ZibaldiBack

policy

Privacy

Last updated 29 July 2026

01The short version

Your manuscript is yours. It is never used to train any AI model, it is never sold, and it is never read by us except in the narrow circumstances named in clause 07. We collect the least we can get away with: an email address so you can sign in, and the work you choose to put in.

02What we store, and why

Your email address. Used to sign you in by magic link, to send you an invite when someone shares a book with you, and for service notices. There is no password, so there is no password for anyone to steal.

Your work. Books, scenes, captured fragments, research notes, characters, plot rows, story-bible entries, and manuscript text. Held in a Postgres database at Supabase in the US East region, with row-level security so a query can only ever reach the workspaces you belong to.

A little configuration. Your display name, theme and interface-font choice, notification preferences, and — if you supply one — your own Anthropic API key.

Invited people's email addresses. When you invite someone to a workspace, we store the address you typed so the invite can be matched when they sign in.

Plainly

An email address, the writing you put in, and a handful of settings. No tracking profile, no advertising identifiers, no data brokers.

03Your manuscript lives on your device first

The editor is local-first. As you type, text is written to IndexedDB in your own browser and then synced to your account. Drafting keeps working with the network off, and the copy on your machine is a real copy, not a cache of ours.

Clearing your browser storage removes the local copy. Where it has synced, your account still holds it.

04AI: what is sent, and what is never done with it

AI features are opt-in and sit on a dial. At the default position the model can read, research, remember and ask questions, and cannot produce prose for your book. With AI switched off, nothing about your work leaves our infrastructure for any model.

When you do use an AI feature, the relevant context — the passage, notes or story-bible entries that feature needs — is sent to Anthropic for processing and the response comes back to you. Under the API terms we rely on, your content is not used to train models.

You may supply your own Anthropic API key instead, in which case those requests are billed to and governed by your own account with them. That key is stored in your profile row and protected by the same row-level security as everything else; if you would rather it not sit in our database at all, leave it blank and use the bundled option.

Plainly

Nothing you write trains a model. With the dial off, nothing goes to a model at all.

05Cookies and local storage

No advertising or analytics cookies. What we set is functional and short: a Supabase session cookie so you stay signed in, a cookie remembering which workspace you were last standing in, and two local-storage entries for your theme and interface font so the page does not flash the wrong one before it loads.

06Processors we rely on

Supabase — authentication, database, and the magic-link emails. Anthropic — AI processing, only when you use an AI feature. Cloudflare — hosting, plus Turnstile on the sign-in form, which checks that a request comes from a person and not a script. Turnstile receives your IP address and browser signals for that check; it does not read your work.

Cloudflare and Supabase keep operational logs — request and error records — as part of running the service.

07When a human would look at your work

Only two situations. If you ask us to, because you have reported a problem we cannot reproduce without looking. Or if we are legally compelled, in which case we will tell you unless we are prohibited from doing so. We do not read manuscripts for quality control, product research, or curiosity.

08Sharing and collaborators

A book belongs to a workspace. Anyone you add to that workspace can see the books in it, at the level their role allows — owner, editor, or reader. Removing someone ends their access. Nothing is public unless and until we build a share feature and you choose to use it.

09Your control

You can export your work, correct anything in it, and delete your account, which deletes the workspaces you alone own and the books in them. Backups age out on their own cycle after that. Depending on where you live you may have further rights over access, portability, correction and erasure; ask and we will honour them rather than making you cite the statute.

10Children

Zibaldi is not intended for anyone under 13, and we do not knowingly collect their information.

11Changes, and how to reach us

If we change something that materially affects what happens to your work, we will say so by email rather than silently editing this page.

Privacy questions: privacy@zibaldi.com. Anything else: support@zibaldi.com.

Plain-English summaries in the grey boxes are there to be helpful, not to replace the text around them. If the two ever disagree, the full text governs.