Last updated: 2026-05-03

Privacy Policy

This Privacy Policy describes how Perry Labs LLC ("we," "us," or "Perry Labs") collects, uses, and shares information when you use Fractal Flow (the "Service") at fractalflow.ai. Read it together with our Terms of Service, which govern your use of the Service. Capitalized terms not defined here have the meanings given in the Terms.

1. Information We Collect

1.1 Account information

  • Email address. Required to create an account and receive transactional email such as sign-in confirmations, billing receipts, and password resets.
  • Password. If you sign up with email and password, your password is stored as a hash by our authentication provider. We never see your plaintext password.
  • Identity provider profile data. If you sign up with a third-party identity provider (such as Google), we receive the basic profile information that provider returns through OAuth, including your email address.

If we add features in the future that ask for additional account information (for example, a display name or a profile photo), this policy will be updated to reflect that before the features are introduced.

1.2 Payment information

Payments are processed by Stripe. Stripe collects your payment method directly; we do not see, store, or process your card number, security code, or full billing address. From Stripe we receive a customer identifier and your subscription status so that we can grant or restrict access to paid features. Stripe processes your information under its own privacy policy.

1.3 Content you submit

The Service is a writing application, and your writing is the most important data we hold. We store the content you create or upload while using it, including:

  • The novels and projects you write — their titles, premises, synopses, outlines, chapters, scenes, and timelines.
  • Your World Bible material — characters, locations, and other elements you describe, the relationships between them, and any images you attach to them.
  • Reference materials you upload to inform AI suggestions, in the formats and within the size limits the Service supports.
  • Your conversations with the AI brainstorming and editing features, and the AI-generated outputs they produce.
  • A history of changes to your work, including the AI prompt and model used when an AI was involved, so you can undo edits and so we can debug, improve the Service, and use the material as described in Section 5 of the Terms.

1.4 Usage and operational data

  • AI usage records. For each AI request we record the operation, the model used, and token and cost metrics so we can apply rate limits, plan capacity, and understand usage. The text of your prompts and AI outputs is stored alongside your other writing content as described above.
  • Aggregate usage counts of generations, embeddings, and images per account per day.
  • Rate-limit counters keyed to your account, used to prevent abuse.
  • Feedback you submit. Ratings on AI generations and any bug reports or feature requests you send through the in-app feedback form, together with limited browser metadata that helps us reproduce issues. Bug reports may include an optional contact email if you choose to provide one.
  • Server and security logs. Standard request metadata (such as path, status code, timestamp, and IP address) retained for a limited period for operations and security purposes.

When you accept the Terms of Service or Privacy Policy at signup or after a version update, we record the document and version you accepted, the time, your IP address, and the browser identifier you used. This is the record that you agreed and is retained while your account exists and for a reasonable period afterward.

1.6 Cookies, pixels, and similar technologies

We use the following categories of cookies and similar technologies:

  • Strictly necessary — cookies that keep you signed in and short-lived cookies used to complete sign-up flows and similar one-time interactions. The Service will not work without these.
  • Advertising and measurement — cookies, pixels, and similar tags provided by advertising platforms (such as Meta and Google) that help us measure the effectiveness of our advertising, attribute sign-ups to the campaigns that drove them, and reach people who have shown interest in the Service. These tools may set their own cookies and may share information about your visit (such as the pages you viewed and actions you took, your IP address, and an advertising or device identifier) with the advertising platform that supplies them.

Where required by law, we will ask for your consent before loading advertising and measurement tags and provide controls to manage your choices.

1.7 Information collected by advertising platforms

If you click one of our ads or interact with a page that loads an advertising or measurement tag, the advertising platform that supplies the tag may collect information directly from your browser, including your IP address, browser and device identifiers, the page you are on, and certain actions you take on the Service. The advertising platform processes that information under its own privacy policy and may combine it with information it already holds about you.

2. How We Use Your Information

We use the information described in Section 1 to:

  • Operate the Service — authenticate you, store your projects, generate AI suggestions, and let you export your work.
  • Process payments — initiate checkout, receive subscription status updates, and gate access to paid features.
  • Communicate with you — send transactional email (sign-in confirmations, billing receipts) and respond to support requests at support@fractalflow.ai.
  • Enforce limits and prevent abuse — apply rate limits, detect suspicious patterns, and respond to security incidents.
  • Debug, monitor, and improve the Service — use server logs, error reports, and feedback to find and fix problems and to plan what to build next.
  • Market the Service — measure the performance of our advertising, attribute sign-ups to the campaigns that drove them, and reach people who are likely to be interested in the Service, including through retargeting on third-party advertising platforms.
  • Train, fine-tune, evaluate, and develop AI writing and editing models. As described in Section 5 of the Terms, submitted content and AI outputs are used as part of large aggregated datasets to train models that may be used commercially or offered as products separate from the Service. Training does not transfer ownership of your work; you retain copyright in everything you write. Trained models do not store your manuscript as a discrete, retrievable copy and are not associated with your name or account.
  • Comply with the law and enforce our Terms — respond to lawful requests, exercise our legal rights, and protect the safety of our users and others.

