Monitored company
Storyblok
clause.watch tracks 2 legal documents published by Storyblok, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
Policy date: October 6, 2025
Company: Storyblok GmbH
Scope: Storyblok’s website, application, services, communications, and interactions with users. The document provided appears incomplete—it ends during the section on “Special Category Data.” Some important provisions, including the full rights, retention, international-transfer, and possibly dispute sections, may be omitted.
1. Data Collection & Usage
Information collected
Depending on how you interact with Storyblok, it may collect:
- Website and app usage data: IP address, browser and operating system details, language, referring URL, requested pages/files, timestamps, HTTP status, data transferred, latency, caching and other log information.
- Cookies and tracking data: Cookies, pixels, web beacons, device identifiers and similar technologies.
- Contact and business information: Name, email, country, phone number, employer, industry, company size, job title and other contact details.
- Account information: Name, email, password, username, SSO identifier and, for two-factor authentication, telephone number.
- Communications and support data: Chat messages, support requests, surveys, feedback, feature requests and other information voluntarily submitted.
- Payment-related data: Billing address and transaction information. Storyblok states that credit-card numbers do not enter Storyblok systems and are handled by payment processors.
- Marketing and newsletter data: Email address, subscription/consent records, and potentially whether newsletters are opened or viewed through tracking pixels.
- Data from other sources: Publicly available information, LinkedIn or company websites, data-enrichment providers, event organizers, partners, advertising and market-research companies, other users, and linked third-party accounts.
Purposes
Storyblok uses data to provide and secure its services, operate accounts, process payments, respond to requests, provide support, troubleshoot, analyze usage, improve products, communicate with users, conduct marketing and advertising, and investigate security incidents.
Storyblok relies on several legal bases, including contract performance, pre-contractual steps, consent, and legitimate interests.
Customer Content
When Storyblok processes personal data contained in content uploaded by a Storyblok customer, it says it acts as the customer’s data processor, not as the controller. That processing is governed by the customer contract and Storyblok Data Processing Agreement. This distinction is important: users may need to exercise rights through the organization that controls the relevant content.
2. User Rights
The policy says Storyblok complies with GDPR, Austrian law, CCPA/CPRA and several U.S. state privacy laws. These laws may provide rights such as:
- Access to personal data
- Correction of inaccurate data
- Deletion
- Data portability
- Restriction or objection to processing
- Withdrawal of consent
- Opting out of certain marketing or targeted advertising
- Appeal or complaint rights where applicable
The excerpt does not provide the detailed procedure, verification requirements, response deadlines, or contact details for exercising these rights. Newsletter consent can be withdrawn at any time, although Storyblok may retain consent records to defend against claims.
3. Third-Party Sharing
Storyblok shares data with service providers supporting hosting, analytics, advertising, marketing, payments, accounting, support and communications. Named providers include:
- AWS, Vercel and Netlify
- Segment/Twilio
- Google Analytics and Google Ads
- LinkedIn, X/Twitter, Facebook, 6Sense, G2 and Capterra
- Hotjar
- Salesforce, Mailchimp and Zendesk
- Stripe and NetSuite
- Atlassian/Jira, Google Workspace and other linked services
With cookie consent, website or app usage data may be transmitted to multiple advertising and analytics providers, including providers in the United States. Opting out substantially limits this sharing, although essential cookies remain and anonymized data may still be sent to Google Analytics and AWS.
Social-media platforms may independently track users, particularly when users are logged in. Storyblok disclaims responsibility for those platforms’ separate processing.
4. AI/ML Training
The provided policy does not state that personal data or customer content is used to train AI or machine-learning models. It also does not expressly promise that such data will never be used for training. The document should therefore not be treated as a clear no-training commitment.
Customer Content is said to be processed under the customer agreement and Data Processing Agreement, so the relevant contract should be reviewed for AI, analytics, subprocessors and service-improvement permissions.
5. Key User Obligations
Users must:
- Safeguard account passwords and credentials.
- Notify Storyblok immediately if credentials are compromised or used without authorization.
- Manage cookie preferences and understand that disabling cookies may affect functionality.
- Avoid submitting unnecessary sensitive information through chats, forms or support channels.
- Review privacy settings when linking Google, social-media or other third-party services.
- Avoid using the services for individuals under 16; Storyblok says it does not knowingly collect their data.
6. Liability & Disputes
The privacy policy itself does not set out a dispute-resolution process, governing law, arbitration terms, caps on liability, or remedies. It refers to Storyblok’s separate General Terms and Conditions, which should be reviewed for those provisions.
Storyblok limits responsibility for processing performed independently by social-media and other third-party providers. Security safeguards and ISO 27001 certification are described, but they are not an absolute guarantee against breaches.
7. Changes
The excerpt gives an effective date but does not explain how policy changes will be announced or whether continued use constitutes acceptance. Users should monitor the policy, account communications and website notices for updates.
Terms and Conditions
Storyblok Terms & Conditions: Key User Overview
> Scope note: The Terms do not contain the full privacy, data-processing, or AI rules. They incorporate Storyblok’s separate Privacy Policy, Data Protection Agreement (DPA), and AI Terms, which should be reviewed before use.
