Privacy Policy

1. Who We Are

NovelChat ("NovelChat," "we," "us," or "our") provides web and mobile experiences that let readers converse with AI-powered versions of their favorite fictional characters. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit novelchat.app, our mobile apps, or any other service that links to this policy (collectively, the "Service").

Because we operate globally, we follow key privacy regulations such as the EU/UK GDPR, the US CCPA/CPRA, and other applicable laws. "Personal information" (or "personal data") means any information that identifies, relates to, describes, or can reasonably be linked to an individual.

2. Information We Collect

CategoryExamplesSourcePurpose
Account DataName, display name, email address, password hash, authentication tokens, profile photoYouA–D
Content & ContextChat prompts, messages, annotations, favorites, feedback formsYouA–C
Subscription & Transaction DataPlan type, renewal date, purchase receipts, payment method (tokenized)You / StripeA–C, E
Device & Usage DataIP address, device type, OS, browser, app version, timestamps, crash logs, pages viewed, referring URLsAutomaticB–D
Cookies & TrackingSession cookies, preference cookies, analytics cookies, local storageAutomaticB–D
Third-Party DataSocial-login IDs, avatar image, contact e-mail from OAuth providers; aggregated analytics from PostHog/Google AnalyticsThird partiesB–D

Purposes reference:
A = Provide & secure Service B = Improve & develop C = Personalise experience
D = Legal & compliance E = Payments & accounting

3. Why We Process Your Data (Legal Bases)

Legal Basis (GDPR)Typical Processing Activities
ContractCreating an account, delivering chat interactions, processing payments
Legitimate InterestsDetecting abuse, analytics, product improvement, basic marketing
ConsentOptional email newsletters, non-essential cookies, beta features
Legal ObligationTax reporting, fraud prevention, responding to lawful requests

For California residents, "legitimate interests" is equivalent to "business purpose" under the CCPA/CPRA. We do not sell your personal information.

4. How We Use Information

5. How We Share Information

RecipientWhySafeguards
Cloud & Infrastructure Vendors (e.g., Vercel, Supabase, AWS/S3)Hosting, storage, database, backupsStandard contractual clauses (SCCs), encryption in transit & at rest
Payment Processor (Stripe)Billing, refunds, tax calculationPCI-DSS compliance, tokenised payments
AI Model Providers (OpenAI, Anthropic)Generate chat responsesAPI agreements prohibit reuse for model training without opt-in
Analytics & Crash Reporting (PostHog, Google Analytics, Sentry)Product analytics, error diagnosticsIP masking, GDPR-compliant DPA
Professional AdvisorsAccounting, legal, or audit supportConfidentiality duties
Business TransfersMerger, acquisition, financing, or asset saleNotice & choice before transfer
Law EnforcementRespond to valid court orders or legal obligationsLegal review & minimisation

We never share user-generated content publicly unless you choose to publish or share it.

6. International Data Transfers

We are headquartered in US, but many of our vendors operate in the US and other countries. Whenever we transfer personal data internationally, we rely on:

7. Your Rights & Choices

RegionRights
EU/UK & USAccess • Rectification • Erasure • Restriction • Portability • Objection • Withdraw consent
CaliforniaKnow • Delete • Correct • Opt-out of sharing (sale) • Limit use of sensitive data
Other RegionsSimilar rights may apply; contact us for local specifics

To exercise a right, email privacy@novelchat.app or use the in-app Privacy Center. We respond within 30 days (or as required by law). You may also lodge a complaint with your supervisory authority.

8. Data Retention

We keep personal data only as long as necessary for the purposes described above:

9. Security Measures

We implement industry-standard safeguards:

Despite our efforts, no system is 100% secure, so we encourage you to use unique, strong passwords and enable 2FA on your account.

10. Children's Privacy

NovelChat is not directed to children under 13 (or the age defined by local law). We do not knowingly collect personal information from minors. If you believe a child has provided us data, contact privacy@novelchat.app and we will delete it promptly.

11. Cookies & Similar Technologies

We use:

You can control cookies through your browser settings or our in-app cookie banner. Disabling some cookies may affect Service functionality.

12. Third-Party Links

The Service may link to external sites (e.g., Goodreads, publisher pages). We are not responsible for their privacy practices. Review their policies before providing personal data.

13. Changes to This Policy

We may update this Policy to reflect legal, technical, or business changes. When we do, we will:

14. Contact Us

Data Controller

Grandzero LLC

1021 E Lincolnway Suite #8147

Cheyenne, Wyoming 82001, United States

Email: info@grandzero.dev

If you have questions, concerns, or need this notice in another format, please reach out anytime.