What happens to what you write
In plain English, without legalese.
Quick summary
- With an account and the agreement accepted, what you save is linked to your account and can be exported and deleted.
- Writing requires an account — the account is what stores your work, and creating one means accepting that storage.
- Writing, book composition, and export work without artificial intelligence.
- External features identify exactly what will be sent before you click.
- Deleting the account deletes the book from the server. The app cannot undo it.
- People who operate the editorial studio cannot read what you write.
Where your answers are kept
With an account and the agreement accepted, your book is stored on the app server — that is what lets you find it again in any browser. This is the primary version, visible only to your account, and “delete the book” removes it from the active database. Temporary technical copies may exist in local recovery and backups, within the limits explained below. Standalone passages you save outside the book remain in your account library under the same rule. If you used one of the four external features described below, deleting the book does not delete any security records retained by the provider.
If a local recovery draft — from this tab or left by an earlier version of the app — does not match the version confirmed by the server, the app blocks new saves so neither version is overwritten. The local copy stays available for you to download and recover; it is not reopened or deleted automatically.
What an account stores
Writing requires an account; reading these public pages does not. An account uses an email address and password, and creating one means accepting storage. The server stores only:
- the account email address, used to sign in, confirm the address, and reset the password — never for marketing;
- the date the email address was confirmed, if it was confirmed;
-
the canonical code of the language you choose for the interface, or
no value until you choose one. The code neither translates nor changes
anything you wrote. The legal editions of this policy exist in
en,pt-BR, andes; this does not by itself publish those languages throughout the interface. When a legal edition is requested, the app selects only the exact locale and never substitutes another language as a fallback; -
the privacy-policy acceptance record: date, exact locale, operational
territory
BR, semantic version, short version, algorithm, and representation of the text used to produce the SHA-256, plus a code derived from the email address (HMAC) — not the readable email address. New acceptances identify the HTML article that was shown. Receipts from before semantic versioning honestly record that they identified the ERB source file, without relabeling it as displayed bytes. Changing only the language does not create a new acceptance when the semantic version is the same. This record is legal evidence of acceptance. While the account exists, the record accompanies it and is not eligible for pruning. After account deletion, it survives without a link to the account, and its five-year retention period is counted from the deletion date; -
your book, in the same format as the
livrosection of the complete export file, with a technical revision number that prevents two tabs from overwriting each other — the server validates only the file shape and size and does not read or interpret any passage. Your markers travel inside it: which passages you excluded from source lookup and the historical marker for a possible rewriting suggestion. In old books, that marker may mean only that earlier use can no longer be reconstructed with certainty; it does not claim a suggestion was made. The marker does not return to “no” when a card is deleted, because it keeps the PDF authorship statement truthful; - two technical account fields: a monotonic revision number and a random UUID epoch. They contain no text and together prevent an old tab from recreating the book after “delete the book.” The epoch changes after each deletion; both fields remain while the account exists, even when there is no book, and are deleted with the account;
- when you delete a standalone text, the random technical UUID of that source — without its words, a hash of its words, or a date or time. This marker prevents an old tab from recreating the text after deletion. A new confirmed import may release the same identity; the remaining marker is deleted with the account;
- your choices for the PDF book — page format, interior, cover, and palette and, if you write them, the dedication, epigraph, and back cover text, which are your words and are printed in the book;
- if you upload a cover image, the version prepared by the server — re-encoded, stripped of metadata (including GPS location), and limited in size. The original image is not stored, and deleting the cover, the book, or the account also deletes this image;
- when you request it, the latest PDF version of your book, composed on the server from the stored book — generating another replaces the previous one, and deleting the book or account also deletes the PDF;
- passages in the account library: text you save on its own in the Write screen, outside any book, and fragments from the cards. Older files may also contain a support question offered by the app; its origin remains marked and it is not presented as your own words. Everything can be exported, deleted one item at a time, and removed with the account;
