Privacy Policy
Last updated: 16 July 2026
1. Who we are
ChapterFlow (“we”, “us”) operates the AI writing studio at chapterflow.tech and the ChapterFlow Offline desktop application. We are based in India. For anything in this policy, contact support@chapterflow.tech.
This policy explains what personal data we collect, why, who processes it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where it applies to you, the EU/UK General Data Protection Regulation (GDPR).
2. What we collect
- Account data — your email address, display name, and optional date of birth, collected when you sign up (directly or via Google sign-in).
- Your writing — manuscripts, chapters, story bibles, research notes, prompts, and any other content you create or submit in the studio.
- Transaction data — credit purchases, order identifiers, license keys, and a credit ledger of grants and deductions. Your card, UPI, or bank details never reach our servers; they are entered directly with our payment processor, Razorpay.
- Technical data — an essential session cookie that keeps you signed in, and standard server logs (IP address, request time) kept for security and debugging.
We do not use analytics, advertising, or tracking cookies. The desktop offline edition stores your writing locally on your own machine and sets no cookies.
3. Why we process it (legal bases)
- To provide the service (contract): running your account, generating chapters you request, maintaining your credit balance, issuing licenses.
- To take payment and keep financial records (contract and legal obligation): processing orders via Razorpay and retaining transaction records as required by Indian tax and accounting law.
- To keep the service secure (legitimate interest): server logs, fraud prevention, abuse detection.
- With your consent, where we ask for it — for example if we ever introduce optional analytics. We will not rely on this policy alone to add tracking later.
4. AI processing of your writing
When you use a generation feature (chapters, story bibles, articles, short stories, research, humanizing, auditing), the relevant text you provide is sent to Anthropic (USA), whose Claude models produce the output. Anthropic processes this content as our service provider under its commercial API terms and does not use your inputs or outputs to train its models. Your writing is never shared with other users, and we do not use it to train models either.
5. Who else processes your data
- Supabase — authentication and database hosting (account data and your writing).
- Razorpay (India) — payment processing. Razorpay is an independent data fiduciary/controller for the payment data you enter with it.
- Anthropic (USA) — AI text generation, as described above.
- Hostinger — the virtual server (India region) our application runs on.
Because these providers operate in different countries, your data may be transferred outside your own country, including to the United States. Where GDPR applies, such transfers rely on the providers' standard contractual clauses and equivalent safeguards. We do not sell personal data, ever.
6. How long we keep it
- Account data and your writing — for as long as your account exists. Deleting your account (Profile → Delete account) permanently removes them.
- Financial and transaction records — retained as long as Indian tax and accounting law requires, even after account deletion, in de-identified form where possible. Razorpay retains its own records of payments.
- Server logs — rotated automatically and kept only briefly for security and debugging.
7. Your rights
Under both the DPDP Act and the GDPR you can:
- Access and export your data — use Profile → Download my data for a machine-readable copy of your account, writing, and transaction history (this also satisfies GDPR data portability).
- Correct your data — edit your name and date of birth in Profile, or email us for anything else.
- Erase your data — use Profile → Delete account. This permanently deletes your account, writing, and wallet; it cannot be undone. Records we must keep by law (Section 6) are the only exception.
- Withdraw consent at any time where processing is based on consent.
- Complain — to the Data Protection Board of India (DPDP Act) or your local supervisory authority (GDPR), though we'd appreciate the chance to resolve it first.
- Nominate (DPDP Act) — you may nominate another person to exercise these rights for you in case of death or incapacity, by emailing us.
8. Grievance redressal
Our Grievance Officer can be reached at support@chapterflow.tech or via the contact page. We acknowledge grievances within 72 hours and aim to resolve them within 30 days.
9. Children
ChapterFlow is for users aged 18 and over. We do not knowingly process children's data; if you believe a minor has created an account, contact us and we will delete it.
10. Security & breach notification
All traffic is encrypted in transit (HTTPS), data access is restricted by row-level security keyed to your account, and payment credentials never touch our infrastructure. If a breach affecting your personal data occurs, we will notify you and the relevant authority (the Data Protection Board of India, and supervisory authorities where GDPR requires) without undue delay.
11. Changes to this policy
If we make material changes, we will update the date above and notify you in the app or by email before the changes take effect. Continued use after that constitutes acceptance of the updated policy.