and jurisdiction, disclosure of identifiers, device information, commercial information, internet activity, approximate location, or inferences to advertising or analytics partners may be considered a “sale,” “sharing,” targeted advertising, or cross-context behavioral advertising under applicable law, even if no money is exchanged. Where required, Company will provide a “Your Privacy Choices,” “Do Not Sell or Share My Personal Information,” or comparable mechanism and will process recognized universal opt-out signals.

You may control certain technologies through Company’s cookie settings, browser settings, device controls, industry opt-out tools, or the privacy-choice mechanism made available through the Services. Blocking technologies may affect functionality. Consent-based cookies will not be activated before consent where applicable law requires prior consent.

Company does not knowingly sell or share Personal Information of children in a manner prohibited by law and does not use identifiable child information for targeted advertising without required parental authorization.

8. How We Disclose Information

Company may disclose information to the following categories of recipients for the purposes described in this Policy:

Corporate affiliates and entities that own, operate, support, administer, license, or provide portions of the Services.

Affiliates may process information as service providers, processors, joint controllers, independent controllers, business units, or successors, depending on the activity, corporate structure, and applicable law. Where legally required, Company will identify the relevant entity, allocate responsibilities, and provide additional notice or choice.

Cloud, hosting, storage, AI, image, voice, translation, moderation, analytics, communications, security, identity, age-assurance, parental-consent, fraud-prevention, customer-support, and other technology providers.

Payment processors, banks, card networks, subscription providers, tax services, accountants, auditors, insurers, and financial advisers.

Printers, manufacturers, fulfillment providers, carriers, customs agents, retailers, distributors, publishers, Marketplace operators, licensees, promotional partners, and other commercial partners necessary for requested transactions or authorized Marketplace activity.

Advertising, measurement, affiliate, referral, social-media, and marketing partners, subject to applicable consent and opt-out rights.

Professional advisers, claimants, counterparties, arbitrators, courts, regulators, law-enforcement agencies, government authorities, and other persons where reasonably necessary for legal compliance, rights protection, safety, or dispute resolution.

Investors, lenders, insurers, acquirers, sellers, advisers, and other transaction participants in connection with actual or proposed financing, diligence, merger, acquisition, restructuring, bankruptcy, asset sale, or transfer of the Services.

Other recipients at the individual’s direction, with consent, in connection with a requested integration, or as otherwise permitted by law.

Service providers and processors are permitted to use information only for contracted or legally permitted purposes. Some recipients act as independent businesses or controllers and process information under their own privacy policies.

9. Public Features, Marketplace Activity, and User-Directed Disclosure

Storais are private by default. Company does not publicly publish a private Storai merely because it was generated, saved, purchased, or included in a subscription.

If a customer affirmatively submits a Storai for Marketplace review and Company accepts it under applicable Marketplace Terms, Company may process and disclose the accepted Storai, authorized Customer Content, creator information, listings, previews, promotional materials, sales information, and related data for review, publication, advertising, retail, distribution, licensing, fulfillment, customer support, rights management, and wind-down. Separate releases or consents may be required for identifiable persons, minors, endorsements, testimonials, digital replicas, or other materially different uses.

Following Marketplace withdrawal, Company may continue processing, disclosing, licensing, and commercializing information and content as permitted by the Marketplace Terms, existing sublicenses, sell-off rights, legal obligations, applicable releases and consents, and the Terms of Service, including through fictionalized, de-identified, anonymized, adapted, or materially modified versions.

Information posted through public profiles, reviews, comments, testimonials, social features, or public Marketplace listings may be viewed, copied, indexed, or redistributed by others. Do not make information public unless you are authorized and comfortable doing so.

10. Sensitive Data

Company may process Sensitive Data only where reasonably necessary for a disclosed purpose, with consent where required, or as otherwise permitted by law. Categories may include account credentials; precise geolocation if a feature requires it; government identifiers for identity, tax, rights, or compliance purposes; health or accessibility information voluntarily supplied for personalization or support; biometric identifiers or information; and identifiable information concerning a child.

