Your data

Privacy Policy

Interim notice

Our legal registration details are being finalised alongside our public launch. If you have questions about how we handle your data in the meantime, please contact us. The substantive terms below reflect our current practice; specific registration details will be updated shortly.

Privacy Policy

Last updated: 05 August 2026


Your writing is yours. That's not a marketing line - it's the principle that shapes every decision we've made about how AuthorsLab handles your data. This policy explains, in plain terms, what we collect, why we collect it, how we protect it, and what control you have over it.

Please read it. We've tried to make it worth your time.


1. Who we are

AuthorsLab is operated by [Legal entity — confirming with co-founder], a company registered in England and Wales (company number [Pending]). Our registered address is [Pending].

When this policy refers to "AuthorsLab", "we", "us", or "our", it means AuthorsLab Ltd.

We are not currently registered with the UK Information Commissioner's Office (ICO); registration will be confirmed as part of our public launch.

You can reach us about anything in this policy at privacy@authorslab.ai.


2. What this policy covers

This policy covers all personal data we collect when you:

  • visit authorslab.ai or any subdomain
  • create an account and use the AuthorsLab platform
  • communicate with us by email or through the platform

It does not cover third-party websites we may link to. Those sites have their own privacy policies, and we're not responsible for them.


3. The data we collect

3.1 Account data

When you create an account, we collect:

  • your name
  • your email address
  • your password (stored in hashed form - we never see or store your password in plain text)
  • your phone number, if you choose to provide one

3.2 Manuscript content

AuthorsLab is built around your manuscripts. When you upload or create work on the platform, we store:

  • the full text of your manuscript, chapter by chapter
  • the title, genre, word count, and any other descriptive information you provide
  • version history as your manuscript evolves

This content lives in your account. It belongs to you. See Section 7 for how we keep it protected.

3.3 AI conversation history

Every conversation you have with an AI persona on AuthorsLab - Alex, Sam, Jordan, Taylor, Kai, Riley - is retained in your account as part of your project record. This includes:

  • the full transcript of each session
  • the context the AI used when responding

We keep this history so that each persona can carry meaningful continuity across sessions. You can request deletion of your conversation history at any time (see Section 10).

3.4 AI-generated content

The platform creates editorial and creative outputs on your behalf, including:

  • developmental feedback and structural notes
  • line-edit suggestions and copy-edit corrections
  • cover image drafts
  • marketing copy and launch plans
  • formatted manuscript files

These are stored in your account alongside your manuscript.

3.5 Payment data

If you subscribe to a paid tier, payment is handled by Stripe. We receive a record that payment was made and your subscription status, but we do not store your card number, bank details, or CVV. Stripe holds that information under its own privacy and security standards.

3.6 Usage and analytics data

We collect aggregate data about how the platform is used - which features are accessed, how long sessions last, which pages are visited. This data is analysed in aggregate and is not used to build individual behavioural profiles for advertising purposes.

Our current analytics provider is Vercel Analytics. This may change; we'll update this policy when it does.

3.7 Technical data

When you use the platform, we automatically collect standard technical information including:

  • your IP address
  • browser type and version
  • device type
  • pages visited and time spent
  • referring URLs

4. How and why we use your data

We use your data for specific, legitimate purposes. Here's what they are, and the legal basis we rely on under UK GDPR and EU GDPR for each.

PurposeLegal basis
Providing the AuthorsLab service - storing your account, manuscript, and outputsContract performance (Article 6(1)(b))
Processing AI editorial requests - passing manuscript excerpts to Anthropic or cover prompts to OpenAIContract performance (Article 6(1)(b))
Sending transactional emails - account confirmation, password resets, notificationsContract performance (Article 6(1)(b))
Processing payments via StripeContract performance (Article 6(1)(b))
Analysing aggregate platform usage to improve the serviceLegitimate interests (Article 6(1)(f))
Complying with legal obligations (e.g. tax records, responding to lawful requests)Legal obligation (Article 6(1)(c))
Sending product updates or feature announcements by emailLegitimate interests (Article 6(1)(f)) - you can unsubscribe at any time

We do not use your data for automated profiling that produces legal or similarly significant effects on you.


5. How we share your data

5.1 Subprocessors

We share data with a defined list of third-party service providers (subprocessors) who process data on our behalf. These are the companies that make the platform work. The full list is published separately at authorslab.ai/legal/subprocessors and updated when it changes.

The key ones to know about:

  • Supabase - stores your account data, manuscript files, and AI-generated content. Data is held in eu-west-2 (London).
  • Anthropic - receives manuscript excerpts and conversation context to generate editorial responses via the Claude API. Anthropic does not use your content to train its models under our commercial API agreement.
  • OpenAI - receives cover description prompts to generate cover images via DALL-E. OpenAI does not use your content to train its models under our commercial API agreement.
  • n8n Cloud - orchestrates the AI editing pipelines that coordinate requests between the platform and Anthropic/OpenAI.
  • Stripe - processes subscription payments.

Every subprocessor we use is bound by a data processing agreement. None of them may use your data for their own purposes.

5.2 Publisher access - explicit and author-controlled only

AuthorsLab has a planned feature that allows you to invite a named publisher into specific surfaces of a book project - cover design, formatting, and marketing planning. This is entirely your choice. You initiate it. You control it. You can revoke it.

