Privacy Notice
Effective August 17, 2026 · Version 2026-08-17.copyright-retention
What NovelVerse collects, who else processes it, and what you can do about it. This notice covers hosted AI processing, image safety scanning, analytics, and error monitoring.
On this page
- Who is responsible for your information
- What NovelVerse collects
- Hosted AI processing — what leaves NovelVerse
- Image scanning
- Registration protection, error monitoring, and analytics
- Copyright submissions
- Who else processes your information
- Where your information goes
- How long information is kept
- Your rights
- Account deletion and backups
- Records kept after deletion
- Changes to this notice
Who is responsible for your information
NovelVerse is operated by Dave Zachary Macarayo. Dave Zachary Macarayo, based in the Philippines, is the Personal Information Controller for the information described here. NovelVerse is not a registered company.
This notice is written against Philippine law — principally the Data Privacy Act of 2012 (Republic Act 10173) and, for child protection obligations, Republic Act 11930.
To ask about your information, exercise a right described below, or raise a concern, email privacy@novelverse.ink. You can also use the account controls in Settings or the appeal link included with any restriction notice.
What NovelVerse collects
Directly from you:
- Account information: email address, username, and password hash. A display name is optional.
- An adult attestation. You enter a date of birth once; it is evaluated and discarded, and only a version identifier and timestamp are kept — never the date.
- What you write: manuscripts, drafts, chapters, comments, reviews, posts, messages, lists, and profile details.
- What you upload: cover images, avatars, and any other images, plus voice recordings if you choose to register a voice profile.
- Reading and usage activity: what you read and how far, bookmarks, follows, and interactions. Reading history can be paused in Settings.
- Technical information collected automatically: IP address, browser and device characteristics, and request timing.
Hosted AI processing — what leaves NovelVerse
This is the most important section of this notice. NovelVerse's AI features do not run on NovelVerse's own hardware. They run on third-party model providers, which means your text and audio leave our systems.
When you use Nova search or chat, writing assistance in the editor, proofreading, or generated audio, the content needed for that action — which may include prompt text, a selection, a scene, a chapter, or an entire manuscript, depending on the scope you choose — is transmitted to one or more model providers. Before an action you confirm individually — such as generating audio or registering a voice — NovelVerse shows you its exact Credit cost and the scope being sent. Where the AI action is itself what you came to do, such as Nova chat and Nova search, NovelVerse shows your remaining allowance on the surface you are working in, and every charge is itemised in your Credits Log.
NovelVerse also performs background AI processing that you do not directly request: generating embeddings so your work is searchable, summarising chapters for continuity, and extracting world details for the editor's reference panels. This processing uses the same third-party providers.
Requests are routed dynamically. NovelVerse chooses among providers at request time based on capability, available quota, and load, so the same action performed twice may reach different providers. This notice lists the full set of providers your content may reach rather than pretending a single one is used; the list is below, under who else processes your information.
Provider handling of submitted content varies, and you should assume the least favourable case unless stated otherwise. Some providers commit not to train on or retain inference content. Others — particularly the free and trial tiers this demonstration relies on — may retain submitted content, use it to improve their services or models, or subject it to human review under their own terms. Where a provider's exact terms are unclear, NovelVerse treats it conservatively and assumes content may be retained or used for improvement.
Because this is a free, non-commercial demonstration, provider data-use posture is disclosed in this notice rather than used to exclude providers. If that trade-off is not acceptable for a particular work, do not use AI features on it, and turn off the Hosted AI Preference for that novel.
Every novel has a Hosted AI Preference, controlled by its owner and enabled by default. Turning it off stops new background AI processing of that novel, cancels background work that has not yet been sent to a provider, and retires the system-generated embeddings and summaries derived from it. Reading, writing, publishing, and keyword search continue to work normally. Explicit AI actions you confirm yourself still run, because you are asking for them at the moment you ask.
Work already sent to a provider cannot be recalled. Deleting content from NovelVerse removes it from NovelVerse; it does not reach into a provider's systems.
NovelVerse keeps a short-lived operational log of AI calls — timing, model, token counts, and cost estimates — to debug and account for usage. It is purged automatically after 14 days.
Image scanning
Every image uploaded to NovelVerse is scanned automatically before it is published. Uploads are held in quarantine, decoded and re-encoded, and checked against known-material hash databases and automated classifiers for sexual content, minors, and graphic violence. Only an image that passes is published, and only a re-encoded derivative is ever served.
This scanning uses third-party providers, which means an uploaded image or a derived hash of it may be processed outside the Philippines under those providers' data-processing terms. No such scanning is applied to text you write — posts, comments, messages, and manuscripts are reviewed by a person only when someone reports them.
An image detected as child sexual abuse material is sealed rather than reviewed: it is never rendered to staff, never published, and is handled, reported, and preserved under the timelines Republic Act 11930 requires. Appeals can ask for reconsideration without the image being shown to anyone.
Registration protection, error monitoring, and analytics
Sign-up is protected by Cloudflare Turnstile. Completing the challenge sends your IP address and browser characteristics to Cloudflare so it can judge whether the request is automated. NovelVerse receives only the verdict.
Application errors are captured by Sentry to diagnose faults. An error report can include the URL, browser details, and a stack trace, and may incidentally contain identifiers present in the failing request.
NovelVerse records product analytics — which features are used, and how reading progresses — to decide what to build. This is used in aggregate.
