Privacy Policy

Please read this carefully

Last updated: 10 September 2026. Effective from the same date.

The short version

  • Your manuscript is yours. We never use it to train AI models, and neither do the providers who power our AI features.
  • We do not sell your personal information, and we do not share it for advertising.
  • AI only runs when you actively trigger it — typing "/" in the editor, generating an outline, or running the Story Analyzer. If you never do those things, nothing you write is sent to an AI provider. When starting a new story, you can also choose to build your outline entirely by hand instead.
  • Email us to delete your data, and we do it within three days.
  • You can export your work at any time, in several formats, for free.

The rest of this page gives the details. If anything is unclear, email support@authorflows.com and we will answer plainly.

1. Who we are

AuthorFlows is a browser-based novel writing tool built and run by its two founders, based in Casablanca and Meknes, Morocco. AuthorFlows is the name we trade under.

We are the data controller for the personal data described on this page. There is no separate privacy department. The founders handle privacy requests directly.

Contact for anything on this page, including data requests and complaints: support@authorflows.com. We are a small team and we answer our own email.

2. What we collect

  • Account data. Your name and email address, your account settings, and either a sign-in link sent to your email or a linked Google account, depending on how you sign in.
  • Your writing. Everything you create in the studio: manuscripts, chapters, outlines, characters, story maps, timelines, and notes.
  • Billing data. Your subscription status, plan, renewal date, and the country used for tax. We never see or store your card number. That stays with our payment partner, described in section 5.
  • Usage and technical data. Your IP address, browser and device type, which pages and features you use, word counts, and error logs.
  • Support data. Any email you send us and whatever you choose to include in it.

We do not deliberately collect sensitive data such as health, ethnicity, or religious or political belief. Fiction can contain anything, so if your manuscript touches on those themes we treat it as writing, not as information about you.

3. Why we use it

If you are in the EU, the EEA, or the UK, we need a lawful basis for each use. Here is what we do and why.

  • To run your account, store your writing, and sync it across devices. This is us delivering the service you signed up for (performance of a contract).
  • To process AI requests you trigger. Same basis: it is part of the service you chose (performance of a contract).
  • To take payment and manage your subscription. Contract, and legal obligations around tax and accounting.
  • To send service emails such as receipts, security notices, and changes to this policy. Contract, and our legitimate interest in keeping you informed.
  • To send product emails about new features. Consent, which you can withdraw at any time by emailing support@authorflows.com.
  • To keep accounts safe and investigate abuse or fraud. Our legitimate interest in protecting users and their manuscripts.
  • To understand how the studio is used so we can improve it. Consent where cookies require it, otherwise our legitimate interest.
  • To respond to legal requests and defend legal claims. Legal obligation, and legitimate interest.

Where we rely on legitimate interests, you can object at any time. See section 8.

4. How AI features work

This is the part that matters most to writers, so we are being specific.

What we never do. We do not use your manuscripts, outlines, characters, or anything else you create to train, fine-tune, or improve AI models. Not ours, and not anyone else's. We do not sell your writing, share it with other users, or use it to generate content for other people.

Nothing runs in the background. AI features only run when you actively trigger them: typing "/" to continue writing, selecting a paragraph to rephrase, expand, summarise, or improve, generating an outline, or running the Story Analyzer. If you never do any of those things, nothing you write is ever sent to an AI provider. When you start a new story, you can also choose to build your outline entirely by hand instead of generating it with AI.

What actually happens, when you do trigger it:

  • Only the text needed for that request is sent, over an encrypted connection, to OpenRouter, the AI infrastructure provider we use to route requests to the language model that actually generates the response. For an editor request that is usually the surrounding passage, not your whole book.
  • The model processes it and returns a suggestion to you.
  • We use OpenRouter, and the model providers it routes requests to, under commercial API terms that contractually forbid them from using your content to train or improve their models.
  • The provider may hold the text briefly, currently up to 30 days, only to detect abuse of their own platform. After that it is deleted. They may not use it for anything else.

About the output. AI suggestions are generated text. They can be wrong, generic, or similar to text produced for someone else. You decide what to keep. Copyright in AI-generated writing is treated differently from country to country, and in some places material generated purely by AI may not be protected at all. If that matters for your publishing plans, check the rules where you publish. See our Terms of Service.

5. Who else can see your data

We share the minimum needed to run the service. The categories are:

  • Our payment partner, which receives your name, email, billing address, country, and transaction details in order to sell you the subscription, take payment, handle tax, and issue invoices.
  • Vercel, our hosting provider, and Neon, our database provider, which together store your account and your writing.
  • UploadThing, our file storage provider, which stores images you choose to upload, such as character portraits.
  • OpenRouter, our AI infrastructure provider, which receives only the text needed for an AI request you trigger, and routes it to the model that generates the response.
  • Google, if you choose to sign in with your Google account. It receives only what is needed to confirm who you are.
  • Resend, our email delivery provider, which receives your name and email address so we can send you service and product emails.
  • Authorities or advisers, where the law requires it or we need to defend a legal claim.

You can ask us for the current list of the specific companies we use. Email support@authorflows.com and we will send it.

