Privacy Policy
Last updated August 24, 2026
This page describes what TwoLensStory actually collects and does with it. It's written to match the real system, not a template — if something below sounds unusually specific, that's why.
What we collect
- An anonymous device token. The first time you visit, we generate a random token stored in your browser's local storage (not a cookie). It has no personal information in it — it's how a ritual you start stays linked to you across a single visit.
- What you write during a ritual. Your answers and any private reflection you enter are stored so the ritual can complete and, if you choose a paid product, so a result can be generated for you.
- Your email, only if you give it to us. Requesting a private return link is the only thing that asks for an email. We store it to send that link and to let you return to your content later.
- Payment information — handled by Stripe, not by us. Card details never touch our servers. We store a payment reference and receipt (amount, date, product) for accounting.
What we don't collect
We don't ask for your name, and nothing about the product requires it. We don't run advertising trackers or sell data to third parties. We don't include your written ritual content in analytics, application logs, or any email we send you.
Service providers
- Stripe — processes payments. See Stripe's own privacy policy for what they hold.
- Resend — delivers our transactional email (return links, receipts). They see the email address and message content of what we send, not your ritual content.
Analytics and logs
We record a small set of product-usage events (for example, "a ritual started" or "a purchase completed") tagged only with a scenario/session identifier — never the text you wrote. Application logs follow the same rule: operational information only, no ritual content.
Retention
Your ritual content, generated results, and check-in answers are kept until you delete them (see Data & Deletion) or, if you never return, indefinitely — we don't currently run an automatic time-based deletion. Payment/accounting records are retained longer, since they may be needed for tax, fraud-prevention, or dispute purposes — those records don't contain your ritual content.
Backups
Our database is backed up as part of normal server operations. Deleting your data removes it from the live database immediately; it may persist in a backup for a limited period before that backup is itself cycled out. We don't have a precise, published backup-retention duration to state here.
Security
We restrict server access and use standard transport encryption (HTTPS) for everything you send us. Content in our database is not individually field-level encrypted. No system is perfectly secure, and we can't promise otherwise.
Your choices
You can delete your eligible data yourself at any time from your private space — see Data & Deletion for exactly what that does. You can also turn off optional reminder emails from the same page.
Jurisdiction and legal basis
LEGAL REVIEW REQUIRED. This section intentionally does not state a specific governing jurisdiction, a formal legal basis for processing (e.g. GDPR Article 6), or statutory retention periods — those require a real legal review, not an invented answer. If you have questions about your rights under a specific law, contact us and we'll do our best to help.
Contact
Questions about this policy or your data: support@twolensstory.com.