隐私政策
文档版本:
另请参阅我们的 服务条款 以及 我们如何处理 AI 和你的写作.
Novilot 是面向小说作者的写作应用。手稿是你可以放入软件的最私密内容,本页会准确说明手稿和其他数据会发生什么。简而言之:写作属于你,我们只用它运行你请求的功能,绝不出售数据,也绝不使用你的文字训练 AI 模型。
我们收集什么
- 账户数据。 您的电子邮件地址和密码的哈希版本(使用 bcrypt 进行哈希处理;我们看不到密码本身)。
- 你的写作。 项目、章节、故事圣经条目、大纲、笔记、章节版本,以及你在应用中创建的其他内容。这些内容会被保存,以便应用再次展示给你。除非你明确分享(例如创建 beta 读者链接),否则它们不会公开。
- 人工智能工作数据。 To power features like autocomplete, continuity checking, and voice matching, we store material derived from your manuscript: summaries, style profiles, continuity observations, and text embeddings. These are private working data, subject to the deletion and retention details below.
- 使用数据。 你使用的功能和基本产品事件(例如运行了一次分析),以及用于公平计费的积分使用情况。我们还会统计你为个人目标和连续写作记录写下的字数。
- 计费数据。 Payments are handled by Dodo Payments. We never see or store your card number; we store your Dodo Payments customer and checkout references, subscription status, and payment and refund records needed to maintain your credit balance.
- 你发送给我们的消息。 你在应用中提交的反馈和发送给我们的邮件。
AI 功能如何使用你的手稿
Anthropic's Claude API processes manuscript passages for AI features. OpenAI's embeddings API processes paragraphs and search queries to support meaning-based manuscript search. Preparing this search index can run in the background after you save or import chapters. Requests use encrypted connections. A full-manuscript analysis may process the entire manuscript within the coverage shown for that scan.
- We do not use your writing to train AI models or opt your manuscript into provider training programs. Anthropic and OpenAI do not train on commercial API content by default.
- We send content needed for the feature and its supporting processing, such as search indexing. Provider retention is separate from model training.
- AI 结果(建议、分析)存储在您的帐户中,因此您无需付费重新生成它们。
AI provider retention
We do not promise Zero Data Retention. Anthropic's standard API policy deletes inputs and outputs within 30 days, with exceptions for legal obligations and policy enforcement. Flagged content may remain for up to two years and safety classifications for up to seven years. Feedback deliberately submitted to Anthropic can be retained for five years and may be used for training; we do not submit your manuscript as provider feedback.
OpenAI's standard API abuse-monitoring retention is up to 30 days, with longer retention possible for legal or safety reasons. The embeddings endpoint does not retain application state. Deleting a project in Novilot does not itself erase provider logs or override their retention obligations.
See Anthropic's retention policy 以及 OpenAI's API data controls.
Human access
Private means your manuscript is not public or available to other writers unless you share it. It does not mean end-to-end encryption: our servers and processors need readable text to provide the service. People with privileged infrastructure or database access can technically access it. Operational access must be limited to what is necessary for support, debugging, security, abuse investigations, or legal obligations, not browsing your work for personal or commercial use.
Service providers can also permit authorized human access under their agreements, including safety review. We cannot promise that no person will ever review content. Text you choose to include in a support message is available to the people handling it.
分析
We use Google Analytics and PostHog to understand how the product is used so we can improve it. PostHog session replay is configured to mask text and inputs. Sentry helps diagnose errors; request-body collection and default personal-data collection are disabled, and replay text and inputs are masked. Diagnostic metadata may still be processed. We do not intentionally send manuscript text to analytics or error reports. We do not run ads.
Cookie
- nc_session:让您保持登录状态的重要 cookie。没有它,应用程序就无法运行。
- 来自 Google Analytics 和 PostHog 的分析 cookie,仅用于上述目的。
你的数据存在哪里,以及谁会处理它
你的数据存储在托管的 Postgres 数据库中,并通过 Vercel 提供服务。我们只会为运行 Novilot 的必要目的与服务提供商共享数据:
- Vercel(托管)
- Prisma Postgres(数据库)
- 人择(AI 功能)
- OpenAI (manuscript and query embeddings for search)
- Dodo Payments(支付)
- Resend(事务邮件)
- Google Analytics 和 PostHog(分析)
- Sentry (error monitoring)
- Dropbox and GitHub (only when you connect an external backup destination)
We do not sell your data. Manuscript processing is limited to providing the service, your chosen sharing and backup features, and necessary legal or security obligations.
保留与删除
- Project deletion removes its manuscript, chapter history, Story Bible, summaries, continuity records, embeddings, and saved analyses from the active database. Manuscript-derived voice profiles are invalidated so they cannot keep deleted excerpts.
- Chapter deletion removes that chapter and its version history, and invalidates affected derived analyses and voice profiles. Project-level Story Bible entries, outlines, and notes you have retained remain until you edit them or delete the project.
- To delete your entire account, contact us (see below). Account deletion removes your writing, AI working data, usage history, profile, and linked in-app feedback from the active database. Records required by law, such as payment records held by the payment provider, can have separate retention obligations.
- Our Prisma Postgres plan keeps automated database snapshots for seven days. Deleted data can remain in an earlier snapshot until it expires. This backup window is separate from the AI-provider retention and external copies described on this page.
- Exports, copies shared with others, and backups in your connected Dropbox or GitHub account are not erased by deleting a Novilot project or account. You control those copies separately.
- The browser can hold analysis caches and unsynced edits. Deleting through the app clears the affected local copies on that device. Copies on offline or other devices may remain until cleared there.
- 你可以随时从应用中导出手稿(DOCX、EPUB、HTML、Markdown 或 PDF)。
你的权利
根据你的居住地(例如 GDPR 或 CCPA 的适用范围),你可能有权访问、更正、导出或删除个人数据,也有权反对某些处理。请联系我们;无论你身在何处,我们都会尊重这些请求。
儿童
Novilot 不面向 13 岁以下儿童,我们不会明知故犯地收集他们的数据。
变更
如果我们更改本政策,会更新本页和顶部日期。如果更改实质性影响手稿的处理方式,我们会在生效前通过应用或邮件通知你。
联系我们
邮箱 support@novilot.com,或使用应用程序内的“发送反馈”按钮。隐私请求由人工回答。