Privacy Policy

Last updated

At a glance

What Novelio collects

We collect the information you give us to create and run your account, including account details, story content, file uploads, billing details handled through Stripe, support messages, and referral codes if you use them. We also collect technical and security data needed to keep Novelio working.

Optional services stay off until you allow them

Necessary services are always active. Product analytics, marketing or referral tools, support chat, and diagnostics only run in a browser or WebView after the matching consent choice there. When you are signed in, limited server-side PostHog and Meta conversion checks separately require a current consent mirror on your account before they run.

Browser, web app, and mobile WebView

This notice applies to Novelio web pages, including pages opened in a mobile app WebView. Cookie settings control optional browser or WebView services. Necessary mobile app storage, sign-in state, security tokens, and offline cache may still operate because they are required to provide the service.

Your creative work is yours

Novelio does not claim ownership of the manuscripts, notes, character dossiers, worldbuilding entries, timelines, and other creative material you store in the workspace.

How to change your choice

Use the Cookie settings button in the site footer or, in the web app, Settings > Privacy & Data > Cookie settings. You can also contact us at support@novelio.app with privacy questions or requests.

SUMMARY OF KEY POINTS

This summary covers the main points of our privacy notice. For more detail, read the full sections below.

What personal information do we process? We process account details, story and workspace content, uploads, billing and subscription records, support messages, referral data when used, and technical or security information needed to run Novelio.

Do we use cookies or similar technologies? Yes. Necessary storage keeps the service working. Optional browser services only start after the matching consent choice.

Which optional providers do we use? Firebase Analytics, Google Analytics, and PostHog for Product analytics; Meta Pixel, Endorsely, and Meta Conversions API for Marketing; Chatwoot for Support; and Sentry for Diagnostics.

Do we send any optional server-side events? Only in limited cases. Signed-in Product analytics and Marketing checks rely on a current consent mirror stored on your account before limited PostHog or Meta server-side events are sent.

Your creative work is yours. Novelio does not claim ownership of the creative material you store in the product.

How do you change or withdraw consent? Use Cookie settings in the footer of the marketing site or, in the web app, Settings > Privacy & Data > Cookie settings.

WHAT INFORMATION DO WE COLLECT?

Information you provide directly

We collect personal information you choose to give us when you create an account, build your workspace, contact support, or make a purchase.

  • Account and profile information such as name, email address, username, pen name, and authentication details
  • Creative and workspace content such as manuscripts, notes, characters, worlds, timelines, story-bible entries, and uploaded files
  • Billing and subscription records, while payment card details are handled by Stripe rather than stored directly by Novelio
  • Support messages and related account context
  • Referral or promotion codes if you use them

Payment Data. Payment data is handled by Stripe. You can review their privacy notice at https://stripe.com/privacy.

We do not ask for government IDs or biometric data as part of normal use. Because Novelio is a creative workspace, personal data may also appear inside the content you choose to write, upload, or send to support.

Information collected automatically

We automatically collect technical, usage, and security information needed to operate Novelio. This may include IP address, browser and device characteristics, app version, log and request data, auth or session state, storage and cache status, App Check or similar security signals, and your current consent choices.

If you allow optional services, those providers may also collect browser identifiers, event data, or provider-specific support, marketing, analytics, or diagnostic information as described in this notice.

Information from service providers

We may receive limited information from providers that help us run Novelio, such as payment and subscription status from Stripe, referral identifiers from Endorsely, support context from Chatwoot, and analytics or conversion reports from providers you have allowed.

HOW DO WE PROCESS YOUR INFORMATION?

We process your information to provide, secure, support, and improve Novelio, and to comply with law. Optional services are used only when the matching consent choice applies.

  1. Create and manage accounts, sign-ins, and subscriptions
  2. Store, sync, cache, and display your stories, notes, files, and workspace structure
  3. Protect the service through security, abuse-prevention, App Check, logging, and related safeguards
  4. Respond to support requests and service communications
  5. Process billing, payments, and account administration
  6. Measure product usage with Firebase Analytics, Google Analytics, and PostHog only after Product analytics consent
  7. Measure marketing and referrals with Meta and Endorsely only after Marketing consent
  8. Provide Chatwoot support chat only after Support consent
  9. Diagnose crashes and performance issues with Sentry only after Diagnostics consent
  10. Comply with legal obligations and enforce our terms

WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

Where applicable law requires a legal basis, we generally rely on:

  • Performance of a contract to create accounts, provide the workspace, store content, and run the service you asked for
  • Consent for optional Product analytics, Marketing, Support chat, and Diagnostics
  • Legitimate interests for security, fraud prevention, service administration, and internal operations that do not override your rights
  • Legal obligations for tax, accounting, compliance, and other required records

WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We share personal information only with providers that help us run Novelio or an optional service you have allowed.

