Privacy Policy
Last updated: 2026-08-11. Draft — pending legal review before public launch.
Summary. Material you create in Scribegrove ("Content") is encrypted at rest under a key associated with your account and managed by Scribegrove. Because Scribegrove manages that key, Scribegrove retains the technical ability to decrypt Content, and does so to operate the Service and to diagnose and resolve defects, errors, and support requests. Scribegrove does not use Content to train artificial-intelligence models, does not sell or license Content, and does not incorporate Content into its own or any third party's works. You may delete your Grove conversation history at any time from within the application.
What we collect
Account data
- Email address (required for sign-in + transactional emails)
- Display name (optional)
- Stripe customer ID (for billing only)
- License records (which tier, status, period end)
AI request metadata
- Request ID (for tracing)
- Model used (e.g. claude-sonnet-4-6)
- Input + output token counts
- Latency, status code, timestamp
- Cap-weighted token debit amount
- Our cost from the upstream provider
AI proxy metering logs auto-expire after 90 days.
Device data (for sync)
- Device type (e.g., web)
- Display name you give it (e.g., "Surface Book")
- Browser version, OS version
- Last seen timestamp
Content (manuscripts, canon, notes, and Grove conversations)
Manuscripts, series records, Author Directives, notes, and conversations with the Grove assistant (collectively, "Content") are stored encrypted at rest using AES-256-GCM under a key associated with your account. Encryption keys are managed by Scribegrove so that account recovery by standard email-based password reset remains available — the same key-custody model operated by comparable hosted services. Unauthorised access to the database alone yields ciphertext.
Because Scribegrove manages the encryption keys, Scribegrove retains the technical ability to decrypt Content. Decryption occurs in two circumstances: (a) to perform operations you initiate, including synchronisation, AI requests you submit, shares you create, and export; and (b) for Support Purposes, meaning the diagnosis and resolution of defects, errors, and support requests affecting you or the Service. Access for Support Purposes requires both the service credentials and the key-management secret, and is limited to personnel holding them.
You may delete your Grove conversation history for a book at any time using the clear control in the application. Doing so deletes the stored conversation and its derived summary. Deletion of your account is addressed under Your rights below.
What we don't collect
- Browser history, cookies from other sites, system fingerprints
- Behavioral analytics inside the app (no third-party tracking SDKs)
- Your IP address beyond what's needed for the immediate request (no IP logging in DB)
How we use it
- Provide the service (billing, sync, AI proxy)
- Support and diagnostics. Where a defect, error, or support request requires it, authorised personnel may access the relevant Content in order to identify and remedy the underlying cause.
- Send transactional emails (license keys, payment failures, weekly usage summary)
- Detect abuse (per-user QPS limits, daily cost ceiling)
- Aggregate margin telemetry (anonymous tier-level totals — no per-user details)
Scribegrove does not: (a) use Content to train, fine-tune, or evaluate artificial-intelligence models, whether its own or those of any third party; (b) sell, rent, or license Content, or disclose it to data brokers; (c) use Content for advertising, audience targeting, or profiling; or (d) reproduce, adapt, or otherwise exploit Content — including characters, settings, and story elements — in its own works, in marketing materials, or in the works of any third party. Except as set out in this policy, Content is accessed only at your direction.
Third parties we share with (operational only)
- Supabase — database hosting, auth, edge functions
- Stripe — payment processing (they see card details; we don't)
- Upstream AI model vendors — cloud AI inference (the relevant passage is sent to fulfill the request you make, under contractual no-training agreements)
- Replicate / fal.ai — image generation (Publishing add-on; your prompt is sent to the model you select)
- Resend — transactional email delivery
- Backblaze B2 / Vercel / Railway — infrastructure hosting
Your rights
- Export: download all your data anytime from the account portal (manuscripts ship as ZIP)
- Delete: delete your account anytime from the account portal. Soft-deleted for 30 days (in case of accident), then purged
- Clear conversations: delete your Grove conversation history for any book at any time from within the application; the stored conversation and its derived summary are deleted
- Correct: update profile fields anytime; update DB records via support
- EU users (GDPR): right to access, rectify, erase, restrict, port, object
- California (CCPA): right to know, delete, opt-out of "sale" (we don't sell)
Data residency
At launch: US-only. EU region will be added when demand justifies (Supabase + Backblaze both offer EU regions; we'll route EU users to EU infrastructure when enabled).
Cookies (marketing site only)
We use Plausible Analytics — privacy-friendly, no cookies, no cross-site tracking, no personal data collected. The app itself uses zero third-party analytics SDKs.
Contact
Privacy questions: privacy@scribegrove.com
