1. Overview
NovelThread is a local-first desktop writing app for long-form fiction. This policy explains how we handle information about you when you use the app and this website.
Core commitment: your work belongs to you. All creative data lives on your own device by default. Unless you sign in and explicitly enable cloud sync, your manuscripts never touch our servers.
NovelThread is operated by NovelThread Team, an independent team based in Singapore, and is offered globally. Our primary servers are in Singapore.
2. Information we collect
Account information (optional): only when you sign in with Google or Apple do we collect the provider account identifier and any email address or display name the provider supplies, for sign-in and account management. Local writing features do not require an account.
Sync data (optional): only if you sign in and actively enable cross-device sync are your works, story-bible entries and app settings transmitted to and stored on the sync server. The sync servers are in Singapore; you can turn sync off at any time.
Subscriptions and payment: paid subscriptions are processed by Stripe only. We never see or store your full card details; we keep only subscription status such as tier and validity.
3. Information we do not collect
The current NovelThread desktop app ships with no behavioural analytics, profiling or ad-tracking components. We do not sell your data, and your creative writing is never used for AI training.
4. AI features and third-party model providers
When you invoke an AI feature — such as continuation, polishing or the AI assistant — the text context needed for that request is sent to a model provider for processing.
With official models, the context needed for a request travels through the NovelThread model service and uses NovelThread AI credits.
BYOK requires an active Plus, Pro or Max subscription, verified with NovelThread before use. When you configure an OpenAI-compatible provider with your own API key, requests go directly from your device to that provider without passing through the NovelThread servers; you pay the provider and usage does not use NovelThread credits. The API key stays in local secure storage, and the provider’s privacy policy governs its processing.
We never log AI request content, including prompts, manuscripts or context, and user data is never used for AI training. If you bring your own API key (BYOK), your chosen provider handles data under its own privacy policy.
When you are not invoking AI features, your manuscript does not leave your device for AI processing, except where you have enabled sync.
5. This website
This website sets no advertising or analytics cookies, and its fonts are self-hosted. Cloudflare provides hosting, content delivery and security protection; to deliver pages and prevent abuse, Cloudflare processes necessary network logs such as IP addresses, request headers and access times. The site currently uses no behavioural profiling or advertising tracking.
6. The waitlist
When you join the waitlist, we collect your email and consent record. Your reason for interest and work area are optional. Your information is used to notify you when the product is available.
Cloudflare Workers processes submissions and Cloudflare D1 stores them. Cloudflare Turnstile helps prevent automated abuse. The registration database does not store request IP addresses or browser identifiers.
To request access to or deletion of your registration, contact support@novelthread.app.
7. Security and retention
Local data is protected by your device and operating system; we recommend full-disk encryption and regular backups.
All user data we store in the cloud is encrypted at rest, and data in transit is encrypted with TLS. Sync servers are located in Singapore.
If a paid subscription ends and is not renewed, cloud data associated with that account is kept for 30 days from the end of the paid period. After that the system automatically deletes cloud copies of your works, media files and sync records. Local data on your device is unaffected.
The account itself and its subscription-status records are kept until you ask us to delete them.
8. Your rights
You can access, export, edit or delete local data on your device at any time. It remains entirely under your control.
You can close your account in the app after re-authentication. Once the backend durably accepts the request, account access ends immediately; the request cannot be cancelled and the account cannot be restored. Novels stored on this device are not deleted with the account, while server data is removed by the backend process under this policy. You may also use the Contact page for access or correction requests.
9. Children
NovelThread is not directed at people under 18. Please do not create an account or use sign-in features if you are under 18. If we learn we have collected a minor’s personal information, we will delete it promptly.
10. Changes and contact
When this policy changes we will publish the new version here and update the date above; material changes will be flagged in the app or prominently on the site.
The controller and operator is NovelThread Team. For privacy-rights requests or other privacy questions, use the Contact page or support@novelthread.app; this is also the public data-protection contact address.