Noveletta Privacy Policy

Effective Date: September 10, 2026 Last Updated: September 10, 2026 Previous version: December 23, 2025

This Privacy Policy explains how Guildling LLC ("Guildling," "we," "us," or "our") collects, uses, discloses, and protects information when you use Noveletta (the "Service"), including our websites, applications, Canon (our reading and writing tools), and related services.

If you do not agree with this Privacy Policy, do not use the Service.

1. Who We Are

Controller (GDPR) / Business (U.S.): Guildling LLC Address: 365 S 43rd St, Boulder, Colorado 80305, USA Contact: legal@noveletta.com

If you are located in the EEA/UK, the "controller" of your personal data is Guildling LLC.

2. Scope

This Privacy Policy applies to personal data we process when you:

  • visit our website(s) or read our blog,
  • create an account or sign in,
  • browse the knowledge base, set your reading position, or save works to your library,
  • write, import, or publish fiction through Canon, or read fiction published there,
  • collaborate on a work as an invited team member, or invite others,
  • subscribe to our newsletter,
  • send us feedback, or
  • contact us for support.

3. What We Collect

We collect information in three main ways: (a) information you provide, (b) information collected automatically, and (c) information from third parties.

3.1 Information You Provide

  • Account information: email address, handle / display name, the sign-in identities you link to your account (see Section 3.3), and account settings.
  • Profile information: optional bio, avatar, and preferences (including newsletter and spoiler/chapter settings).
  • Reading activity: works you add to your library, your current chapter for each work, favorites, likes, and reader display preferences. This information is private to your account.
  • Author Content (Canon): manuscripts, chapters, books, cover images, blurbs, author's notes, your private notes and story bible, files you import (EPUB, DOCX, Markdown), publishing schedules, and the visibility and access settings you choose. Author Content is private to you and the collaborators you invite until you publish it. See Section 6.
  • Team and collaboration information: the email addresses of people you invite to work with you on a work, the role you assign them, and the org (studio) your works belong to. If you are invited, we hold the email address you were invited at until you accept or the invitation expires (14 days).
  • Feedback and communications: feedback submitted through the Service (including the page and chapter you were on, if you provide it), messages to support, survey responses, and other communications.
  • Newsletter subscription: your email address and the source and date of your subscription. See Section 11.
  • Payment information (if/when paid features exist): subscription status and transaction metadata. We do not intend to store full payment card numbers; payment processing will be handled by a third-party processor. No paid features exist as of the Last Updated date.

3.2 Information Collected Automatically

When you use the Service, we may collect:

  • Device and usage data: IP address, device/browser type, operating system, pages viewed, referrer URLs, and diagnostic logs.
  • Rate-limiting and security data: your IP address and, when signed in, your account ID are used to count requests to certain features (sign-in, feedback, imports, AI processing) so that we can prevent abuse. These counters are short-lived and are not used for any other purpose.
  • Aggregate analytics and performance data: we use cookieless analytics (see Section 9) that record page views and performance timings without identifying you across sites.
  • Cookies and similar technologies: strictly necessary cookies and local storage used for login/session, security, and your preferences. See Section 9.

3.3 Information From Third Parties

We may receive:

  • Sign-in provider information: when you sign in or link an identity with Google, Apple, or Discord, we receive a stable identifier, your email address, and basic profile details as permitted by your provider settings. Magic-link sign-in uses only your email address.
  • Anti-abuse verification: when you sign up with a magic link, Cloudflare Turnstile verifies that you are not a bot. Cloudflare processes your browser and connection information for that purpose under its own privacy policy. We receive only a pass/fail token.
  • Service provider data (for example, uptime or delivery logs) in connection with operating the Service.

4. How We Use Information

We use personal data to:

  • Provide and operate the Service (create accounts, authenticate you, keep your reading position, display content according to your spoiler and access settings, host and publish Author Content).
  • Build the knowledge base for each work, including with automated processing described in Section 7.
  • Enable collaboration (deliver invitations, apply roles, show collaborators who else is on a work).
  • Maintain safety and integrity (prevent abuse, spam, and fraud; secure accounts; enforce our rules; rate-limit expensive operations).
  • Communicate with you (support responses, critical notices, policy updates, service messages, and, with your consent, our newsletter).
  • Improve the Service (debugging, performance monitoring, product development, aggregate analytics).
  • Process payments (if/when paid features exist, via a third-party processor).
  • Comply with legal obligations and enforce our agreements.

5. Legal Bases for Processing (GDPR)

If you are in the EEA/UK, we rely on the following legal bases:

  • Performance of a contract (Article 6(1)(b)): to provide the Service you request, including hosting and publishing Author Content and building the knowledge base for works you publish.
  • Legitimate interests (Article 6(1)(f)): to secure and improve the Service, prevent abuse, understand usage in aggregate, and operate the knowledge base for publicly available works. We balance these interests against your rights.
  • Consent (Article 6(1)(a)): for the newsletter and any optional feature that asks for it. You can withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)): where we must comply with law.

