Zuletzt aktualisiert: August 8, 2026

Overview

Underfiction is designed with privacy as a core principle. We don't sell your information, we don't use advertising trackers, and we don't read your stories. Your library syncs across your devices so you don't lose it, and you can turn that off or export it as a portable file at any time.

1. Story and library storage

Stories, characters, worlds, and their images and video are stored on your device and, while sync is on, on our servers so they reach your other devices. Narration is not synced: it is a regenerable cache and stays on the device that produced it.

Stories are encrypted at rest with AES-256-GCM using a per-user key. That key is wrapped by a server-held key, which means we hold the means to decrypt your stories and do not do so outside of operating the service — we do not read them, and we do not use them to train models. We do not claim to be unable to read them. Characters and worlds are stored as structured account data without this encryption.

Sync is on by default for signed-in accounts. You can turn it off with one switch in Settings. When sync is off, your stories, characters, and worlds exist only on that one device — deleting the app, or clearing your browser's site data, deletes them, and we cannot recover them for you. You can export one story with its media and connected records, or your complete library, as a portable .underfiction file at any time, whether sync is on or off.

Synced records are removed when you delete your account or ask us to remove them.

If you deliberately publish a shared excerpt, we store a plaintext copy on our servers. That copy contains the title, selected turns, cast and world names, and any continuation data you enable in the publish preview, such as world text, character descriptions, personality notes, backstory, story directions, and model identifier. Anyone with the unlisted link can retrieve that data. You can revoke the link from account settings; deleting your account also deletes your shared excerpts.

If you publish a world, character, or story, we store a plaintext copy of it — its text, images, tags, and your pen name — and serve it publicly. When someone imports it, they get a full independent copy on their own device. Revoking the item or deleting your account removes it from our servers; copies already imported stay where they are and cannot be recalled.

2. What we collect

Account information

When you create an account, we collect your email address, name (if provided via OAuth), and password hash (for email/password accounts only — we never store plaintext passwords).

If you publish, you choose a pen name. Your pen name is public: it is the byline on every item you publish, it is visible to anyone browsing, and it stays on items you have already published if you later change it. We never derive it from your email address, and your email address is never shown alongside your items.

Usage data

When you generate content, we record the AI model used, token counts (input and output), and the associated cost. This data is linked to your account for billing. We do not store prompt or response text in generation usage records.

For published items and shared excerpts, we store the publishing account, the pen name shown on the item, creation and revocation dates, the content rating and the classifier's rating verdict, tags, report count, import count, and cryptographic hashes used to count distinct reporters. Published item text is sent to xAI once at publish time to set that rating; the result is stored with the item. When a share visit leads to a new account, we may store the originating share slug as that account's signup source. For other accounts we may store a coarse acquisition channel instead, such as search:google or direct.

Payment information

Payment processing is handled by Stripe on the web and Apple for iOS in-app purchases. We store provider identifiers needed to reconcile purchases and credit balances. We never receive or store your full card number, CVV, or bank details.

3. How we use your information

To provide and operate the service, process credit purchases, track usage for billing, authenticate your identity, send transactional emails (password resets, account verification), store and synchronize your library when sync is enabled, and detect and prevent abuse.

We use published-item and shared-excerpt data to serve what you deliberately publish, let readers continue the story or import the item, let you revoke what you published, handle abuse reports, and measure whether shared links lead to account creation.

We do not use your data for advertising, profiling, or marketing. We do not sell your personal information to third parties.

4. Third-party services

Venice AI — AI inference Your story context is sent to Venice for generation. Venice separates your identity from your content at the infrastructure level — the model provider does not receive your Underfiction account identity.

xAI — Narration and publish classification Where you request spoken narration, the text to be spoken is sent to xAI. When you publish an item, its text is sent to xAI once to set the item's content rating. Neither call carries your account identity.

Stripe and Apple — Payment processing Stripe handles web payment transactions. Apple handles iOS in-app purchases.

Google & Apple — Authentication If you sign in with Google or Apple, we receive basic profile information (name, email, profile image) as authorized by you during the OAuth flow.

5. Cookies and tracking

We use a session cookie for authentication. This cookie is strictly necessary for the service to function and does not track your behavior across other sites.

We also use a first-party security cookie to limit free trials, prevent repeated welcome-credit abuse, and protect the service from automated signup farming. The cookie contains a random identifier, is not readable by browser JavaScript, and is stored server-side only as a cryptographic hash. It is not used for advertising or cross-site tracking.

When you visit a shared excerpt, we set a first-party share_src cookie containing that excerpt's unlisted slug for up to 30 days. If you create an account in that period, we use it once to record the share as the signup source and then delete it. It is not used for cross-site tracking or advertising.

On your first visit we also set a first-party landing_src cookie holding a coarse label for how you arrived — search:google, social:reddit, direct, or the domain of the site that linked you — for up to 30 days. It records no page address, no search terms, and no identifier. If you create an account in that period, we use it once to record the signup channel and then delete it. It is not used for cross-site tracking or advertising.

We use PostHog, hosted in the European Union, to collect anonymous usage statistics — page views, referrer sources, and device types. Analytics run in cookieless mode: nothing is stored on your device, IP addresses are discarded after processing, and individual visitors cannot be identified. During a short transition period we also run Umami, a cookie-free analytics tool with the same properties.

We do not use advertising trackers or third-party tracking scripts.

6. Data retention

Account data is retained for as long as your account is active. Usage records (token counts, costs) are retained for billing and accounting. Synced stories, characters, worlds, and their images and video are retained while your account is active and are deleted, along with your uploaded images and video, when you delete your account or ask us to remove them. Deleted records are held as tombstones for 30 days so the deletion reaches your other devices, then removed. Content on a device persists until you delete it or clear local app/browser data.

Live and revoked published items and shared excerpts remain associated with your account so you can manage them and we can maintain a takedown audit trail. They are deleted when your account is deleted. Distinct-reporter hashes are deleted with the item.

7. Data security

We implement reasonable security measures including encrypted connections (HTTPS), hashed passwords (bcrypt), encryption at rest for synced stories, and secure session management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Depending on your jurisdiction, you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion of your account and associated data, object to or restrict certain processing, or request a copy of your data in a portable format. To exercise any of these rights, contact us at [email protected] or through our Discord.

9. Age restriction

The service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information, please contact us at [email protected] and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the service after changes are posted constitutes acceptance of the revised policy.

11. Contact

If you have questions about this privacy policy, reach us at [email protected] or through our Discord.