Privacy

Provenance ledger — every AI edit is auditable

The short version

  • We do not train AI on your manuscript. Ever. Not our AI, not third-party AI, not any AI.
  • Your book is stored on our servers so you can access it from any device. It's not shared with anyone.
  • AI prompts go to OpenRouter — the model provider we use — which does not train on the content of prompts.
  • Grammar checking is local. It runs in your browser and never leaves your device.
  • You can delete your account at any point and everything except billing records is removed.

The rest of this page explains each of those in detail. Privacy is one of the reasons authors pick this app over the consumer chat products, and we don't want the guarantees to be footnotes.

What we store

Under your account, in a local database on our server plus a durable cloud mirror, we store:

  • Your manuscript — every document, chapter, scene, paragraph, plus the ULID that identifies each paragraph so we can track provenance
  • Your Lore Book — every character, location, object, faction, event, concept, and note, plus aliases and any portraits you generated
  • Your Outline — Acts, Chapters, Scenes, statuses, and word targets
  • Your Vault sources — any files you've uploaded (their original bytes, plus the extracted text used for search and AI context)
  • Your chat threads and Pad sessions — the full message history in each
  • Your voice fingerprint if you've generated one — a structured JSON style profile, not the source prose
  • Your Provenance ledger — every AI-accepted change, with before-text, after-text, task kind, paragraph IDs, and timestamp
  • Your billing state — subscription tier, transaction history, Deep Analysis credits
  • Your account info — handle, display name, email, and a scrypt hash of your password (never the password itself)

All of this lives in the local database on our server for instant access, and mirrors to a durable cloud database for cross-device sync and backup. See How your data works for the sync detail.

We don't store anything else. We don't build a browsing-history profile of which pages you visited; we don't log your keystrokes; we don't record your window size or your mouse path. If you can't find it in the list above, we don't have it.

What leaves your device

When you use an AI feature, the relevant text (your prompt, plus whatever context the surface needs — a selected paragraph, an outline node, the current chapter) is sent to our servers, which forward it to OpenRouter — a routing layer we use to reach the underlying language models. OpenRouter's terms of service explicitly say they do not use prompt content to train models. The individual model providers (Anthropic, Google, OpenAI, and so on) that OpenRouter routes to also do not train on API traffic — that's a contractually different pathway from their consumer chat products.

If you're on any AI surface — Write, Chat, Templates, Desk, Atomize, the Wizard, Flags, Narrative Flow, Deep Analysis, Voice fingerprint generation, the Brainstorm Pad — the text you send goes to OpenRouter and then to whichever model is currently selected. See Models and AI providers for the full model catalogue.

If you're on a non-AI surface — reading Provenance, browsing the Outline, editing a Lore entry, searching with Ask, running grammar checks — no text leaves our servers for AI processing. Ask uses SQLite FTS5 on our end and never calls a model; the grammar checker runs in your browser and never calls anything.

The specific bytes that go over the wire on an AI run are: the user prompt, the system prompt (which may include your voice fingerprint if enabled and any @-mentioned Lore entries), and the response. Everything else — cookies, session state, your list of manuscripts — stays on our servers.

What stays entirely on your device

Grammar checking runs entirely in your browser via a local WASM library (Harper.js, ~1.5 MB, lazy-loaded the first time you toggle grammar on). When you enable grammar in the Write footer, the check runs on the paragraph as it appears on your screen — nothing about it is sent anywhere, not even to our own server. That's a hard commitment: there is no code path from the grammar check to a network call. If you inspect the network tab while grammar is running, you will see zero requests fire on each edit.

We chose Harper specifically because it's a self-contained WASM library with no telemetry. The alternative (a cloud grammar API) would have been faster to build but would have meant piping every paragraph of your book to a third party continuously as you type — a privacy pattern we weren't willing to ship.

The other things that stay entirely local are your DevTools state, your browser zoom level, and any browser extensions you have installed. None of it is visible to us.