6. What Is Public and What Is Private

Noveletta has both public and private surfaces. What is visible depends on the surface and the settings chosen by the person who owns the content.

Public (or visible to anyone with the link):

  • The knowledge base (entities, timelines, quotes, summaries) for works whose owner has made it public or unlisted.
  • Chapters an author has published with public access, and the work's hub page (cover, blurb, table of contents).
  • Your handle and avatar where they appear alongside content you publish or contribute.

Private:

  • Draft and scheduled chapters, author's notes, your private notes and story bible, unpublished revisions, and imported files.
  • Works, and knowledge bases, that their owner has set to draft or private. The knowledge base for a work is never more visible than the work itself.
  • Your library, reading position, favorites, likes, memberships, and feedback.

Who can see private content:

  • You, and the collaborators you invite, according to the role you assign them.
  • Noveletta staff, in limited circumstances. Our staff can access unpublished content only to provide support you request, to investigate abuse, security, or legal issues, or where the law requires. Every staff access to unpublished chapters or notes is recorded in an access log that includes who accessed what and when. We do not read your drafts to review them for editorial purposes and we do not use them for marketing.

Even if you delete content, copies may persist temporarily in caches, backups, and logs, or where other users have quoted or referenced public content.

7. Automated Processing and AI Model Providers

Noveletta uses large language models ("models") to extract structured information from chapter text: which characters, places, and items appear, what changed, notable quotes, and short summaries. This section explains what we send to models, who provides them, and the protections that apply. It applies equally to works we index from other sites and to Author Content published through Canon.

7.1 What is sent to a model

  • The text of a chapter being processed, in whole or in overlapping segments, together with the work's configuration (entity types, facets, and extraction instructions).
  • When a new work is set up from a public site, the pages needed to locate its table of contents.
  • Reviewer prompts used to grade the quality of extraction output.

We do not send your account information, email address, reading activity, library, private notes, or story bible to a model provider. We do not use models to generate fiction, to continue a story, or to imitate an author's voice; summaries and descriptions are written to be neutral, and any reference to the source is a short, attributed quotation.

7.2 Model providers and the terms they must meet

We use model providers under paid, business terms, never under consumer or free-tier terms. Any provider we use must, by contract:

  1. Not train on your content. The provider may not use our prompts (which include chapter text) or the model's responses to train, fine-tune, or improve its models or products.
  2. Act only as our processor. The provider processes content solely to return a response to us, under a data processing agreement, and may not use it for its own purposes.
  3. Limit retention to safety monitoring. The provider may retain prompts and responses only for a limited, published period and only to detect abuse of its service and meet legal obligations. Content retained for that purpose may be reviewed by the provider's authorized staff for that purpose alone. Where a provider offers a zero-retention option that we qualify for, we use it.
  4. Not claim ownership of the content we send or the responses returned.

As of the Last Updated date, our model provider is Google (Gemini API), used through a billed Google Cloud project under Google's Gemini API paid-services terms and Data Processing Addendum. Google states that it does not use paid-services prompts or responses to improve its products, and that it logs them for up to 55 days solely to detect and prevent violations of its Prohibited Use Policy. We review these terms when they change and will update this section if our provider or the terms materially change.

7.3 What we keep

The knowledge base we build is stored by us and is the product you see. It consists of structured records (entities, appearances, state changes, relationships, quotes, and summaries), each stamped with the chapter it came from.

Author Content you publish through Canon is stored by us because hosting it is the Service. For works we index from other sites, we process chapter text to build the knowledge base and keep what we need to operate, verify, and re-run that processing. We do not republish the text of indexed works.

7.4 Human review

Model output is a starting point, not a final record. Our team reviews and corrects extraction output, and we intend to open editing to authors and contributors. Reviewers see the knowledge-base records and the chapter they were extracted from; they do not see your private notes.

7.5 Removal

If you are the author or rightsholder of a work and you do not want it processed or indexed, contact legal@noveletta.com and we will remove it. Deleting Author Content from Canon deletes the knowledge base derived from it, subject to the backup and log persistence described in Section 12.

7.6 Automated decisions

We do not make decisions that produce legal or similarly significant effects about you solely through automated processing.

8. How We Share Information

We may share information as follows:

8.1 Service Providers (Processors)

We use vendors to run the Service. These vendors process personal data on our behalf under contractual obligations and may not use it for their own purposes.

  • Supabase — database, authentication, and file storage. Account data, profile, reading activity, Author Content, the knowledge base, and feedback.
  • Vercel — web hosting and delivery, plus cookieless analytics and performance measurement. Request logs (including IP address) and aggregate page-view and timing data.
  • Google (Gemini API) — model provider for knowledge-base extraction (Section 7). Chapter text and work configuration only.
  • Resend — transactional email (sign-in links, invitations, account notices) and the newsletter. Email address, message content, and delivery events.
  • Upstash — short-lived counters for rate limiting. IP address and account ID.
  • Cloudflare — Turnstile bot verification on signup. Browser and connection information, processed by Cloudflare.
  • Render — background processing of knowledge-base jobs. Chapter text and knowledge-base records.

