Privacy policy
Last updated 24 September 2026. Effective 24 September 2026.
This policy explains what Authrot collects about you, what we do with it, who else receives it, how long we keep it, and the rights you have over it. It covers the website at authrot.app, the Authrot app, and the emails we send.
The short version: we keep what we need to run your account, your projects and your bill. Your writing is sent to an AI model only when a feature you use needs it. We do not sell your data, we do not advertise, we do not track you across other sites, and neither we nor the model providers we use train AI models on your writing.
1. Who we are
Authrot is run by Recharge8 LLC, a Texas limited liability company, P.O. Box 100, San Ygnacio, Texas 78067, United States ("we", "us"). For the personal data described here we are the controller (the "business" under US state laws).
Privacy questions and requests: [email protected]. Anything else: [email protected].
2. What we collect
You give us
Account details. Your email address and, if you give one, a display name.
Sign-in details. If you sign in with Google, Apple or Microsoft, that provider tells us your account identifier there, your email address, whether it is verified, and your name. From Google we also receive the web address of your profile picture, which we show in the app. We never receive your password for those accounts. Apple may give us a private relay address instead of your real one; we use it like any other address. If you add a passkey, we store its public key and the name you give it, never anything that could sign in as you. Authrot has no passwords.
Your writing and everything in your projects. Chapters, drafts, notes, outlines, story-bible entries, writing rules, comments, images you upload for chapter ornaments, and the full history of every change. When you import files, they are read in your browser and only the converted text reaches us: the original file is never uploaded, though we keep its file name to show where the text came from.
Your conversations with the assistant. What you type, and the exact text we send to and receive from the AI model on your behalf, including the parts of your project it was given to work with.
Collaborators' email addresses. When you invite someone to a project, you give us their email address. We use it only to let that person join.
Billing choices. Your plan, trial, purchases, spending limits and email preferences. If you cancel, the reason you pick and anything you choose to write in the box.
Your own model keys. If you add an API key for a model provider, we store it encrypted (see §8).
Messages to us. Anything you send to our support or privacy addresses.
Collected as you use Authrot
Session and security records. For each signed-in device: when it signed in, how, its IP address, and its browser and operating system (the "user agent"). A log of sign-in events (sign-ins, failed codes, passkeys and providers added or removed) with the email address, IP address and user agent involved.
Usage of AI models. For every model call: who made it, in which project, for what feature, which model, how many tokens it used, and what it cost. This record does not contain the text itself.
Emails we sent you. The address, which email it was, its subject line, and whether delivery succeeded.
Preferences. Your theme, density and reading settings (see §9).
From other companies
Stripe, our payment processor, tells us whether a payment succeeded, the payment method type (card, bank account), a fingerprint that lets us recognise the same card again (used only to limit free trials to one per card), and refunds or disputes. We never receive your full card number or bank details.
Google, Apple and Microsoft, if you sign in with them, as described above. Apple may also tell us when you stop using Sign in with Apple or delete your Apple account, and we then disconnect it.
We do not buy data about you, and we do not collect precise location, contacts, biometric data or anything from your device beyond what your browser sends with every request.
3. How we use it, and why we are allowed to
For people in the EU, the UK and similar places, each use needs a legal basis. We rely on these:
To provide Authrot (contract): creating and securing your account, signing you in, storing and syncing your projects, real-time collaboration, the story bible, search, exports, and sending your text to an AI model when you use a feature that needs one.
To bill you (contract, and our legal obligations for tax and accounting): subscriptions, trials, credit packs, refunds, and metering AI usage in credits.
To send the emails the service needs (contract): sign-in codes, security notices (a passkey or sign-in method added or removed), billing notices (trial ending, payment failed, plan changes, low credits, credits expiring) and notices before an idle account is deleted. You can turn off low-credit and credit-expiry reminders in Settings → Plan & credits. We do not send marketing emails; if we ever start, we will ask first or give you a way to opt out, as the law requires.
To keep Authrot and your account safe (our legitimate interest in security): session and sign-in records, rate limits on sign-in attempts, fraud and abuse prevention, limiting free trials to one per person and card, and investigating problems.
To improve Authrot (legitimate interest): working out which features and models are used and what they cost, from the usage records above. We do not read your writing for this.
To handle cancellations and support (legitimate interest): understanding why people leave, and answering you.
To comply with the law and protect our rights (legal obligation, legitimate interest): responding to lawful requests, enforcing our terms, and handling disputes.
You need to give us an email address to have an account. Everything else about your writing is up to you.
No automated decisions about you. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. The AI features change content in your projects, as §4 explains, never your access, price or rights.
