FableFactoryTerms of Service

FableFactory Privacy Policy

Effective and last updated: September 18, 2026

1. Who we are and what this policy covers

FableFactory is operated by Qbical LLC, 301 Benjiman Street, Denton, TX ("FableFactory," "we," "us," or "our"), which operates the browser-based creative service at https://fablefactory.io. The service lets users develop stories, generate images with artificial intelligence, animate images into video, collaborate on projects, and edit images, video, audio, text, and captions on a multi-track timeline.

This policy applies to the FableFactory website and application, including the application named FableFactory on Google's OAuth consent screen. It explains what data we collect, where it comes from, why we use it, when we disclose it, how long we keep it, and how you can control or delete it. The policy is publicly available without signing in. Questions or privacy requests may be sent to support@fablefactory.io.

2. Data collection and use at a glance

Data categorySourceWhat we collectWhy we use it
Google sign-inGoogle, with your permissionGoogle account ID, email, display name, profile pictureCreate, identify, secure, and display your FableFactory account
Other account dataYouEmail address, authentication records, account preferences, redeemed invite codeProvide access, authenticate you, and administer the private beta
Creative contentYou and requested AI generationsPrompts, projects, storyboards, references, uploads, generated media, timeline data, Director conversationsCreate, edit, store, render, and deliver your projects
CollaborationYou and collaboratorsInvitee email, role, invitation status, editing activity and locksShare projects and prevent conflicting edits
BillingYou and StripePlan, token balance, purchases, payment status; not full card detailsProcess purchases, subscriptions, refunds, and prevent fraud
Technical recordsYour browser and our hosting systemsIP address, browser/device type, request time, security events, and error detailsOperate, secure, troubleshoot, and prevent abuse of the service
CommunicationsYou and our email systemsSupport messages and transactional email recordsRespond to requests and deliver account, security, receipt, and invitation notices

We do not collect sensitive Google service content such as Gmail messages, Google Drive files, contacts, calendars, or Google Photos. We do not sell personal data or use personal data for targeted advertising.

3. Google sign-in data: access, use, storage, and sharing

Data and permissions requested

Google sign-in is optional. If you select "Continue with Google," we request only the standard OAuth scopes openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile. These allow Google to provide your unique Google account identifier, email address, display name, and profile picture after you consent. We do not request any restricted or sensitive Google product scope.

How we use Google data

  • Your Google account ID and email identify your FableFactory account and sign you in.
  • Your email is used for account, security, collaboration, billing, and support communications.
  • Your name and profile picture display your identity in account and collaboration interfaces.
  • Authentication records help detect fraud, abuse, and unauthorized access.

How we store and disclose Google data

We store the Google account ID, email, name, and profile picture in our access-controlled account systems for as long as your FableFactory account is active. Authentication infrastructure providers process this data solely to operate sign-in, hosting, security, and support. We do not send your Google profile data to AI generation providers, Shotstack, or Stripe merely because you used Google sign-in.

We do not sell Google user data; use it for advertising, credit decisions, or audience profiling; allow it to be used to train artificial-intelligence models; or permit humans to read it except when necessary for security and abuse investigation, legal compliance, support you request, or with your explicit consent. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Sign-in tokens

When you sign in with Google, Google issues authentication tokens to complete the sign-in. Our authentication provider exchanges these tokens server-side to verify your identity; Google access and refresh tokens are not retained beyond the sign-in exchange and are never exposed to your browser or to other service providers. Your ongoing access uses a FableFactory session credential stored in your browser's secure storage, which expires automatically and is deleted when you sign out or delete your account.

Your Google controls

You can revoke FableFactory's future Google access at any time from your Google Account connections. Revoking access prevents future Google sign-in but does not by itself delete your FableFactory account. Delete your stored FableFactory data through Account Settings while signed in, or email support@fablefactory.io from the address associated with your account.

4. Creative content and AI processing

We collect the materials you submit or create, including project names, stories, prompts, storyboards, scene settings, cast and world references, uploaded images, video and audio, generated outputs, captions, timeline arrangements, exports, and Director conversations. We process this content only to provide the creation, editing, collaboration, storage, generation, moderation, and export features you request; respond to support requests; and secure the service.

Prompts and the reference media needed for a generation are sent to Replicate and the selected AI model provider. Media and timeline instructions needed for an optional cloud export are sent to Shotstack. These providers process that content to complete your request and may retain inputs and outputs for limited operational periods under their own policies. FableFactory does not use your prompts, uploads, Google profile data, or generated content to train AI models.

