Legal record / published
Privacy Policy
Last updated August 12, 2026
This policy is effective August 12, 2026. It explains what we collect when you use sopher.ai, why we collect it, and what control you have over it. The short version: we collect what the product needs to work, your manuscripts are private unless you deliberately create a reader link, and we do not sell or share personal data for cross-context behavioral advertising.
Who we are
sopher.ai operates this Service. For privacy questions, requests, or complaints, contact us at support@sopher.ai. If you send a request, we may ask for information needed to verify that you control the relevant account before we disclose or delete account information.
What we collect
- Account data — your name, email address, and avatar, from the sign-in provider you choose. Authentication is operated by Clerk.
- Your writing — briefs, outlines, manuscripts, story-bible entries, and edits, stored so you can return to them.
- Usage metering — a record of each AI model call your account makes (model, token counts, cost) so we can show you exactly what you spent. This record contains accounting and usage metadata, not the text of your book.
- Product events — events such as wizard steps, starting or finishing a book, exporting, and applying an edit. Events may be associated with your account after sign-in; their properties are restricted to small scalar values and are not used to store manuscript text.
- Safety and support records — information needed to prevent abuse, enforce our terms, investigate service failures, handle support requests, and comply with law. This can include a limited excerpt or moderation record when a safety check requires one.
- Payment records — handled by Stripe. We store the transaction reference and credit amount; we never see or store card numbers.
Who processes it
- AI model providers(currently Anthropic and Google, via Vercel’s AI Gateway) receive your brief and manuscript text to generate and edit your book, under terms that do not permit training on your content.
- Infrastructure — Vercel (hosting, file storage), Neon (database), Clerk (authentication), Stripe (payments).
- Analytics providers — Google Analytics and Vercel Analytics measure public-page visits and performance so we can improve the site. They are not loaded on the authenticated Studio, admin, API, or reader-link routes, and they never receive your manuscript text.
We do not sell personal data, run third-party advertising trackers, or share your manuscripts with anyone except the processors above, as needed to run the Service, and the people you deliberately invite through a reader link.
Reader links
If you create a reader link, we capture an immutable edition of the manuscript and make it available to anyone who has that secret link until it expires or you revoke it. Reader pages carry search-engine exclusion directives, do not run marketing analytics, and do not create or update attribution cookies. A recipient can still copy, print, save, or redistribute what they can read. The secret stays in the browser-only fragment of the shared URL and is exchanged for a scoped, HttpOnly reader-session cookie. Our database stores a one-way fingerprint, not the bearer secret. After creation you can revoke a link but cannot ask us to reveal it again. Revocation disables the reader page and optional download; it cannot recall copies a recipient already made.
Cookies
We use cookies for sign-in sessions (set by Clerk), reader sessions opened from a deliberate secret link, your theme preference, Google Analytics measurement (the _ga family), and two first-party cookies of our own: sopher_aid, a random identifier that lets us count a visit as one visit, and sopher_attr, which records how you first arrived (a campaign tag or referring site) so we know which channels are worth continuing. Both are first-touch cookies and last for up to 90 days; the referring site is stored as a domain only, never a full address. Neither contains your manuscript. There are no advertising cookies. You can block analytics cookies in your browser or with Google’s opt-out add-on without affecting the product.
We also record which steps of the book wizard you reach, and when a book is started, finished, or exported. This is product measurement — how far people get and where they get stuck — and it is never joined to the contents of what you write.
Retention and deletion
Your content is kept while your account exists. We may review content when required to enforce our terms, operate safety checks, or comply with law; such review is limited to that purpose. Deleting a project removes its manuscript, story bible, reader editions, reader links, and generated files. Expired or revoked reader snapshots are eligible for cleanup after 30 days. Deleting your account removes your account record and all projects; transaction records are retained as required for tax and accounting. To delete your account, use your account menu or email us. Some backups or fraud-prevention records may persist for a limited period before their normal secure deletion cycle.
Security and international processing
We use authentication, scoped access controls, secure transport, project-level ownership checks, and operational safeguards designed to protect your information. No internet service can guarantee absolute security, so do not use sopher.ai to store information that requires a specialized regulated system. sopher.ai and the processors listed above may process information in countries other than where you live. Where applicable, we use the contractual or other safeguards required for those transfers.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and remove it where appropriate.
Your rights
You can export your manuscripts at any time from the product. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information, and to withdraw consent where processing relies on consent. You may also have the right to opt out of sale or sharing; we do not sell personal data or share it for cross-context behavioral advertising. Email support@sopher.ai to exercise a right. We will not discriminate against you for making a lawful privacy request, subject to applicable legal exceptions and verification requirements.
Third-party links
The Service may link to third-party sites or services. Their privacy practices are governed by their own notices, not this policy. Review those notices before providing information.
Changes
Material changes to this policy will be posted here with a new “last updated” date.
sopher.ai / legal01