Company may use Sensitive Data to provide requested features, verify identity or authority, prevent fraud, maintain security, comply with law, protect users, process Marketplace or payment requirements, and fulfill other purposes specifically disclosed at collection. Company will not use Sensitive Data for an unrelated or materially different purpose without any additional notice or consent required by law.

Unless separately authorized and legally permitted, Company will not sell, lease, trade, or commercialize identifiable child information, biometric identifiers or biometric information, authentication credentials, government identifiers, private communications, identifiable photographs, or identifiable voice recordings as standalone data products.

11. Children’s Privacy and Parental Controls

The Services are intended for adults. Children may be depicted in or benefit from Storais, but they may not independently create accounts, enter contracts, or directly submit Personal Information unless Company expressly offers a compliant child-directed or mixed-audience experience.

An adult who submits information about a minor represents that the adult is the parent, legal guardian, or otherwise has legally sufficient authority and all required permissions. Company may request verification and may suspend processing, remove information, or decline a request if authority is uncertain.

Where Company has actual knowledge that it collects Personal Information online directly from a child under thirteen, or another protected age under applicable law, Company will provide required notice and obtain verifiable parental consent before collection, use, or disclosure unless a legal exception applies. Parents may be offered the ability to review, delete, correct, or prevent further collection or use of a child’s information, subject to identity and authority verification and lawful exceptions.

Company will not knowingly publicly publish, market, license, or commercially distribute a Storai containing an identifiable minor’s name, photograph, voice, likeness, biography, or other Personal Information without the parental or legal-guardian consents and releases Company determines are required. Company may remove, replace, fictionalize, or anonymize identifying details before publication.

Company retains identifiable child information only for as long as reasonably necessary for the disclosed purpose, subject to legal, safety, accounting, dispute, fraud-prevention, completed-transaction, and backup requirements. Company may require, and will obtain where legally required, additional parental or guardian consent, releases, verification, or authorization for targeted advertising, independent third-party disclosure, generalized model training, digital replicas, voice use, public promotion, or materially different uses.

12. Biometric, Facial, Voice, and Digital-Replica Information

Photographs, video, audio, and voice recordings may be processed to create illustrations, character renderings, voice stylizations, likenesses, personalized products, or other requested outputs. A photograph or ordinary recording is not necessarily biometric information. Whether information qualifies as biometric information depends on the technology used, the information extracted, the purpose, and applicable law. Extraction or use of face geometry, voiceprints, or other identifiers may trigger biometric laws.

Where legally required, before collecting or generating a biometric identifier, biometric template, or biometric information, Company will provide a separate written notice describing the collection, purpose, duration, use, disclosure, retention, security, and destruction practices and will obtain the required written release or consent. The separate biometric notice and release controls for that processing.

Company will not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information where prohibited by law. Company will not disclose biometric identifiers or information except with consent, to complete an authorized transaction, to service providers subject to appropriate restrictions, as required by law, or as otherwise legally permitted.

Company will maintain any legally required public retention and destruction policy. Unless a shorter period is required, biometric identifiers or information subject to such a policy will be permanently destroyed when the initial purpose has been satisfied or within three years after the individual’s last interaction with Company, whichever occurs first, subject to lawful preservation obligations.

Consent to create an illustrated likeness does not by itself authorize creation of a photorealistic digital replica, reusable face model, synthetic voice clone, reusable voice model, endorsement, or public promotional asset. Separate authorization may be required for those uses.

13. Retention and Deletion

Company retains information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services; maintain continuity; support reorders, subscriptions, warranties, and Marketplace activity; preserve security and fraud records; comply with accounting, tax, payment, recordkeeping, and legal duties; resolve disputes; enforce agreements; maintain backups; and protect rights.

Retention periods vary based on the type of information, sensitivity, customer settings, account status, transaction history, legal requirements, operational need, available deletion controls, and whether information has been aggregated or de-identified. Company may archive or delete inactive accounts, drafts, previews, generated assets, Customer Content, and incomplete projects under its retention practices. The Services are not an archival or backup service.

Deleting continuity, Story Bible, or similar memory information may permanently remove saved characters, relationships, preferences, prior assets, and project history and may prevent Company from recreating, reordering, continuing, or matching prior Storais.

