We built a tool for making shows, made one with it, and it made us a studio.
This policy covers this website and the software Cornstalk Studios LLC makes: StoryBarn, and any tool of ours that connects to a third-party platform such as TikTok or YouTube on your behalf. The short version: we collect what a tool needs to do the job you asked for, keep it where you can see it, and sell none of it. The tools differ in where your data goes, so each is described on its own below.
The site is static pages. It sets no cookies, runs no analytics, and asks nothing of you. Our hosting provider keeps ordinary server logs (address, time, page requested) for operating the service, and we do not use them to identify visitors.
Our analytics tool connects to a platform such as TikTok only after you sign in there and approve the specific permissions it asks for. With that approval it may read:
— basic profile information, such as your display name, username and avatar;
— account statistics, such as follower, following, like and video counts;
— statistics for the videos you own, such as views, likes, comments and shares.
It uses this data only to show your own analytics back to you. It does not post on your behalf, change your account, read private messages, or collect data about anyone other than the account that signed in.
Access tokens and any exported figures are stored on the computer where that tool runs, in files you can open and delete. The only server it talks to is the platform's own interface; we do not copy your platform data to our servers, share it, or sell it. Revoke the tool from your platform's connected-apps settings, or run its sign-out command, and its access ends and its stored token is removed. Deleting any exported files removes the rest. Nothing remains with us, because nothing was sent to us.
StoryBarn is different: it runs on our server, and what you make with it lives there under your account until you export or delete it.
Your account is an email address, a password (stored hashed, never in the clear), the date you joined, and the productions you make. The tool also keeps a count of your monthly allowances, and a ledger of every generation it makes for you — which production, what for, how much of a provider's capacity it used and an estimated cost. You can see your own ledger inside the tool. The people who run this deployment can see everyone's, because they pay the provider bill.
Cookies. StoryBarn sets a signed session cookie: it is how the tool knows you are signed in, and it carries the token that protects its forms. A visitor who starts a production without an account is given a guest identity in the same cookie, which lasts thirty days. The sign-up and start pages use Cloudflare Turnstile to tell a person from a script; Cloudflare's script runs on those pages under Cloudflare's own privacy policy.
Work you make as a visitor is reachable only from the browser that made it, unless you ask for the link by email. That email is sent to the address you give, once, and the address is not kept. Unclaimed visitor work is kept for at least thirty days and then deleted; making an account is what keeps it.
What leaves our server. To make anything, the tool sends what you gave it to the provider that generates it: the text of your story and bible, your uploaded photographs where they are used as references, and the briefs it writes for voices and pictures. The providers it may use are Google (text, pictures, video, voices and music), ElevenLabs (voices and music), Freesound (searching for sounds), and Pexels (stock footage). Each handles what it receives under its own terms. Nothing is sent to any provider except to do the thing you pressed.
Publishing. The tool publishes only when you approve a release, and only through accounts you own and connect yourself. Today that is YouTube, through Google's sign-in; TikTok, Instagram and other platforms will follow as each is supported, each through its own sign-in and the permissions it asks for. For a platform you connect, the tool keeps the record of what it published and where, and may read back that platform's own statistics for those releases to show them to you. It never publishes, schedules or cross-posts without your approval. You can revoke its access from the platform that granted it at any time.
Other people in your material. The tool will not generate a picture of a recognisable person from a photograph you upload unless you have tagged that photograph as one of your characters and the production's own policy allows real likenesses. Photographs and stories you upload are your responsibility: if they show or describe real people, you need the right to use them that way.
Where it is kept. On Google Cloud, in the United States, on a disk we back up. Do not treat StoryBarn as your only copy of your work: every production can be exported whole, and we promise no fixed period of retention beyond the life of your account.
Deleting it. Ask us and we remove your account and everything under it. There is no self-serve button for that yet; export first if you want to keep the work.
We may revise this policy. The date at the top says when.
Ask through the company page, where the people who run Cornstalk Studios are named.