Billing

Subscription payments and Deep Analysis credit purchases are handled by our payment processor. Card details never touch our servers — the processor handles the checkout in an iframe or hosted page and returns a webhook token that lets us mark your account paid. Your card number, expiration date, and CVV are never sent to us, cached by us, or logged by us.

Your subscription tier and credit balance are stored on our end (in the cloud, deliberately not mirrored to the local database — see How your data works). Your card details are not.

You receive receipts to your account email. If we need to reach you about a billing issue — a failed renewal, a chargeback investigation, a refund we processed — that's the address we use. We don't email you for marketing purposes on the billing address.

Billing records are retained for legal reasons (tax, accounting, chargeback windows) even after account deletion. That's the one class of data we can't wipe on request.

Do you train AI on my manuscript?

No.

We don't have an AI training pipeline, and we don't send your text to anyone who does. Every AI feature in Manuscripts.ai works by sending your prompt to a model provider, receiving the response, and showing it to you. The prompt is not stored on our side for retraining purposes; the response is stored only where you'd expect it (in the Provenance ledger if you accepted it, in the chat thread if you sent it, and so on).

Voice fingerprint is generated from your prose, but the fingerprint itself is a structured JSON profile ("sentence rhythm: uses fragmentary two-word sentences for emphasis", "avoid list: elaborate metaphors, semicolons") — not the source prose. The fingerprint is stored only under your account. It's used to prime AI responses on your future runs; it's not shared, aggregated, or used to influence any other user's output. See Voice fingerprint for how the profile is built and what it contains.

If we ever change any of the above, we will tell you before we do — not in a footnote, in an email.

What about the model providers themselves?

OpenRouter is the routing layer; the actual language models come from providers like Anthropic, Google, OpenAI, DeepSeek, Meta, and others. Those providers' API terms are clear that they do not train on API traffic. This is a contractual difference from their consumer chat products (ChatGPT, Claude.ai, Gemini.google.com), which may train on user chat by default. The API pathway we use does not train.

You can verify this yourself — the terms of service pages are public. OpenRouter's are at their website; each downstream provider has their own. If you want to pin a specific model that you've personally verified doesn't train, use the picker on the Settings page to lock in that model.

Who can see my manuscript

  • You — always
  • Anyone signed in as your account — anyone with your handle and password, or your Google login if you connected one. This is why we recommend a strong unique password
  • The team behind Manuscripts.ai, in narrow support cases when you specifically ask us to look at something. We don't browse manuscripts casually. Support access is intentional, logged internally, and scoped to what's needed to answer the question you asked. If you email us "chapter 4 is doing something weird" we'll open chapter 4; we won't scroll through the rest

No one else. Your manuscript is not shared, sold, indexed, published, or aggregated. It doesn't feed a training set, a public gallery, a "featured authors" widget, or a search engine.

Deleting your account

Open your account settings (via the avatar menu in the top-right of any page) and use Delete account. This is a hard delete:

  • Every manuscript, Lore Book, Outline, Vault source, chat thread, Pad session, voice fingerprint, and Provenance ledger under your account is removed from both the local database and the cloud mirror
  • Your account row and password hash are removed
  • Any sessions currently signed in as your account are invalidated
  • Billing records are retained — subscription payment history and Deep Analysis credit purchases are kept for tax and accounting reasons (typically for the retention period required by our jurisdiction)

Deletion happens immediately and is not reversible. If you're deleting because you're worried about something specific, email support first — we might be able to help you achieve what you actually wanted (a fresh manuscript, a different account, a password reset) without losing your work.

Contacting us about privacy

If you have a specific question we haven't answered here, email support with the subject line "Privacy question." We answer these ourselves, not through a template bot. If your question is about a specific piece of your data — "what do you have on me" — put "Data request" in the subject line and we'll produce a full account dump within a reasonable window.