Legal
Privacy.
Last updated: 29 May 2026
What we collect
The email you sign in with and the content you create in the studio (manuscripts, chapters, voice profiles, cover designs, publishing destinations). That's it. No tracking pixels, no third-party analytics in the writing experience.
How we use it
Your email is used for sign-in and transactional notifications (welcome, cover ready, publish ready, billing alerts). Your content is rendered back to you and exported when you publish or download.
How we store it
Manuscripts and metadata live in Supabase Postgres with row-level security so other writers can never see your work. Sensitive fields are encrypted and decrypted server-side only.
Where your work is stored
Your manuscripts and covers live in Tome's Supabase, protected by row-level security and encrypted in transit and at rest. Exports are generated on demand and downloaded by you; nothing is locked away.
What we share
Nothing, except: (1) requests we make to the AI and content providers Tome uses (Anthropic, fal.ai, Replicate, LlamaParse, and Copyleaks for the publish-time originality check) to fulfil the actions you ask for; (2) error reports to Sentry with PII redacted; (3) anonymised, aggregated usage metrics (page views, error rates) for service health. We don't sell data, and we don't use your content to train AI.
Sub-processors
Tome relies on Supabase (database + auth + storage), DigitalOcean (hosting), Stripe (payments), Resend (transactional email), Sentry (error monitoring), and the AI and content providers Tome uses (Anthropic, fal.ai, Replicate, LlamaParse, Copyleaks). Each operates under their own DPA.
Cookies
We use httpOnly cookies for authentication (session JWT) and OAuth state. No advertising or tracking cookies.
Your rights
You can export every work as PDF, EPUB, DOCX, or Markdown from inside the studio, and download all your data as JSON from Settings → Security. From there you can also permanently delete your entire account and all associated data — instantly, no waiting. Prefer a hand? Email [email protected].
GDPR + UK GDPR
The legal bases we rely on are: contract (operating the service you use), legitimate interest (security monitoring, fraud prevention), and consent (the publishing OAuth flows you initiate). Data subjects can exercise rights under GDPR / UK GDPR by emailing us.
Changes
Material changes to this policy will be announced by email at least thirty days in advance.
Contact
Privacy questions, deletion requests, complaints — [email protected].