1. Data Collection & Usage
Account and personal data
Storyblok may collect and process Account Information, including:
- Names and usernames
- Email addresses and login credentials
- Passwords or SSO identifiers
- Billing, tax, and contact information
- Information needed to create, administer, maintain, and secure an account
Storyblok acts as a data controller for certain account-related personal data, such as email addresses and access credentials. The Privacy Policy governs this processing.
Customer Content
Customer Content may include text, documents, images, video, audio, software, and other files uploaded or transmitted through the service. The customer remains responsible for its legality, accuracy, security, and integrity.
Storyblok receives a broad, royalty-free, worldwide right to use Customer Content during the agreement term, but only as necessary to provide and properly perform the services.
Usage Data
Storyblok may collect performance and usage information generated by customer and user activity within Storyblok. This may include aggregated, statistical, and analytical information. Storyblok owns the Usage Data.
The Terms specifically state that Usage Data does not include performance or usage data from the customer’s websites or their visitors.
Backups
Customers are responsible for creating backups. Enterprise customers may be offered a backup option using their own cloud storage, but backups are not created by default. Self-service customers are expressly told that Storyblok does not provide backups.
2. User Data Rights
The Terms do not list detailed access, correction, deletion, portability, objection, or restriction rights. Those rights, where applicable—particularly under the GDPR—are addressed in the Privacy Policy and DPA.
Users should consult those documents for:
- How to submit data-rights requests
- Retention and deletion periods
- International data transfers
- Security measures
- Controller/processor responsibilities
If an account uses an organization’s email domain, Storyblok may share account details with that organization. The organization may take control of the account, access or disclose information, restrict access, or delete information.
3. Third-Party Sharing
Confidential information may be disclosed to Storyblok’s and its affiliates’ employees, contractors, advisers, auditors, and other representatives who need it and are subject to confidentiality obligations.
Data may also be processed or exchanged with:
- Affiliates
- Third-party login, SSO, hosting, integration, or service providers
- Apps and services available through the App Store
- Providers supporting trial, beta, or free features
Third-party services operate under their own terms and privacy policies. Storyblok disclaims responsibility for their security, availability, accuracy, or handling of data. Customers should separately assess every integration before connecting it.
4. AI/ML Training
The Terms acknowledge that Storyblok may offer AI Features using large language models, machine learning, or similar technology. However, they do not state whether Customer Content, Account Information, or prompts are used to train AI models.
Use of AI Features is governed by the separate Storyblok AI Terms, incorporated by reference. Users should review those terms for:
- Whether inputs or outputs are retained
- Whether data is used for model training or improvement
- Third-party AI providers
- Confidentiality and security protections
- Ownership and permitted use of AI outputs
5. Key User Obligations and Restrictions
Customers must:
- Provide accurate and current account and billing information
- Protect passwords and prevent unauthorized access
- Notify Storyblok promptly of security incidents or misuse
- Ensure users and affiliates comply with the Terms
- Stay within technical, user, traffic, API, storage, and other plan limits
- Maintain their own backups
- Use current APIs and SDKs
- Obtain all rights and consents for uploaded content
Prohibited conduct includes reverse engineering, unauthorized copying or resale, account sharing among multiple users, security testing, bypassing limits, illegal or fraudulent activity, infringement, harmful content, attacks on systems, and spam.
Storyblok may suspend accounts, users, spaces, or throughput without advance notice where it reasonably believes there is a security risk or breach. Fees generally continue during suspension.
6. Liability and Disputes
- Services are generally provided “as is” and “as available.”
- Storyblok does not guarantee uninterrupted, error-free, compatible, or commercially successful operation.
- Indirect losses—such as lost profits, revenue, goodwill, business interruption, or most data losses—are excluded.
- For certain claims, liability is capped at amounts paid during the preceding 12 months; self-service liability is even more restricted, generally requiring intent or severe gross negligence.
- Customers bear significant indemnity risk for unlawful or infringing Customer Content.
- Disputes are governed by Austrian law, with exclusive jurisdiction in Linz, Austria.
- Claims for damages must generally be brought within one year of learning of the damage.
7. Changes and Renewal
Storyblok may automatically modify, deprecate, or update services. Material changes are normally announced through the in-service changelog; Breaking Changes require at least 30 days’ notice. The customer is responsible for updating its systems. The exclusive remedy for an unresolved Breaking Change is termination and a limited pro-rata refund.
Subscriptions generally auto-renew unless cancellation is provided at least 30 days before term expiry. Fees may increase at renewal.
For self-service customers, material Terms changes will generally receive an attempted 30-day notice. Continued use means acceptance; stopping use does not generally entitle the customer to a refund.
Change history
2026-09-06 · Privacy Policy
2026-08-21 · Privacy Policy
No
2026-08-21 · Privacy Policy
No
2026-08-20 · Privacy Policy
2026-08-18 · Privacy Policy
2026-08-18 · Privacy Policy
Summary of the Diff
Scope of Change
- The diff states only that approximately 4,740 words were added.
