← NovelForge

Privacy Policy

Last updated: 2026-08-27

NovelForge is operated by an individual developer based in the Czech Republic. This policy explains what we collect, how we use it, and the choices you have. For any data requests, see §7.

1. What we collect

2. How we use it

To provide cross-device sync and backup, authenticate you, secure the service, and (with consent) improve the product. We do not sell your data. We do not use your manuscripts to train AI models — see §9.

3. Storage & security

Your manuscripts are stored with server-side encryption at rest (R2/B2 bucket-level) and transferred over TLS. By default, to provide sync, backup, and real-time collaboration, our infrastructure can process project content – the same operational model as collaborative writing tools like Google Docs or Notion. Access is restricted to automated systems and a single account maintainer; no third party has access. You can also enable client-side end-to-end encryption in the app: cloud sync blobs are then locked with your passphrase (and recovery code), so even we cannot read them.

4. Sub-processors

ProviderPurpose
Google Cloud RunServer hosting (US – us-central1)
Backblaze B2 + CloudflareObject storage + CDN
ResendTransactional email
OpenRouter / OpenAI / Google Gemini / AnthropicAI completions (only when you enable AI features; selected text is sent to your chosen provider)

5. Retention

Auth logs ~90 days, audit log ~1 year, backups ~35 days, deletion tombstones ~90 days. You can request export or deletion of your account data at any time.

6. Your rights

You can access, export, correct, or delete your data. Account deletion is available in-app and on the web (delete-account.html) – a soft-delete with a 30-day grace period, then permanent purge (cascading to backups within 90 days). For other requests, email §7 and we will respond in a reasonable timeframe. EU users may also contact their local data protection authority.

7. Contact

Questions or requests: privacy@novelforge.cc.

7b. Breach notification

If a security breach affecting your personal data occurs, we will notify the relevant data protection authority within 72 hours of becoming aware of it where required by law (GDPR Article 33), and notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).

8. Children

NovelForge is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has registered, contact us at §7 and we will delete the account.

9. AI training

This is the same promise as in the licence, written here so it is easy to find.