Skip to content

Trust & Security

Your work, your data, your trust - protected by design.

We're a small studio that takes your trust seriously. Your card details, your password, your identity and your creative work are protected by the same names the largest companies in the world rely on - not home-grown shortcuts. Here's exactly how, in plain language.

Yours to keep and control

Your projects stay yours - protected from the first keystroke.

Full commercial rights on every tier, exportable project files, and nothing of yours used to train a model. Encrypted in transit and at rest, on the same infrastructure the industry already depends on.
Your StoryboardCanvas production project file protected by encryption and trusted providers

How we protect you

Six promises we keep

Your card never touches us

Payments run on Stripe Hosted Checkout - PCI-DSS Level 1. Your card goes straight to Stripe; we never see or store it. Plan and credits arrive together, or not at all.

Your password is yours

Sign-in is handled by Clerk and encrypted by them. We never see your password and never store it. Prefer Google? Sign in with one tap instead.

Encrypted in transit and at rest

Every connection is TLS (HTTPS), and your scripts, projects and media are encrypted at rest. GDPR-compliant by design - privacy isn't a setting, it's the default.

Your work is yours

We never claim ownership of your creative work. Export your data any time, and delete your account with full erasure - self-serve, no support ticket required.

AI that respects you

Your scripts and production data are never sold, and never used to train public AI models. AI features only ever read the content you hand them, when you ask.

Cancel anytime, no traps

Manage or cancel through Stripe's own portal - no lock-in, no retention calls. Free, view-only collaborators cost nothing. Real people review refund requests.

Six plain promises

Six lines you can hold us to.

Your card never touches us, your password is yours, everything is encrypted both ways, your work stays yours, AI only reads what you hand it, and you can cancel any time. Plain promises, not fine print.
The six StoryboardCanvas promises that protect a filmmaker's card, password, data and work.
Standing on the best

The same names the big studios bank on.

Stripe takes the payment, Clerk guards the login, Supabase encrypts what's stored, Vercel serves it over TLS. Security isn't where a small team should improvise - so we don't, we stand on the best in the world at each job.
The trusted provider stack underpinning StoryboardCanvas - Stripe, Clerk, Supabase and Vercel.
The StoryboardCanvas developer's promise - built in the open, profit-funded, for the long run.

The developer's promise

Built in the open, for the long run

StoryboardCanvas is profit-funded, not VC-funded - no investors to please, nothing to flip. The price you join at is the price your project keeps, for its whole life. Every upgrade we ship lands on every tier, retroactively: the twenty apps in your plan today are the twenty in your plan tomorrow.

We build in the open. Every release is written up in plain language in the public changelog, and the roadmap is a live ballot - every vote reorders what we build next. You can see exactly what changed, what's coming, and why.

Trust, in your own questions

Is my card data safe with StoryboardCanvas?

Yes. Payments run on Stripe Hosted Checkout, which is certified PCI-DSS Level 1 - the highest level in the card industry. Your card details go straight to Stripe and are never seen, handled or stored on our servers. You can cancel or manage your subscription any time through Stripe's own self-serve Customer Portal.

Where is my password stored?

Nowhere we can reach it. Authentication is handled by Clerk, an industry-standard identity provider. Your password is encrypted and managed entirely by Clerk - we never see it and never store it. You can also sign in with Google instead of a password, and every new account is verified by email code.

Is my data encrypted?

Yes - in transit and at rest. All traffic is served over TLS (HTTPS), and your projects, scripts and media are encrypted at rest in our database and storage. The platform is GDPR-compliant by design.

Who owns the scripts and projects I create?

You do. Your content is yours under our Terms of Service - we never claim ownership of your creative work. You can export your data, and you can delete your account and request erasure of your data at any time, self-serve, from your account settings.

Are my scripts or production data used to train AI?

No. Your scripts and production data are never sold, and are not used to train public AI models. AI features only send the specific content you ask them to work on, when you invoke them.

What happens to my data if I cancel?

Cancelling is self-serve through the Stripe Customer Portal - no lock-in, no emails to write, no phone calls. Your data stays yours: export it before you go, and request full erasure whenever you like.

Who else touches my data? (Sub-processors)

A short, named list, and no one else. Supabase (Postgres database + file storage), Vercel (application hosting), Clerk (sign-in and identity), Stripe (payments), Resend (transactional email), and OpenAI (only for the AI features you explicitly invoke). We do not sell data, and we do not share it with advertisers or data brokers - there are none, because there is no ad product. A current sub-processor list is available in writing on request for anyone who needs it for a compliance file.

Where is my data physically stored?