Payments. Subscriptions are sold and processed by Armitage Labs OÜ, trading as Creem, at Telliskivi Street 57b/1, Tallinn 10412, Estonia. Creem is the merchant of record, which means Creem is the legal seller of your subscription, issues your invoice, and handles VAT and sales tax. Creem handles your payment data as its own controller under its privacy notice. We never receive your full card details.

Who reads your writing. Only you, by default. AuthorFlows is run by two people, and both have technical access to the database that stores your work. We look at manuscript content only when you ask us to for support, when we have to investigate a security or abuse problem, or when the law requires it. We do not read manuscripts out of curiosity or for product research.

We do not sell your personal information and we do not share it for cross-context behavioural advertising.

If AuthorFlows is ever sold or merged, your data may transfer as part of that. We will tell you before it happens.

6. Where your data goes

We operate from Morocco. Our providers are located in the European Economic Area and the United States. Your data therefore moves across borders.

Where data leaves the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK Addendum where it applies, or on an adequacy decision where the destination country has one. Data is encrypted while it travels. You can ask us for details of these safeguards by email.

7. How long we keep things

  • Your account and your writing: for as long as your account is open.
  • Email us at support@authorflows.com to delete your data, or if your account is suspended or closed: we delete it within three days.
  • Backups: our hosting provider takes automatic backup copies of the database. Content you delete can remain inside those copies for a short period, until they are replaced by newer ones. We do not use backups for any purpose other than restoring the service after a failure.
  • Text sent to AI providers: held by the provider for up to 30 days for abuse monitoring, then deleted.
  • Billing and invoice records: held by Creem, not by us. Creem's published retention is 3.5 years for contract data from the end of the contract, and 7 years for accounting records under the Estonian Accounting Act. Tax law requires this, so these records survive deletion of your AuthorFlows account.
  • Support emails: 12 months.

Export before you delete. Deletion is permanent and we cannot bring your manuscripts back. Export first. A chapter can go out as .txt, .doc, .pdf, .md, or .html, and a whole story as .doc, .pdf, or .txt.

8. Your rights

Wherever you live, email support@authorflows.com to use any of the rights below. We reply within one month, we do not charge, and we will not treat you worse for asking.

If you are in the EU, the EEA, or the UK, you can ask us to give you a copy of your personal data, correct anything wrong, delete your data, restrict how we use it while a dispute is sorted out, or send your data to another provider in a machine-readable format. You can object to any use we base on legitimate interests, and you can opt out of marketing at any time. Where we rely on consent, you can withdraw it, which does not affect anything we did before you withdrew it.

You also have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office at ico.org.uk. In the EU you can find yours through the European Data Protection Board. We would rather you came to us first so we can fix it.

We do not make automated decisions about you that have legal or similarly significant effects.

If you are in California, the CCPA as amended by the CPRA gives you the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be treated differently for exercising those rights.

In the last 12 months we collected the categories described in section 2: identifiers such as name, email, IP address and account ID; customer and billing records; commercial information about your subscription; internet activity such as which features you use; approximate location from your IP address; and the content you write. The only sensitive personal information we handle is your login credentials, which we use solely to sign you in and for nothing else. We disclosed these categories to the providers listed in section 5, for the business purposes described there.

We have not sold personal information or shared it for cross-context behavioural advertising in the past 12 months, and we do not do so now. We do not knowingly sell or share the information of anyone under 16. You may use an authorised agent to make a request, and we will ask for proof.

If you are in another US state with a comprehensive privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana, you have similar rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and profiling. Use the same email address. If we turn a request down, you can appeal by replying to our answer, and you can complain to your state Attorney General.

9. Cookies

We use cookies to keep you signed in to your account and to remember your settings. Without these the studio cannot work, so they are always on. That is the main thing cookies do here.

We also use tools that help us understand how the studio is used and how the website performs. Where those require your consent under the rules in your country, we ask for it first, and you can change or withdraw your choice at any time.

You can block or delete cookies in your browser settings, but if you block the essential ones you will not be able to stay signed in.

10. Security

We will not pretend to be a large company with a security department, so here is what is actually true. Traffic between your browser and AuthorFlows is encrypted using HTTPS. Sign-in is handled through email links and Google, so there is no password of ours to compromise. Your work sits in a managed cloud database, and access is limited to the two founders. The database is encrypted where it is stored, and our hosting provider takes automatic backup copies.

No system is completely safe. If a breach happens that puts your data at risk, we will tell the relevant authority within 72 hours where the law requires it, and we will tell you without delay where the risk to you is high.

11. Children

AuthorFlows is not for children under 16. If you are between 16 and 18, use it with a parent or guardian involved. Where local law sets a lower age for consenting to online services, we apply that age instead, and never below 13. We do not knowingly collect data from children below these ages. If you think a child has given us data, email us and we will delete it.

12. Changes to this policy

We update this page when the product or the law changes. The date at the top is always the current version. If a change materially affects your rights, we will email you at least 30 days before it takes effect.

13. Contact

Questions, requests, or complaints: support@authorflows.com

AuthorFlows, Meknes 50000, Morocco.