Endpaper

Privacy

Last updated [date of publication]

Your writing is yours. This page says what we keep, how we protect it and who else touches it. We have tried to say nothing that is not true today.

Who we are

Endpaper is run by [legal name of the person or company], in [country or state].

What we keep

  • Your account: your email address, your name, a hash of your password (never the password itself), and the passkeys or Google account you use to sign in. A pen name and contact details, if you add them for your title page.
  • Your writing: your manuscripts, drafts, chapters, titles, and your character and setting notes.
  • Your writing habits: how many words you wrote on each day, your daily goal, and your deadline. These are numbers, not text.
  • Sign-in details: when you last signed in, a short label for the browsers you have used (such as "Chrome on macOS"), and the technical details your browser sends. While you are signed in, our session record holds your IP address and browser type.
  • If you ask for an invitation: your email address and name.

We do not run advertising. We do not sell or rent your information to anyone. We do not collect product analytics at the moment. If that changes we will say so here first, and you will be able to opt out.

How your writing is protected

Everything you write is encrypted before it is stored. Each manuscript has its own key, and that key is itself locked by a master key held at Amazon Web Services (AWS). If someone copied our database or a backup, they would find no readable chapter, note or manuscript title.

That is not the same as "we cannot read it". Endpaper has to open your writing to show it to you, so our systems can. We also keep a recovery key, stored offline, so that a lost password or a failure of our own servers cannot cost you your book. We do not read what you write. We would open a manuscript only if you ask us to, to restore your work, or if the law requires us to.

Some things are not encrypted: your email address, name, pen name and contact details, your word counts by day, and the times you signed in.

What is not in our logs

Our logs and error reports record ids and counts, never your text, titles or notes. A test in our code checks this.

Who else handles your information

We use a few other companies to run Endpaper. Each sees only what its job needs.

  • Laravel Cloud hosts the app and its database.
  • Amazon Web Services holds the master encryption key (KMS) and sends our email (SES). It never receives your text, only the keys that lock it.
  • Nightwatch receives error reports and technical details of requests, with no writing in them.
  • [Backup provider] stores our encrypted backups.
  • Google, only if you choose to sign in with Google. We receive your name and email address from it.

Your information is stored in [region]. [Add the transfer wording that applies, once the region is chosen.]

Cookies

We use only the cookies the site needs to work: one that keeps you signed in, one that protects forms from forgery, and one that remembers a browser you have signed in from before, so that we can warn you about sign-ins from a browser we do not know (it lasts five years), and, only if you tick "Keep me signed in", one that keeps you signed in on that browser (it lasts about five years). Nothing is used for advertising or tracking.

How long we keep things

  • While you have an account, we keep what you have written until you remove it.
  • When you delete a manuscript, it is deleted for good from our live database. Copies remain in our daily backups, which we keep for about two weeks.
  • When your account is deleted, copies remain in our daily backups for about two weeks more. We also keep a short record of the deletion (a random identifier and the date, with no name, email address or writing) so that restoring a backup does not bring your account back.
  • When you cut a chapter from a draft, the text is kept in the manuscript so that cutting never destroys writing. A note you delete is hidden, and its text stays in our database until the manuscript is deleted.
  • Logs are kept for [30] days. [Confirm against Laravel Cloud and Nightwatch retention once deployed.]

Your choices

  • You can download your manuscripts as Word and PDF files at any time.
  • You can edit your name, pen name and contact details on your account page.
  • You can delete your account yourself on your account page. We wait 30 days before erasing anything, and if you sign in again in that time the deletion is cancelled. After 30 days your account and everything in it is deleted for good.
  • To get a copy of everything we hold about you, or to correct it, email us. [Confirm the time we promise to reply within.]
  • [If readers in the UK or EU are expected: add the rights and the regulator to complain to.]

Security notices

We email you when something sensitive happens on your account, such as a new sign-in from an unknown browser, a changed password, or an added or removed passkey. These are not marketing.

AI and your writing

Nothing you write is ever used to train an AI model, by us or by anyone else. Endpaper has no AI features today. If we add one, it will follow this rule, and we will describe it here first.

Changes

If we change this page in a way that matters, we will email you before it takes effect.