Privacy Policy

How information—including manuscripts and other creative data—is collected and handled.

Effective date: July 11, 2026

1. Basic policy

the NovelShaft operator (the “Operator”) handles information collected while providing NovelShaft in accordance with applicable law.

Manuscripts, ideas, reference material, and conversations with AI are central to a user’s creative work. The Operator does not process that content beyond what is needed to provide the service.

2. Information collected

Account and authentication

  • Primary and secondary email addresses, display name, and display-language setting
  • Login methods, authentication state, MFA configuration, and email-address verification state
  • Identifiers provided by Google or Apple external login
  • Times and states related to account creation, updates, and deletion requests

Passwords are managed by Amazon Cognito and are not stored in the NovelShaft application database.

Creative data and service use

  • Projects, manuscripts, structure, outlines, and notes
  • Messages sent in chat and AI responses
  • Uploaded reference material, PDFs, text, images, and other supported files
  • Search chunks, features, embeddings, and search results generated from manuscripts and reference material
  • Audio sent for transcription and the resulting text
  • AI operation type, usage, time, result, and error information
  • Ratings and reports submitted about AI output, public works, or authors
  • Publication-term consent and public work and author identifiers
  • Creative-assist acquisition, selected project, conversation, reports, and save result
  • Publication settings, export history, and other operation information

Billing and subscriptions

  • Plan, billing period, subscription state, and plan-change state
  • Payment result, invoice, refund, dispute, payment event, and transaction identifiers
  • AI-credit grants, use, expiry, adjustments, reversals, and unsettled-use history
  • Paid creative-assist purchases and acquisition reconciliation
  • Stripe, App Store, and Google Play customer, transaction, purchase, order, subscription, refund, and account-association identifiers needed for reconciliation

Stripe processes card numbers and security codes. Apple processes iOS and iPadOS in-app payment methods, and Google Play processes Android payment methods. NovelShaft does not store those payment-instrument details in its application database.

Communication, device, and contact

  • IP address, browser, operating system, device type, and access time
  • Operation history, errors, incidents, and security events
  • Name, reply email, subject, and message entered in the contact form
  • Contact receipt time, notification state, and response history

3. Purposes of processing

  • Account registration, identity verification, login, and security
  • Manuscript management, AI assistance, search, transcription, publication, and export
  • AI processing requested by the user and delivery of its result
  • Creative-assist provision, acquisition management, conversation continuity, and report saving
  • Subscription, billing, refund, AI-credit, and paid creative-assist management
  • Improving response quality and experience using user-submitted AI-response ratings
  • Receiving and reviewing safety reports, reducing harm, moderation, reconsideration, and audit
  • Incident investigation, fraud prevention, audit, reliability, and quality improvement
  • Responding to contacts and sending important notices
  • Compliance with law, the Terms of Service, and protection of rights

The Operator does not use a user’s creative content for unrelated advertising, training a general-purpose model owned by the Operator, or creating datasets for other users. Any future use for a different purpose would be explained in advance and supported by a separate legal basis when required.

5. Service providers and international transfers

NovelShaft uses external services and limits information sent to what each operation needs:

PurposeServiceMain information
AuthenticationAmazon CognitoEmail, authentication information, and external-login identifiers
External loginGoogle / AppleAccount identifier, email when provided, and information required for login
Web paymentsStripeCustomer, subscription, invoice, and reconciliation information
Mobile purchasesApple App Store / Google PlayProduct, transaction or purchase token, subscription and refund state, and account association
AI processingOpenAIText, reference material, audio, and processing instructions selected for the operation
Storage and deliveryAmazon Web Services and related providersApplication data, uploaded files, and logs
Contact notificationAmazon SESName, reply email, subject, and contact message
AnalyticsGoogle AnalyticsPages, access time, device, browser, and usage information only after optional cookies are allowed

A provider may process information outside the user’s country or region. The Operator uses applicable transfer mechanisms and reasonable safeguards such as contracts, access control, and encryption. Users may ask about the safeguards used where applicable law provides that right.

6. Retention and deletion

Information is kept only as long as needed, considering account and subscription state, processing purpose, legal retention duties, possible disputes, security needs, and backup cycles.

After account deletion completes, creative data—including manuscripts, projects, chats, reference material, creative-assist conversations and reports, and derived search data—and ordinary-use personal identifiers are generally deleted or anonymized.

Publication-term consent is kept as long as required for the applicable version and audit. Evidence for unresolved safety reports is kept until review completes. For resolved reports, retained content excerpts, free-form notes, and direct identifiers are deleted 180 days after resolution unless legal preservation is required.

Minimum records needed for billing, accounting, refunds, disputes, fraud prevention, security, and evidence of completed deletion may be retained for a limited purpose and period. Complete removal from backups and external services may take additional time.

7. Security

The Operator uses reasonable safeguards including access control, authentication, encryption in transit, separation of secrets, logging and monitoring, backups, and vulnerability response.

8. Your rights

Depending on applicable law, users may request information about processing, access, correction, completion, deletion, restriction, objection, cessation of third-party disclosure, and data portability.

Consent may be withdrawn. Processing based on legitimate interests may be opposed for reasons related to the user’s particular situation.

Identity verification may be required. Submit a request through support. Users in the European Economic Area may complain to the supervisory authority responsible for their residence, workplace, or the place of an alleged infringement.

9. AI and automated processing

The interface identifies when the user is interacting with AI. AI generates writing, suggestions, search results, and other output from user instructions and information related to the work.

A creative assist that uses a project may process the manuscript and reference material in that selected project as context. The current feature cannot exclude individual items, so users should confirm the scope before starting.

AI output may be inaccurate or unsuitable. The user decides whether to adopt, edit, publish, or sell it. The Operator does not let AI alone make a decision with legal or similarly significant effects on a user.

Published work reported for serious safety categories may be temporarily hidden to reduce harm while a human operator reviews it. Permanent removal or account restriction is decided after human review.

10. Cookies and similar technologies

Essential cookies maintain login, security, and cookie settings. Some features, including login, may not work if essential cookies are blocked.

Optional cookies and services such as Google Analytics are not enabled before permission is given. Reject and allow choices are offered together, are stored for 180 days, and may be changed at any time.

11. Children

The service is intended for people aged 18 or older and may not be used by anyone under 18.

12. Changes to this Policy

This Policy may change with the service, providers, or law. A material change will be communicated by a reasonable method before it takes effect.

13. Contact

Contact us about personal information through the support page. Information that applicable law requires to be available about the personal-information handling business may also be requested there and will be answered without undue delay.