Privacy Policy

STORY FRUITION LLC PRIVACY POLICY

Last updated August 2026

Welcome to Story Fruition LLC ("we," "us," or "our"). This privacy notice describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:

 

By continuing to use the Service after being presented with this Privacy Policy, and where required by applicable law, by providing your affirmative consent, you acknowledge our data practices as described in this policy. We will not use or share your information with anyone except as described in this Privacy Policy. Unless otherwise defined in this Privacy Policy, terms used herein have the same meanings as in our Terms and Conditions, accessible at https://www.storyfruition.com/terms.

Questions or concerns? Please contact us at [email protected].

 

SUMMARY OF KEY POINTS

This summary provides key points from our privacy notice. You can find more details in the full sections below.

 

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use.

Do we process sensitive personal information? If you use Missy, we collect voice recordings, which may constitute biometric data under applicable law. We treat this data with heightened care as described in the Biometric and Voice Data section below.

Do we receive information from third parties? We may receive information from public databases, marketing partners, social media platforms, and other outside sources.

How do we process your information? We process your information to provide, improve, and administer our Services, for security and fraud prevention, and to comply with law. If you use Missy, your interaction data is used to train and improve the Missy AI system, which Story Fruition LLC develops and owns. We use licensed third-party providers to power certain features, like voice cloning, but under contract, they may not use your data to train their own AI models.

With whom do we share personal information? We share information only with named service providers and as required by law. We do not sell your personal information.

How do we keep your information safe? We maintain organizational and technical safeguards. No electronic transmission is 100% secure; we cannot guarantee against unauthorized access by third parties.

What are your rights? Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information. See the Your Privacy Rights section below.

How do you exercise your rights? Send an email titled "Data Subject Access Request" to [email protected]. We will respond in accordance with applicable law.

 

  1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you voluntarily provide to us.

We collect personal information you voluntarily provide when registering, expressing interest in our products, participating in activities, or contacting us. This may include your email address, name, phone number, physical address, and postal address.

Sensitive and Biometric Information — Missy Users

If you use the Missy AI platform, we collect voice recordings and voice print data for the purpose of creating and operating your personalized AI coaching agent. Voice prints constitute biometric identifiers under Illinois BIPA, Washington State law, Texas CUBI, the California Consumer Privacy Act (CCPA/CPRA), Cal. Civ. Code § 1798.140, and other applicable statutes. By providing voice data, you expressly consent to its collection, use, and storage as described in this Policy and in the Biometric and Voice Data section below.

We also collect training content, expertise documents, and materials you upload to customize your Missy agent, as well as conversation data generated between your Missy agent and end users.

Payment Data

If you make purchases, we collect data necessary to process your payment, such as your payment instrument number and associated security code. Payment processing is handled by Stripe, Inc. Your use of Stripe is subject to the Stripe Privacy Policy.

Social Media Login Data

We may offer registration via existing social media accounts (Facebook, Twitter/X, or others). If you register this way, we collect information as described in the How We Handle Social Logins section.

Information automatically collected

In Short: Some information is collected automatically when you visit our Services.

We automatically collect device and usage information including IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services. This is used for security, operations, and analytics.

The information we collect includes:

  •  Log and Usage Data. IP address, device information, browser type, date/time stamps, pages and files viewed, searches, features used, system activity, error reports, and hardware settings.
  •  Device Data. Computer, phone, tablet, or other device information including IP address, device and application identification numbers, location, browser type, hardware model, ISP/mobile carrier, operating system, and system configuration.
  •  Location Data. Device location, which may be precise or imprecise based on GPS and IP address. You may opt out via device settings, though some features may be limited.

Information collected from other sources

In Short: We may collect limited data from public databases, marketing partners, and social media platforms.

To provide relevant marketing and keep our records current, we may obtain information from public databases, joint marketing partners, affiliate programs, data providers, and social media platforms. This may include mailing addresses, job titles, email addresses, phone numbers, IP addresses, social media profiles, and intent data.

 

  1. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide and improve our Services, for security, fraud prevention, and legal compliance, and — for Missy users — to train and improve the Missy AI system exclusively within Story Fruition LLC.

