Skip to the main content
InkReady

Privacy. What we hold, and for how long.

Your manuscript is the most personal thing this product touches. This page says what we store, where it goes, and what closing your account removes and what it leaves behind. Where a thing is designed but not yet wired, it says that instead of writing around it.

What we store

What we store, and how long we keep it

Anything attached to your account is deleted when the account is deleted. The periods below are the separate rule for records that outlive a single account. A scheduled job runs the deletions daily, so these are the periods we keep rather than periods we intend to.

Your account
The email address you sign in with. There is no password: signing in works by a link we email you.Kept while the account exists.
Your books
The brief you write, the outline, the chapters, anything you import, the covers, the rendered print files, and the preflight reports run against them. These live in our database and in our own file storage.Kept while the account exists.
Billing
Nothing yet. Billing is not live. When it launches it runs through Polar as merchant of record, which means Polar takes the payment and holds the card details; the schema on our side is built to store the identifiers Polar returns, and has no field for a card number.This row changes when billing ships.
Payment event records
The raw notifications a payment provider sends us, kept so a purchase can be reconciled if something goes wrong. Empty until billing ships.Target retention 90 days. If you close your account first, the parts of them naming you are redacted then, except identifiers under twelve characters, which are skipped on purpose because a short string would match half the table.
Model call records
One row per call to a model, holding what it cost and how long it took. It stores a hash of the prompt, never the prompt and never your text.Target retention 90 days.
One-time link identifiers
The record that stops a single-use link being replayed.Target retention 30 days.
Download records
Each time you download your book pack or your account data, we write down that it happened and how much was in it: counts and a size, never a second copy of what you downloaded.Kept while the account exists, and deleted with it.
The erasure record
When an account is erased we keep proof that it happened: a keyed hash of the account id, timestamps, and whether each registered provider confirmed. The key never reaches the database, so the finished record holds no address and no account id in the clear.Target retention 365 days.

Where prompts run

Every prompt runs on our servers

The browser never holds a prompt and never holds a model key. Your brief, outline and chapters go from our server to OpenRouter, which routes each call to the model provider that writes that stage. Nothing about your book is sent from your browser to a model provider.

Your text is held in the tables that hold your book, in our own file storage as imports and rendered files, and it is staged for the render worker while a book is being built. Our job and cost records store a hash of each prompt rather than the prompt, so the text is not copied into our operational logs.

Training

We do not train on your books, and here is the part we do not control

We do not train models on your content. We do not sell it or licence it to anyone. We do not read your manuscripts as a matter of course; a person here opens one when you ask us to look at something.

What we cannot claim is the whole chain. Your text passes through OpenRouter to whichever model provider writes that stage, and each provider has its own terms about training on data that reaches it. We are working through those terms provider by provider. When that review is done this page will name each provider and what its terms commit to. Until then, this section is the honest state of it rather than a settled promise about anyone but us.

Who else

Who else touches your data

These are the providers we configure, plus the model providers our gateway routes to. We update this list when we change a provider.

Supabase
Accounts, and the database and file storage that hold your books.We run it in the EU, in Frankfurt.
Google Cloud Run
The render worker that typesets your book, builds the print files, and measures them for the preflight report.We run it in the EU, in Frankfurt (europe-west3).
OpenRouter
The gateway that carries each prompt from our server to the model that writes the text.United States.
Anthropic and OpenAI
The model providers OpenRouter routes to today. Which model writes which stage is a table in our code, and when it changes this row changes with it.United States. See the section below on training.
Vercel
Hosts the site and runs its server code.United States company. We have not pinned a region, so we do not claim one.
PostHog
Product analytics. What we send it is described below.We run it on their EU project, in Frankfurt.
Resend
Sends account email: sign-in links, confirmations when you change your address, and the one survey message after a download asking whether Amazon accepted the files.United States company. We have not pinned a region, so we do not claim one.
Cloudflare
Domain and DNS, and the forwarding behind our support address.Global network.
Polar
Merchant of record, once billing ships. Polar would take the payment, hold the card details, handle sales tax and VAT, and issue the receipt.Not yet processing anything for us.

