Legal
Privacy Policy
This policy describes the information ChapterMuse collects about you, why we collect it, who we share it with, and the rights you have to control it.
Last updated 23 May 2026
1. Who is the data controller
Paul Morris, a sole trader based in the United Kingdom trading as ChapterMuse, is the controller of personal data processed through the service. You can reach us about data protection at privacy@chaptermuse.com.
2. What we collect
Account information
- Your name (or pen name), email address, and authentication credentials. If you sign in with a third-party provider (e.g. Google), we receive the basic profile fields they pass to us.
- Account settings, preferences, and the themes you select.
Content you create
- Everything you write or upload — manuscripts, chapters, paragraphs, character sheets, plot grids, mind maps, scene cards, notes, comments, and any media you attach. We store this so we can sync it across your devices and serve it back when you ask for it.
- Activity within the Writers' Corner community: posts, replies, reactions, follows, and reports.
Technical telemetry
- Standard server access logs (IP address, user agent, requested URL, response status). These help us diagnose errors and detect abuse.
- Limited product analytics (which pages were visited, which features were used). We use this in aggregate to improve the product. It is not sold and is not enriched against third-party datasets.
3. What we do NOT do
We do not train any machine-learning model on your writing. We do not sell personal data to third parties. We do not run third-party advertising trackers across the product.
4. Why we process your data (legal bases)
- Performance of a contract. To provide the service you signed up for — host your manuscripts, sync them across devices, render the community.
- Legitimate interests. To secure the service, prevent abuse, debug errors, and improve the product based on aggregate usage patterns.
- Consent. Where we ask for it — e.g. before subscribing you to optional email digests, or before setting non-essential cookies (see the Cookie Policy).
- Legal obligation. Where we are required to retain or disclose data by law (e.g. to respond to a valid court order).
5. Who we share it with
ChapterMuse uses a small set of vetted sub-processors to operate the platform. They process data on our instructions under written contracts that meet Article 28 GDPR requirements:
- Vercel Inc. — hosting and CDN for the application; storage of uploaded images (covers, character portraits, spine artwork).
- Database provider. A managed PostgreSQL service hosts the operational database. Data is encrypted at rest and in transit.
- Authentication providers. If you sign in with Google or another federated identity provider, that provider receives the standard OAuth challenge and returns a profile token.
- Email transport. Transactional email (verification, password reset, notifications you opted in to) is sent via a third-party email service.
We may also disclose information where required by law, to protect our rights, or to prevent imminent harm. Where lawful and possible, we will notify you of such disclosures.
6. International transfers
Some of our sub-processors are based outside the UK and EEA. Where transfers occur, we rely on UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or adequacy decisions to safeguard your data.
7. How long we keep it
- Your account and content are retained while your account is active.
- When you delete content or your account, we remove the data from active systems immediately and from routine encrypted backups within 35 days.
- We may keep limited records longer where required to comply with law, resolve disputes, or enforce our agreements (e.g. billing records).
8. Your rights
Under UK and EU data-protection law you have the right to: access the data we hold about you, ask us to correct or delete it, object to processing, request restriction or portability, and withdraw any consent you previously gave. Exercise any of these by emailing privacy@chaptermuse.com. We will respond within one month.
If you believe we have mishandled your data, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local EEA supervisory authority. We'd appreciate the chance to address it first.
9. Security
We use industry-standard safeguards — encrypted transport (HTTPS), encrypted backups, access controls, and audit logging — to protect your data. No system is perfectly secure, but if we ever suffer a personal-data breach that meets the notification threshold we will inform the relevant authority and affected users without undue delay.
10. Children
ChapterMuse is not designed for children under 16. We do not knowingly collect personal data from children below this age. If you become aware that a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the product and by email where appropriate. The “last updated” date at the top of this page always reflects the current version.
12. Contact
Privacy questions: privacy@chaptermuse.com. For general support, use the contact page.