We process your personal information for the following purposes:

  •  Account creation and authentication. To create and manage your account.
  •  Service delivery. To provide the requested service, including Missy AI coaching sessions.
  •  User support. To respond to inquiries and resolve issues.
  •  Administrative communications. To send details about products, services, policy changes, and similar information.
  •  User-to-user communications. To facilitate communication between users where offered.
  •  Feedback. To request feedback and contact you about your use of our Services.
  •  Marketing and promotions. To send marketing communications in accordance with your preferences. You may opt out at any time.
  •  Targeted advertising. To develop and display personalized content and advertising.
  •  Security and fraud prevention. To monitor and protect our Services.
  •  Analytics. To identify usage trends and assess marketing effectiveness.
  •  Missy AI training (proprietary). Conversation data, voice recordings, and interaction content from Missy sessions may be used solely to train, improve, and refine the Missy AI system within Story Fruition LLC. This data is never used to train third-party AI models. See the AI Training Data Policy section for full details.
  •  Vital interests. To protect the vital interests of a person where necessary. 

 

  1. WHAT LEGAL BASES DO WE RELY ON?

In Short: We process personal information only when we have a valid legal basis — consent, contract, legitimate interests, or legal obligation.

EU and UK Users (GDPR / UK GDPR)

The GDPR and UK GDPR require us to identify our legal bases for processing. We rely on:

  •  Consent. Where you have given us explicit permission, including for voice/biometric data and non-essential cookies. You may withdraw consent at any time by contacting us at [email protected].
  •  Performance of a Contract. Where processing is necessary to fulfil our obligations to you or at your request before entering a contract.
  •  Legitimate Interests. Where processing is reasonably necessary for our legitimate business interests and those interests do not outweigh your rights. Examples include analytics, marketing, fraud prevention, and improving our Services.
  •  Legal Obligations. Where processing is necessary to comply with applicable law, cooperate with authorities, or exercise or defend legal rights.
  •  Vital Interests. Where processing is necessary to protect someone's life or safety.

Canadian Users (PIPEDA / Quebec Law 25)

We process your information where you have given express or implied consent. You may withdraw consent at any time. In exceptional cases, we may process without consent as permitted by law, including for fraud investigations, business transactions, legal proceedings, or publicly available information.

Quebec Law 25 grants additional rights including the right to data portability and the right to be forgotten. Requests may be directed to [email protected].

 

  1. BIOMETRIC AND VOICE DATA

This section applies to all users of the Missy AI platform. Voice prints, voice recordings, and voice-cloned data are biometric identifiers under Illinois BIPA, Washington State law, Texas CUBI, the California Consumer Privacy Act (CCPA/CPRA), Cal. Civ. Code § 1798.140, as amended by SB 1223 (2024), and other applicable laws. We collect and process this data only with your explicit prior written consent, as provided during Missy onboarding.

What we collect

  • Voice samples and recordings you provide to create your voice-cloned Missy agent.
  • Voice print data derived from those recordings.
  • Text transcripts created when your speech is converted to text.
  • Training content and materials you upload to customize your agent.

Speech-to-text processing. When you speak to Missy, we process your voice to create a text transcript and, for certain features, a voiceprint that powers your voice-cloned agent. The voice recording and any voiceprint are biometric information under the laws listed above and receive the protections described in this section. The text transcript by itself, without the audio or a voiceprint, is not biometric information, but it is still protected as personal information under this Policy.

How we use it

  • To create and operate your personalized Missy AI coaching agent.
  • To generate voice-cloned responses that replicate your speaking style.
  • To train and improve the Missy AI system, solely within Story Fruition LLC (see AI Training Data Policy).
  • We do not sell, lease, trade, or otherwise profit from your biometric data.
  • We do not share your biometric data with third parties except as required for service operation (e.g., secure cloud storage providers bound by confidentiality obligations).

Retention and destruction

Biometric data is retained only as long as necessary for the purposes described above, and in any event no longer than three (3) years from the date of collection or the termination of your account, whichever is sooner. Upon expiry, biometric data is permanently deleted using industry-standard secure deletion methods. You may request earlier deletion by contacting [email protected].

Your biometric rights

You have the right to receive a copy of this biometric data policy prior to providing any biometric data. You may request access to, correction of, or deletion of your biometric data at any time by contacting [email protected].

Washington My Health My Data Act (MHMDA)

Voice recordings and biometric identifiers derived from them may, depending on how they are used, constitute “consumer health data” under Washington's My Health My Data Act if they reveal or could be used to infer your physical or mental health status. If MHMDA applies to our processing, we will provide the additional disclosures and obtain the affirmative consent it requires in a separate Consumer Health Data Privacy Policy at storyfruition.com/consumer-health-data-privacy-policy, rather than through this Privacy Policy alone, and you will be able to revoke that consent at any time by contacting [email protected]. We do not sell consumer health data, and consistent with MHMDA we do not use geofencing around healthcare facilities to collect consumer health data or to send you location-based notifications, messages, or ads related to your consumer health data.