Following a valid deletion request or account termination, Company may retain information reasonably necessary for completed products, previously authorized Marketplace activity, legal compliance, dispute resolution, fraud prevention, safety, accounting, tax, payment disputes, ordinary backup cycling, and enforcement of agreements. Company is not required to reverse completed transactions, recall distributed products, invalidate prior lawful disclosures, or delete information from backups before ordinary cycling unless law requires otherwise.

Certain tax, accounting, payment, order, subscription, fraud, chargeback, insurance, dispute, and legal records may commonly be retained for seven years or longer where reasonably necessary or required by law, subject to applicable retention limitations.

Aggregated or De-identified Data may be retained indefinitely where it is no longer Personal Information under applicable law. Company may also retain a suppression record sufficient to honor an opt-out or deletion request.

14. Security

Company uses administrative, technical, physical, and organizational safeguards designed to protect Personal Information, taking into account the nature and sensitivity of the information, the processing context, available technology, and cost. Measures may include access controls, authentication, encryption where appropriate, logging, vendor review, confidentiality obligations, monitoring, testing, backup, incident response, and data minimization.

No method of transmission, storage, or processing is completely secure. Company cannot guarantee absolute security. Users are responsible for protecting credentials, maintaining secure devices, avoiding unauthorized sharing, and promptly reporting suspected compromise.

Where required by law, Company will notify affected individuals and authorities of a qualifying security incident. Company may use contact and account information to deliver security notices and may take protective actions such as credential resets or access restrictions.

15. Your Choices and Privacy Rights

Depending on where you live and subject to legal exceptions, you may have rights to request access, confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, or an appeal; to opt out of sale, sharing, targeted advertising, or certain profiling; and to limit certain uses of Sensitive Data.

You may submit a request through the privacy-request method made available through the Services or by emailing privacy@storaiverse.com. Company may require information reasonably necessary to verify identity, residency, account relationship, authority, and request scope. Authorized agents may submit requests where permitted, subject to verification of the agent’s authority and the consumer’s identity.

Company may deny or limit a request where permitted by law, including when information cannot be verified, is exempt, is needed to complete a transaction, protect security, prevent fraud, comply with law, establish or defend claims, exercise free-expression rights, or conduct permitted internal uses. Company will provide an explanation and appeal instructions where required.

Company will not unlawfully discriminate against an individual for exercising privacy rights. Different prices, rates, levels, or quality may be offered where permitted, including through loyalty, subscription, or financial-incentive programs disclosed in separate terms.

Any loyalty, subscription, rewards, referral, discount, or financial-incentive program that is subject to special legal requirements may be governed by separate program terms or notices describing material terms, how to participate or withdraw, and any legally required explanation of the relationship between the benefit and the value of Personal Information.

Marketing and Communications

Company may collect and maintain email, SMS, push-notification, postal-mail, telephone, in-app, and other communication preferences, consent and opt-out history, and communication records. You may unsubscribe from promotional email using the link in the message, reply STOP to eligible marketing texts, adjust available preferences, or use another offered opt-out method. You may continue to receive transactional, account, security, legal, billing, subscription, and service communications.

Consent Withdrawal

Where processing is based on consent, consent may be withdrawn prospectively through the method stated in the applicable notice or by contacting Company. Withdrawal does not affect processing already lawfully completed and may prevent Company from providing a feature that requires the information.

16. United States State Privacy Disclosures

This Section supplements the remainder of the Policy for residents of U.S. states with comprehensive privacy laws, to the extent those laws apply to Company and the individual.

This Policy, together with any just-in-time notice presented at or before collection, is intended to provide disclosures required under applicable U.S. state privacy laws. Where a separate notice at collection, sensitive-data notice, or consent is required, Company will provide it at or before the relevant collection or processing.

