Privacy Policy

Last updated: 2026-07-20. This policy explains what thegeul collects, how it is used, and the choices you have. Short version: your writing lives on your device first, syncs only when you choose, and is never used to train AI.

1. What we collect

Account data: email address and authentication identifiers (via Supabase; social sign-in — Google, Apple, Kakao, or X — shares your email and basic profile from that provider). Synced content: manuscripts, diary entries, notes, and settings — only if you enable cloud sync. Payment data: handled by Paddle (merchant of record); we do not receive your card number. Usage of managed AI is metered for credit accounting.

2. Local-first: what stays on your device

Your writing is stored in your browser's local database (IndexedDB) on your device. Preferences (theme, language, skin) are stored in localStorage. BYOK API keys are stored only on your device and are never sent to or stored on our servers.

3. AI processing

When you invoke an AI feature, the relevant content is sent to the AI provider you selected (e.g., Anthropic, OpenAI, Google) to generate a response, subject to that provider's privacy terms. We do not use your content to train models, and we do not sell your data.

4. Cookies and localStorage

We use localStorage and essential cookies for sign-in sessions and preferences. We do not run third-party advertising trackers on the landing page or in the app.

5. Sharing and processors

We share data only with processors needed to run the service — subprocessors: Cloudflare (hosting/edge), Supabase (database and authentication), Paddle (payments, as merchant of record), and the AI providers you invoke (content is sent only when you run an AI feature). If you connect an external sync destination you choose (WebDAV, Google Drive, Dropbox, OneDrive), your content is stored with that provider under your own account and their terms. We do not sell personal data.

6. Retention, deletion, export

Retention: synced content is retained while your account is active; managed-AI usage records are kept for credit accounting. Deletion: you can delete synced data in the app, or request account deletion by contacting support@thegeul.com from your account email — your synced content and account data are removed from our servers within 30 days, except where law requires retention (e.g., payment records kept by Paddle). Local copies on your devices remain under your control. Export is available anytime (Markdown ZIP, PDF, EPUB).

7. Security

Data in transit is encrypted (TLS). Synced data is protected by per-user access rules (row-level security). No method of storage is 100% secure; keep your account credentials safe.

8. Your rights · changes · contact

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your data — contact us to exercise them. Governing law: to be determined (placeholder pending legal review). We will announce material changes to this policy in the service. Contact: support@thegeul.com.

This page is a pre-legal-review template. The governing-law placeholder will be finalized before commercial launch.