VSProse
  • Home
  • Features
  • Compare
  • Blog
  • ProseDrop
Request Access

Privacy Policy

Effective date: 28 July 2026

Data controller: Toby Weston, sole proprietor, Switzerland. Niederdorfstrasse 82, 8001 Zurich, Switzerland

Contact: [email protected]

1. The short version

  • Your manuscript lives on your computer, in ordinary files you control. You never upload it to us for storage.
  • Our servers never store your prose. Not for a day, not for an hour. When you run a pass, your text is held in our API’s memory for the seconds the request takes and is never written to our disk or our database. There is nothing on our side to keep, to lose, or to hand over.
  • No other user ever sees a word of it. Nothing you write is published, and none of it is ever shown to another user.
  • Your text does leave your machine, and we will not pretend otherwise. It goes — encrypted — to our server, which passes it to a third-party model provider for processing, and the suggestions come back. The processing happens on their hardware, not yours. §4 sets out the whole path.
  • What we do keep is bookkeeping: how many pages you used, which model ran, what it cost.
  • We do not sell or rent personal data, and we run no ad trackers. Our website statistics are self-hosted and cookieless. Our signup system does set a small number of first-party cookies of our own, so that a signup can be matched to the campaign that brought you here — no ad networks, no cross-site tracking, nothing sold, and nothing that follows you off our site.

2. What we collect, and why

DataExactly whatWhy (legal basis)
Account Email address, display name, password (stored as a salted Argon2id hash — we cannot read it) To run your account (contract)
Billing Your Stripe customer reference, subscription status, and a ledger of purchases, refunds and pages. We never see or store your card number. Payment, tax, fraud prevention (contract / legal obligation)
Usage records Per editing run: pages, tokens, which model, cost, timestamp. No manuscript text. Correct billing, service integrity (contract / legitimate interest)
Chapter metadata Chapter title, word count, and a SHA-256 fingerprint of the content — a one-way hash. Your text cannot be reconstructed from it. To count usage per chapter without holding your prose (contract)
Devices Device name, platform, app version, the sign-in key your device registers, last-seen time Signing you in across devices (contract)
Security and server logs IP address, user agent, security events (sign-in, token refresh). Kept 12 months. Account security and abuse prevention (legitimate interest)
Beta applications What you tell us in the application form, and our notes on it Deciding who to admit to the closed beta (pre-contractual steps / legitimate interest)
Marketing email Your address, your double-opt-in confirmation, opens and clicks — only if you joined the waitlist or a course Consent. Withdraw any time; every email has an unsubscribe link.
Website statistics Aggregate page counts, self-hosted and cookieless. No cross-site tracking, no advertising IDs. Legitimate interest
Signup cookies A small number of first-party cookies, set by our own signup system on the pages you visit, so a later signup can be matched to the campaign that brought you. Ours, not an ad network’s. Legitimate interest
Support The emails you send us Answering you (legitimate interest)

3. What we deliberately do not collect

No manuscript storage on our servers. No card numbers. No ad-tech, no third-party analytics scripts, no data broker, no sale or rental of personal data to anyone, ever.

One honest footnote to that: our website does load two ordinary things from Google — web fonts, and a YouTube video where we have embedded one. Google therefore sees your IP address when those load. We have not asked them to track you and we get nothing back about you, but we would rather name it than let “no third-party scripts” read as more than it is.

4. What happens to your text when you run an edit

This is the section that matters. Read it.

The path. You start a pass. Your app splits the chapter into pieces — roughly 500 words at a time — and sends them over an encrypted connection to our API, along with whatever context the pass needs (your outline, a synopsis, the character list, story notes). Our API forwards each request to OpenRouter, Inc., our AI routing provider, which routes it to a large model provider for processing. The suggestions come back the same way and land in your app, where you accept or reject them.

What our servers keep: none of it. The prose exists in our API’s memory for the seconds the request takes and is never written to disk or database. What is written down is the bookkeeping in §2 — page counts, token counts, model, cost. This is a property of how the service is built, not a policy we could quietly change one afternoon.