Categories Collected, Used, and Disclosed

During the preceding twelve months, Company may have collected and disclosed for business or commercial purposes the categories described in this Policy, including identifiers; customer records; protected classifications where voluntarily supplied or inferred and legally permitted; commercial information; payment and transaction information; internet or network activity; approximate or precise geolocation; audio, visual, and similar information; professional or education information where relevant; Sensitive Data; and inferences. Sources and purposes are described in Sections 3 and 4, and recipient categories are described in Section 8.

Sale, Sharing, and Targeted Advertising

Company does not sell Personal Information for money as a standalone data-broker product. Company may, however, disclose identifiers, device information, commercial information, internet activity, approximate location, or inferences to advertising, analytics, affiliate, or social-media partners in ways that may be defined as sale, sharing, targeted advertising, or cross-context behavioral advertising. Residents with applicable rights may opt out through the privacy-choice mechanism provided through the Services or by using a recognized universal opt-out signal.

Company does not knowingly sell or share Personal Information of consumers under sixteen without any affirmative authorization required by law. Company does not use or disclose Sensitive Personal Information for purposes requiring a California right to limit unless disclosed through a separate notice and a legally compliant limitation mechanism is provided.

Appeals

Where required, a resident may appeal Company’s decision on a privacy request by replying to the decision or using the stated appeal method. Company will respond within the period required by law and provide any required regulatory complaint information.

California “Shine the Light”

California residents may request information about certain disclosures of Personal Information to third parties for their own direct-marketing purposes where applicable. Requests may be sent to privacy@storaiverse.com with “Shine the Light” in the subject line.

Metrics and Recordkeeping

Company may retain request records, verification materials, response logs, and related information for the period required by law and may publish request metrics if required.

17. International Users and Cross-Border Transfers

Company is based in the United States. Personal Information may be processed in the United States and other countries where Company, affiliates, vendors, or partners operate. Those countries may have privacy laws different from those of the individual’s jurisdiction.

Where required for transfers from the European Economic Area, United Kingdom, Switzerland, or other jurisdictions, Company may rely on adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum, approved certification frameworks, contractual safeguards, consent, performance of a contract, establishment or defense of claims, important public-interest grounds, or other lawful transfer mechanisms. Where required, Company will conduct transfer assessments, implement supplementary contractual, technical, or organizational safeguards, and execute applicable transfer documents with recipients.

Legal Bases

Where applicable law requires a legal basis, Company processes Personal Information based on one or more of the following: performance of a contract or steps requested before entering a contract; compliance with legal obligations; legitimate interests of Company or others, balanced against individual rights; consent; protection of vital interests; or another lawful basis. Legitimate interests may include operating and improving the Services, personalization, security, fraud prevention, analytics, customer support, marketing, business planning, rights protection, and corporate transactions.

EEA, UK, and Swiss Rights

Subject to applicable law, individuals may have rights of access, correction, erasure, restriction, portability, objection, and withdrawal of consent, and may complain to a supervisory authority. Objections to direct marketing will be honored as required. Where Company relies on legitimate interests, individuals may request information about the balancing assessment to the extent required by law and not legally privileged or confidential.

18. Automated Processing and Profiling

Company may use automated systems to personalize experiences, recommend content, detect fraud, moderate content, prioritize support, estimate preferences, assess quality, identify security risk, and assist Marketplace or operational decisions. These systems may use account, transaction, usage, content, device, and inferred information.

Company does not intend to make decisions producing legal or similarly significant effects solely through automation unless disclosed and permitted by law. Where applicable law grants a right to opt out of certain profiling or to obtain information, human review, or an appeal, Company will provide the required mechanism.

Automated tools may assist with Marketplace review, account or content restrictions, fraud holds, age assurance, identity or authority verification, payment screening, moderation, rights disputes, customer support prioritization, and quality assessment. Company may use human review, request additional information, or provide review or appeal mechanisms where required by law or Company policy.

Generated creative outputs, recommendations, moderation flags, age-assurance signals, fraud scores, and quality classifications may be imperfect. Company may use human review and may request additional information before taking consequential action.

19. Third-Party Services and Links

The Services may link to or integrate with third-party websites, applications, stores, payment systems, social networks, authentication tools, or other services. Those third parties may collect information directly and act under their own privacy policies. Company is not responsible for independent third-party privacy practices.

