Privacy Notice
Your manuscript is the most personal thing you will give us. This notice explains, in plain terms, what we collect, why, who else touches it, how long we keep it, and what you can ask us to do. It covers Novelward AI, operated by Novelward.
The short version
- Your writing is private by default. There is no public gallery, feed, or share link.
- We do not use your manuscripts, prompts, or generated text to train AI models — ours or anyone else’s.
- We collect the minimum we need: your email, a display name, your consent records, and the work you choose to upload. No birth date, no address book, no precise location, no advertising profile.
- You can export everything, and you can delete your account and your projects.
1. What we collect
Account and identity
Your email address (used to sign you in and to send you service messages) and the display name you enter at setup. Sign-in is by one-time emailed link, so we never receive or store a password.
Consent and attestation records
We record that you confirmed you are 16 or older, that you accepted these terms and this notice, and — for each manuscript — your rights affirmation (that you wrote it, are licensed, have permission, or verified it is public domain). Each of those is stored with a timestamp and the exact policy version you agreed to, because we need to be able to show what you agreed to and when. We record your age attestation only as “confirmed 16 or older” — we do not store your date of birth or your age.
We also store whether you opted in to marketing email. That one is kept as a simple on/off preference you can change at any time, not as a versioned consent record.
Your creative content
The manuscript file you upload (including its filename) and everything derived from it: the parsed passages and chapters, your Story Map and its facts, a “voice profile” describing your style — tone, tense, and point of view — continuation proposals and the scenes you accept, your branches and every saved version, your coaching conversations, and the files you export. This is the material we treat most protectively.
Operational records
Records that let the service run and stay accountable: background job state, audit entries for sensitive actions, request-deduplication keys, and aggregate usage counts. These deliberately exclude your creative content — no manuscript text, generated prose, coach messages, Story Map facts, project titles, filenames, or download links appear in our logs, analytics, queues, or crash reports. Our logging and analytics layers reject any field that is not on an explicit safe list.
What we do not collect
We do not collect birth dates, school or employer details, your contacts, precise location, or behavioural advertising profiles. We do not use third-party advertising networks, and we do not use analytics or error-reporting vendors that receive your IP address or device identifiers to build a profile of you.
2. Why we use it, and on what basis
We use your data to authenticate you, run the features you ask for, keep the service secure, meet our legal obligations, and understand product usage in aggregate. Where the law requires a lawful basis, ours is performing our contract with you (running the service), your consent (marketing email, which you can withdraw at any time), and our legitimate interests (security, abuse prevention, and aggregate measurement). Your specific rights and the exact legal bases depend on where you live; if you are in a region with data-protection law — such as the EU or UK (GDPR), Vietnam (PDPD), or a US state privacy law — contact privacy@novelward.pro to exercise them.
3. AI processing
When you ask for an analysis, a continuation, a continuity check, or a coaching reply, we send the relevant part of your work — selected passages, the canon facts involved, and your instruction — to our AI provider so it can produce a result. We send what the task needs, not your whole library.
Your content is not used to train models. Private manuscript content and generated continuations are never used to train our models or a provider’s models. We route AI requests through OpenRouter, which forwards them to an upstream model provider — currently Anthropic’s Claude models, served via Amazon Bedrock — under a configuration that restricts routing to providers offering zero data retention and that prohibits the use of your content for training. We verify which provider served each request and reject any response that does not come from the approved provider.
If we change our AI provider or the upstream models we route to, we will update this notice with the provider’s identity.
4. Who else processes your data
We use a small number of providers to run the service. They act on our instructions and may not use your content for their own purposes.
- Supabase — our database and authentication provider. Holds your email address and all project records, and delivers your one-time sign-in links.
- OpenRouter — routes AI requests to an upstream model provider (see “AI processing” above) under a zero-retention, no-training configuration. Receives only the passages and instruction a given task needs, never your whole library.
- Paddle — our authorised reseller and merchant of record for all purchases. Paddle is the seller on your receipt and handles payment, tax, and invoicing. Card details go to Paddle, never to us; we hold no card data.
- Our hosting provider — we run the application and encrypted file storage on a dedicated server we operate. Manuscript files are uploaded directly to that storage and are not routed through the web layer, and they are scanned for malware before we process them.
We keep our list of providers current; email privacy@novelward.pro for the up-to-date list and processing locations. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
5. Staff access
Staff access to manuscript-bearing systems is prohibited by default. It is permitted only for documented support, security, or legal workflows, requires authorisation, and is written to an audit log. Support tooling is built so that a request can be handled without exposing your writing broadly.
6. How long we keep it
- While you are using it. Project content stays while your account and project are active.
- When you delete. Deleting a project removes access immediately and queues the underlying data for deletion. Our target is removal from active databases, search indexes, vector representations, caches, stored file versions, and generated exports within seven days.
- Backups. Creative content in rolling backups expires within 30 days, unless a documented legal hold applies.
- Exports. Files you generate expire after seven days; download links are authorised at the moment you request them and last 15 minutes.
- Inactivity. We plan to delete accounts after 24 months without a sign-in, with notices 30 days and 7 days beforehand and a simple way to keep the account by signing in.
- What survives. Billing records, security records, and records under legal hold may be kept where the law requires, held separately from your creative content.
7. Your choices and rights
- Export. You can export your manuscript and accepted work as a DOCX, and your Story Map, Memory Receipts, and Human Contribution Log as Markdown or JSON, at any time and on every plan.
- Delete. You can delete individual projects, or your whole account, from your privacy settings. We ask you to re-authenticate first, because deletion is permanent.
- Marketing. Marketing email is off unless you opt in, and you can turn it off again in settings.
- Access and correction. Write to privacy@novelward.pro and we will help.
Depending on where you live, you may have additional rights — such as access, correction, deletion, portability, or objection — and the right to complain to your local data-protection authority. Contact privacy@novelward.pro and we will help you exercise them.
8. Security
We encrypt data in transit and at rest, separate production access by role with least privilege, keep secrets out of our source code and client apps, scan uploads for malware before processing them, and audit staff access to systems that hold manuscripts. No system is perfectly secure, and we will tell you and the relevant authorities about a breach affecting your data as required by applicable law.
9. Young writers
Novelward AI is for people aged 16 and over, and we ask you to confirm that when you sign up. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact privacy@novelward.pro and we will restrict it and follow our deletion process.
10. Changes to this notice
We version this notice. If we make a material change — particularly one that changes how your writing is processed — we will tell you before it takes effect and ask you to review it.
11. Contact
Privacy questions: privacy@novelward.pro. Everything else: support@novelward.pro. Novelward AI is operated by Novelward, Thang Long Avenue, Hanoi, Vietnam.