  • Google Firebase / Google Cloud. Authentication, database, file storage, cloud functions, security, and optional analytics infrastructure
  • Stripe. Billing, subscriptions, and payment processing
  • PostHog. Product analytics and limited server-side analytic events after current Product analytics consent
  • Meta. Browser marketing measurement through Meta Pixel and limited server-side conversion events through Meta Conversions API after current Marketing consent
  • Endorsely. Referral and affiliate attribution after Marketing consent
  • Chatwoot. Support chat after Support consent
  • Sentry. Error and performance diagnostics after Diagnostics consent

We may also disclose information when required by law, to protect Novelio or others, or as part of a merger, financing, sale, or business reorganization.

Some providers may process data in the United States or other places where they operate. This notice does not list every provider location or every subprocessor country because those details can change over time.

DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

Yes. On web and browser-based experiences, Novelio uses cookies and similar technologies for necessary service operation and, if you allow them, optional Product analytics, Marketing, Support, and Diagnostics services.

On the marketing site, Google Analytics and PostHog can run under Product analytics, and Meta Pixel can run under Marketing. Firebase Analytics, Endorsely, Chatwoot, and Sentry can run only in the Novelio web app after the matching category is allowed. Limited server-side PostHog and Meta events are described below.

CategoryProvidersPurposeHigh-level dataKnown storage
NecessaryNovelio, Firebase Auth, Firestore, Storage, Cloud Functions, and App CheckStore your privacy choice, keep you signed in, load and save workspace data, upload files, protect requests, and support offline use.Consent choices, authentication or session data, security tokens, request metadata, cached or offline data, and the content or files you ask us to store.Known web storage includes the novelio_cookie_consent cookie. Necessary app or browser storage may also use IndexedDB, local storage, and similar app storage for sign-in persistence and offline cache.
Product analyticsFirebase Analytics, Google Analytics, and PostHogUnderstand how visitors and authors use Novelio so we can improve navigation, features, reliability, and product decisions.Page and route views, clicks, feature-use events, browser and device details, referrer data, and, when you are signed in and have allowed Product analytics, your Novelio user ID and limited account metadata used for analytics.Known storage includes _ga and _gid. PostHog uses in-memory analytics persistence; older ph_* and __ph_* browser storage is cleared on withdrawal. Browser Product analytics stays off until you allow it. When enabled, PostHog includes privacy-filtered session replays and marketing-page interaction heatmaps. Forms and search content are excluded; author text and inputs are masked and story, account, and media regions are blocked.
Marketing and referralMeta Pixel, Endorsely, and Meta Conversions APIMeasure campaigns, attribute referrals, and record marketing-related conversions such as trials or plan purchases.Browser marketing identifiers, page and referrer data, and referral code and referral identifier data. When a referral is recorded after current Marketing consent, Endorsely may receive your user ID, name, email, referral identifier, and referral status. Limited server-side Meta conversion events may include contact and conversion details such as email, phone number, plan, and price when available.Known storage includes _fbp, _fbc, and localStorage referralCode. Browser marketing tools stay off until you allow them.
SupportChatwootProvide in-product chat support and connect support conversations to your Novelio account when you choose to use support chat.Chat messages and, if you are signed in, account context such as your user ID, email, display name, avatar URL, phone number if present, and a signed identity hash for Chatwoot.Known Novelio-side storage includes localStorage chatwootIdentity. Support chat stays off until you allow it and may be unavailable in some embedded WebView contexts.
DiagnosticsSentryDiagnose crashes, frontend errors, and performance problems.Error details, browser and device information, route and performance data, and, if you are signed in, limited account context such as user ID, email, display name, and subscription status metadata.Diagnostics initializes only after consent. Sentry session replay is disabled. PostHog session replay is controlled separately under Product analytics.

Use the Cookie settings button in the footer of the marketing site or, in the web app, Settings > Privacy & Data > Cookie settings to review or withdraw optional consent. If an embedded mobile WebView does not expose those controls, open the page in a full browser or use the app setting when available.

Withdrawing consent stops future optional processing in that browser or WebView and clears certain known optional-provider storage where our current implementation supports it. It does not automatically delete optional-provider information collected before withdrawal or remove information required for necessary services.

When you are signed in, Novelio also mirrors only your Product analytics and Marketing choices to your user record. Limited server-side PostHog and Meta conversion checks use that current mirror and fail closed when the mirror is missing, stale, malformed, or denied.

Our current server-side PostHog sanitization is designed to exclude manuscript text, prompt text, character names, scene names, and similar creative-content fields from those events.

HOW DO WE HANDLE YOUR SOCIAL LOGINS?

