Privacy Policy
Effective: 2026-09-10
How account, writing, reading and payment data are handled, and how to make a privacy request. Using the writing service does not automatically publish a private manuscript.
On this page
1. Scope and operator
EvoronAI is an individually operated service for AI-assisted creation and ebook reading. This policy covers personal data processed through the library, writing studio, accounts, purchases and customer support. “We” means the individual operating the service under the EvoronAI brand, responsible for the relevant data processing within this service. Privacy contact: support@evoronai.com.
This policy explains information you provide, records generated through use, and information received through payment confirmations, public reference sources and complaints. Third-party sites and services have their own privacy rules; our legal duties for our own processing remain applicable.
2. Accounts, verification and acceptance records
Registration requires an email, password and the pen name requested by the form. These enable account creation, verification emails, sign-in and account recovery. Without required information, the corresponding account function cannot be completed. Passwords are stored as salted scrypt hashes. We also process email-verification and password-reset records and session identifiers. Session records include device or browser descriptions, network-address hints, creation, last-use and expiry times to identify and revoke sign-ins.
When you accept the terms and acknowledge reading the privacy policy, the account stores the policy version, content digest, confirmations, server-recorded time, language and confirmation source. A policy update does not automatically create a new acceptance record. Pen names may accompany public works or reviews; login emails are not automatically published as author information.
3. Writing materials and AI models
Conversations, book settings, uploaded attachments, references, drafts, revision instructions, cover prompts and results support the planning, writing, editing, cover creation and export you request, and save your progress. Large language model (LLM) requests may contain relevant source text, chapters, extracted attachment content and context, not just your latest instruction. This does not automatically publish a private manuscript, but necessary providers process relevant content when fulfilling the request.
Requests routed through OpenRouter send content to OpenRouter and the model provider handling the request. Other configured model or image interfaces are handled by their respective providers. OpenRouter request metadata includes model, usage and latency information; content logging and downstream data practices depend on provider policies and actual settings. Zero retention and exclusion from training are not universal properties of all models. Contact support before submitting material subject to confidentiality or sensitive-data requirements.
Submit only material you are entitled to process and need for the task. Research sends query terms to search services and retrieves relevant public pages; personal information included in a query may travel with that request. Facts, authorship and source information from third-party pages may be retained as references.
4. Manuscript image searches
Manuscript image searches retrieve real-material candidates from Wikimedia Commons. Queries may be supplied by you or developed during planning from relevant manuscript context; queries and asset requests are sent to that service. Previews, source links, authors, licenses, retrieval times and selection status are stored in the image library. Selected assets are verified and downloaded, with the image and provenance record retained.
Displaying candidates neither publishes your manuscript nor means you have adopted an image. Manuscript image searches do not invoke AI image generation; text-model processing used for planning remains as described above. Opening third-party previews or source pages sends the network request information needed for access to those providers.
5. AI cover content screening
Text prompts for AI cover generation and revision are screened through the Creem Moderation API before they reach the image model. Screened text may include your book title, pen name, scene description, revision instructions and context excerpts needed for generation. This is a separate purpose from payment processing through Creem. Requests use a random identifier and do not separately attach your login email, account identifier, payment details or complete manuscript. Personal information you include in the prompt still travels with that prompt.
Screening evaluates prompt content and returns allow, flag or deny. A flag, denial or unavailable screening service stops the relevant generation request and displays an error. You may revise the request, retry later or challenge the decision through support. Screening prevents restricted image generation; it does not certify a work’s facts, copyright or licensing.
To verify execution and troubleshoot, the private audit record stores the time, random request identifier, screening environment, decision and provider result identifier. This dedicated record does not store the prompt text, generated image or full provider response; other writing and operational records may contain relevant content. Creem’s processing and retention of received prompts depend on its service terms and applicable arrangements.
6. Private drafts, reading and publication
Shelves, bookmarks, progress, reading preferences and reviews support reading and synchronization; some settings are stored in the browser. Unpublished private projects are subject to account access controls and are not part of the public library. The authorized operator and necessary providers may still process relevant private material to operate the service, troubleshoot or handle your support request.
