Last updated: August 5, 2026

Overview

Underfiction is designed with privacy as a core principle. We don't sell your information, we don't use advertising trackers, and current clients keep your creative library on your device with portable exports for backup and transfer.

1. Story and library storage

Stories, characters, worlds, and library media — including imported and generated images, video, and narration — are stored locally on your device. You can export one story with its media and connected records or your complete library as a portable .underfiction file.

Underfiction is retiring its former cloud-sync and library-image upload systems in stages so already released app versions continue to work during the transition. Older versions with those features enabled may have uploaded story, character, world, or settings records and character or world images to your account. Current clients do not use those image uploads. Synced stories are encrypted at rest using a per-user key; other legacy database records are stored as structured account data. Legacy database records are removed when you delete your account or ask us to remove them.

If you deliberately publish a shared excerpt, we store a plaintext copy on our servers. That copy contains the title, selected turns, cast and world names, and any continuation data you enable in the publish preview, such as world text, character descriptions, personality notes, backstory, story directions, and model identifier. Anyone with the unlisted link can retrieve that data. You can revoke the link from account settings; deleting your account also deletes your shared excerpts.

2. What we collect

Account information

When you create an account, we collect your email address, name (if provided via OAuth), and password hash (for email/password accounts only — we never store plaintext passwords).

Usage data

When you generate content, we record the AI model used, token counts (input and output), and the associated cost. This data is linked to your account for billing. We do not store prompt or response text in generation usage records.

For shared excerpts, we store the publishing account, creation and revocation dates, explicit-content flag, report count, and cryptographic hashes used to count distinct reporters. When a share visit leads to a new account, we may store the originating share slug as that account's signup source. For other accounts we may store a coarse acquisition channel instead, such as search:google or direct.

Payment information

Payment processing is handled by Stripe on the web and Apple for iOS in-app purchases. We store provider identifiers needed to reconcile purchases and credit balances. We never receive or store your full card number, CVV, or bank details.

3. How we use your information

To provide and operate the service, process credit purchases, track usage for billing, authenticate your identity, send transactional emails (password resets, account verification), maintain legacy library records during the sync-retirement window, and detect and prevent abuse.

We use shared-excerpt data to serve links you deliberately publish, let recipients continue the story, let you revoke published links, handle abuse reports, and measure whether shared links lead to account creation.

We do not use your data for advertising, profiling, or marketing. We do not sell your personal information to third parties.

4. Third-party services

Venice AI — AI inference Your story context is sent to Venice for generation. Venice separates your identity from your content at the infrastructure level — the model provider does not receive your Underfiction account identity.

Stripe and Apple — Payment processing Stripe handles web payment transactions. Apple handles iOS in-app purchases.

Google & Apple — Authentication If you sign in with Google or Apple, we receive basic profile information (name, email, profile image) as authorized by you during the OAuth flow.

5. Cookies and tracking

We use a session cookie for authentication. This cookie is strictly necessary for the service to function and does not track your behavior across other sites.

We also use a first-party security cookie to limit free trials, prevent repeated welcome-credit abuse, and protect the service from automated signup farming. The cookie contains a random identifier, is not readable by browser JavaScript, and is stored server-side only as a cryptographic hash. It is not used for advertising or cross-site tracking.

When you visit a shared excerpt, we set a first-party share_src cookie containing that excerpt's unlisted slug for up to 30 days. If you create an account in that period, we use it once to record the share as the signup source and then delete it. It is not used for cross-site tracking or advertising.

On your first visit we also set a first-party landing_src cookie holding a coarse label for how you arrived — search:google, social:reddit, direct, or the domain of the site that linked you — for up to 30 days. It records no page address, no search terms, and no identifier. If you create an account in that period, we use it once to record the signup channel and then delete it. It is not used for cross-site tracking or advertising.

We use PostHog, hosted in the European Union, to collect anonymous usage statistics — page views, referrer sources, and device types. Analytics run in cookieless mode: nothing is stored on your device, IP addresses are discarded after processing, and individual visitors cannot be identified. During a short transition period we also run Umami, a cookie-free analytics tool with the same properties.

We do not use advertising trackers or third-party tracking scripts.

6. Data retention

Account data is retained for as long as your account is active. Usage records (token counts, costs) are retained for billing and accounting. Locally stored content persists until you delete it or clear local app/browser data. Legacy cloud-synced database records are removed when you delete your account or request their removal. Legacy character and world image uploads are retained temporarily while the old upload system is retired; you can request their removal at any time, and remaining legacy image uploads will be deleted when the transition ends.

Live and revoked shared excerpts remain associated with your account so you can manage them and we can maintain a takedown audit trail. They are deleted when your account is deleted. Distinct-reporter hashes are deleted with the excerpt.

7. Data security

We implement reasonable security measures including encrypted connections (HTTPS), hashed passwords (bcrypt), encryption at rest for legacy synced stories, and secure session management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Depending on your jurisdiction, you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion of your account and associated data, object to or restrict certain processing, or request a copy of your data in a portable format. To exercise any of these rights, contact us at [email protected] or through our Discord.

9. Age restriction

The service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information, please contact us at [email protected] and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the service after changes are posted constitutes acceptance of the revised policy.

11. Contact

If you have questions about this privacy policy, reach us at [email protected] or through our Discord.