NovelAI Privacy Policy

Effective: September 10th, 2026

In short: your stories are end-to-end encrypted and we cannot read them, and we do not store the prompts you send for generation. Section 2 explains both.

1. Who is responsible

Anlatan Inc., 501 Boylston Street Floor 10, Boston, MA 02116, United States, is the controller of the personal data described in this policy. You can reach us at support@novelai.net.

2. End-to-end encryption and prompts

Your stories are end-to-end encrypted. Your stories, including their lorebooks, and your scripts and prompt chunks are encrypted in your browser before they are saved, with a key derived from your password that never leaves your device. We store only the encrypted data and cannot read it. If you lose your password, we cannot recover it either. The part of a story you send for generation is processed in readable form to produce the output and is not kept, as described next.

We do not store your prompts. What you send for generation is processed only to produce your output and is not kept. The only exception is an encrypted cache of uploaded images, held for up to one hour. Your image generation history is kept only on your device. If you publish an image on Explore, the generation settings embedded in it, including its prompt, are published with it.

3. What we process, why, and on what legal basis

PurposePersonal dataLegal basis
Providing the service you signed up for: your account, the content you store, generation, NovelAI Explore, contests, support, and emails about your account.Your account details, the content you store (end-to-end encrypted, see section 2), what you submit for generation (processed, not stored), your usage history, and your messages to us.Performance of our contract with you.
Taking payments and issuing invoices.Your billing details, partial payment-method details and transaction records. Full card numbers and security codes go directly to our card gateway and never reach us.Performance of our contract. Keeping invoices and tax-jurisdiction records after your account closes: our legal obligation under tax and accounting law, and our legitimate interest in keeping accounting records and defending payment disputes.
Recording your consent choices.Your consent choices and when you made them.Our legal obligation to be able to show that you consented.
Preventing fraud, abuse of free features, and unlawful content.Technical data about your device and connection, account and payment identifiers, and records of past enforcement.Our legitimate interest in protecting the service and its users from fraud and misuse.
Keeping the service secure and working.Technical logs and error reports.Our legitimate interest in the security and reliability of the service.
Sending marketing emails.Your email address, subscription status and which features you use.Your consent.
Measuring how the service is used and how our advertising performs.A visitor identifier and records of how you arrived at and use the service, such as pages viewed, features used and purchases. This never includes your prompts, your stories or anything you generate.Your consent, for the tools you can switch on or off under "Manage Cookies". Our legitimate interest in understanding and improving the service, for our own usage statistics.

Data we receive from others. From the payment and security providers in section 5: payment and authentication results, chargeback notices, and risk assessments. From Google, if you sign in with Google: the account data described in section 4.

Data you must provide. An email address and a password to open an account, or a Google account plus a separate encryption password if you sign in with Google, and a billing address to pay. Without them we cannot provide the account or take the payment.

4. Signing in with Google

If you choose to sign in with Google, Google sends us your Google account identifier, your email address, whether Google has verified that address, and, for Google Workspace accounts, your organisation's domain. We request no other access to your Google account and do not store anything else Google includes in the sign-in response.

We use the Google account identifier for one purpose only: to recognise you when you sign in again. The identifier itself is shared with no one other than the hosting providers that run our systems, and it is deleted with your account.

Your email address becomes the email address of your NovelAI account. From then on it is handled like any account email: we use it for messages about your account, for billing if you pay, for marketing emails only if you opt in, and, in hashed form, to prevent abuse. It reaches the providers listed in section 5 for those purposes, and after you delete your account it is kept only as described in section 6.

We do not sell Google user data, use it to target advertising, or use it to develop, improve or train AI models. NovelAI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If we want to use Google user data in a new way, we will tell you and ask for your consent before doing so.

5. Who receives your data

  • Hosting and network: CoreWeave, Cloudflare, Google Cloud (backups). They run our servers, network and backups and hold the data described in this policy.
  • Scripts and media loaded in your browser: Google (fonts); jsDelivr (editor assets); YouTube (embedded videos); rss2json (blog feed). Each receives only your IP address and browser details when the resource loads.
  • Payments: Chargebee (billing and invoices); our card gateway and card acquirer. They receive the payment data described in section 3.
  • Email: Mailgun (account emails); Customer.io (marketing emails, only if you opted in). They receive your email address and the messages we send you. Customer.io also receives your subscription status and which features you use, so that we can send you emails that are relevant to you.
  • Account and payment security: Fingerprint and Google reCAPTCHA Enterprise receive technical data about your device and connection; Google Sign-In, the account data described in section 4.
  • Analytics, advertising measurement and consent management: PostHog; Plausible Analytics; Google (Tag Manager and Google Ads); Osano. They receive the usage data described in section 3, never your prompts or content; Osano receives your consent choices.
  • Error monitoring, support and internal messaging: Sentry (technical error reports); Zendesk (what you send to support); Slack (internal notices about your account).
  • The public, for anything you publish on Explore.

None of these providers receives your prompts or anything you generate, other than as traffic passing through our hosting and network providers on the way to our servers. Your stories reach our hosting and backup providers only in the encrypted form described in section 2, which neither we nor they can read. What you publish on Explore is public by your choice.

6. How long we keep it

DataKept for
Your account, the content you store and your account event logUntil you delete your account.
Usage recordsUntil erased at your request.
What you submit for generationNot stored. Uploaded images are held in an encrypted cache for up to one hour.
Payment recordsInvoices and tax-jurisdiction records, as long as tax and accounting law requires. Other payment records, including your billing name and address, until erased at your request.
Fraud-prevention recordsFor as long as we operate the service. Removing individual records would weaken our ability to recognise repeat fraud and abuse, so we keep them after an account is deleted and, where our interest in preventing fraud overrides, when erasure is requested.
Technical logs and error reportsUp to 90 days, or one year when kept for a support case.
Usage analyticsUp to 6 months. The profile held by our analytics provider, until erased at your request.
Marketing profileUntil you withdraw consent or delete your account.
Explore postsUntil you delete them.
Backups90 days. Data you delete remains in backups until they expire.

After you delete your account in settings we keep the fraud-prevention and payment records above, including a hashed form of your email address, and the usage records and analytics profile until you ask us to erase them.

7. Your rights

If you are in the European Economic Area, you have the right to access your personal data, to have it rectified or erased, to restrict its processing, to receive the data you provided in a portable format, and to object to processing based on our legitimate interests. Where processing is based on your consent, you may withdraw it at any time without affecting processing that already took place. We may refuse erasure and objection requests that concern our fraud-prevention records where our interest in preventing fraud overrides, as set out in section 6; we assess each request. You also have the right to complain to a data protection authority.

To exercise these rights, use your account settings or write to support@novelai.net.