- in the music area, when you use it: lyrics you write or approve, together with frozen versions and the record of each approval; the list of words you ask never to be sung; the two specific consent records; and the audio — candidate audio retained for seven days and then discarded automatically, and an approved version kept until you delete it. None of this is circulated and there is no public showcase. What you wrote — the lyrics, frozen versions, each approval, the word list, and both consent receipts — is included in full in your data request; approved audio can be downloaded as MP3 with the lyrics as text from the same screen. The candidate audio is not included because it expires after seven days and a permanent copy would defeat that deadline; deleting a song leaves only an opaque marker so an old restore cannot bring it back;
- an old text-version setting: yes or no, with no text, retained only for compatibility with earlier accounts and files. The app no longer offers rewriting by artificial intelligence;
- if your account operates the editorial studio — the workspace for people who maintain app content — the role assigned to it and the record of actions taken with that role: who acted, what they did, what it affected, the reason they wrote, and the result. This record cannot be changed after it is written and is subject to a two-year retention period. After that period, it can be removed only through the protected maintenance operation, never by normal runtime or a deployment. The reason is free text written by the operator and may contain anything that person enters — including someone’s name or email address; it never stores what you wrote in the app. No studio role can access any account’s book, passages, cover, or PDF;
- if your account writes in the editorial studio, the work it did there: saved drafts and frozen versions, with the date of each record; reviews and publications, each with its date and the reason written by the person who performed it. Drafts and versions may store app text — notices, tasks, and editorial instructions that guide the machine — written by operators, never what you wrote. Versions are not deleted on a schedule because they are what makes it possible to roll back a publication;
- internal identifiers generated by the database and the technical links that associate sessions and the book with the account;
- a random technical key that selects your local space, without containing your name or any passage from the book;
- a slow, salted hash of the password — never the password itself;
- hashes of session tokens — the readable token exists only in the protected cookie;
- technical credential-version counters used to invalidate old sessions when the password changes;
- account creation and update dates and session creation and expiration dates.
We do not request or store a legal name or phone number. The email address is used only to operate and protect the account: sign in, confirm the address, and reset the password. It is never used for advertising. To deliver those transactional messages, the app sends Resend the recipient address, subject, and message body, including the confirmation or reset link; Resend acts as the delivery provider. IP address, browser, and User-Agent are not stored in the app’s tables, sessions, or request logs. Outside the account data inventoried above, the account does not store the text sent through the first three external features. The music area is the exception that stores data; it is described below. Editorial work written by an operator follows its own inventory above.
To contain automated attempts, the app temporarily uses the received
network-address prefix (IPv4 /32 or IPv6 /64),
a random identifier stored in the browser’s encrypted session, and,
when needed, the email address provided. These values form HMAC keys
with separate purposes; they do not appear in readable form in the cache,
and counters expire within at most one hour. Registration also has a
global counter with no identifier to contain distributed abuse — when it
closes, all registration waits for up to one hour, including legitimate
attempts. As with any internet service, Fly.io must still process IP
addresses and network metadata to deliver and protect the connection.
Forgot your password? Reset is through a link sent to the account email address. Sessions stop authenticating within 30 days and can be ended earlier. Each account has at most ten active sessions; the oldest are ended when this limit is reached, and ending another session requires the current password. During normal operation, expired records are removed by a bounded sweep that runs every 15 minutes.
Before deleting the account, you can export your data to your own file in portable format v6, including the book, standalone texts, language preference, and receipt metadata. Importing that file restores the preference but never turns an exported receipt into a new acceptance. When you confirm deletion, the server first validates your credentials and issues a short-lived authorization; only then are the book and the account deleted from the server, and the browser clears local traces. If this preparation fails, the request is not sent and nothing is deleted. After confirmation, the email address and password are not sent again in the final deletion request.
Deleting the account removes the email address, technical key, password hash, sessions, and book from the active database. Database backups and recovery history may preserve an earlier version of this data for up to seven days; volume snapshots, for up to five days. They remain isolated and cannot be used for normal sign-in. Every restore first occurs in a separate database and revokes sessions; if it is not possible to prove that the restore includes every deletion and credential change, restored accounts are deleted before the database serves the public. Deletion does not reach files you exported.