4. The AI features and your writing
Authrot's assistant and background passes are powered by third-party AI models. When you use one, the text it needs is sent to the model's provider and the answer comes back to us:
Chat sends your message, the parts of the project it needs (the open chapter, your selection, anything you attach, relevant story-bible entries, your writing rules and an outline), and the conversation so far.
Reading a chapter into the story bible sends that chapter and what the bible already records.
Building a bible from imported notes sends those notes.
Organising a project sends a list of its documents with their titles, sizes and opening lines.
Sorting an import sends file names, titles and the first 900 characters or so of each file, never whole files.
Suggesting names and titles sends the project details the suggestion is about.
We do not send your name, email address or account details to model providers.
Models we host are provided by Anthropic. Anthropic does not use this text to train its models. It deletes inputs and outputs within 30 days, except when a request is flagged under its usage policy, when it may keep them for up to two years (and its safety classification scores for up to seven). See Anthropic's privacy policy. If a model declines a request, Anthropic may pass it to another Anthropic model to answer.
Your own keys. If you add a key for another provider (such as OpenAI, DeepSeek, Google Gemini, Mistral, xAI, OpenRouter, GitHub Models, or a server you run), requests you make with that key go to that provider under your own agreement with them, and their terms decide how they store it and whether they train on it. Read them before you add a key. In particular, DeepSeek stores data in the People's Republic of China and its policy says it may use data to improve its models.
We do not use your writing to train AI models, and we will not start without asking you first.
5. Who else receives your data
We share personal data only with the service providers who help us run Authrot, only for that purpose, and under contracts that limit their use of it:
Anthropic (United States): AI models, as described in §4.
Stripe (United States): payments, subscriptions and refunds. Stripe collects your payment details directly on its own pages and also uses them for its own fraud prevention and legal duties; see Stripe's privacy policy.
Resend (United States): delivers our emails. It receives your address and the email's content.
Cloudflare (global): stores the images you upload for chapter ornaments, in a private store.
Our hosting provider: runs our servers and database, where your account and projects are stored.
Google, Apple and Microsoft, only if you sign in with them. We send them nothing about your writing. Disconnect them any time in Settings → Account & sign-in.
We also share data:
With the people you work with. Members of a project you share see your name, email address, your edits and their history, and your cursor while you are both editing. If you are on a Studio plan and share your credits, you can see how much each member has spent. Your conversations with the assistant are private to you, even in a shared project.
With the model provider you choose for your own keys (§4).
When the law requires it, for example a valid court order, and when needed to protect someone's safety or our rights. Where we can, we tell you first.
If the business changes hands. If Recharge8 LLC merges, is acquired, or sells Authrot, your data would pass to the new owner under this policy, and we would tell you before it did.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising, as California law defines those words. We have never done either.
Our own staff. A small number of administrators can see account, billing and usage records, sign-in and security records, and the settings of background jobs, to run the service and help you. The app does not let them open your projects. We look at project content only when you ask us to, or when we must to investigate abuse, a security problem, or a legal request.
The demo project. Every account can read a demo project. It is always one we wrote ourselves, never yours.
6. Where your data is processed
We are based in the United States, and your data is processed there and wherever our providers operate. When personal data leaves the EU, the UK or Switzerland for a provider, we rely on the EU–US Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified, and otherwise on the European Commission's standard contractual clauses and the UK addendum. Ask us for a copy of the safeguards that apply.
If you choose a model provider in another country with your own key, such as DeepSeek in China, your data goes there because you asked for it to.
7. How long we keep it
Your account stays until you delete it. An account with no plan and no sign-in for twelve months is deleted after two email warnings, 30 days and 7 days before; people you share projects with are warned too.
Your projects stay until you delete them or your account is deleted. A project you delete disappears from Authrot at once; its data remains in our database until your account is deleted, so we can restore it if you ask. Write to us if you want a deleted project erased sooner.
Conversations stay with your account. Deleting a conversation hides it; it is erased with your account.
Work in other people's projects stays in their project when you leave or delete your account, because it is part of their book; your name is removed from it.
Sessions end after 30 days without use and after 90 days in any case; their records are removed 30 days after they end. Email sign-in attempts are removed after two days.
Security, email and audit records (sign-in events, the list of emails we sent, and a record of administrative actions) are kept as long as they are needed to protect accounts, investigate problems and show what we did, and are not removed when an account is deleted.
Billing records in our database are removed with your account. Stripe keeps its own records of your payments for as long as the law requires.
Your own model keys are deleted when you remove them or delete your account.
