Chính sách quyền riêng tư
Phiên bản tài liệu:
Cũng xem điều khoản dịch vụ và cách chúng tôi xử lý AI và chữ viết của bạn.
Novilot là ứng dụng viết cho nhà văn tiểu thuyết. Bản thảo là thứ cá nhân nhất bạn có thể đưa vào phần mềm, và trang này giải thích chính xác điều gì xảy ra với nó và phần còn lại của dữ liệu. Phiên bản ngắn: chữ của bạn vẫn là của bạn, chúng tôi chỉ dùng để chạy tính năng bạn yêu cầu, không bao giờ bán dữ liệu, và không bao giờ dùng chữ của bạn để huấn luyện mô hình AI.
Chúng tôi thu thập gì
- Dữ liệu tài khoản. Địa chỉ email của bạn và phiên bản băm của mật khẩu (băm bằng bcrypt; chúng tôi không thấy mật khẩu).
- Bài viết của bạn. Dự án, chương, mục Story Bible, dàn ý, ghi chú, phiên bản chương, và bất cứ gì khác bạn tạo trong ứng dụng. Được lưu để ứng dụng hiện lại cho bạn. Không bao giờ công khai trừ khi bạn chủ động chia sẻ (ví dụ, liên kết độc giả beta bạn tạo).
- Dữ liệu làm việc của AI. To power features like autocomplete, continuity checking, and voice matching, we store material derived from your manuscript: summaries, style profiles, continuity observations, and text embeddings. These are private working data, subject to the deletion and retention details below.
- Dữ liệu sử dụng. Tính năng nào bạn dùng và sự kiện sản phẩm cơ bản (ví dụ, rằng một phân tích đã chạy), cộng lượng dùng tín dụng để tính tiền công bằng. Chúng tôi cũng đếm từ đã viết cho mục tiêu và chuỗi của chính bạn.
- Dữ liệu thanh toán. Payments are handled by Dodo Payments. We never see or store your card number; we store your Dodo Payments customer and checkout references, subscription status, and payment and refund records needed to maintain your credit balance.
- Tin nhắn bạn gửi cho chúng tôi. Phản hồi bạn gửi trong ứng dụng và email bạn gửi cho chúng tôi.
Cách các tính năng AI dùng bản thảo của bạn
Anthropic's Claude API processes manuscript passages for AI features. OpenAI's embeddings API processes paragraphs and search queries to support meaning-based manuscript search. Preparing this search index can run in the background after you save or import chapters. Requests use encrypted connections. A full-manuscript analysis may process the entire manuscript within the coverage shown for that scan.
- We do not use your writing to train AI models or opt your manuscript into provider training programs. Anthropic and OpenAI do not train on commercial API content by default.
- We send content needed for the feature and its supporting processing, such as search indexing. Provider retention is separate from model training.
- Kết quả AI (gợi ý, phân tích) được lưu trong tài khoản để bạn không phải trả để tạo lại.
AI provider retention
We do not promise Zero Data Retention. Anthropic's standard API policy deletes inputs and outputs within 30 days, with exceptions for legal obligations and policy enforcement. Flagged content may remain for up to two years and safety classifications for up to seven years. Feedback deliberately submitted to Anthropic can be retained for five years and may be used for training; we do not submit your manuscript as provider feedback.
OpenAI's standard API abuse-monitoring retention is up to 30 days, with longer retention possible for legal or safety reasons. The embeddings endpoint does not retain application state. Deleting a project in Novilot does not itself erase provider logs or override their retention obligations.
Xem Anthropic's retention policy và OpenAI's API data controls.
Human access
Private means your manuscript is not public or available to other writers unless you share it. It does not mean end-to-end encryption: our servers and processors need readable text to provide the service. People with privileged infrastructure or database access can technically access it. Operational access must be limited to what is necessary for support, debugging, security, abuse investigations, or legal obligations, not browsing your work for personal or commercial use.