When a user directs Company to send information to a third party or activates an integration, Company may disclose the information reasonably necessary to fulfill the request. Disabling the integration does not require the third party to delete information already received; requests should also be directed to that third party.

20. Business Transfers and Organizational Changes

Company may disclose and transfer information in connection with an actual or proposed financing, investment, insurance placement, audit, diligence review, merger, acquisition, consolidation, reorganization, bankruptcy, receivership, asset sale, affiliate transfer, joint venture, outsourcing, or other corporate transaction. Recipients may use information to evaluate, negotiate, complete, integrate, administer, or operate the transaction and related business, subject to applicable law and contractual protections where appropriate.

If a successor or assignee becomes responsible for Personal Information, it may continue processing consistent with this Policy, applicable law, and any additional notice or consent required for materially different practices.

21. Changes to This Policy

Company may revise this Policy prospectively to reflect changes in the Services, technologies, business, vendors, laws, or processing practices. Company will post the revised Policy and update the “Last Updated” date. Additional notice, renewed consent, or a new choice will be provided where required for a material change, including materially expanded use of Sensitive Data, generalized training of identifiable Customer Content, targeted advertising, or public commercialization of private Customer Content.

Changes will not retroactively authorize public Marketplace publication of a private Storai, transfer ownership of Customer Content, or eliminate privacy rights that cannot lawfully be waived. Continued use after the effective date may constitute acknowledgment where permitted, but consent will not be inferred where affirmative consent is legally required.

22. Contact Us

Privacy inquiries and requests may be directed to:

Storaiverse Inc. Privacy Office 30 N. Gould Street, Suite R Sheridan, Wyoming 82801 USA Email: privacy@storaiverse.com

General support: support@storaiverse.com. Legal notices: legal@storaiverse.com. A privacy request sent to another address may be redirected to the Privacy Office.

Where legally required, Company will appoint and identify an EEA representative, UK representative, data-protection officer, or other regional contact. Current contact information will be posted through the Services or an applicable regional notice.

APPENDIX A — ILLUSTRATIVE DATA-PROCESSING MATRIX

This matrix summarizes common processing activities. Actual processing depends on the features used, customer choices, applicable notices, and law.

ActivityInformationPurposesTypical Retention Criteria
Accounts and authenticationContact details, credentials, device and security dataCreate and secure accounts; authenticate; prevent abuseAccount life plus security, legal, and backup periods
Storai creation and personalizationCustomer Content, prompts, preferences, Story Bible data, generated assetsGenerate, edit, personalize, maintain continuity, support reorders and sequelsWhile needed for the feature, account, order, continuity, legal, or backup purposes
Orders and subscriptionsContact, payment, shipping, tax, order and billing dataProcess transactions, fulfill, renew, refund, account, prevent fraudTransaction life plus tax, accounting, chargeback, warranty, and legal periods
AI safety and improvementEligible content, interactions, labels, errors, quality and safety signalsEvaluate, secure, debug, improve, and develop Company systemsAs needed for evaluation, product development, legal, and de-identification purposes
MarketplaceAccepted Storai, creator, rights, tax, payout, listing, sales and promotional dataReview, publish, distribute, market, license, pay, support, and wind downMarketplace term plus sell-off, tax, audit, legal, and archival periods
Analytics and marketingDevice, usage, campaign, commercial and inferred dataMeasure, attribute, personalize, advertise, research, and optimizeAs configured by technology, consent, opt-out, and business need
Security and legalLogs, identifiers, communications, evidence, verification and dispute dataPrevent fraud, investigate, enforce, comply, defend claimsAs needed for security, limitation periods, legal holds, and compliance
Biometric-enabled featuresBiometric identifiers or information where generatedProvide the expressly disclosed feature; verify or personalize where authorizedUnder the separate biometric policy and applicable law
STORAIVERSE™

Storai's that last a lifetime.

© 2026 Storaiverse / Storaibook. All rights reserved.

Explore

Kids’ StoraisAdult StoraisStorai Gifts

Company

Our StoraiPricingFAQ

Legal

Privacy PolicyTerms of Service