3. Sub-processors and Third Parties

We share information with the following providers under contractual obligations to protect it. They process your information on our behalf and do not receive it for their own marketing.

  • Supabase — authentication, database, and file storage.
  • Vercel — application hosting and content delivery.
  • Stripe — payment processing and subscription management.
  • OpenAI and Anthropic — AI model providers used to generate text, embeddings, and other AI outputs based on the inputs and context you submit.
  • Identity providers you choose to sign in with (such as Google) — only if you select that option.
  • Advertising and measurement platforms (such as Meta and Google) — used to measure the performance of our advertising, attribute sign-ups, and reach prospective users. Information shared with these platforms is described in Sections 1.6 and 1.7.
  • Infrastructure providers used for ancillary functions such as rate limiting and email delivery.

Each provider processes information under its own terms. As of the "Last updated" date at the top of this page, our AI providers do not, by default, train their public models on data submitted through their APIs but may retain it briefly for abuse monitoring under their own policies. If our configuration or providers change in a way that affects this, this policy will be updated.

We do not sell your personal information for money. However, our use of advertising and measurement tags described in Sections 1.6 and 1.7 may constitute "sale" or "sharing" of personal information for cross-context behavioral advertising under California law and similar concepts under other state privacy laws. You can exercise your right to opt out as described in Section 5. We may also disclose information when required by law, valid legal process, or to protect the rights, property, or safety of Perry Labs, our users, or others.

4. Data Retention and Deletion

We retain your account information and content for as long as your account is active. You can delete an individual project from within the Service at any time. You can also delete your entire account from Settings → Delete account; this cancels any active subscription and permanently removes your projects, world-bible material, uploaded reference files, and account data. After deletion, content is removed from active systems within a reasonable period.

If you have lost access to your account and cannot use the in-product delete control, email support@fractalflow.ai and we will delete the account on your behalf after verifying your identity.

Some data is retained longer where required for legitimate business purposes, including transaction records kept for tax and accounting compliance, security logs, and backups that age out on a fixed schedule.

Important limitation about AI training. Content that has already been incorporated into a trained or in-training AI model cannot be extracted from that model. Deleted content will not be used in any new training runs initiated after deletion. See Section 5.5 of the Terms of Service for the full terms.

5. Your Rights

Depending on where you live, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — ask us to delete your personal information, subject to the limitation in Section 4.
  • Portability / Export — receive your content in a portable format. The Service offers in-product export of your projects to common document formats.
  • Objection or restriction — object to or restrict certain processing.
  • Withdrawal of consent — where we rely on consent, withdraw it at any time.
  • Opt out of "sale" or "sharing" — if you are a California resident (or a resident of another U.S. state with a similar law), you have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising as described in Section 3. Exercise this right at any time by clicking Your Privacy Choices in the footer of any page and turning off Advertising and measurement. We also honor recognized opt-out preference signals (such as Global Privacy Control) sent by your browser: when GPC is detected, advertising and measurement tags are not loaded regardless of any other setting.

If you are in the European Economic Area, the United Kingdom, or Switzerland (GDPR), or in California (CCPA/CPRA), or in another jurisdiction with similar laws, these rights apply to you in the form provided by your local law. The fastest way to exercise the most common rights is from within the Service: deletion via Settings → Delete account, export from your project's export menu, and advertising opt-out via Your Privacy Choices in the footer. For anything that cannot be self-served, email support@fractalflow.ai. We will not discriminate against you for exercising your rights.

6. Security

We use industry-standard administrative, technical, and physical safeguards. Connections to the Service are encrypted in transit, and stored data is encrypted at rest by our infrastructure providers. Credentials for our AI providers are held server-side and are never exposed to the browser. Access controls and rate limits are enforced on every API request.

No system can be guaranteed 100% secure. If we become aware of a breach affecting your personal information, we will notify you and the appropriate authorities as required by law.

7. Children's Privacy

The Service is not intended for users under 13 years of age, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided personal information to us, contact support@fractalflow.ai and we will delete it.

8. International Data Transfers

We are based in the United States. Our sub-processors may operate in the United States or other countries. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our providers operate. Where required, we and our providers use appropriate safeguards such as the European Commission's Standard Contractual Clauses for cross-border transfers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Service or by email and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date means you accept the updated policy.

10. Contact

Most requests can be handled from within the Service:

  • Delete your account — Settings → Delete account.
  • Export your work — the export menu inside any project.
  • Manage cookies and advertising opt-out — Your Privacy Choices, in the footer of every page.

For anything that cannot be handled from within the Service, contact support@fractalflow.ai.

Cookies on Fractal Flow

We use cookies that are necessary to run the site and, with your consent, cookies and pixels from advertising and measurement platforms (such as Meta and Google) so we can see how our ads perform and reach people who might want to write with us. You can change your choice any time from Your Privacy Choices in the footer. See our Privacy Policy.