Legal
Privacy policy
Plain language for how we handle your account and manuscripts during early access. Counsel-reviewed policy arrives alongside production billing.
Data controller
The data controller for Cursyv is Jedd Soh, doing business as cyberPotions. Neither cyberPotions nor Cursyv is a registered company; we operate as a sole proprietorship until revenue supports formal entity registration. Data-subject requests and privacy enquiries go to privacy@cursyv.app.
Our commitment
Your manuscript stays yours — never training data for generative models. Card payments via Stripe when billing opens — no charge during early access.
1. Who this applies to
This policy covers visitors to cursyv.com, account holders at the writing workspace (/desk), and anyone who opens an Edit share link you send.
2. What we collect
- Account data — email, display name, password hash (via Supabase Auth), and plan tier metadata.
- Manuscript data — manuscripts, chapters, TipTap document JSON, Encyclopedia entities and links, History checkpoints (SHA-256 fingerprints and timestamps), and Edit review comments anchored to plain-text offsets.
- Operational data — request paths, error traces, and aggregate analytics via Vercel Analytics. We do not log manuscript body text in application logs.
- Payment data (when billing opens) — billing status and Stripe customer identifiers. Card numbers stay with Stripe.
3. How we use data
We use your information solely to:
- Authenticate you and keep your session secure.
- Store, autosave, restore, and export your drafts and proof fingerprints.
- Power Encyclopedia links, History, Edit share links, and collaboration features you enable.
- Operate, debug, and improve the service without selling or profiling you for ads.
- Process payments when you choose a paid plan after billing opens.
4. What we do not do
- We do not sell your personal data or manuscript content.
- We do not use your prose to train generative AI models.
- We do not show your manuscripts to anyone you did not explicitly share with.
- We do not run generative prose features inside the editor — see our approach.
5. Where data lives
Manuscript rows live in Supabase Postgres with row-level security — other accounts cannot read your chapters. The application is hosted on Vercel. TLS encrypts data in transit on every endpoint we control.
6. Subprocessors
We rely on vetted providers to run the service. A formal subprocessor list will publish before production billing; current processors include:
Supabase
Authentication and Postgres database (manuscripts, chapters, History, Encyclopedia, review comments).
Region · United States (configurable per project)
Vercel
Application hosting, edge delivery, and privacy-conscious analytics (no manuscript content in analytics events).
Region · Global edge network
Stripe
Payment processing when billing opens — card metadata only; we never store full card numbers.
Region · United States
7. Retention and deletion
Drafts persist while your account is active. Delete a History entry and its fingerprint row is removed with the chapter scope you chose. Delete your account by emailing hello@cursyv.app — manuscript rows are removed within 30 days unless law requires a longer hold.
Revoke any Edit share link from the collaboration panel; previously issued URLs stop resolving new sessions once rotated.
8. Your controls
- Export manuscripts and Proof Record bundles (JSON + README) from the workspace.
- Delete individual History entries or entire manuscripts from Desk.
- Revoke Edit links and resolve review comments on your timeline.
- Request access, correction, or deletion — we respond within 30 days.
9. Cookies and analytics
Session cookies keep you signed in. Vercel Analytics collects aggregate page views without manuscript content. We do not use third-party ad trackers on the writing surfaces.
10. Children
Cursyv is not directed at children under 13. We do not knowingly collect data from children. Contact us if you believe a child has created an account.
11. International transfers
If you access Cursyv from outside the United States, your data may be processed in the US or other regions where our subprocessors operate. We use providers with standard contractual safeguards where required.
12. Changes
If we materially change this policy, we will email account holders before the effective date and note the revision here. Card payments via Stripe when billing opens — no charge during early access.
13. Contact
Privacy questions and data subject requests: hello@cursyv.app
Last updated: May 2026 · Operating practice during early access — counsel review before production billing.