1. What we collect
Your account
- Your email address. You have to verify it before the service will generate anything. You must be 18 or older to create the account.
- Your pen name — or names. You are asked for one when you register, and you can hold several, with one marked as the default. Each book chooses which one it publishes under. The pen name is what goes on the title page, and on a free book's cover in the showcase.
- Not your legal name. This is deliberate. Registration does not ask for it, because it is friction and a privacy liability, and it is only needed if you later register a copyright. If that day comes you will be asked then.
Your book, and everything that goes into it
- The premise and every intake answer — including the dedication, the epigraph, the scenes you already picture, the things to avoid, and the comparison titles you name.
- The book itself — the story bible, every chapter, the cover art and the exported files.
- The authorship record. Every human decision is logged as it happens: each sentence you rewrite, each outline or reference sheet you approve, each cover prompt you edit, each mid-draft question you answer. This is what your edit share is calculated from.
Payment
Payments are handled by Stripe. Card numbers never reach us.What we store on our side is a Stripe customer id, the email Stripe has for that customer, a subscription or price lookup key, and invoice ids. A billing address is collected only if tax requires it.
2. Your prompts are an unpublished manuscript
A premise, an outline and a draft are the most sensitive thing a writer owns. We treat them as confidential: your premise, your story bible and your outline are never shown to other users, never published, and never used as examples. The finished book is different on the free tier, and section 4 says exactly how: its cover can appear in the showcase, and signed-in members can read it.
We do not train or evaluate models on your premises, story bibles, or manuscripts.
Confidential on our side is only half the answer, because writing your book means sending your text to a model provider. Here is what that routing actually does:
- Free-tier books are drafted by DeepSeek V4-Flash, reached through OpenRouter. Every OpenRouter call is sent with
data_collection: "deny", which is the setting that refuses provider logging and training on that traffic. On the free tier every stage — planning, drafting and the continuity check — runs on that one model. - Paid-tier books are planned to draft on Google's Gemini, bought directly from Google rather than through OpenRouter.
- Your text is sent repeatedly. The story bible is rebuilt byte-for-byte as the leading part of every chapter request, so material from your intake is transmitted on each of 35 or more calls per book, not once.
We cannot promise that a provider never logs a request on their side. We can say what we send, and that we do not opt in to collection.
3. Who else sees your data
These are the companies involved in running the service. Each entry says what that company actually receives. Data-processing agreements and standard contractual clauses with them are not claimed as signed. They will be in place before any EU paid traffic.
- OpenRouter
- Routes the free tier's drafting to DeepSeek V4-Flash. Receives your story bible and chapter instructions — which means your premise and intake answers — on every chapter call, and returns the generated prose. Calls carry
data_collection: "deny". - Google AI
- Planned to draft paid-tier books through Gemini, bought directly from Google. Receives the same material as above for those books.
- fal.ai
- Generates cover art. Receives the cover brief — a description built from your story bible, plus any prompt text you edit yourself. It does not receive your chapters.
- Supabase
- The database. Holds your account, your pen names, your books and chapters, your authorship record, and your credit balance. This is the one that holds everything.
- Cloudflare
- Serves the website. As the host it necessarily sees request metadata, including IP addresses. Cloudflare Web Analytics, when enabled, is cookieless.
- Stripe
- Takes payment for credits and subscriptions. Receives your card details directly; we do not. We keep the identifiers listed in section 1.
- Resend
- Sends transactional email — verification, and the message telling you your book has finished. Receives your email address and the contents of those messages.
- Sentry
- Receives error reports from the website and the book engine so a failed run can be found. Reports are stripped of long strings; we do not send premises, outlines, chapter prose or story bibles there.
Cover-art and title screening is done in-process, by us. There is no separate moderation vendor at MVP, so there is no eighth processor seeing your titles for that job.
4. The gallery, and what is public
The showcase shows book covers, and signed-in members can open a public book and read it. It exists as social proof, not as a marketing channel, and what appears in it depends on your tier. The text of a book is never public to the open web: reading it needs an account, and the premise behind it is never shown to anyone.
- Free books are public, with the pen name on the book. The cover can appear in the showcase, andsigned-in members can read the book. It is not public to the open web.There is no private option on the free tier.That is the trade for the book costing nothing, and it is stated on the pricing page for the same reason it is stated here.
- Paid books are private by default, cover and text both. Appearing in the gallery is something you opt into, not something you opt out of.
- Upgrading unlocks privacy retroactively. If you wrote a free book and later regret its cover being public, moving to a paid plan lets you make it private.