 

  1. AI TRAINING DATA POLICY

Story Fruition LLC operates Missy, a proprietary AI coaching system. Conversation data, voice recordings, and interaction content collected through the Missy platform may be used by Story Fruition LLC solely to train, improve, and refine the Missy AI system.

This data is used exclusively by Story Fruition LLC to train and improve the Missy AI system. We use licensed third-party providers to power certain Missy features, such as voice cloning and natural language processing; under contract, these providers may process your data only to deliver those features and are prohibited from using it to train their own AI models. Your Missy training data is never sold, and it is never used to train any third-party large language model or foundation model operated by Google, OpenAI, Anthropic, or any other external AI provider. All Missy training data, and the Missy models themselves, remain proprietary to Story Fruition LLC.

AI Interaction Disclosure

When you interact with Missy, you are interacting with an artificial intelligence system, not a human. Missy generates responses based on trained AI models and the content you provide. While Missy is designed to provide useful coaching and guidance, its responses should not be treated as professional advice. Story Fruition LLC is not liable for decisions made in reliance on Missy's output.

Automated Processing

The Missy platform uses automated processing to generate coaching recommendations, feedback, and assessments based on your voice, content, and interaction patterns. This automated processing does not produce legally binding decisions about you. You have the right to request human review of any Missy output that affects you by contacting [email protected].

EU / UK Users — EU AI Act

In accordance with the EU AI Act and GDPR Article 22, we disclose that Missy uses automated processing to generate recommendations and assessments. You have the right to: (a) be informed that you are interacting with an AI system; (b) obtain an explanation of how Missy generates its outputs; and (c) request human review. To exercise these rights, contact [email protected].

If you have questions about how your data is used within the Missy system, please contact us at [email protected].

 

  1. SERVICE PROVIDERS AND DATA SHARING

In Short: We share data only with named service providers who are contractually bound to protect it, and as required by law. We do not sell your personal information.

We engage the following categories of service providers who may access personal data only to perform services on our behalf:

  •  Payment processing: Stripe, Inc. (stripe.com/privacy)
  •  Cloud infrastructure and storage: Secure cloud providers hosting our platform and Missy data in encrypted environments.
  •  Voice cloning and AI/ML services: Third-party providers that process voice data solely to deliver the Missy voice cloning functionality. These providers are prohibited from using your data for their own model training.
  •  Analytics: Web analytics tools that help us understand how our website and Services are used.
  •  Email and marketing platforms: Tools used to deliver marketing communications in accordance with your preferences.

All service providers are bound by data processing agreements requiring them to maintain confidentiality and security. We do not sell, trade, or transfer your personal information to outside parties for their own marketing purposes.

Missy Creators and End Users

If you are a creator (a person who builds a Missy AI agent for use by others), your end users interact with your agent through our platform. End user conversation data is accessible to you as the creator and to Story Fruition LLC as the platform operator. End users may request access to or deletion of their conversation data by contacting [email protected]. We do not sell or share end user conversation data for marketing purposes.

International Data Transfers

Our Services are operated from the United States. If you are located outside the United States, your data may be transferred to and processed in the US, which may have different data protection laws than your home country. For transfers from the EU or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms. For transfers from Canada, we ensure equivalent protections are in place. Contact [email protected]  for information about the specific transfer mechanisms used.

 

  1. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on your location, you may have the following rights:

  •  Right to access. Request a copy of the personal information we hold about you.
  •  Right to correction. Request correction of inaccurate or incomplete information.
  •  Right to deletion. Request deletion of your personal information, subject to certain legal exceptions.
  •  Right to restrict processing. Request that we limit how we use your data in certain circumstances.
  •  Right to data portability. Request a machine-readable copy of your data (EU/UK and Quebec users).
  •  Right to object. Object to processing based on legitimate interests or for direct marketing.
  •  Right to opt out of sale or sharing. We do not sell personal information. You may opt out of the sharing of your information for targeted advertising at any time by using the "Do Not Sell or Share My Personal Information" link on our website, by contacting [email protected] , or by sending a browser or device signal such as Global Privacy Control (GPC), which we treat as a valid opt-out request. If this changes, you will have the right to opt out.
  •  Right to opt out of targeted advertising. You may opt out of cross-context behavioral advertising at any time.
  •  Right to limit the use of sensitive personal information. Voice recordings and voiceprint data are sensitive personal information under the CCPA/CPRA. You may dire ct us to limit our use of this data to what is reasonably necessary to provide the Services by contacting [email protected].
  •  Right to withdraw consent. Where processing is based on consent (including for biometric data), you may withdraw consent at any time without affecting prior lawful processing.
  •  Right to human review of automated decisions. You may request human review of any Missy AI output that affects you.
  •  Right to lodge a complaint. If you are in the EU or UK, you may lodge a complaint with your local data protection supervisory authority, or with the UK Information Commissioner’s Office (ICO), without prejudice to any other rights described in this Policy.