The four situations in which your text can leave the app
1 · Lenses
You select one to three visible passages. Only those passages leave when you click “Send”; using journey questions sends no text.
2 · Interview
You select the passages you want to share. “Create with selected passages” sends them; “Use the journey question” does not send those passages to the AI service.
3 · See a related passage
When you select a passage from your writing and request a related passage, only that selected passage is sent — and the screen shows the exact text first, word for word, so you can check and confirm it. It passes through source-collection search and OpenAI. What comes back is a one-time response containing passages by other authors, with work and location. None of this is stored: not the selected passage, the response, or the question. Your text is not rewritten and nothing is added to your book.
4 · Music from what you wrote
There is a music area, open to people who sign in, where a person can turn passages they personally selected into lyrics and then a song. This output is different from the three above, and the difference is why it is stated here: it stores data. The selected text goes to OpenAI to propose lyrics; lyrics approved by the person, together with style choices from a closed catalog and the requested model name, go to a music-generation service; and generated audio returns to OpenAI to check whether what was sung matches the lyrics. There are two separate consent steps: one authorizes processing what the person wrote, and the other authorizes external transfers and names both recipients — the music engine and sung-audio transcription. Before the content goes to the engine, the screen shows the exact request body that will leave, field by field, using the names those fields have on the network; the person may decline the sung-audio check, losing the check but not approval. The audio file is stored on the server — a candidate for seven days before automatic disposal, and the approved version until the person deletes it. The work passes through a queue, what the person wrote is included in their data request, and approved audio is downloadable from the screen. Rejecting a candidate erases its audio immediately. Deleting an approved song erases its audio from the app and leaves an opaque marker so an old restore cannot bring it back. Revoking either consent stops new generations, erases the audio of candidates and approved songs, and appends a revocation receipt. Lyrics, frozen versions, decisions, the word list, consent receipts, candidate records used for quota, and opaque markers remain while the account exists. Account deletion removes the remaining music rows from the active app database; any downloaded file remains with the person. None of those local controls asks the music engine to erase, or proves that it erased, the request, job, audio, or security logs. Retention and deletion at the engine depend on the provider’s controls and terms.
In the first three situations, the app does not store the text in a database, file, queue, or application log. That describes storage in the app, not at a recipient. For OpenAI text calls in those situations and in the music lyric proposal, OpenAI states that it may retain prompts and responses in abuse-monitoring logs for up to 30 days and longer when required by law or reasonably necessary for security, unless the project has approved special controls. We therefore do not promise that the text disappears from the provider immediately.
Do not send a full name, address, official document, medical information, or any other data you do not want to share with an external service. The complete writing, composition, and export journey works without AI.
If you dictate by voice
The browser converts speech to text and may send audio to its provider’s own recognition service. This app neither receives nor stores the audio: it receives only the text shown in the field. Prefer not to depend on that service? You can type instead.
What we count, which is not about you
We count how many times certain navigation events arrive each day — only the aggregate total. These counters are not linked to an account or session and store no text or participant identifier. This helps locate confusing passages but is not a count of unique people. We do not measure how long you took on each sentence or store what you answered or wrote.
During an address change, we also count the daily total of authenticated actions still arriving through the former address. This number is used only to determine when it is safe to end the drain. It stores no account, session, route, IP address, or content; it records only the day, total, and time of the latest update.
If this computer belongs to someone else
A university lab, library, or someone else’s home: the primary copy of your text remains on the account server, but while you work the browser may keep a temporary local recovery draft in the tab’s storage. Sign out AND close the app’s tabs before leaving — an open tab still shows what was on screen. Any export, PDF, or approved audio you download remains on that computer until you remove it.
This is not an assessment
There is no grade and no ranking, and no one — teacher, institution, or anyone else — receives your text through this app. If you want to show it, you are the one who chooses to do so.