- Covers and titles are reviewed before they appear in the showcase, not just the premise behind them. That review is in-house, and a book whose cover or title changes afterwards leaves the showcase until it is reviewed again.
5. Private is not the same as deleted
Both exist, and they do different things. This distinction is deliberate, because a service that offers only the first is quietly refusing the second.
- Private hides a book from the showcase and from other members. It stays in your library, and we still hold it.
- Deleted means gone from the app.
You can erase your account yourself fromyour account page. When you do:
- App data for that account — books, chapters, pen names, authorship events, passkeys, covers — is removed from the product.
- The credit ledger is kept. It is append-only.
- The login identity is tombstoned (stripped, not replayed as a person).
- Files you have already downloaded stay on your device. Nothing we do reaches your hard drive.
- Host backups follow the residual windows of Supabase and, when object storage is in use, R2. Those windows are the host’s, not a number we invent here.
We delete what we hold. We cannot delete a model provider’s inference logs.
How long we keep things
- An open account — while it is open.
- The identity tombstone and the credit ledger — seven years after erasure.
- The authorship record — the life of the account, then the same seven-year window. We will export it on request. We do not warrant it for a copyright office.
- Application logs and Sentry error reports — about 90 days.
6. Cookies and analytics
There is no fat consent banner, because we do not set marketing trackers. If that changes, the banner comes back and this section will name the new cookie.
__Host-sw_session — the login session. HttpOnly, Secure, SameSite=Lax, host-only (it cannot span the public site and the app). About 30 days; the tokens inside it rotate sooner.sw_device — reserved for abuse prevention, about 365 days when it is set. First-party. Not used for analytics. The day anything reads it for analytics it reclassifies, and the abuse exemption is lost.__Host-sw_flash and__Host-sw_pending_email — short-lived functional cookies (two minutes and ten minutes) so a form can finish without putting your email or an error in the address bar.__Host-sw_return — short-lived (ten minutes) functional cookie set only when you sign up or log in from a showcase book, so the link in your email brings you back to that book. It holds the book's address and nothing else, and is deleted when used.
Analytics, when enabled, is Cloudflare Web Analytics, which is cookieless. Turnstile is Cloudflare’s challenge on signup and login; it is not a cookie we set.
One thing that is not a cookie but still leaves this site: every page loads its fonts from Google Fonts. Your browser makes a request to Google on each page view and discloses your IP address to Google in doing so. There is a recorded decision to self-host the book's interior font; the website's own fonts still load from Google.
7. How we protect it
The measures that are decided, rather than aspirational:
- Provider API keys are server-side only. Your browser never holds one.
- Rate limits run per account and per IP address, which means IP addresses are processed for abuse prevention.
- Everything you type is treated as untrusted. Text you supply is marked off explicitly and handed to the model as material for a book, never as instructions to follow — because your premise is repeated inside every chapter request, so anything smuggled into it would persist across the whole book rather than affecting one call.
No system is perfectly secure.
8. Your rights over your data
Soft launch is United States first. We do not take paid traffic from the EU, the UK or Canada until processor agreements, a chosen establishment, and a request process for those laws exist. That is why this page does not claim GDPR or CCPA readiness.
In practice you can read your books, make paid books private, erase your account, and — on a paid plan — download PDF and EPUB files of the book. Beyond that:
- A copy of what we hold. Paid export already gives you the book files. A “download my data” zip — premise, story bible, chapters, authorship record — is available on requestat hello@shadowwriter-ai.com. Self-serve comes later.
- Erasure. Self-serve fromyour account page, as in section 5.
If we have a personal-data breach, we will email affected users without undue delay. Where GDPR later applies, we will also notify the lead authority within 72 hours of becoming aware, when that law requires it. The operator of Zedara LLC owns that response until it is delegated. Write tohello@shadowwriter-ai.com.
9. Children
You must be 18 or older to create an account. The service can write a children’s book as output. It does not offer accounts for children, and it is not directed at them.
10. Contacting us, and changes to this policy
The operator is Zedara LLC. Privacy and legal notices go tohello@shadowwriter-ai.com. Copyright complaints go todmca@shadowwriter-ai.com— that address is on the terms; it is not a second privacy inbox. A registered street address is not published yet. Until it is, notices go by email. There is no separate data-protection officer or EU representative while launch stays US-first.
If we make a material change, we will email the address on the account at least 30 days before it takes effect. Continued use after that date is acceptance.
Last updated 20 September 2026. Working defaults; not counsel sign-off.