Information & policies

Security at Storybook Studio

We design Storybook Studio so family photos and books are private by default, while recognizing that no internet service can guarantee absolute security.

How we protect customer data

  • Private object storage with short-lived signed access links.
  • Row-level database policies that scope customer records to the authorized account.
  • Encrypted HTTPS transport and managed encryption at rest.
  • Server-only provider credentials and restricted administrative access.
  • Security headers, dependency monitoring, audit trails for privileged support access, and idempotent background processing.

Responsible disclosure

If you believe you found a security vulnerability, email security@storybookstudio.io. Include reproduction steps, the affected URL, and potential impact. Do not access another person’s data, perform denial-of-service testing, or disclose the issue publicly before we have had a reasonable opportunity to investigate.

Account safety

Use a unique password, protect access to your email account, and sign out on shared devices. Contact support@storybookstudio.io if you believe your account was accessed without permission.