Legal
Privacy Policy
How Moneditor handles account data, manuscripts, model requests, billing identifiers, technical information, retention, and account deletion.
Last updated · May 2026
Manuscript ownership
Moneditor does not use your writing to train its own models.
Your manuscripts, outlines, and generated content remain yours. Text is sent to a selected AI provider only when needed to perform a generation request you initiate.
1. Who We Are
Moneditor is an AI-assisted book writing and KDP publishing tool operated by Vladimir Valcourt, operating as Moneditor. The operator contact address is 2 Cedar Pond Drive, Warwick, RI 02886, United States. References to "Moneditor", "we", "us", or "our" refer to that operator. Questions? Email privacy@moneditor.com.
2. Data We Collect
- Account data — name and email address you provide at signup.
- Content data — book projects, chapters, outlines, and notes you create inside the app. This data is stored securely and is never used for AI training.
- Usage data — writing session lengths, word counts, and content-free funnel events such as page views, prototype completion, book creation, and exports. Funnel events do not store manuscript text, email addresses, IP addresses, or URL query strings. This data is not sold.
- Payment data — billing is handled by Stripe. We store only a Stripe customer ID; we never see or store raw card numbers.
- Technical data — IP address, browser type, and cookie identifiers for authentication and security.
3. How We Use Your Data
- To create and manage your account.
- To deliver the AI writing and KDP preparation features you request.
- To process subscription payments via Stripe.
- To show you your personal writing analytics (streaks, word counts, goal progress).
- To send transactional emails (e.g. password reset, billing receipts). We do not send marketing emails without your explicit opt-in.
- To diagnose errors and improve the service through aggregate, anonymised analytics.
4. AI and Your Content
When you use AI features, your text is sent to the provider selected for that request. Supported providers include OpenAI, Anthropic, OpenRouter, Google Gemini, xAI, DeepSeek, Mistral, and Groq. The provider handles the request under its API terms solely to return the generation you requested. When you supply your own API key (BYOK mode), the key is encrypted in storage and decrypted on the server only to send the AI request you initiated.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Supabase — database and authentication hosting.
- Vercel — application hosting, delivery, and request processing.
- Resend — transactional and consented email delivery.
- Stripe — payment processing.
- AI providers — strictly for in-session generation as described above.
- Law enforcement — only when legally required.
6. Data Retention & Deletion
Your data is retained for as long as your account is active. You can delete your account and all associated content at any time from Settings. Upon deletion, active content is removed and backup copies expire under the documented backup-retention schedule. Identifiable product events are retained for no more than 400 days; anonymised aggregate totals may be retained indefinitely.
7. Your Rights
Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal data; to restrict or object to processing; and to withdraw consent. To exercise any right, email privacy@moneditor.com. We will respond within 30 days.
8. Security
All data is encrypted in transit (TLS) and at rest. API keys you store are individually encrypted with AES-256-GCM before being written to the database. We follow security best practices and conduct periodic reviews.
9. Changes to This Policy
We may update this policy occasionally. Material changes will be communicated via email and an in-app notice at least 14 days before taking effect.