Backups. Data removed from our database can remain in encrypted backups until they are overwritten, within 30 days.
Model providers keep what they receive for the periods in §4.
8. How we protect it
All traffic to Authrot is encrypted in transit (HTTPS).
There are no passwords to steal. Sign-in uses one-time email codes, passkeys, or Google, Apple or Microsoft.
Your browser never holds your session token where page scripts can read it, and we store only a hash of it.
Model keys you add, and the token Apple gives us, are encrypted with AES-256-GCM before they are stored; model keys are never shown again, not even to you.
Invitation links and sign-in codes are stored only as hashes and expire.
Every project checks your role before anything is read or changed. Sensitive account changes need a recent sign-in, and each new passkey or sign-in method triggers an email to you.
You can see every signed-in device in Settings → Account & sign-in and sign any of them out.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
9. Cookies and browser storage
We use a few first-party cookies, none for advertising or analytics, and no third-party trackers:
__Host-authrot_session: keeps you signed in. Lasts until the session ends (at most 90 days).__Host-authrot_signin,__Host-authrot_oauth,__Host-authrot_link: tie a sign-in you started to the browser you started it in, so a code or provider response cannot be used elsewhere. Last 10–15 minutes.authrot_theme,authrot_density,authrot_voice: remember the look you chose. Last one year.
The app also keeps your reading settings (font, size, zoom) and which panels you had open in your browser's local storage. These never leave your device.
The sign-in cookies are strictly necessary. The look-and-feel cookies are set only when you choose a setting; to stop them, reset your choices in Settings or clear this site's cookies in your browser. Stripe's checkout and the sign-in providers' pages are on their own sites and set their own cookies there.
Do Not Track and Global Privacy Control. Because we do not track you across sites, sell or share your data, these browser signals do not change anything we do. We treat them as an opt-out anyway.
10. Your choices and rights
In Authrot you can:
See and change your name, sign-in methods, passkeys and devices (Settings → Account & sign-in) and email preferences (Settings → Plan & credits).
Export any project you can open, as PDF, Word, EPUB, Markdown or text, with its story bible and planning as data files.
Delete your account and every project you own (Settings → Account).
Wherever you live, you can also ask us to:
tell you what personal data we hold about you and give you a copy, including in a portable form;
correct it (for example, to change the email address on your account);
delete it;
restrict or object to how we use it, including anything we do on the basis of legitimate interests;
withdraw any consent you gave, without affecting what we did before.
Email [email protected] from the address on your account. We may need to confirm it is you before acting, and will reply within one month (sooner where a law requires it). Some data we must keep, for example to meet tax law, protect against fraud, or defend a legal claim; if so, we will say what and why. Using your rights will never cost you anything or change the service you receive.
Appeals. If we turn down your request, reply with "appeal" and someone who did not handle it first will review it within 45 days and tell you the result and why.
Complaints. Tell us first at [email protected]; we acknowledge complaints within 30 days. You can also complain to your data protection authority at any time: in the EU, the authority where you live or work; in the UK, the Information Commissioner's Office.
11. More for US residents
Several US states give their residents rights over their data. We give every user the rights in §10, whatever state they live in. In the terms California law uses, in the last twelve months we collected:
Identifiers: name, email address, account identifiers, IP address.
Customer records: name and email, and billing status (payment details are held by Stripe, not us).
Commercial information: plans, purchases, credits and usage.
Internet activity: sign-in records, browser and device type, and how you use features.
Account login credentials, which count as sensitive: sign-in codes, passkeys and provider identities, used only to sign you in.
Inferences: none.
Content you create, which may include personal information about you or others, depending on what you write.
We collect these from you, your browser, and the companies in §2, for the purposes in §3, and disclose them only to the recipients in §5. We keep them as §7 describes. We do not sell or share personal information, including of anyone under 16, and we use sensitive personal information only for purposes the law permits, so there is nothing to opt out of or limit.
You may use an authorised agent to make a request; we may ask them for your signed permission and ask you to confirm your identity.
12. More for people in the EU and UK
Our legal bases are listed in §3, transfers in §6, and your rights and how to complain in §10.
13. Children
Authrot is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and its data. If you think a child is using Authrot, tell us at [email protected].
14. Changes to this policy
When we change this policy, we update the date at the top. If a change matters, for example a new kind of data, a new use of it, or a new company that receives it, we email you at least 30 days before it applies and say so in the app. We will never use data we already hold in a new way that needs your consent without first getting it.
15. Contact
Recharge8 LLC, P.O. Box 100, San Ygnacio, Texas 78067, United States. [email protected].