1. Information we collect
We collect the following categories of data: Account and identity. Name, email address, and profile or account details you provide when you sign up or manage your account (including through our authentication partner). Your content. Text, documents, project structure, Atlas entries, images you upload, and other materials you create or import in the Service—including content processed for real-time collaboration and backups as part of normal operation. Technical and usage data. Such as device type, operating system, browser type and version, approximate location derived from IP (for example country or region), timestamps, diagnostics, and in-app events. We use this to run the Service securely, fix bugs, understand feature usage, and plan capacity. Billing-related data. When you subscribe to a paid plan, our payment and subscription partners process billing details (for example payment method metadata) according to their own policies. We do not store full payment card numbers on our servers. Support and communications. Messages you send us (for example feedback or support email) and related metadata.2. How we use your information
We use personal data to:- Provide, operate, and improve the Service (including sync, collaboration, search, and AI features you choose to use)
- Authenticate users, secure accounts, and prevent abuse
- Analyze usage in aggregate or pseudonymous form to improve product quality and performance
- Send service-related messages (for example security notices or transactional email)
- Comply with legal obligations and enforce our Terms of Service
- Respond to your requests and support questions
3. Legal bases (GDPR)
Where GDPR applies, we rely on:- Contract — processing necessary to provide the Service you requested
- Legitimate interests — for example security, product improvement, and analytics that are not overridden by your rights (we aim to use pseudonymous or aggregated data where possible)
- Consent — where we ask for it (for example certain optional communications or non-essential cookies, if applicable)
- Legal obligation — where the law requires us to retain or disclose information
4. Third-party services (subprocessors)
We share data with service providers that help us run Mana. They process data only on our instructions and for the purposes below. Their own privacy notices apply in addition to this policy.
Underlying AI model providers that OpenRouter may call receive only the inputs required to fulfill your request (for example the text you send to grammar check or character chat). Their processing is governed by their terms and privacy policies.
We may add or replace subprocessors as the Service evolves. For material changes, we will update this policy or provide notice as required by law.
5. AI and your writing
We do not use your novels, documents, or other creative content to train our own or third-party foundation models. AI features send text to external providers only when you actively use those features, to return a result to you (for example suggestions or chat replies). Providers may apply transient processing, logging, or safety policies under their own contracts and laws. We choose integrations and settings to minimize unnecessary retention, but you should review provider documentation if you need vendor-specific detail.6. Cookies and similar technologies
Our website and app may use cookies, local storage, or similar technologies for authentication, security, preferences, and analytics (including PostHog). You can control some of these through your browser settings; blocking required cookies may limit certain features.7. International transfers
We and our providers may process data in the European Union, the United States, and other countries where they operate. Where GDPR applies and data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms, unless another legal basis applies.8. Data retention
- Active accounts: We keep your information for as long as your account is active and as needed to provide the Service.
- Deleted accounts: After you request deletion (or we delete your account), we delete or anonymize personal data within a reasonable period, subject to legal retention needs and backup cycles (backups may retain copies for a limited time before rotation).
- Analytics: Pseudonymous analytics may be retained in aggregated or shortened form for longer periods.
9. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit and access controls. No online service is completely secure; we cannot guarantee that unauthorized access, loss, or alteration will never occur. If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms under GDPR, we will notify you and the relevant supervisory authority as required by law.10. Your rights
Depending on where you live, you may have the right to:- Access copies of your personal data
- Rectify inaccurate data
- Erase data in certain circumstances
- Restrict or object to certain processing
- Data portability where applicable
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority (in the EEA, you can contact your local authority)