tome.

Legal

Privacy.

Last updated: 29 May 2026

What we collect

The email you sign in with and the content you create in the studio (manuscripts, chapters, voice profiles, cover designs, publishing destinations). That's it. No tracking pixels, no third-party analytics in the writing experience.

How we use it

Your email is used for sign-in and transactional notifications (welcome, cover ready, publish ready, billing alerts). Your content is rendered back to you and exported when you publish or download.

How we store it

Manuscripts and metadata live in Supabase Postgres with row-level security so other writers can never see your work. Sensitive fields are encrypted and decrypted server-side only.

Where your work is stored

Your manuscripts and covers live in Tome's Supabase, protected by row-level security and encrypted in transit and at rest. Exports are generated on demand and downloaded by you; nothing is locked away.

What we share

Nothing, except: (1) requests we make to the AI and content providers Tome uses (Anthropic, fal.ai, Replicate, LlamaParse, and Copyleaks for the publish-time originality check) to fulfil the actions you ask for; (2) error reports to Sentry with PII redacted; (3) anonymised, aggregated usage metrics (page views, error rates) for service health. We don't sell data, and we don't use your content to train AI.

Sub-processors

Tome relies on Supabase (database + auth + storage), DigitalOcean (hosting), Stripe (payments), Resend (transactional email), Sentry (error monitoring), and the AI and content providers Tome uses (Anthropic, fal.ai, Replicate, LlamaParse, Copyleaks). Each operates under their own DPA.

Cookies

We use httpOnly cookies for authentication (session JWT) and OAuth state. No advertising or tracking cookies.

Your rights

You can export every work as PDF, EPUB, DOCX, or Markdown from inside the studio, and download all your data as JSON from Settings → Security. From there you can also permanently delete your entire account and all associated data — instantly, no waiting. Prefer a hand? Email [email protected].

GDPR + UK GDPR

The legal bases we rely on are: contract (operating the service you use), legitimate interest (security monitoring, fraud prevention), and consent (the publishing OAuth flows you initiate). Data subjects can exercise rights under GDPR / UK GDPR by emailing us.

Changes

Material changes to this policy will be announced by email at least thirty days in advance.

Contact

Privacy questions, deletion requests, complaints — [email protected].