Trust & Security
Your work, your data, your trust - protected by design.
We're a small studio that takes your trust seriously. Your card details, your password, your identity and your creative work are protected by the same names the largest companies in the world rely on - not home-grown shortcuts. Here's exactly how, in plain language.
How we protect you
Six promises we keep
The technology we trust
Built on infrastructure you already trust
We don't reinvent security - we stand on the providers the industry depends on, each doing the one job they're best in the world at.
Payments - PCI-DSS Level 1 hosted checkout. The card rails the largest companies in the world trust.
Authentication & identity - encrypted password management, email verification, Google sign-in.
Database & storage - your projects encrypted at rest, with strict per-account access boundaries.
Global edge hosting - TLS everywhere, served fast and securely from data centres worldwide.
AI features - invoked only on the content you choose; API data is never used to train public models.
Transactional email - verification codes, receipts and call sheets, on a verified sender domain.

The developer's promise
Built in the open, for the long run
StoryboardCanvas is profit-funded, not VC-funded - no investors to please, nothing to flip. The price you join at is the price your project keeps, for its whole life. Every upgrade we ship lands on every tier, retroactively: the twenty apps in your plan today are the twenty in your plan tomorrow.
We build in the open. Every release is written up in plain language in the public changelog, and the roadmap is a live ballot - every vote reorders what we build next. You can see exactly what changed, what's coming, and why.
Trust, in your own questions
Is my card data safe with StoryboardCanvas?
Yes. Payments run on Stripe Hosted Checkout, which is certified PCI-DSS Level 1 - the highest level in the card industry. Your card details go straight to Stripe and are never seen, handled or stored on our servers. You can cancel or manage your subscription any time through Stripe's own self-serve Customer Portal.
Where is my password stored?
Nowhere we can reach it. Authentication is handled by Clerk, an industry-standard identity provider. Your password is encrypted and managed entirely by Clerk - we never see it and never store it. You can also sign in with Google instead of a password, and every new account is verified by email code.
Is my data encrypted?
Yes - in transit and at rest. All traffic is served over TLS (HTTPS), and your projects, scripts and media are encrypted at rest in our database and storage. The platform is GDPR-compliant by design.
Who owns the scripts and projects I create?
You do. Your content is yours under our Terms of Service - we never claim ownership of your creative work. You can export your data, and you can delete your account and request erasure of your data at any time, self-serve, from your account settings.
Are my scripts or production data used to train AI?
No. Your scripts and production data are never sold, and are not used to train public AI models. AI features only send the specific content you ask them to work on, when you invoke them.
What happens to my data if I cancel?
Cancelling is self-serve through the Stripe Customer Portal - no lock-in, no emails to write, no phone calls. Your data stays yours: export it before you go, and request full erasure whenever you like.
Who else touches my data? (Sub-processors)
A short, named list, and no one else. Supabase (Postgres database + file storage), Vercel (application hosting), Clerk (sign-in and identity), Stripe (payments), Resend (transactional email), and OpenAI (only for the AI features you explicitly invoke). We do not sell data, and we do not share it with advertisers or data brokers - there are none, because there is no ad product. A current sub-processor list is available in writing on request for anyone who needs it for a compliance file.
Where is my data physically stored?
Your projects, scripts and media live in our Supabase Postgres database and Supabase Storage; the application runs on Vercel's edge network. Both are US-hosted by default. If your production has a contractual data-residency requirement (a broadcaster or commissioner sometimes does), contact us before you sign up rather than after - we would rather tell you honestly what we can and cannot meet than discover it together in week three.
How exactly is my data encrypted?
In transit, everything is served over TLS (HTTPS) - no exceptions, including uploads. At rest, the database and file storage are encrypted by our infrastructure providers. To be precise about a phrase that gets misused: this is not end-to-end encryption. We hold the keys, because the application has to read your script to break it down, generate frames from it and search it. Any product that offers AI features over your content and also claims end-to-end encryption is describing something that cannot be true. We would rather be exact than reassuring.
Can your staff read my scripts?
Access is limited to what is needed to run and support the service, and it is not casual. Support access to a specific project happens when you ask for help with that project. We have no interest in your screenplay beyond keeping it safe and making the software work on it - and if you are working under an NDA that requires a signed confidentiality agreement from every processor, ask us and we will sign one.
What are the storage limits, and what happens if I hit them?
Storage scales with your plan - 2 GB on Free, rising through the tiers. When you reach the limit, new uploads are blocked; nothing already stored is deleted, and nothing is quietly thrown away to make room. You can free space, upgrade, or export and archive. We will not delete your footage to protect our margins.
Are there backups, and how do I get my work out?
The database is backed up on a rolling schedule by our infrastructure provider. But backups are our safety net, not your export route: your real protection against any vendor - including us - is that you can leave with everything. Scripts export to Final Draft (.fdx), Fountain and PDF; shot lists, cast, crew, schedule, budget and locations export to CSV; storyboards export as images and PDF; the animatic exports to video and editorial formats; and the wrap package downloads the entire project as one ZIP. Do it any time, on any plan, without asking us.
If I delete my account, is it actually deleted?
Yes. Deletion is self-serve from your account settings and is actioned as an erasure request, not a hidden flag - your projects, scripts, media and personal data are removed. A short window exists between the request and completion so the request can be verified and so an accidental deletion can be reversed; after that it is gone and we cannot recover it for you. Anything you want to keep, export first (see above).
Does OpenAI keep a copy of my script?
AI features send only the specific content you ask them to work on, at the moment you invoke them - not your whole project, and not continuously in the background. That content is processed by OpenAI to return your result. Your work is not used to train public AI models, we do not sell it, and no AI feature runs on your script unless you press a button that says it will. If your production requires a zero-retention arrangement with the model provider, ask us before you upload the script.
What if a script is unreleased and under embargo?
That is most of them, and it is the whole reason this page exists. Practical protections: the project is private to you and the people you invite; external reviewers get a scoped share link rather than an account with access to everything; you can revoke a share at any time; and we will sign an NDA where a production requires it. If a project is high-sensitivity enough that a web application is the wrong answer, we would rather tell you that than take the money.
How do you protect my account itself?
Sign-in is handled by Clerk: passwords are encrypted and stored by them, never by us; sign-in with Google is available if you would rather not have a password at all; every new account is verified by email code; and sessions are managed by Clerk with server-side verification on every request. On the higher tiers, SSO/SAML and audit logs are available for organisations whose IT department requires them.
What happens if there is a security incident?
We tell you. If a breach affects your data we will notify affected users without undue delay and tell you what happened, what was affected and what we are doing - as GDPR requires, and as basic decency requires before that. We would rather publish an uncomfortable incident note than have you learn about it from someone else. Security concerns can be reported directly to us and we will respond; we do not treat a disclosure as an attack.
Do you have SOC 2 or ISO 27001?
Not today, and we are not going to imply otherwise with a badge that means nothing. We are a small, profit-funded team; formal certification is expensive, slow, and something we will pursue when the customers who need it are here to justify it. What we can offer now: a named sub-processor list, a signed NDA, a DPA on request, honest answers to a security questionnaire, and the ability to walk away with all your data at any time. If your commissioner mandates a certification we do not hold, tell us - we will say so plainly rather than waste your procurement cycle.
Do you track me around the web?
No. There is no advertising product, no ad pixels, no third-party trackers following you off the site, and nothing is sold to data brokers. We use privacy-respecting analytics to count what pages get used so we know what to build next - not to build a profile of you.
Full detail lives in our Terms of Service. Still unsure? Ask us anything →


