Last updated: 2026-06-24. DRAFT — not legally binding until reviewed.
Draft notice: first-pass policy. Final version will be presented before any monetized feature ships.
Account info: email, username, optional display name, optional bio, optional avatar URL, password (bcrypt-hashed, never stored in plain text).
Content: stories, beats, characters, world elements, themes, forum posts, direct messages, Hall of Fame entries — i.e. what you write.
Usage data: AI prompt logs (for cost tracking + bug investigation), audit logs of moderator actions, error logs, basic request metadata (IP address, user agent — retained briefly for rate-limiting and abuse mitigation).
Payment info (when subscriptions launch): handled by Stripe. We store a customer ID; Stripe stores the card details.
Run the Service: render pages, send notifications, deliver AI features, prevent abuse. Internal analytics on aggregate usage to decide what to build next. Customer support and bug investigation.
We do not:
We share your data only with the service providers we need to operate One More Draft: AI providers that turn your prompts into text, images, and audio; database and file-storage hosting; an email service; our application host; and a payment processor when subscriptions launch. We do not sell your data, and we share your content with these providers only as needed to deliver the feature you asked for.
Current sub-processors
The specific providers behind those categories today. We keep this list current; last updated 2026-06-24.
You can:
Active accounts: data retained until you delete the account or the item.
Soft-deleted accounts: personal info wiped immediately; system row retained as a tombstone so authored content can be attributed as "[deleted account]" without breaking other people's data.
AI prompt logs: retained 90 days, then aggregated/anonymized.
Backups: continuous WAL replication with a 30-day rolling retention.
Passwords are bcrypt-hashed at rest. Sessions are random tokens with server-side validation. All traffic is HTTPS. We use parameterized queries everywhere (no SQL injection surface) and run a strict CSP. Vulnerability reports go to security@onemoredraft.com.
The Service is not directed at children under 16. We don't knowingly collect data from anyone under 16. If you believe we have, email privacy@onemoredraft.com.
The Service may be hosted in or transmit data through countries outside your country of residence. By using the Service, you consent to such transfer.
Material changes will be announced via in-app notice and email (if opted in) at least 30 days before they take effect, except where immediate change is required by law or to address a security incident.
Privacy questions: privacy@onemoredraft.com.