- No actual added, deleted, or replaced legal language is included.
- As a result, the substantive legal effects of the changes cannot be determined from the material provided.
Customer Data and AI Training
- The supplied diff does not identify whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Used to develop products, algorithms, or analytical tools;
- Shared with affiliates, vendors, or third-party AI providers;
- De-identified, aggregated, or otherwise processed for model training;
- Retained after termination for AI-related purposes; or
- Excluded from training by default or only upon customer opt-out.
- It is therefore not possible to determine whether the revised terms create new permissions or risks concerning AI training.
Important Risks That Cannot Yet Be Assessed
The missing text prevents analysis of potentially significant changes involving:
- Ownership and licensing of customer data and outputs;
- Confidentiality and permitted uses;
- Data retention and deletion;
- Disclosure to subprocessors or model providers;
- Security and privacy obligations;
- Use of usage data, telemetry, prompts, or uploaded content;
- Customer opt-out or consent requirements;
- Indemnification, liability limitations, and regulatory compliance; and
- Whether customer data may be combined with other customers’ data.
Conclusion
The provided material is only a description of the diff’s length, not the diff itself. A reliable legal analysis requires the actual text of the additions, deletions, and replacements—particularly provisions addressing customer content, data use, machine learning, artificial intelligence, model training, product improvement, confidentiality, and subprocessors.
Between 2025-06-17 and 2025-12-16 · Privacy Policy
Key Changes and Risks
1. Major expansion and restructuring
- The policy is substantially expanded from a short website/cookie notice into a comprehensive privacy policy covering:
- Website visitors
- Storyblok customers and users
- Prospective customers
- Business partners
- Event attendees
- Employees and job applicants
- It now expressly applies to use of the Storyblok Services at
app.storyblok.comand incorporates the General Terms by reference. - The policy adds detailed definitions of “Personal Data” and identifies compliance with the GDPR, Austrian data-protection and telecommunications laws, and multiple U.S. state privacy laws, including the CPRA, VCDPA, Colorado, Utah, and Connecticut laws.
2. Expanded data collection and purposes
The revised policy identifies substantially more categories and sources of data, including:
- IP address, name, email address, contact information, account and payment data
- Communications, feedback, usage data, cookies, analytics, and social-media identifiers
- Information received from affiliates, business partners, event organizers, commercial partners, other users, and connected third-party applications
- Employment and applicant information
Storyblok may use data for additional purposes, including:
- Marketing and commercial activities
- Service improvement and product development
- Customer support, analytics, security, legal compliance, and business operations
- Feedback interviews following unsuccessful sales or RFP processes
This creates broader potential uses of customer and contact data, particularly for analytics, marketing, and product improvement.
3. AI and model-related processing
New AI processing expressly disclosed
The policy newly states that:
- Voluntary feedback interviews may be video-recorded.
- Third-party tools, such as Klue, may use artificial intelligence to analyze interview videos and extract insights.
- Recordings and AI-generated analyses may be stored in and connected with Storyblok’s internal systems and service providers.
- Mindtickle is listed as a business service provider for call recording, “including AI transcript.”
Important limitation and risk
- The policy does not expressly say that customer content, account data, communications, or Storyblok Service data will be used to train Storyblok’s or a third party’s general-purpose AI models.
- However, the language permits AI analysis, transcription, storage, and internal use of recordings and feedback, without clearly stating:
- Whether providers may use the data to train their models
- Whether data is de-identified before AI processing
- Whether prompts, outputs, transcripts, or recordings are retained
- Whether enterprise customers can opt out of these AI uses
- Whether customer-submitted Storyblok content is excluded from model training
Customers should seek contractual confirmation that their content and confidential information will not be used for AI training except with express written authorization.
4. Broader sharing and international transfers
- The policy expands disclosures to affiliates, professional advisers, numerous service providers, connected apps, and third parties involved in transactions such as mergers or acquisitions.
- It lists extensive U.S. and international providers and relies on adequacy decisions, Standard Contractual Clauses, and Data Privacy Framework mechanisms.
- This increases the number of potential data recipients and cross-border transfer risks.
5. Administrative control over customer accounts
For organization-managed accounts, administrators may:
- Access, retain, modify, or delete account information
- Restrict or terminate access
- Access information stored in the account
- Enable third-party apps that receive account details and selected content
Users should not assume that content in a work-managed account is private from the employer or account administrator.
6. Retention and deletion
- Account information may remain after deactivation so other users can continue using the Services.
- Deactivating access does not delete content already added to a space.
- Retention periods are added for financial records, logs, communications, marketing preferences, cookies, and legal claims, but some periods remain broadly defined as “as necessary.”
Between 2025-02-15 and 2025-10-11 · Terms and Conditions
No
Between 2023-02-09 and 2024-08-22 · Privacy Policy
Between 2023-06-01 and 2024-04-03 · Terms and Conditions
No
Between 2020-06-26 and 2022-06-20 · Terms and Conditions
No