Privacy Policy

Standard-practice version for a solo, self-funded project — not custom counsel-reviewed text. See the note at the end before relying on this.

Data controller: Anton Gurevich (individual), United Kingdom.
Privacy requests / data protection contact: anton@odysseymapper.com
Supervisory authority (UK): Information Commissioner's Office (ICO). EU users may also complain to their local supervisory authority.

What DraftHarbor collects

Your project stays local by default, but an account is required. DraftHarbor stores projects in your browser's local storage. Signing in sends account and authentication data to Firebase. We don't operate analytics or tracking on your writing.

For every account (email/password or Google sign-in): account identifiers and authentication records, via Firebase Authentication (email address, display name if you set one, account creation/sign-in timestamps).

If you enable optional cloud backup: encrypted project revisions and image assets. Manuscript text, project metadata, and any image assets are all encrypted on your device before upload; we do not hold the passphrase or recovery key required to decrypt any of it, and cannot read your manuscript or your images. Also: technical records — project/revision identifiers, content hashes, sizes, MIME types, timestamps, and device identifiers.

If you deliberately publish a Library edition, the selected manuscript text and images, edition title, invited reader email addresses, access settings, and immutable edition history are stored in readable form so readers can open it. Library editions exclude project notes, research, lore, metadata, and any unselected content. A private edition is account-restricted; an unlisted edition can be read by anyone who receives its link. Library editions are not end-to-end encrypted like cloud backups.

If you explicitly invoke Story Intelligence, relevant manuscript and, where you choose, research text is sent through DraftHarbor's service to OpenAI to produce the requested analysis. DraftHarbor uses its own OpenAI provider account with a monthly usage cap; you do not supply an API key. AI requests are not automatic. DraftHarbor does not use your writing to train AI models.

We do not sell your data or currently run behavioural advertising.

We can't read what you back up

Manuscript text and image assets are both end-to-end encrypted on your device before they ever leave it. DraftHarbor has no technical ability to read any content you back up to the cloud — there is no server-side review or scanning of any kind, for text or images. This is the same technical position as fully encrypted messaging apps: we could not inspect your content even if legally compelled to, because we do not hold the key.

This statement applies to cloud backups only. Private Library editions and text deliberately sent to Story Intelligence must be processed in readable form to provide those features.

Lawful basis and purposes

We process the data above to: provide the service you've asked for (contract), secure the service and prevent abuse (legitimate interest), and comply with legal obligations. Where we rely on legitimate interest, that interest is keeping the service safe and functioning — we don't use it to justify marketing or profiling.

Who we share data with

Processors: Firebase/Google Cloud (authentication, database, private Library editions, encrypted storage, hosting) and OpenAI (only for Story Intelligence requests you explicitly initiate).

Legal disclosure: we may disclose limited account and technical metadata when required by law (for example, a lawful law-enforcement request) — this does not include your encrypted content, which we cannot decrypt.

We do not sell or rent your personal data to third parties for their own marketing purposes.

International transfers

Firebase/Google Cloud infrastructure for this project is located in the United States. Your account, private Library editions, and technical data may therefore be transferred internationally. Cloud-backup content is encrypted on your device and is never stored there in readable form. Library editions and text deliberately submitted to Story Intelligence are processed in readable form for those features. Google and OpenAI provide their own applicable data-processing safeguards.

Retention

Active cloud backups and private Library editions are retained until you delete them or close your account. Revoking an edition immediately removes reader access, but its immutable version history may remain until deletion. AI usage records retain operational metadata needed to enforce usage caps; DraftHarbor does not store manuscript text in those usage records. Records required for security, abuse reporting, or a legal hold may be retained separately and for longer, as required by law.

Your rights

If you're in the UK or EU, you have rights to access, correct, delete, restrict, or export your personal data, and to object to certain processing. In practice, most of this is self-service in the app: you can export projects through the built-in .draftharbor download and permanently delete your account and cloud data from the account screen. For requests that are not available through those controls, or if self-service deletion fails, contact anton@odysseymapper.com. We'll respond within a reasonable time and may need to verify your identity first. You also have the right to complain to the ICO (UK) or your local supervisory authority (EU) if you believe we've mishandled your data.

Children

DraftHarbor is not directed at children under 16, and accounts require you to confirm you meet that minimum age.

Changes to this policy

We may update this policy from time to time. Material changes will be noted with an updated date.

This is the standard, common-practice approach used by most small, self-funded software projects — a plain-language privacy notice covering what's collected, why, international transfers, and how to exercise your rights. It is not a substitute for a formal DPIA or jurisdiction-specific legal advice.