Skip to content
thestory.runWe're launching, and gathering feedback as we go. Tell us what works and what doesn't, we're glad to hear it.
TeamsFeaturesPricingManifesto
Start for free

Privacy Policy

Last updated: 11 September 2026

This policy covers two things, and they are governed differently. The Site is the marketing website at thestory.run and its help centre. The App is the product at app.thestory.run, which people use through their employer.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

Who is responsible for what

For the Site and the early-access list, Swat.io GmbH is the controller within the meaning of the GDPR. It decides what is collected and why, and it answers your requests itself.

For use of the App by the employees of an organisation, that organisation is the controller. Swat.io GmbH processes the resulting data solely as a processor, on its instructions, under a Data Processing Agreement. Direct requests to your own organisation; a request that reaches us is forwarded there.

For the payment and invoicing data of a paying customer, Swat.io GmbH is the controller, as is its payment provider (section 5.1).

Section 2 covers the Site, section 3 the App.

1. Data controller

The controller for the Site is Swat.io GmbH, an Austrian company. Full contact details are listed in our Imprint.

For data protection inquiries, including requests to access, correct or delete your data, write to lab@swat.io. If you use the App through your employer, address your organisation’s administrator, who is the controller.

2. The Site

2.1 Analytics

When you visit the Site, our analytics tool records page visits, clicks, scroll behaviour, and performance metrics. It is cookieless, your IP address is not stored, and no profile is built about you.

In the App the same tool records what you do, not what you write: which screens you open, which controls you press, and errors the app encountered. Your ideas, drafts and coach conversations are never sent to it, and it stores nothing on your device.

The App identifies you to the tool by name, email address, interface language and organisation. That is the complete list. Nothing from your ideas, drafts or coach conversations is attached to it.

The App’s feedback box is provided by the same tool. Text you enter there is sent to PostHog. Nothing else you write in the App is.

2.2 Where a signup came from

A link from the Site to the App’s sign-in carries which page you clicked it on, any campaign parameters in the address you arrived with, and the host of the referring website (for example google.com, never the page or your search terms).

We store this with the sign-in request in our own database (Frankfurt) and record it once against the account in the analytics tool in 2.1. Nothing is stored on your device.

3. The App

Here we act on your organisation’s instructions. This is what the App holds.

3.1 Your account

  • Email address: how you sign in. There is no password; we email a single-use link, whose token is stored only as a hash.
  • Your name and, if you upload one, a picture: shown to colleagues.
  • Sessions: for each signed-in session, the time, the IP address and the browser’s user-agent string, so you can review your open sessions and end any you do not recognise. The session token is stored only as a hash.

3.2 What you write

Your ideas, drafts, finished pieces, coach conversations, and the wins you choose to share. Within your organisation, colleagues see a finished or published piece, never an unfinished draft.

3.3 The coach

The coach sends the text you are working on to Anthropic’s Claude models via Amazon Bedrock under an EU inference profile, so the request stays within EU regions. Under AWS’s terms, inputs and outputs are not used to train models. Conversations are retained so you can return to a draft. See section 4.

3.4 Your LinkedIn connection

If you connect LinkedIn, we store four things: your LinkedIn person identifier, your LinkedIn profile name, a copy of your LinkedIn profile picture, and an access token. The token is encrypted at rest, bound to your account, and never displayed to anyone. We request four permissions (openid, profile, email, w_member_social). We cannot read your LinkedIn feed, connections, messages, or posts written elsewhere.

Disconnecting deletes all of it immediately: the token, the identifier, the name, and the LinkedIn post identifiers of anything published through us.

3.5 Your organisation

Membership and role, your teams, campaigns, and a log of actions taken in the organisation (who published, who changed a campaign), readable by administrators. Coordination views show topics and timing, never anybody’s unfinished text.

4. How we use AI

Where AI is used. In one place: the coach. It reads the text you are working on and answers with questions, notes, and marks on your own sentences. It also writes a whole post for you in the one case you deliberately ask it to, which the product calls a cheat.

Who supplies the models, and where they run. Anthropic’s Claude models. By default the call goes through Amazon Bedrock under an EU inference profile, so it stays within EU regions, and under AWS’s terms inputs and outputs are not used to train models.

An organisation may instead supply its own Anthropic key, so that its coaching runs on its own account rather than ours. Its coach calls then go to Anthropic PBC in the United States instead of to Bedrock, under the organisation’s own agreement with Anthropic and its own terms. Your organisation’s administrator chooses this; if you want to know which way yours is set, ask them.

Your writing is not training data. Not for us, not for the model providers. We do not use anybody’s ideas, drafts, coach conversations, or published pieces to train a model, and we do not permit our providers to. This is a contractual commitment in the Data Processing Agreement, not just a preference.

AI-generated text is labelled, permanently. When you ask the coach to write a post for you, that post is marked as written by the coach. The mark cannot be removed, including by rewriting the text afterwards. Everything else you write is marked as yours.

No decision is made about you by a machine. See section 7.

5. Where your data is processed

Our processors, and where they run. Unless stated otherwise, everything is in the European Union.

Amazon Web Services EMEA SARL (AWS)
Hosting and database for the App, transactional email, and file storage for pictures: all in eu-central-1 (Frankfurt). Static hosting and CDN delivery for the Site. The coach's model calls run on Amazon Bedrock under an EU inference profile. AWS privacy notice.
PostHog, Inc. (United States, EU Cloud)
Product and site analytics. Processing and storage take place exclusively in the EU Cloud (Frankfurt), under a data processing addendum. The company is American, so the Standard Contractual Clauses of the European Commission apply to any access from the USA. PostHog privacy policy.
Slack Technologies, LLC (optional, United States)
Only if your organisation's administrator connects Slack. Then the App can post a short notice into your own Slack workspace: the topic of a piece and who published it, never the text of anybody's writing. Not connected means nothing is sent. The transfer to the USA is based on certification under the EU-US Data Privacy Framework. Slack privacy policy.
LinkedIn Ireland / LinkedIn Corporation (United States)
Only when you press publish. The text of that post and your identity go to LinkedIn so it can appear on your profile, which is the point of the action. This is a transfer on your own instruction (Art. 49(1)(a) GDPR), and the post is public by nature.