Our current web experience does not rely on active social sign-in to use Novelio. If we enable a social login provider in the future, that provider may share basic account information needed to authenticate you, and we will update this notice as appropriate.

HOW LONG DO WE KEEP YOUR INFORMATION?

We keep personal information for as long as necessary to provide Novelio, maintain security and operations, comply with law, resolve disputes, and enforce our agreements.

When you confirm account deletion, primary Novelio-managed account data and user-authored content are scheduled for deletion 14 days after verification. You may cancel the request before deletion begins.

After deletion processing, we may retain limited billing, tax, accounting, compliance, legal, fraud-prevention, security, support, vendor, referral payout, operational log, and deletion-audit records where required or permitted by law or needed to protect the service.

Optional-provider retention can differ from Novelio-managed retention because each provider operates its own systems and policies. This notice does not attempt to list an exact retention period for every provider or transfer location.

HOW DO WE KEEP YOUR INFORMATION SAFE?

We use organizational and technical safeguards intended to protect your information. However, no website, app, storage system, or data transmission can be guaranteed to be 100% secure.

DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect personal information from children under 18 years of age. If we learn that we have collected personal information from a child under 18, we will take reasonable steps to deactivate the account and delete the data. If you believe a child has provided us information, please contact support@novelio.app.

WHAT ARE YOUR PRIVACY RIGHTS?

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, limit or object to certain processing, or withdraw consent where consent is the basis for processing.

Withdrawing optional consent: Use Cookie settings in the footer of the marketing site or, in the web app, Settings > Privacy & Data > Cookie settings. This changes the current browser or WebView choice and does not affect processing that already happened before withdrawal.

Marketing communications: You can unsubscribe from marketing emails using the unsubscribe link in the message. We may still send service messages needed for accounts, billing, security, or support.

Account Information

You can review or update much of your account information by signing in and using your account settings.

To request account deletion, sign in to the web app, open Settings > Account > Delete Account, review what will be deleted, re-enter your account email, and enter the 16-digit code we send you. If you cannot use that flow or access that email inbox, contact support@novelio.app for support guidance.

Most browsers also let you clear cookies or local storage directly, but using Cookie settings is the best way to update Novelio's optional-service choices without interrupting necessary services more than needed.

DO-NOT-TRACK FEATURES

We do not currently respond to Do-Not-Track signals because there is no uniform industry standard for recognizing and acting on them.

DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Residents of some US states may have rights to request access to, correction of, deletion of, or a copy of personal information, and to appeal certain request decisions. You may also withdraw consent where consent is the basis for processing, including optional browser-based services.

To exercise these rights, contact support@novelio.app or use the account tools described in this notice. We may need to verify your identity or authority before acting on a request.

If we deny a request and applicable law gives you an appeal right, you may appeal by emailing support@novelio.app.

DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?

If you are in the EEA, UK, Switzerland, Canada, Australia, New Zealand, South Africa, or another region with applicable privacy law, you may have rights such as access, correction, deletion, portability, restriction, objection, or complaint rights.

You can contact us first at support@novelio.app. If local law gives you a right to complain to a regulator, you may also contact your local authority. For example, users in the EEA, UK, and Switzerland may contact the relevant EEA data protection authority, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.

DO WE MAKE UPDATES TO THIS NOTICE?

Yes. We may update this notice from time to time to reflect changes to Novelio, our providers, or applicable law. The updated version will be shown by the revised date at the top of this page.

HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, email support@novelio.app or contact us by post at:

Novelio Story Works, LLC.

1045 E Mckellips Rd. Suite 3

Mesa, AZ 85203

United States

HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Depending on the law that applies to you, you may have the right to request access to, correction of, or deletion of personal information, or to withdraw consent where applicable.

For account deletion, sign in to the web app and use Settings > Account > Delete Account. The signed-in flow explains what will be deleted, asks you to re-enter your account email, sends a 16-digit verification code, and schedules deletion for 14 days after confirmation. If you cannot use that flow, contact support@novelio.app for support guidance.

For other privacy requests, email support@novelio.app. We may ask for information needed to verify your identity before we act on the request.

Jump to section
  1. Summary of key points
  2. What information do we collect?
  3. How do we process your information?
  4. What legal bases do we rely on?
  5. Who do we share your information with?
  6. Cookies, consent, and optional services
  7. How do we handle social logins?
  8. How long do we keep your information?
  9. How do we keep your information safe?
  10. Do we collect information from minors?
  11. What are your privacy rights?
  12. Do-Not-Track features
  13. Privacy rights for United States residents
  14. Privacy rights in other regions
  15. Do we update this notice?
  16. How can you contact us?
  17. Review, update, or delete your data