No analytics is collected until you allow it. It stays off for signed-out visitors and account holders alike until you record a choice, and no choice at all is treated exactly as a refusal. You can change your answer at any time, from this page or from Settings, and account holders keep a separate durable analytics off switch that overrides everything else. A refusal is enforced where events are emitted, not merely at reporting time, and no visitor identifier is created for anyone who has not agreed to one. Withdrawing removes the one you were given.
That choice covers product analytics and nothing else. Turnstile and Sentry, described just above, are not analytics and are not part of it: sign-up has to be protected against automated abuse, and a fault has to be diagnosable at all. Neither does the choice cover the account details, the work you write and upload, or the technical information listed under what NovelVerse collects — that is what running the service requires, and it is described there rather than folded into a question it is not part of.
Your answer is recorded against the specific purpose it was asked for. If that purpose changes, you are asked again rather than the old answer being carried over to something you did not agree to.
Copyright submissions
Sending a Copyright Notice, or answering one with a Counter-Notice, means giving NovelVerse identifying and contact information along with a description of the material at issue. Neither requires a NovelVerse account.
The process cannot continue without telling each side what the other claimed, so NovelVerse forwards the relevant substance of a submission to the other party. Contact between the parties is mediated by default: NovelVerse passes messages rather than handing over your details. A home address or telephone number is disclosed only where it is legally necessary.
Submissions are snapshotted when they arrive, so what was claimed cannot be quietly edited afterwards. The Copyright Notice and Takedown policy sets out the full process; how long any of it is kept is below.
Who else processes your information
NovelVerse runs on infrastructure and services operated by other companies. Each processes information on our behalf for the purpose named:
- Vercel — hosting for the web application.
- Oracle Cloud Infrastructure (Singapore) — hosting for the API and real-time services.
- Neon — the PostgreSQL database holding accounts and content.
- Cloudflare — DNS, CDN, R2 object storage for images and audio, Turnstile, and Workers AI inference.
- Neo4j Aura — the graph store used for relationship and recommendation data.
- Resend — delivery of transactional email such as verification and password reset.
- Sentry — application error monitoring.
- Amazon Web Services — Rekognition image classification, and key management for sealed safety evidence.
- Sightengine — image classification for the safety pipeline.
- Project Arachnid (Shield) — known-material hash matching for child protection.
- Model providers reachable by AI routing: Groq, Cerebras, Cloudflare Workers AI, Google, Mistral, OpenRouter, NVIDIA, OpenCode, Vercel AI Gateway, Anthropic, OpenAI, Voyage AI, Cohere, Jina, and ZeroEntropy.
- Voice and audio providers: ElevenLabs, Fish Audio, Cartesia, and Speechmatics.
Where your information goes
The providers above operate outside the Philippines, so using NovelVerse necessarily involves transferring your information abroad — principally to the United States, the European Union, and Singapore. Transfers are made under each provider's own data-processing terms.
How long information is kept
Account information and content are kept while the account exists. AI operational logs are purged after 14 days. Safety evidence and moderation records are kept for the period the relevant obligation requires. Analytics are retained in aggregate.
Copyright cases follow a fixed schedule. A submission that is rejected, abandoned, incomplete, or never qualified keeps its claimant details and evidence for 90 days after the case closes. The payload is then purged, leaving a content-free record that the case existed and how it ended.
A qualified notice, a counter-notice, a hold, and the communications around them keep the minimum necessary case evidence for four years after final resolution, and are then securely purged. Encrypted operational backups may hold a copy for at most 30 further days, as described under account deletion and backups.
Only the claimed passages and the context needed to understand the decision are kept — not whole works. An active court or IPOPHL matter is retained while it is live and reviewed every 90 days. Retention beyond these periods requires a scoped legal hold recording who authorised it, why, who owns it, when it is reviewed, and when it expires.
A finding of copyright submission abuse leaves a non-public keyed marker holding no evidence and no submission content. It expires twelve months after the most recent finding.
Your rights
Under the Data Privacy Act you have the right to be informed, to access your information, to correct it, to object to processing, to erasure or blocking, to data portability, to damages, and to complain to the National Privacy Commission.
In practice: Settings holds a full account export and the deletion request, profile and content edits are available throughout the product, analytics and reading history each have their own opt-out, and every restriction notice carries an appeal link. Rights that no in-product control covers can be exercised through the contact path in the first section.
Account deletion and backups
Requesting account deletion starts a 14-day cancellation grace period. Signing in during that period cancels the request. When the grace period ends, NovelVerse purges the account and removes account-linked objects from ordinary product use.
Encrypted operational backup copies may persist for at most 30 additional days after purge. These recovery copies are inaccessible to ordinary product flows and are used only for restricted operational recovery. They age out automatically under the backup retention policy.
Records kept after deletion
Deleting an ordinary account leaves no identity record behind. If an account is deleted while a suspension is in force, NovelVerse keeps a one-way keyed digest of the verified email address and of any linked sign-in identities. It holds no readable address, no username, and nothing about what was written or read.
That digest has exactly one use: refusing a new account created from the same identity while the restriction lasts. It expires when the suspension would have expired, and in no case later than twelve months. It is never used for search, recommendations, ranking, or analytics, and a refusal can be challenged through the appeal link issued with the original suspension notice.
Changes to this notice
This notice may be revised — for example when a provider is added or removed, or when legal review refines it. Each published version carries a version identifier, and NovelVerse records which version you acknowledged and when. A material revision asks you to acknowledge the new version before you continue using features that require it.