Terms & Conditions
Last Updated: May 24, 2018
The StoryZ software is written for applying motion effect on your photos and create video story or make your pictures live.
Animate your still image, make your digital art using StoryZ. By accessing or using the StoryZ software and services, you agree to be bound by the following terms, conditions, restrictions and limitations.
By downloading or using the app, these terms will automatically apply to you – you should make sure therefore that you read them carefully before using the app. You’re not allowed to copy, or modify the app, any part of the app, or our trademarks in any way. You’re not allowed to attempt to extract the source code of the app, and you also shouldn’t try to translate the app into other languages, or make derivative versions. The app itself, and all the trade marks, copyright, database rights and other intellectual property rights related to it, still belong to Andor Communications Pvt. Ltd.
Andor Communications Pvt. Ltd. is committed to ensuring that the app is as useful and efficient as possible. For that reason, we reserve the right to make changes to the app or to charge for its services, at any time and for any reason. We will never charge you for the app or its services without making it very clear to you exactly what you’re paying for.
The StoryZ app stores and processes personal data that you have provided to us, in order to provide our Service. It’s your responsibility to keep your phone and access to the app secure. We therefore recommend that you do not jailbreak or root your phone, which is the process of removing software restrictions and limitations imposed by the official operating system of your device. It could make your phone vulnerable to malware/viruses/malicious programs, compromise your phone’s security features and it could mean that the StoryZ app won’t work properly or at all.
You should be aware that there are certain things that Andor Communications Pvt. Ltd. will not take responsibility for. Certain functions of the app will require the app to have an active internet connection. The connection can be Wi-Fi, or provided by your mobile network provider, but Andor Communications Pvt. Ltd. cannot take responsibility for the app not working at full functionality if you don’t have access to Wi-Fi, and you don’t have any of your data allowance left.
If you’re using the app outside of an area with Wi-Fi, you should remember that your terms of the agreement with your mobile network provider will still apply. As a result, you may be charged by your mobile provider for the cost of data for the duration of the connection while accessing the app, or other third party charges. In using the app, you’re accepting responsibility for any such charges, including roaming data charges if you use the app outside of your home territory (i.e. region or country) without turning off data roaming. If you are not the bill payer for the device on which you’re using the app, please be aware that we assume that you have received permission from the bill payer for using the app.
Along the same lines, Andor Communications Pvt. Ltd. cannot always take responsibility for the way you use the app i.e. You need to make sure that your device stays charged – if it runs out of battery and you can’t turn it on to avail the Service, Andor Communications Pvt. Ltd. cannot accept responsibility
With respect to Andor Communications Pvt. Ltd.’s responsibility for your use of the app, when you’re using the app, it’s important to bear in mind that although we endeavour to ensure that it is updated and correct at all times, we do rely on third parties to provide information to us so that we can make it available to you. Andor Communications Pvt. Ltd. accepts no liability for any loss, direct or indirect, you experience as a result of relying wholly on this functionality of the app.
At some point, we may wish to update the app. The app is currently available on Android and iOS – the requirements for both systems (and for any additional systems we decide to extend the availability of the app to) may change, and you’ll need to download the updates if you want to keep using the app. Andor Communications Pvt. Ltd. does not promise that it will always update the app so that it is relevant to you and/or works with the iOS/Android version that you have installed on your device.
However, you promise to always accept updates to the application when offered to you, We may also wish to stop providing the app, and may terminate use of it at any time without giving notice of termination to you. Unless we tell you otherwise, upon any termination, (a) the rights and licenses granted to you in these terms will end; (b) you must stop using the app, and (if needed) delete it from your device.
Security of StoryZ User Data: The FB Platform Data and other types of user data related to login and user activity, is collected using REST APIs that have been deployed on AWS cloud. The collected details are not shared to any other third party system in any form. For fair use of the user data we have enabled following security checks at different layers of data transfer and persistence.
TLS Communication: All data is exchanged from device to backend server over HTTPS [TLS-1.2], to avoid any "man in the middle" attacks. The app has also been pinned using domain certificate public key that is used for HTTPS calls, to ensure data read at AWS origin only. Kindly find the screenshot "elb-security-policy-TLS-1.2.png".
Param Validation and Hash Guarding of APIs: The parameter values shared through APIs are validated based on regex expressions. Apart from this we have enabled hash guarding of APIs in which we create a hash at device based on params values and a shared salt, and validate this by again generating hash using the same algorithm and match these hashes. The hash guarding helps in fighting “man-in-the-middle” attacks.
SSL Pinning of Apps: SSL pinning has been enabled for all the communication between app and AWS infrastructure, as an additional security layer for application traffic and to validate the remote host’s identity. For SSL pinning we have implemented “Certificate Pinning”. For this we have stored the root certificates of AWS root domains in our application which have a very long expiry date.
Private VPC: StoryZ backend that includes microservices, databases and websites has been deployed on AWS in a VPC. It separates our StoryZ backend infra within AWS infra and gives control over the virtual networking environment, including resource placement, connectivity, and security. Kindly find screenshot “storyz-private-vpc.png”.
Security Group: We have configured separate security groups having a unique list of IPs and PORTS for access to specific resources like EC2 instances, lambda functions, databases and AWS services. Each resource is behind some security group that limits the availability of the resource. Moreover the database is accessible from within the VPC only. Kindly find the screenshot “rds-db-security-group.jpg”.
Authorisation using IAM configured roles : AWS Identity and Access Management (IAM) is a web service that helps in secure control access to AWS resources. IAM is used to control users who are authenticated (signed in) and authorised (has permissions) to use resources. We have provided role based limited access to different stakeholders - sysadmins, QA team and content uploaders. For accessing the web services like S3 using AWS console MFA has been enabled for all users. Kindly find screenshot "aws-storyz-mfa.png".
Limited Access for RDS Instance: The RDS service where the data is saved has been configured on VPC "storyz-vpc (vpc-0e252d59e50f2ebe0)", and not on default RDS settings to ensure extra level of security within AWS infrastructure. Also the Security Group of RDS ensures RDS access within AWS infra only. Please refer to screenshots "storyz-db-live-conf.jpg" and “rds-db-security-group.jpg”.
Changes to This Terms and Conditions : We may update our Terms and Conditions from time to time. Thus, you are advised to review this page periodically for any changes. We will notify you of any changes by posting the new Terms and Conditions on this page. These changes are effective immediately after they are posted on this page.
Contact Us
If you have any questions or suggestions about our Terms and
Conditions, do not hesitate to contact us.
support@storyzapp.com