The honest limits. We are not going to tell you your text is never touched by anyone else’s computer, because it is:

  • The processing happens remotely, on the model provider’s hardware. Nothing about VSProse’s editing runs locally on your machine, and any surface of ours that suggests otherwise is wrong.
  • Once a request reaches a third-party provider, what that provider does with it is governed by their terms, not ours. Some providers hold a request for a short period for safety and abuse checks where their own terms require it.
  • The mix of model providers varies by operation and by availability. The current list is available on request — write to us and we will tell you who is on it today.

What is never true: we do not sell your writing, we do not license it to anyone, and we do not publish it or show it to another user.

5. Who processes data for us

ProcessorWhat they doWhere
StripePayments (we never hold card data)EU / USA
HetznerServer hostingGermany / Finland (EU)
Amazon Web Services (SES) Sending transactional and course email Ireland (EU), eu-west-1
Amazon Web Services (S3) Encrypted offsite backups of our databases — account, billing and usage records. No prose, because none is ever written to those databases. Germany (EU), eu-central-1
OpenRouter, Inc.Routing AI requests (§4)USA
Model providers, reached via OpenRouter Producing the editing suggestions (§4) USA / EU
Our own self-hosted systems (email, statistics, site content) Run on our own servers. No third party receives your data through them. EU
Cloudflare, Inc. Edge proxy, DDoS filtering and TLS termination for our website and API. All traffic — including manuscript text and sign-in tokens in transit — passes through Cloudflare’s network before it reaches our servers. USA (global edge network)
Domain Discount 24 Inbound mail hosting (IMAP mailboxes) for @vsprose.com addresses, including hello@ and the catch-all. Distinct from AWS SES, which is outbound-only. Support and rights-request emails land here before anyone reads them. Germany (EU)
Google (Fonts) Serves font files on every pageview; receives the requesting visitor’s IP address as a normal side-effect of the request. No cookie set. USA
YouTube (Google) Video embed on the homepage. A visitor who loads it is a visitor Google can identify, per YouTube’s own terms. USA

Where a processor sits outside Switzerland and the EEA — Stripe, AWS, OpenRouter, Cloudflare, and US model providers — the transfer relies on that provider’s standard contractual clauses and, where they are certified, the EU–US and Swiss–US Data Privacy Framework. Domain Discount 24 is excluded from this list: its confirmed jurisdiction is Germany (EU/EEA), so no cross-border transfer clause applies to it.

6. How long we keep things

  • Your manuscript: we never keep it. It passes through our API’s memory and is never written down, so there is nothing on our side to retain, to delete, or to hand over. The files themselves are a matter between you and your own disk.
  • Account and page-ledger data: for as long as your account exists.
  • Financial records: 10 years from the end of the financial year they belong to — Swiss Code of Obligations Art. 958f requires accounting records and vouchers to be kept that long.
  • Usage records: 24 months, then reduced to aggregates.
  • Security and server logs: 12 months.
  • Beta applications: until the beta ends, then deleted unless you have an account with us.
  • Marketing list: until you unsubscribe, or after 24 months of no engagement.
  • Backups: encrypted, rolling, overwritten within days.

7. Your rights

You can ask us for access, correction, deletion, restriction, portability, or to object — and you can withdraw consent at any time. Write to [email protected] and we will answer within one month.

We answer under the Swiss Federal Act on Data Protection (FADP) and, for users in the EU and UK, under the GDPR and UK GDPR.

To delete your account, email us. We remove your account record, your device records and your chapter metadata. Financial ledger entries stay only as long as the law obliges us to keep them.

You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU/UK, to your national data-protection authority.

8. Changes

We post changes here with a new effective date. Material changes are emailed to account holders.

Home Features Compare How It Works FAQ Blog Manifesto How we work ProseDrop
Terms Privacy Refunds

© 2026 VSProse. A Lobster Books product.