Privacy policy
Effective 1 October 2026 · Endless River Labs Ltd.Stora is operated by Endless River Labs Ltd.. This notice explains how we handle information for stora.rocks, its hosted MCP server and its plugins. Contact hello@endlessriver.xyz about privacy or your account.
Information we handle
- Account information: your email address, optional name, workspace membership, settings and invitations.
- Workspace content: apps and store identifiers, tracked keywords and markets, public store observations, competitor research, listing drafts, decisions and experiment notes that you or your connected assistant save.
- Optional Apple Ads connection: the credentials an administrator configures and the aggregate campaign, keyword, query, spend and install reports imported from Apple. Stora does not receive individual ad viewers' identities through these reports.
- Access and operational records: sessions, hashed login codes, API-key and OAuth token hashes, client registration and connection details, security rate limits, audit events and technical request/error records.
- Support messages and information you choose to send us.
Purposes and legal bases
We use account information and workspace content to provide the service you request, authenticate access, collect store observations and return reports. Our basis for this account processing is performance of our agreement with you. For business contacts acting for an organisation, we rely on our legitimate interest in providing and administering that organisation's service.
We use limited access, audit and technical information to prevent abuse, enforce workspace permissions, diagnose failures and keep the service reliable. We rely on our legitimate interests in security and reliable operation. We handle support messages to answer your request, on the same service or legitimate-interest bases. Where a legal obligation requires records or disclosure, we process the necessary information for that obligation.
Your AI connections
When you connect Stora to Claude, ChatGPT, Codex or another MCP client, you select a workspace and its read, tracking/write or administrator permissions. The client receives the tool results it requests within that connection. Its provider processes conversations and those results under its own terms and privacy policy. Check the provider's settings before connecting confidential business information.
Stora does not receive your whole conversation or send workspace content to a model-training service of its own. A client's tool requests can contain the arguments needed for a task. Do not send passwords, private keys or unnecessary personal information as tool arguments. Disconnect at Connected apps; this stops future token access but does not remove results already received by the client.
Service providers and public sources
Cloudflare hosts the website, worker, database and security services, including Turnstile checks at ordinary email sign-in. Resend delivers sign-in and invitation emails. Apple and Google provide public store information; Apple Ads provides the optional reports you authorise. These providers process the information needed for their roles. We do not sell your workspace data.
Hosting, email delivery and the AI provider you choose can involve processing outside the UK or EEA. The relevant provider's processing locations and contractual safeguards apply to its role. Contact us for information about the arrangements relevant to your account. Public store listings are collected from store services; they can include developer names and other information the publisher made public.
Cookies and security
Stora uses an essential HttpOnly session cookie to keep you signed in. The browser stores the selected workspace so the app can open it. Authentication and abuse-prevention mechanisms are needed to operate the service. Provider infrastructure processes network requests to deliver and protect it.
Stora stores API keys and OAuth codes/tokens as hashes. Apple Ads private credentials are encrypted in the database. Workspace checks restrict access to the account associated with the session or delegated connection. These measures reduce risk; no service can guarantee perfect security.
Retention and deletion
Account details, workspace settings, drafts and connection/audit records remain while needed to operate the account and support its history. Request account deletion through hello@endlessriver.xyz; we verify your authority before deleting a shared workspace. Legal requirements, active disputes or security investigations can require limited records to be retained.
Automated retention removes expired sessions and short-lived authentication records. OAuth access tokens last one hour and refresh tokens last 30 days; expired token/code records are cleared by scheduled housekeeping. Detailed search snapshots are reduced after 90 days and removed after 400 days. Rank and visibility history is kept for up to 730 days, competitor/digest history for up to 180 days, and imported Apple Ads reporting history for up to 400 days. These periods describe the configured recurring jobs; cleanup completes when those jobs run. Deleting an app removes its workspace records. Shared public-source caches can remain independently of an account.
Backup copies and provider operational records follow the hosting provider's recovery and retention mechanisms and may persist after active database deletion. We do not use deleted content to continue providing reports.
Your rights
Depending on applicable law, you can request access, correction, deletion, portability, restriction or object to processing based on legitimate interests. Contact hello@endlessriver.xyz. We may ask for information needed to verify your request. You can also complain to the UK Information Commissioner's Office or your local supervisory authority.
Providing an email address is necessary for an ordinary Stora account. Optional Apple Ads credentials are only needed for that integration. Stora's analysis supports your decisions; it does not make automated decisions about people's legal or similarly significant rights.
Changes
We update this page and its effective date when the service's handling of information changes. Material changes will be brought to users' attention through the service or the account contact details.