5.1 Billing: Stripe

Stripe is listed separately because it is not our processor. For the processing of payments, Stripe acts as an independent controller: it decides its own anti-money-laundering checks, fraud detection, PSD2 obligations, and card-scheme rules, and it answers for them itself.

Stripe receives the paying customer’s billing and payment data, not the writing of anybody using the App. Card numbers never reach us: payment is taken on Stripe’s hosted checkout. We store only the subscription status, the billing period, and the brand and last four digits of the card. Stripe privacy policy.

6. How long we keep it

  • Your account and your writing: for as long as your organisation has an account with us. When the agreement ends we keep the data for a further 30 days so your organisation can export it, and delete it thereafter; your organisation can ask for immediate deletion at any time, and statutory retention obligations are unaffected. You can delete your own pieces at any time.
  • Sign-in links: single-use, and pruned shortly after they expire.
  • Sessions: until they expire or you end them.
  • LinkedIn credential and identifiers: until you disconnect, which deletes them immediately.
  • Rate-limit counters (which include IP addresses of unauthenticated requests, to stop abuse): deleted after 24 hours.
  • Site analytics: up to 12 months, in a form that cannot be linked back to a person.
  • Sign-in link records (the email address the link was sent to, and where the signup came from): deleted within an hour of the link expiring.
  • Billing records (subscription status, billing period, card brand and last four digits): for as long as the account is billed, and afterwards for the seven years Austrian accounting law requires (section 212 UGB, section 132 BAO).

7. Automated decisions, and what the App measures about you

No automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR takes place. Nothing in the App decides anything about you on its own: no metric changes your role, restricts your access, ends your account, deletes your work, or reports you to anybody.

The App does measure things, and which of them a colleague can see is set out below.

Visible only to you: your streak, your badges, your mood check-ins and the run of days behind them, the weeks below the cadence you set yourself, the coach’s assessment of your current draft, and how much of a draft is in your own words. These feed the coach’s notes to you and nothing else. Mood check-ins are never visible to anyone else.

Colleagues and administrators can see these:

  • Cadence attainment. On the team calendar, for each member of a team you are in, how many days their own cadence asked for and how many pieces they planned and published in the period, drawn as a share of their own target. An organisation administrator sees this for every team.
  • Published count. On the organisation’s member list, the lifetime number of published pieces per member, visible to every member of the organisation and sortable by that number.
  • Planned and published pieces, and who paused. Topics and timing on the shared calendar, and the names of people who have paused their cadence. The reason someone paused is never shown, deliberately, because one of the reasons is being unwell.

These are automated evaluations of how somebody is working. They exist for coordination, they are visible by design, and none of them triggers any action. Whether your organisation uses the team layer at all is its decision: it is the controller.

The one thing the App does on its own is write you a note. If a day you chose to publish on passes without a post, it tells you, in the app and by email or Slack if you asked for those. It goes to you and to nobody else.

8. Your rights

You have the following rights under the GDPR:

  • Right of access (Art. 15): confirmation of whether we process data about you, and a copy of it.
  • Right to rectification (Art. 16): correction of inaccurate data.
  • Right to erasure (Art. 17): deletion, subject to legal retention requirements.
  • Right to restriction (Art. 18): limitation of processing.
  • Right to data portability (Art. 20): your data in a machine-readable format.
  • Right to object (Art. 21): to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)): where processing rests on consent, such as the early-access list or your LinkedIn connection.
  • Right to lodge a complaint (Art. 77) with a supervisory authority. The competent authority for Swat.io is the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).

Write to lab@swat.io; we respond within 30 days as required by Art. 12(3) GDPR. For data in the App, we forward the request to your organisation, which is the controller, and help it answer.

9. Cookies

The Site uses none. No analytics cookie, no advertising cookie, no consent banner needed under Art. 5(3) of the ePrivacy Directive.

The App uses three, all strictly necessary and none for tracking: the session cookie that keeps you signed in, and two short-lived cookies used while connecting LinkedIn and while installing Slack, each verifying that the round trip returned to the browser it started in. The App’s analytics store nothing on your device: events are tied to your account, not to a cookie.

10. Security

Everything is encrypted in transit with TLS, and everything we store is encrypted at rest. Credentials we hold on your behalf carry a second layer of encryption on top of that. Sign-in and session tokens are kept only as hashes. Every record is scoped to its organisation on every query, and that isolation is covered by its own automated tests.

The full technical and organisational measures are published at thestory.run/toms.

11. Changes

We may update this policy. The date at the top reflects the most recent revision; material changes are announced on the Site and, where required, communicated directly.

12. Contact

Questions, requests, and complaints about personal data: lab@swat.io.

Company details: swat.io/en/imprint.

Product

  • Features
  • Pricing
  • Business case
  • Manifesto

Resources

  • Help center
  • Facts
  • Changelog

Legal

  • Terms
  • Privacy
  • Data processing
  • Security measures
  • Imprint

For machines

  • For AI
  • API

Preferences

  • Deutsch
© 2026 thestory.runBuilt by Swat.io GmbH, Vienna, Austria.
Featured on ScrollLaunch
Featured on MakeItLast