Privacy Policy

Last updated: August 2026

1. Who we are

NovelForge is operated by [Your Business Name], registered at [Your Registered Address]. In this policy, "we", "us", and "our" refer to the operator of NovelForge. Our contact email for data enquiries is [email protected].

2. What data we collect

We collect and process the following categories of personal data:

  • Account information - your name, email address, and hashed password when you sign up with email, or the name, email, and profile image provided by Google when you sign in with Google SSO.
  • Billing data - your subscription plan, purchase history, and top-up credit balance. Payment card details are collected and processed directly by our payment processor (Stripe) and are never stored on our servers.
  • Project content - the novels, manuscripts, chapter text, and related creative content you generate using NovelForge.
  • Usage data - pages visited, features used, and session information collected via Google Analytics (using cookies, see our Cookie Policy).
  • Support messages - your name, email, and message content when you submit our contact or support form.

3. Why we process your data (legal bases)

  • Contract performance - to create and manage your account, deliver the novel-creation pipeline, process payments, and manage your subscription.
  • Legitimate interests - to improve our service, prevent fraud, and respond to your support requests.
  • Consent - for analytics cookies (you can withdraw consent at any time via the cookie banner).
  • Legal obligation - to comply with tax, accounting, and regulatory requirements.

4. Who we share data with

We share personal data only with service providers that are necessary to operate NovelForge:

  • Stripe - payment processing (name, email, billing details). Stripe's privacy policy.
  • Google - authentication (when using Google Sign-In) and analytics. Google's privacy policy.
  • AI service providers - your project content is sent to AI language-model providers to generate manuscripts. Content is processed in transit and is not retained by these providers beyond the generation session.
  • Hosting and infrastructure providers - who store and serve the application and your data.

We do not sell your personal data to third parties.

5. Data retention

We retain your account and project data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are required to keep it for legal, accounting, or fraud-prevention purposes. Anonymised or aggregated data that cannot identify you may be retained indefinitely.

6. Your rights

Under UK data protection law (UK GDPR), you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal obligations.
  • Restrict or object to certain processing.
  • Data portability - receive your data in a structured, commonly used format.
  • Withdraw consent for analytics cookies at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

7. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls. No system is perfectly secure, but we take reasonable steps to protect the data you entrust to us.

8. International transfers

Some of our service providers operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.

9. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or a notice on our website. The "Last updated" date at the top reflects the latest revision.

10. Contact

For any privacy-related questions, contact us at [email protected] or via our Contact page.