Legal

Privacy Policy

what we collect, why, and what we never do

Version of 30 July 2026.

The short version

  • Readers can play any story without an account. No sign-up, no name, no email. This is the default, and it is what classrooms should use.
  • We never sell personal data and we run no advertising on Skaz.
  • A story only collects what its author put in it. If there is no input block asking for a name or an email, none is collected.
  • Session replay is off. We do not record screens, keystrokes or what readers type.
  • You can ask us to delete your data at any time by writing to privacy@skaz.io.

1. Who we are

Skaz ("we", "us") operates the story editor at studio.skaz.io and the player at skaz.io (together, the "Service"). For the data described in Section 3 we are the data controller. Contact: privacy@skaz.io.

This policy is written to meet the standard set by the EU General Data Protection Regulation (GDPR) and the UK GDPR. Where your local law gives you stronger rights, those rights apply.

2. Two roles, two sets of data

Skaz has two kinds of user, and the difference matters for privacy:

  • Authors — people who sign up and build stories. We hold an account for them.
  • Readers — people who open a published story link and play it. They need no account.

For author accounts, we are the controller. For anything a story itself asks its readers — a name, an email, a quiz answer typed into an input block — the author is the controller and we act as their processor: we store it and show it back to them, and we do not use it for our own purposes. See Section 6.

3. What we collect

3.1. Author accounts. First and last name, email address, password (stored only as a hash, never in readable form), country, date of birth, chosen language, plan and subscription status. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

Date of birth is collected for one narrow purpose: to check that someone is old enough to publish or open a story marked 18+. It is not used for profiling or advertising.

3.2. Story content. The text, images, branches and variables you create. Yours; we store it so the Service works.

3.3. Play sessions. When anyone plays a published story, we record the playthrough: which blocks were visited, which choices were taken, timestamps, the values of the story's own variables, and whether the session finished or was abandoned. This is what powers the author's sessions view. For an anonymous reader this data is tied to a session identifier, not to a person.

3.4. Reader identity — only when the author asks for it. An author can mark a story as requiring sign-in. Only then is a reader asked to sign in, shown an explicit consent checkbox stating that their email will be shared with the author, and only after they tick it does the author see it. No checkbox, no email. Legal basis: consent (Art. 6(1)(a) GDPR), withdrawable at any time.

3.5. Technical data. IP address and browser user-agent are processed by our servers and hosting provider to deliver the Service and to keep it secure and available. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).

3.6. Product analytics. We use PostHog to understand how the Service is used — pages viewed, stories started and finished, features used. Session replay is disabled, so no screen recording and no capture of what anyone types. Signed-out readers are not given a persistent person profile. Legal basis: legitimate interests, or consent where your jurisdiction requires it for analytics cookies.

4. What we never do

  • We do not sell or rent personal data to anyone, for any purpose.
  • We do not run advertising on Skaz, and we do not build advertising profiles.
  • We do not record your screen or your keystrokes.
  • We do not use story content or reader data to train AI models. Text you send to the AI co-writer is passed to our model provider to answer that request and is not used by us to train anything.
  • We do not require a reader to identify themselves unless the story's author has switched that on.

5. Schools, teachers and students

Skaz is usable in a classroom without collecting anything about a student:

  • A published story plays from a link. Students need no account, no email and no name — hand out the link and they play.
  • Leave the story's "requires sign-in" option off and no reader identity is collected at all. What the author sees is an anonymous session: the path taken and the variables the story itself tracked.
  • If you do add an input block that asks for a name or an email, you decide that and you become the controller of that data — so only ask for what your school actually permits, and prefer a nickname or a seat number to a real name.

Under FERPA (20 U.S.C. § 1232g), a school that uses Skaz in the default, no-account way discloses no education records to us, because none are provided. If your institution needs a data processing agreement, a school-specific addendum, or answers for a vendor review, write to privacy@skaz.io and we will work through it with you.

Author accounts are not intended for children: you must be at least 13 to create one, and at least 18 to create or open a story marked 18+.

6. Data an author collects through a story

Where a story gathers reader data through input blocks or the sign-in requirement, the author decides why and what for, and is the controller of that data. The author must have a lawful basis, tell readers what they are collecting, and honour readers' rights. We process that data only to operate the Service and to display it to that author, and we delete it when the author's story or account is deleted.

If you are a reader and want data removed that an author collected about you, contact the author first. If you cannot reach them, write to privacy@skaz.io and we will help.

7. Who we share data with

We use a small number of processors, each bound to act only on our instructions:

  • Hosting and storage — to run the servers, the database and uploaded images.
  • PostHog — product analytics, as described in 3.6.
  • Email delivery — to send verification and account emails.
  • AI model provider — only for text you deliberately send to the AI co-writer.
  • Payment provider — once paid billing is live, card details go to the payment provider and never touch our servers.

We also disclose data where we are legally required to, and where it is necessary to protect someone's life or safety. Some processors are located outside the EEA and the UK; such transfers rely on Standard Contractual Clauses or an adequacy decision.

8. How long we keep it

  • Account data — while your account exists, then deleted or anonymised within 30 days of deletion.
  • Story content — until you delete the story or your account.
  • Play sessions — while the story exists, so its author can see how it performs.
  • Analytics — retained by PostHog according to our project retention settings.
  • Records we must keep by law (for example billing records) — for the period the law requires.

9. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or hand it to you in a portable format. Where processing rests on consent, you can withdraw that consent at any time without affecting what happened before.

Write to privacy@skaz.io. We answer within 30 days. If you are in the EEA or the UK you also have the right to complain to your national data protection authority.

10. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as hashes, never in readable form. Access to production data is limited to the people who need it to run the Service. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as the law requires.

11. Cookies

We set a session cookie to keep you signed in — without it, accounts cannot work. PostHog sets an analytics cookie to distinguish visits. We use no advertising cookies and no third-party trackers beyond the processors listed in Section 7.

12. Changes

We will post any new version of this policy at https://skaz.io/privacy and change the date at the top. If a change materially affects your rights we will tell account holders before it takes effect.

13. Contact

Privacy questions, data requests, school reviews: privacy@skaz.io

Everything else: support@skaz.io

Content reports: abuse@skaz.io