Your projects, scripts and media live in our Supabase Postgres database and Supabase Storage; the application runs on Vercel's edge network. Both are US-hosted by default. If your production has a contractual data-residency requirement (a broadcaster or commissioner sometimes does), contact us before you sign up rather than after - we would rather tell you honestly what we can and cannot meet than discover it together in week three.

How exactly is my data encrypted?

In transit, everything is served over TLS (HTTPS) - no exceptions, including uploads. At rest, the database and file storage are encrypted by our infrastructure providers. To be precise about a phrase that gets misused: this is not end-to-end encryption. We hold the keys, because the application has to read your script to break it down, generate frames from it and search it. Any product that offers AI features over your content and also claims end-to-end encryption is describing something that cannot be true. We would rather be exact than reassuring.

Can your staff read my scripts?

Access is limited to what is needed to run and support the service, and it is not casual. Support access to a specific project happens when you ask for help with that project. We have no interest in your screenplay beyond keeping it safe and making the software work on it - and if you are working under an NDA that requires a signed confidentiality agreement from every processor, ask us and we will sign one.

What are the storage limits, and what happens if I hit them?

Storage scales with your plan - 2 GB on Free, rising through the tiers. When you reach the limit, new uploads are blocked; nothing already stored is deleted, and nothing is quietly thrown away to make room. You can free space, upgrade, or export and archive. We will not delete your footage to protect our margins.

Are there backups, and how do I get my work out?

The database is backed up on a rolling schedule by our infrastructure provider. But backups are our safety net, not your export route: your real protection against any vendor - including us - is that you can leave with everything. Scripts export to Final Draft (.fdx), Fountain and PDF; shot lists, cast, crew, schedule, budget and locations export to CSV; storyboards export as images and PDF; the animatic exports to video and editorial formats; and the wrap package downloads the entire project as one ZIP. Do it any time, on any plan, without asking us.

If I delete my account, is it actually deleted?

Yes. Deletion is self-serve from your account settings and is actioned as an erasure request, not a hidden flag - your projects, scripts, media and personal data are removed. A short window exists between the request and completion so the request can be verified and so an accidental deletion can be reversed; after that it is gone and we cannot recover it for you. Anything you want to keep, export first (see above).

Does OpenAI keep a copy of my script?

AI features send only the specific content you ask them to work on, at the moment you invoke them - not your whole project, and not continuously in the background. That content is processed by OpenAI to return your result. Your work is not used to train public AI models, we do not sell it, and no AI feature runs on your script unless you press a button that says it will. If your production requires a zero-retention arrangement with the model provider, ask us before you upload the script.

What if a script is unreleased and under embargo?

That is most of them, and it is the whole reason this page exists. Practical protections: the project is private to you and the people you invite; external reviewers get a scoped share link rather than an account with access to everything; you can revoke a share at any time; and we will sign an NDA where a production requires it. If a project is high-sensitivity enough that a web application is the wrong answer, we would rather tell you that than take the money.

How do you protect my account itself?

Sign-in is handled by Clerk: passwords are encrypted and stored by them, never by us; sign-in with Google is available if you would rather not have a password at all; every new account is verified by email code; and sessions are managed by Clerk with server-side verification on every request. On the higher tiers, SSO/SAML and audit logs are available for organisations whose IT department requires them.

What happens if there is a security incident?

We tell you. If a breach affects your data we will notify affected users without undue delay and tell you what happened, what was affected and what we are doing - as GDPR requires, and as basic decency requires before that. We would rather publish an uncomfortable incident note than have you learn about it from someone else. Security concerns can be reported directly to us and we will respond; we do not treat a disclosure as an attack.

Do you have SOC 2 or ISO 27001?

Not today, and we are not going to imply otherwise with a badge that means nothing. We are a small, profit-funded team; formal certification is expensive, slow, and something we will pursue when the customers who need it are here to justify it. What we can offer now: a named sub-processor list, a signed NDA, a DPA on request, honest answers to a security questionnaire, and the ability to walk away with all your data at any time. If your commissioner mandates a certification we do not hold, tell us - we will say so plainly rather than waste your procurement cycle.

Do you track me around the web?

No. There is no advertising product, no ad pixels, no third-party trackers following you off the site, and nothing is sold to data brokers. We use privacy-respecting analytics to count what pages get used so we know what to build next - not to build a profile of you.

Full detail lives in our Terms of Service. Still unsure? Ask us anything →

Trust · then the work

Trust earned, then a studio that delivers.

No card to look around, no sign-up to explore the live demo. When you're ready, start free - your work is protected from the very first keystroke.