We may add vendors for payment processing and error monitoring. When we do, we will list them here.

8.2 Collaborators You Invite

When you invite someone to a work, they can see the work's unpublished content according to the role you give them, and they can see your handle and the handles of other collaborators. When you accept an invitation, the work's owner can see your handle and the email address you were invited at.

8.3 Legal, Safety, and Enforcement

We may disclose information if we believe it is reasonably necessary to:

  • comply with law, regulation, legal process, or governmental request,
  • protect the rights, property, and safety of Guildling, our users, or others,
  • investigate or prevent abuse, fraud, security, or technical issues,
  • enforce our terms and policies.

8.4 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction, subject to this Privacy Policy.

8.5 With Your Direction

We share information when you instruct us to (for example, publishing content, integrating third-party services, or authorizing disclosures).

9. Cookies and Similar Technologies

We use only strictly necessary cookies and local storage:

  • Session and security: to keep you signed in and protect your account.
  • Preferences: your reader display settings, theme, and similar choices.

Our analytics and performance measurement (Vercel Analytics and Speed Insights) are cookieless: they do not set identifiers on your device and do not track you across other sites. Cloudflare Turnstile may set a cookie on the signup page for the purpose of bot detection.

Because we do not use non-essential cookies, we do not currently show a cookie consent banner. If we introduce non-essential cookies or tracking, we will ask for consent where the law requires it and update this section.

You can control cookies through your browser settings. Disabling cookies may prevent you from signing in.

10. No Targeted Advertising / No Sale of Data

We do not run ads, we do not sell personal data, and we do not "share" personal data for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

If this ever changes, we will update this policy and provide the required choices and controls before doing so.

11. Newsletter and Marketing Email

We publish an occasional newsletter about Noveletta. Subscribing is separate from creating an account and is always optional.

  • If you subscribe without being signed in, we send a confirmation email and add you to the list only after you click the confirmation link (double opt-in).
  • If you subscribe while signed in using your account email, or opt in during onboarding or in account settings, we add you immediately and record the choice on your profile.
  • Every newsletter includes an unsubscribe link, and you can also change the setting in your account. Unsubscribing takes effect immediately.

We do not send marketing email without this consent. Service messages (sign-in links, invitations, security and policy notices) are not marketing and are sent as needed to operate your account.

12. Data Retention

We retain personal data for as long as reasonably necessary to provide the Service, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. In particular:

  • Account, profile, reading activity, and Author Content: for as long as your account exists, or until you delete the content.
  • Pending invitations: 14 days, after which they expire.
  • Rate-limiting counters: minutes to hours.
  • Staff access log (Section 6): retained so that access to unpublished content can be audited.
  • Newsletter subscription: until you unsubscribe; an unsubscribed address is kept only to honor the unsubscribe.
  • Model provider abuse logs: as described in Section 7.2, under the provider's terms.

Backups and logs may persist for a limited period after deletion, consistent with reasonable operational needs. We may retain aggregated or de-identified data longer.

13. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data, including row-level access controls on unpublished content, hashed single-use invitation tokens, and audit logging of staff access. However, no system can be guaranteed 100% secure.

14. International Transfers

We are based in the United States and process and store data in the U.S. and in other countries where we or our service providers operate.

For EEA/UK users, when personal data is transferred outside the EEA/UK we rely on appropriate safeguards, such as Standard Contractual Clauses and/or other lawful transfer mechanisms, as required by applicable law.

15. Your Rights and Choices

15.1 GDPR Rights (EEA/UK)

You may have the right to access your personal data, correct inaccurate data, delete your data, restrict processing, object to processing, receive a portable copy, withdraw consent (where processing is based on consent), and lodge a complaint with a supervisory authority.

15.2 U.S. State Privacy Rights

Depending on your state, you may have rights to access, delete, and correct your personal data and to opt out of certain processing. We will honor applicable requests.

15.3 How to Exercise Rights

Some choices are available in the Service: you can change your profile, link additional sign-in identities, manage your library and reading position, edit or delete Author Content, and unsubscribe from the newsletter.

For everything else, including account deletion and a copy of your data, email legal@noveletta.com. We may need to verify your identity before responding. We will not discriminate against you for exercising your rights.

16. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If we learn we have collected such data, we will delete it.

17. Third-Party Links

The Service may link to third-party sites and services, including the original sites of works we index. Their privacy practices are governed by their own policies, not ours.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice by posting the updated policy and updating the Effective Date, and where appropriate via email or in-product notice. Changes to Section 7 (model providers and the terms they must meet) are always treated as material.

19. Contact Us

Email: legal@noveletta.com Mail: Guildling LLC, 365 S 43rd St, Boulder, Colorado 80305, USA

Feedback