Privacy Policy

Pocket Scriptorium Effective date: 27 September 2026

This policy tells you what personal data we collect when you use the Pocket Scriptorium app, website and service (the "Service"), why we collect it, and what rights you have.

1. Who we are

The controller of your personal data is Munda Plus d.o.o., Liminjan 14, 6320 Portorož, Slovenia, registration number 5493218000 ("we", "us").

Contact for privacy questions: [email protected]

2. Short version

3. What data we collect

Data Examples Source
Account data Email address, name, pen name, password (stored as a hash), Apple or Google sign-in ID You
Age confirmation That you confirmed you are 18 or older for the Mature level You
Story data Wizard choices, premises, character names, stories, story bibles, chapter rewrite notes You and the Service
Library activity Published stories, likes, follows, reviews, reports, blocks You
Reading data Reading and listening progress, app settings The app
Device data Device identifier (stored as a hash), platform, app version The app
Purchase data Product, date, transaction ID, subscription status, credit balance and history Apple or Google, through RevenueCat
Technical logs IP address, date and time, request type, errors Our servers
Crash reports Error type and message, where in the code it happened, app version, device model and operating system version. We remove email addresses, sign-in tokens, IP addresses and story text before a report leaves the app or our servers. The app and our servers
Feedback and ideas Feedback you send in the app (kind, star rating, comment, app version and platform), feature suggestions and your votes on the roadmap You
Support messages Your emails to us and our replies You

We do not receive your card or bank details. Apple or Google handles payments.

We do not ask for special categories of data (for example health or religion). Do not put such data about yourself or other real people into your stories.

4. Why we use your data and our legal basis

Purpose Legal basis (GDPR)
Create and run your account, generate and store your stories, sync progress, sell and add credits Contract (Art. 6(1)(b))
Show your published stories, pen name, reviews and likes to other users Contract (Art. 6(1)(b))
Show notifications on your phone about your own stories (for example "Chapter 1 is ready"). The app creates them on your phone; we do not use a push service. Consent, given through your device's notification permission (Art. 6(1)(a)). You can turn it off at any time.
Check stories before publication, handle reports, prevent abuse and fraud, including more than one free credit grant per person or device Legitimate interest in a safe service (Art. 6(1)(f)), and legal duties for online services (Art. 6(1)(c))
Keep the Service secure, find and fix errors, including crash reports Legitimate interest (Art. 6(1)(f))
Measure costs and use in aggregate to improve the Service Legitimate interest (Art. 6(1)(f))
Read your feedback, review your feature suggestions and count votes to decide what to build Legitimate interest in improving the Service (Art. 6(1)(f))
Keep purchase and tax records, answer authorities Legal obligation (Art. 6(1)(c))
Answer your support requests Contract or legitimate interest (Art. 6(1)(b) or (f))

When we rely on legitimate interest, you can object (see section 9).

5. AI processing

5.1 To write a story, we send your story choices (genre, tone, premise, character names, story bible and earlier chapters) to OpenRouter. OpenRouter passes them to the AI model provider that we choose for that length. We do not send your name, email address or account ID.

5.2 We set up our AI routing to use only model providers that do not use this content to train their models.

5.3 An automated system checks a story before it becomes public. It can reject a story that breaks our Terms of Service. This decision has no legal effect on you. You can ask a person to review it at [email protected].

5.4 We do not use your stories to train AI models.

6. Who receives your data

We share data only with service providers who process it for us under a contract, and only as far as they need it:

Recipient What for Location
OpenRouter, Inc. and the AI model providers it routes to Writing stories and checking content USA and other countries
RevenueCat, Inc. Checking purchases and subscriptions USA
Functional Software, Inc. (Sentry) Crash reports, without your name, email address, account ID or story text EU (Frankfurt, Germany)
Apple and Google App stores, payments, sign-in USA and EU
Kamatera, Inc. Servers and backups Frankfurt, Germany (EU)
Mailjet SAS Account and support email EU

Other users see what you publish: your pen name, public stories, reviews and likes on public stories. Other users do not see your email address or your private stories.

We can give data to authorities when the law requires it.

If we sell or merge the business, your data can move to the new owner. This policy continues to apply to it.

7. Transfers outside the EU/EEA

Some recipients are outside the EU/EEA, mainly in the USA. We protect these transfers with the EU Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified under it. You can ask us for a copy of the safeguards at [email protected].

8. How long we keep data

Data How long
Account, stories, library activity, reading data While your account exists. We delete it within 30 days after you delete your account.
Backups Up to 35 days after deletion from the live system
Purchase records and credit history As long as tax and accounting law requires
Technical logs 90 days
Crash reports Up to 90 days
Reports and moderation decisions 1 year after the decision, or longer if a legal claim needs them
Support messages 2 years after the last message
Feedback, feature suggestions and votes While your account exists. When you delete it, your votes and suggestions we have not reviewed are deleted; feedback and approved suggestions stay without your name or email.

Stories saved in the app stay on your device until you remove the download, delete the app or delete your account.

9. Your rights

Under the GDPR, you have the right to:

You can export your data and delete your account in the app under Account. For other requests, write to [email protected]. We answer within one month.

You can also complain to a supervisory authority. In Slovenia, this is the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si. You can also complain in the EU country where you live or work.

10. Children

The Service is for people aged 16 and over. The Mature content level is for people aged 18 and over. We do not knowingly collect data from children under 16. If you think a child under 16 uses the Service, contact us and we will delete the account.

11. Security

We use encrypted connections (TLS), access control, two-factor authentication for staff accounts and encrypted backups. On your device, the app stores stories in its private storage. No system is fully secure. If a breach puts your rights at high risk, we tell you without undue delay.

12. Changes to this policy

We tell you about important changes in the app or by email before they apply. The effective date at the top shows the current version.

13. Contact

Munda Plus d.o.o., Liminjan 14, 6320 Portorož, Slovenia Privacy: [email protected]