Service providers can also permit authorized human access under their agreements, including safety review. We cannot promise that no person will ever review content. Text you choose to include in a support message is available to the people handling it.
Phân tích
We use Google Analytics and PostHog to understand how the product is used so we can improve it. PostHog session replay is configured to mask text and inputs. Sentry helps diagnose errors; request-body collection and default personal-data collection are disabled, and replay text and inputs are masked. Diagnostic metadata may still be processed. We do not intentionally send manuscript text to analytics or error reports. We do not run ads.
Cookie
- nc_session: cookie thiết yếu giữ bạn đăng nhập. Ứng dụng không thể hoạt động nếu thiếu nó.
- Cookie phân tích từ Google Analytics và PostHog, chỉ dùng cho các mục đích trên.
Dữ liệu của bạn sống ở đâu và ai xử lý nó
Dữ liệu của bạn được lưu trong cơ sở dữ liệu Postgres được quản lý và phục vụ qua Vercel. Chúng tôi chỉ chia dữ liệu với nhà cung cấp dịch vụ cần để chạy Novilot, và chỉ cho mục đích đó:
- Vercel (lưu trữ)
- Prisma Postgres (cơ sở dữ liệu)
- Anthropic (tính năng AI)
- OpenAI (manuscript and query embeddings for search)
- Dodo Payments (thanh toán)
- Gửi lại (email giao dịch)
- Google Analytics và PostHog (phân tích)
- Sentry (error monitoring)
- Dropbox and GitHub (only when you connect an external backup destination)
We do not sell your data. Manuscript processing is limited to providing the service, your chosen sharing and backup features, and necessary legal or security obligations.
Lưu giữ và xóa
- Project deletion removes its manuscript, chapter history, Story Bible, summaries, continuity records, embeddings, and saved analyses from the active database. Manuscript-derived voice profiles are invalidated so they cannot keep deleted excerpts.
- Chapter deletion removes that chapter and its version history, and invalidates affected derived analyses and voice profiles. Project-level Story Bible entries, outlines, and notes you have retained remain until you edit them or delete the project.
- To delete your entire account, contact us (see below). Account deletion removes your writing, AI working data, usage history, profile, and linked in-app feedback from the active database. Records required by law, such as payment records held by the payment provider, can have separate retention obligations.
- Our Prisma Postgres plan keeps automated database snapshots for seven days. Deleted data can remain in an earlier snapshot until it expires. This backup window is separate from the AI-provider retention and external copies described on this page.
- Exports, copies shared with others, and backups in your connected Dropbox or GitHub account are not erased by deleting a Novilot project or account. You control those copies separately.
- The browser can hold analysis caches and unsynced edits. Deleting through the app clears the affected local copies on that device. Copies on offline or other devices may remain until cleared there.
- Bạn có thể xuất bản thảo bất cứ lúc nào từ ứng dụng (DOCX, EPUB, HTML, Markdown, hoặc PDF).
Quyền của bạn
Tùy nơi bạn sống (ví dụ, theo GDPR hoặc CCPA), bạn có thể có quyền truy cập, sửa, xuất hoặc xóa dữ liệu cá nhân, và phản đối một số xử lý. Liên hệ với chúng tôi và chúng tôi sẽ đáp ứng các yêu cầu này cho mọi người, bất kể nơi ở.
Thiếu nhi
Novilot không hướng tới trẻ em dưới 13 tuổi, và chúng tôi không cố ý thu thập dữ liệu của các em.
Thay đổi
Nếu chúng tôi đổi chính sách này, chúng tôi sẽ cập nhật trang này và ngày ở đầu. Nếu một thay đổi ảnh hưởng đáng kể cách bản thảo của bạn được xử lý, chúng tôi sẽ báo bạn trong ứng dụng hoặc qua email trước khi nó có hiệu lực.
Liên hệ
Email support@novilot.com, hoặc dùng nút "Gửi phản hồi" trong ứng dụng. Yêu cầu về quyền riêng tư được một người trả lời.