Privacy Policy
Effective 2026-07-24 · under review by counsel. This is a draft; the final wording will be settled by qualified counsel.
Loomnovel is an AI-assisted tool for writing long-form fiction, currently in invite-only / trial beta. We take the manuscripts and personal data you entrust to us seriously. This policy explains what data we process, why, on what legal basis, and what rights you have.
1. Data controller
The data controller for this service is:
Loomnovel, a sole proprietorship operated by its founder Karl, Munich, Germany.
Contact: [email protected]
The controller's full name and serviceable postal address will be published when regular commercial operations begin; until then they are available on request at [email protected].
2. What data we process, why, and on what legal basis
- Account data (email, login credentials) — handled through our authentication provider Clerk, to create and protect your account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Creative content (manuscripts, chapters, worldbook / story settings, your conversations with the AI editorial team, writing preferences) — the core function of the service, used to draft, edit and manage your work. Legal basis: Art. 6(1)(b).
- Style reference texts — reference texts you upload are used only to extract your writing style and are deleted within 24 hours of upload; we keep only a SHA-256 hash for audit purposes, never the original text. Legal basis: Art. 6(1)(b).
- Usage and cost metadata (which model was called, token counts, cost, latency) — for operating the service and accounting for costs. Legal basis: Art. 6(1)(f) (legitimate interests).
- Error and log data — collected via Sentry (EU data centre) to keep the service stable. Legal basis: Art. 6(1)(f).
- LLM observability metadata — collected via Langfuse Cloud (EU); by default only metadata is sent, never your manuscript text, for quality monitoring. Legal basis: Art. 6(1)(f).
3. AI processing and third-party processors
To carry out the AI features you request, we send the necessary content fragments to the third-party processors below. The table sets out each processor's purpose, what it receives, and its region:
| Processor | Purpose | What it receives | Region |
|---|---|---|---|
| Google Cloud Vertex AI (Gemini family) | Primary writing / editing models | Creative content fragments to be processed | Google Cloud infrastructure |
| DeepSeek | Orchestration and fast-tier models | Conversation and creative content fragments | China (Hangzhou) |
| Zhipu AI / Z.ai international endpoint | File-import parsing and image recognition | Uploaded file contents | China |
| Tavily | Web search | Search query terms only | United States |
| Clerk | Account authentication | Email and login data | United States |
| Sentry | Error monitoring | Error and log data | EU |
| Langfuse Cloud | LLM call metadata | Call metadata (no manuscript text by default) | EU |
| Railway | Application and database hosting | All hosted service data | EU West (Amsterdam) |
For Google Cloud Vertex AI, under the Google Cloud terms, input submitted through the API is not used to train its foundation models.
4. Transfers to third countries
Of the processors above, DeepSeek and Zhipu are located in China, and Tavily and Clerk in the United States. China currently has no EU adequacy decision.
For transfers to the processors in China, the legal basis is that the transfer is necessary to perform the contractual service you have actively requested (Art. 49(1)(b) GDPR). Standard Contractual Clauses (SCCs) and a transfer impact assessment are being put in place and are under review by counsel. The content sent to these processors is limited to the fragments necessary to complete the individual generation; your account identity data is not sent. When you use the AI generation features, you are aware of this cross-border transfer.
For transfers to the processors in the United States, Clerk participates in the EU-US Data Privacy Framework.
5. What we do not do
- We do not sell your content.
- We do not use your content to train our own models.
- We run no advertising, no third-party tracking, and no profiling.
6. Cookies and local storage
We use only strictly necessary cookies and local storage: Clerk's session cookie, your theme preference, and interface caching in your browser's localStorage. We use no marketing or analytics cookies, and therefore show no cookie consent banner.
7. Storage and retention
- Creative content is kept until you delete it or close your account.
- Deleted projects go to a recycle bin for 30 days and are then permanently removed.
- Style reference texts are deleted within 24 hours of upload.
- Backups are encrypted and retained for a limited period before rotation.
- The database is hosted in EU West (Amsterdam).
8. Your rights
Under the GDPR you have the following rights:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20) — the product includes a whole-book export
- Right to object (Art. 21)
You also have the right to lodge a complaint with a supervisory authority: you may complain to the data protection authority of the EU member state where you habitually reside.
To exercise any of these rights, contact [email protected].
9. Minors
This service is intended for users aged 18 and over. We have zero tolerance for unlawful content involving minors.
10. Changes to this policy
We will notify you within the app of any material changes. This page always reflects the current version.
11. Contact
If you have any questions about this Privacy Policy, contact: [email protected]