5. Other ways we use data

  • Provide, maintain, personalize, and troubleshoot FableFactory.
  • Authenticate accounts, enforce invitation access, and protect users and projects.
  • Store and serve project media across your devices and to authorized collaborators.
  • Manage subscriptions, token holds, settlements, refunds, and transaction records.
  • Send verification, recovery, email-change, receipt, invitation, and security messages.
  • Comply with law, enforce our Terms, investigate fraud or abuse, and protect legal rights.

We do not use third-party advertising cookies, sell personal information, or "share" personal information for cross-context behavioral advertising as defined by California law.

6. Service providers and other disclosures

We disclose only the data reasonably necessary for the recipient's stated operational purpose. Our principal service providers are:

  • Google: optional account authentication and basic profile data delivery.
  • Lovable Cloud: application hosting, database, authentication, server functions, and security.
  • Amazon Web Services (S3): encrypted storage and delivery of uploaded, generated, and exported media.
  • Replicate and selected AI model providers: prompts and necessary reference media used to produce requested images or video.
  • Shotstack: timeline instructions and temporary media access used to render an export you request.
  • Stripe: billing contact, purchase, subscription, payment status, and fraud-prevention data. Stripe receives payment-card details directly; FableFactory does not store full card numbers.
  • Email delivery providers: email address and message details needed to send authentication and transactional notices.

We may also disclose information when required by law; to protect users, the service, or legal rights; to investigate fraud or abuse; or in a merger, financing, acquisition, reorganization, or sale of assets. A successor must handle personal data consistently with this policy and applicable law.

7. Storage, retention, and deletion

  • Account and Google profile data: retained while your FableFactory account is active and deleted when the account is deleted, except limited records required for security, fraud prevention, legal compliance, or dispute resolution.
  • Active projects and media: retained while your account is active and until you delete them or your account.
  • Unused media: media not referenced by a storyboard or editor timeline may be automatically deleted after 60 days.
  • Deleted media: may remain recoverable for approximately 30 days before permanent removal from active systems and cloud storage.
  • Deleted projects and videos: associated scenes, timeline arrangements, and video-tagged media are removed from active systems and cloud storage.
  • Technical and security records: retained only as long as reasonably needed for troubleshooting, security, abuse prevention, and legal obligations.
  • Billing records: retained as required by tax, accounting, payment, fraud-prevention, and other legal obligations.
  • Backups: residual copies may remain in encrypted backups until overwritten through the normal backup cycle, ordinarily no longer than 90 days.

To delete your account, open Account Settings and use the account-deletion control. If you cannot sign in, email support@fablefactory.io from the account's email address. We may verify your identity. Account deletion removes personal account data, projects, and media subject to the limited legal, security, transaction, and backup exceptions above. Revoking Google access and deleting a FableFactory account are separate actions.

8. Cookies and browser storage

We use essential cookies and browser storage for authentication, security, preferences, editing state, and performance. These technologies are required for service operation. We do not use third-party advertising cookies.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, obtain a copy of, delete, restrict, or object to processing of personal data, and to withdraw consent where processing relies on consent. You may update available account details or delete your account in Account Settings. For any request, email support@fablefactory.io. We may verify your identity before completing it and will respond within the period required by applicable law.

10. Security

We use safeguards designed to protect personal data, including encrypted connections, access controls, row-level database authorization, signed and expiring media links, and restricted administrative access. No method of transmission or storage is completely secure. If a breach affects your personal data, we will provide notice when required by law.

11. Children

FableFactory is not intended for children under 13, or under 16 in the EEA or UK, and we do not knowingly collect their personal data. If you believe a child has provided personal data, contact support@fablefactory.io so we can investigate and delete it.

12. International processing

We and our providers may process data in the United States and other countries whose data-protection laws differ from those where you live. Where required, we use appropriate contractual or other legal safeguards for international transfers.

13. Changes to this policy

We will update this policy when our data practices change and revise the date at the top. For material changes, including a new type or use of Google user data, we will provide additional notice in the service or by email and obtain consent when required before applying the new practice.

14. Contact

Qbical LLC, 301 Benjiman Street, Denton, TX, is responsible for the personal data practices described in this policy. For privacy questions, complaints, access requests, or deletion requests, contact support@fablefactory.io. You can also review our Terms of Service.