 

To exercise any of these rights, send an email titled "Data Subject Access Request" to [email protected]. Please include your name, the email address used to access our Services, and the specific right(s) you wish to exercise. We will respond in accordance with applicable law — within 30 days for GDPR requests, 45 days for CCPA requests (extendable by an additional 45 days where necessary).

 

  1. CHILDREN'S PRIVACY

Our Services are not directed to anyone under the age of 13 in the United States. For users in the European Union and United Kingdom, our Services are not directed to anyone under the age of 16, consistent with GDPR Article 8.

We do not knowingly collect personal information from children under the applicable age threshold. If you are a parent or guardian and believe your child has provided us with personal information, please contact [email protected]. We will delete such information promptly upon verification.

 

  1. COOKIES AND CONSENT

We are implementing a cookie consent banner that will let you accept or decline non-essential cookies (including analytics and advertising cookies) before they are set, and change your choice at any time through a persistent "Cookie Preferences" link. Until that banner is live, non-essential cookies described in our Cookie Policy may load automatically; deploying the banner is one of our highest-priority action items (see the accompanying Compliance Review). Essential cookies necessary for the basic functioning of the Site may be set without consent.

We recognize the Global Privacy Control (GPC) and similar browser-based opt-out signals. If your browser or device sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information and to limit our use of your sensitive personal information for that browser or device.

For a full list of the cookies we use, their purpose, and retention duration, please see our Cookie Policy at https://www.storyfruition.com/cookies.

 

  1. DATA RETENTION

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, and reporting requirements. General retention periods are:

  •  Account and profile data: Duration of your account, deleted within 90 days of account closure.
  •  Missy conversation and session data: Duration of your account, deleted within 90 days of account closure or upon your request.
  •  Biometric / voice data: Maximum 3 years from collection or account termination, whichever is sooner. Permanently deleted upon expiry.
  •  Marketing and communication data: Up to 3 years from last interaction, or until you opt out.
  •  Technical log and usage data: Up to 12 months.
  •  Payment records: 7 years, to comply with tax and financial reporting obligations.

 

When retention periods expire, we will securely delete or anonymize your personal information using industry-standard methods.

 

  1. HOW DO WE KEEP YOUR INFORMATION SAFE?

We implement industry-standard organizational and technical security measures to protect your personal information, including encryption in transit and at rest, access controls, and secure cloud infrastructure with unique identifiers for creator content.

However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. We cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security measures. Use our Services at your own risk and report any suspected security incidents to [email protected].

 

  1. DATA BREACH NOTIFICATION

In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify affected individuals and, where required, the relevant supervisory authority, in accordance with applicable law. Under GDPR and UK GDPR, we will report qualifying breaches to the relevant authority within 72 hours. Under applicable US state laws, we will notify affected residents promptly and without unreasonable delay. Notification will be provided by email or through a prominent notice on our website.

 

  1. WASHINGTON STATE RESIDENTS

If you are a Washington State resident, you may have additional rights under the Washington My Health My Data Act (MHMDA) if we process consumer health data, and under Washington's general data privacy framework. To exercise rights specific to Washington residents, please contact us at [email protected] with the subject line "Washington Privacy Request." If we determine MHMDA applies to our processing of your information, we will publish a separate Consumer Health Data Privacy Policy at storyfruition.com/consumer-health-data-privacy-policy describing that processing in the detail MHMDA requires, in addition to this Privacy Policy; see Section 4 above.

 

  1. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. We will notify you of material changes by posting the updated policy on this page and, where required by law, by email or prominent notice on our website. The date at the top of this policy reflects the most recent update. We recommend reviewing this policy at least once every 12 months, consistent with CCPA requirements; the next scheduled review is January 2027.

 

  1. CONTACT US

For questions about this Privacy Policy, to exercise your privacy rights, or to make a complaint, please contact us:

 

Email (general): [email protected] 

Email (privacy and data requests): [email protected] 

Website: https://www.storyfruition.com 

 

Story Fruition LLC

 

We will review and act upon any privacy request in accordance with applicable data protection laws.