Where we chose the region, it is named above. Where we have not pinned one, the row says so rather than implying that everything stays in the EU.

Analytics

What the analytics see

We use PostHog for page views and for named product events: accounts, projects, generation, preflight, purchases and exports. Each event and each property it may carry is written down in a registry in our code before it can be sent, and the emitter drops anything not on that list. Session recording is off. Autocapture is off, which matters here more than usual: autocapture records the text of what you click, and in this product that text is your manuscript.

PostHog is the only third-party analytics service your browser talks to. If a content blocker stops that request, it stays stopped. We do not route it through our own domain to get around a blocker you turned on.

Your copy

You can download what we hold about you

There is a button on your account page that builds an archive of what your account holds and sends it to your browser. It is not a request you email us and it is not a form we answer in a month. It is a download.

Inside it: your account details and notification settings, every book with its chapters, imports, covers, renders and preflight reports, your credit ledger, the billing identifiers our payment provider returned, your printed links and how often each was opened, and the actual files, both what you imported and every print file and cover we produced. There is a manifest listing the row count of every document and the SHA-256 of every file, so you can check that what arrived is what we sent.

It also tells you what it does not contain and why, in a readme inside the archive itself. Nothing is left out silently: the few records we hold back are ones that carry no content of yours, and each one is named with the reason.

The archive is built by reading the database as you, so it can only ever contain what your own account can see. We do not store a copy of it anywhere, and we never mint a link to it that someone else could follow. We do write down that a download happened and roughly how big it was: the Download records row above says what that holds and why.

Deletion

Closing your account erases it

Take your copy first if you want one: the download above is on the same page, and once the erasure runs there is nothing left for us to send you.

Deletion is self-serve on the account page, not a request you email us. Pressing it starts the erasure: the account and every project, chapter, import, cover, rendered file and preflight report are deleted from the database, then the file storage behind them is cleared, then each registered outside provider is asked to delete its copy. PostHog is the one registered today, and the erasure refuses to record itself finished unless PostHog confirms. Three others are named in our own code and deliberately not called, each with the reason written down: Polar, because billing is not live and there is no customer to erase; error monitoring, because we run none; and our email provider, which sends your sign-in links and the one survey message after a download without creating a contact record, so there is nothing there for us to delete by name. That last one is a real gap and we would rather say so: the delivery logs at that provider name your address and age out on their schedule, not ours.

We tell you which of those actually finished. If a step does not confirm, the page says the erasure is unfinished rather than telling you it is done, and finishing it is our job from there. Ask us at support@inkreadyai.com if you want confirmation.

Some records outlive the account, and none of them is your book:

The erasure record
A keyed hash, timestamps and per-provider outcomes. It is the proof the erasure ran. While a run is unfinished it still holds the identifiers the retry needs; those are cleared the moment it completes.
Payment event records
Not owner-scoped, because a payment notification can arrive before an account exists and must survive after it does not. They join the erasure by redaction rather than by deletion, and the row above says what redaction does not reach.
Printed short links
A paperback carries its URLs forever. The link code stays reserved so it can never be handed to a stranger's page, and it stops resolving. Its owner, its destination and its click records are erased.

Not settled

What is not settled yet

Terms of use, an acceptable-use policy and a copyright statement are drafted and waiting for legal review. They are not published, and nothing on this site treats them as in force. A data processing agreement is drafted alongside them and is not available yet.

Also unfinished, and listed here because you would otherwise have to take the rest on trust: the billing integration and its erasure step, and the review of each model provider’s training terms.

This page is written by the people who built the product and has not been reviewed by a lawyer. It describes what the code does today, including the parts that are not finished. It is not legal advice, and it does not stand in for the terms of use above. Questions, corrections and erasure problems go to support@inkreadyai.com.