Privacy Policy
Effective 19 July 2026
Dear Reader is a service that writes personalized fiction using details you choose to share. That makes your privacy the product, not a compliance afterthought. This policy describes, in plain language, exactly what we collect, why, and what we will never do with it.
The short version
- We collect only what you type into the app, and we use it only to write your story and run the service.
- You control how much the story may use, in tiers, and you can change that at any time.
- We never sell your information, never share it for advertising, and run no analytics or trackers.
- Deleting your account permanently deletes everything, immediately.
What we collect
- Account: your email address and a password (handled by our authentication provider, Supabase; we never see your password).
- Story material you volunteer: questionnaire answers — a name for the story to call you, a region, fears, and (only at the tiers you choose) home details, routines, names of people in your life, and griefs — plus your answers to between-chapter questions and anything you write to the story's antagonist.
- Your exclusions: topics you tell us the story must never use.
- What the service creates for you: your chapters, the story's continuity notes, and any emails written to you.
- Preferences: intensity tier, email opt-in, and push-notification subscriptions.
- Operational records: token counts for the AI calls that write your story (numbers only — never the text), and an append-only log of any administrative action.
- Contact messages: if you write to us through the contact form, the topic, name, email address, and message you submit — read by the operator, used only to respond and to understand what to improve, kept only as long as needed, and never used as story material.
We run no analytics, no advertising trackers, and no third-party scripts. The only cookies are the ones that keep you signed in.
How your material is used
Everything you share is used for exactly one purpose: writing your story and operating the service. Specifically:
- Tiers are consent. Each detail you share is tagged with the minimum intensity tier allowed to use it. A story running at Campfire can never see what you shared for Too Close. Changing your tier changes what the engine may read, from the next chapter on.
- Exclusions are enforced twice — injected as prohibitions into every generation, and re-checked by an automated safety review before you ever see a chapter. Reviews that fail are regenerated or softened, never shown.
- Named people are protected. People you name appear only as fictionalized versions and are never depicted as harmed. You confirm this framing before naming anyone.
- Crisis-flagged material is never used. If an automated classifier believes something you wrote signals real, present distress, that text is permanently excluded from your story and we show you a resources page instead. See "What we are not," below.
AI processing
Your chapters are written by large language models operated by Anthropic. When we send material to generate your story, it is pseudonymized: no email address, account identifier, or authentication data is ever included — you are "the reader," plus only the tier-appropriate details you volunteered. API traffic to our AI provider is not used to train their models under their standard API terms. AI providers act as processors for us and do not receive your identity.
Who can see your material
- You. Your story and everything you shared are visible only to your account. Every table in our database enforces row-level security.
- Administrators, barely. Our operational tools show metadata only — counts, statuses, timestamps. The text you wrote is hidden from staff by default; revealing any of it requires recording a reason, and every reveal is written to a permanent audit log. Crisis-flagged text is held to the same standard.
- Service providers that make the app run, acting on our instructions: Supabase (database and authentication), Anthropic (story generation, pseudonymized), Cloudflare (hosting and delivery, including email delivery when enabled). We share nothing with anyone else.
We do not sell personal information. We do not share it for advertising. We would disclose data only if legally compelled, and then only the minimum required.
Email and notifications
- Account email (such as signup confirmation) is required to operate your account.
- Letters from the story are strictly opt-in, at most weekly, and every one carries a one-click pause link that is honored instantly.
- Push notifications are opt-in, contain no story content ("a new chapter has been written for you"), and can be turned off in settings or your browser.
- The Lights On control pauses all of it at once, instantly.
Retention, export, and deletion
- We keep your material for as long as you keep your account, so your stories can remember.
- You can export everything as JSON from settings at any time.
- Deleting your account is a hard delete: your profile, every detail you shared, your stories, chapters, continuity notes, questions, replies, and queued email are permanently removed, immediately. There is no soft-delete or retention window on our side; short-lived database backups age out on their own schedule.
Security
Data is encrypted in transit and at rest. Access follows least privilege: the browser can only reach your own rows; privileged operations run server-side only; your written content is never put in logs. Administrative actions are audit-logged, append-only.
What we are not
Dear Reader is fiction and entertainment. It is not a crisis service, not therapy, and not monitored in real time by humans. The crisis classifier is a best-effort safety affordance that keeps distressing material out of your story and points you to resources — it is not a substitute for reaching out to a person. If you are in danger or crisis, contact local emergency services or a crisis line.
Age
Dear Reader is for adults. You must be 18 or older to use it.
Changes and contact
If this policy changes materially, we will tell you in the app before the change takes effect. Questions or requests: use the contact form.