Your writing space - your Library, Author Studio, and all conversations with Riley - is never accessible to any third party. Period. No publisher, no partner, no one outside your account can see your drafts, your editorial conversations, or your personal writing history. That boundary is built into the architecture of the platform, not just this policy.

When you do invite a publisher, they see only the surfaces you've opened, only for the book you've specified. No other manuscripts. No chat history. No editorial feedback from Alex, Sam, or Jordan.

5.3 Legal disclosures

We may disclose personal data if required to do so by law, court order, or regulatory authority, or to protect the rights, property, or safety of AuthorsLab, our users, or others. We will tell you if we are required to make such a disclosure unless we are legally prohibited from doing so.

5.4 Business transfers

If AuthorsLab is acquired, merged, or undergoes a change of ownership, your data may transfer to the new entity as part of that transaction. We will notify you before any such transfer takes effect and explain your options at that time.

5.5 What we never do

  • We do not sell your personal data to anyone.
  • We do not share your manuscript with any AI company for training purposes.
  • We do not use your writing to train any model, internal or external.
  • We do not share your manuscript content outside your account except as described in Sections 5.1 and 5.2.

6. International data transfers

AuthorsLab is based in the United Kingdom. Our primary data storage is in the United Kingdom (London, via Supabase). When data is transferred between the UK and the EEA, it moves under the UK Government's adequacy decision for the EEA.

Some subprocessors - including Anthropic, OpenAI, and Stripe - are based in the United States. Transfers to them take place under appropriate safeguards, including the UK International Data Transfer Agreement (IDTA) and/or the EU Standard Contractual Clauses (SCCs), as applicable. You can request copies of the relevant transfer mechanisms by writing to us at privacy@authorslab.ai.


7. How we protect your data

We take data security seriously. Our measures include:

  • Encryption in transit: all data is transmitted over TLS/HTTPS.
  • Encryption at rest: all manuscript files and account data stored in Supabase are encrypted at rest.
  • Authentication: passwords are hashed using bcrypt via Supabase Auth and never stored in plain text.
  • Access controls: access to production data is limited to personnel who need it to operate or maintain the service, and is logged.
  • Subprocessor vetting: we review the security practices of each subprocessor before onboarding them.

No system is completely immune to attack. If we become aware of a security incident that affects your personal data, we will notify you and the relevant supervisory authorities as required by law.


8. How long we keep your data

Data typeRetention period
Account dataFor as long as your account is active, plus 30 days after deletion to allow recovery
Manuscript contentFor as long as your account is active; deleted within 30 days of account deletion
AI conversation historyRetained indefinitely during account activity; deleted on account deletion or earlier on your request
AI-generated outputsFor as long as your account is active
Payment records7 years (UK tax and accounting obligations)
Analytics dataAggregated and anonymised; retained indefinitely in aggregate form
Technical/log data90 days

When data is deleted, it is removed from our live systems. Residual copies in backups are overwritten within 30 days in the normal backup cycle.


9. Your rights

Under UK GDPR (and EU GDPR where applicable), you have the following rights. We take them seriously.

  • Right to access. You can ask us for a copy of the personal data we hold about you.
  • Right to rectification. If any data we hold is inaccurate or incomplete, you can ask us to correct it.
  • Right to erasure. You can ask us to delete your personal data. We'll do so unless we have a legal obligation to keep it (for example, payment records we're required to retain for tax purposes).
  • Right to restriction. You can ask us to restrict processing of your data in certain circumstances - for example, while a dispute about accuracy is resolved.
  • Right to data portability. You can ask for your personal data in a structured, machine-readable format so you can take it to another service. For manuscript content, we will provide your files in the format they were uploaded or in a standard document format.
  • Right to object. You can object to processing based on legitimate interests, including receiving product update emails from us.
  • Rights related to automated decision-making. We don't make automated decisions that significantly affect you, but if we ever do, you'll have the right to human review.

To exercise any of these rights, email us at privacy@authorslab.ai. We'll respond within one calendar month. If we need more time (up to two additional months for complex requests), we'll let you know.

We do not charge for these requests unless they are manifestly unfounded or excessive.


10. Deleting your conversation history

You don't need to delete your whole account to remove AI conversation history. To request deletion of chat transcripts with individual personas, or of all conversation history, email us at privacy@authorslab.ai — we action requests within 30 days. Self-serve deletion tools inside your account settings are not available at launch; we will update this policy when they are.


11. Children

AuthorsLab is intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us and we'll delete it promptly.


12. Cookies

We use cookies and similar technologies on authorslab.ai. Our full Cookie Policy, including a list of the cookies we set and what they do, is available at authorslab.ai/legal/cookies.


13. Changes to this policy

If we make material changes to this policy - changes that affect what data we collect, why we collect it, or who we share it with - we'll let you know by email and by posting a notice on the platform before the changes take effect. You'll have the opportunity to review them before they apply to you.

Minor changes (for example, correcting a typo or updating a company address) will be noted in the "Last updated" date at the top of this page.


14. Complaints

If you're unhappy with how we've handled your data, please contact us first at privacy@authorslab.ai - we'd genuinely like the chance to put it right.

If you remain unsatisfied, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. If you're based in the EU, you may also complain to your local supervisory authority.


15. Contact us

[Legal entity — confirming with co-founder] [Pending] privacy@authorslab.ai