Text, adopted images, covers, titles, descriptions and pen names you publish, together with public reviews, may be accessed, shared, downloaded or indexed. An unlisted publication is not private access control: anyone with the link can still access it. Withdrawing publication and deleting a private project are different actions and cannot automatically retrieve external downloads or caches.
7. Checkout, credits and payment records
We retain account-linked order IDs, packs, amounts, currencies, payment channels, checkout and transaction identifiers, payment and refund status, and credit grants, usage and reversals for delivery, reconciliation, refunds and disputes. Creating a Creem checkout sends the product identifier, order reference, quantity and return URL; manuscript content is not sent as payment information.
Names, emails, billing addresses and payment details entered on Creem checkout pages are processed by Creem and relevant payment partners for transactions, tax, fraud prevention and disputes; the studio does not collect full card numbers. We receive payment and refund notifications to verify orders and adjust credits and may review necessary transaction information for support or disputes. Creem’s own processing is described in its Privacy Notice: https://www.creem.io/privacy.
8. Purchase age declaration
Purchasing writing credits requires a declaration that you are 18 or older. Created orders retain that declaration and the server-recorded confirmation time. This step does not collect a birth date or identity document and is not identity or age verification. The declaration records purchase eligibility, not consent to other data uses or a waiver of consumer rights.
9. Purposes and legal bases
Where these legal bases apply under the relevant law, we process account, creation, reading-sync, order and support information to enter into and perform the service contract you request. Necessary transaction retention, rights requests and valid legal demands are handled to comply with applicable legal obligations. For account protection, abuse prevention, troubleshooting and disputes, we rely on the corresponding legitimate interests where legally permitted and not overridden by your rights and interests.
Where a purpose requires consent by law, consent must be obtained for that purpose. Acknowledging this policy is not blanket consent to all processing or authorization for non-essential marketing, advertising tracking or additional training uses. You can read public works without submitting writing material; withholding information needed for a particular function affects provision of that function.
10. Cookies and browser storage
The hai_session cookie authenticates and maintains sign-in, normally for 30 days, and can be invalidated by sign-out, revocation or expiry. It uses HttpOnly and SameSite protections. Sign-in authentication depends on this cookie; blocking it affects sign-in and protected actions.
Local storage retains language, reading progress, preferences and studio state, generally until cleared or updated by the product. Session storage holds temporary state or input drafts for the browser session. Browser settings let you inspect or clear them, which may remove local preferences or unsubmitted input. These stores serve the corresponding reading and studio functions and are treated separately from sign-in authentication.
Cookies and storage on third-party checkout, preview and source pages are handled by those services under their privacy notices and applicable choices. General acceptance of service terms does not replace consent required for non-essential storage.
11. Operational records and security
Access times, network addresses, browser request information, actions, errors, model usage and support correspondence help operate the service, protect accounts, prevent abuse, reconcile usage and troubleshoot. Diagnostic records and support material you send may contain manuscript or personal-data excerpts. Provide the issue location and necessary excerpts where possible, not whole private manuscripts, passwords or verification codes.
Security measures include password hashing, session validation and revocation, account and project access controls, and payment-notification signature checks. Access is limited to processing needs. Internet transmission and storage still carry risk. Report account anomalies or suspected data exposure to support@evoronai.com with the time and a description.
12. Providers and other recipients
In addition to model, search and payment providers, hosting, email, storage and backup providers process data necessary for the service. Necessary information may also be disclosed to comply with applicable law, respond to valid legal requests, protect users and the service, or handle complaints. Readers are recipients of content you choose to make public.
13. International processing
Hosting, email, model, asset and payment services may process data outside your country or region, where rules may differ. A request can involve providers in several regions; the website server’s location does not determine every subsequent processing location. International processing must meet the legal conditions applicable to that processing. Contact support about relevant recipients, locations and applicable safeguards, including information or copies where legally available.
14. Retention, deletion and backups
Accounts and manuscripts support ongoing access, saving and recovery. Transaction records support delivery, refunds, disputes and applicable financial duties. Operational, security and support records support troubleshooting, abuse prevention and request handling. Retention depends on purpose, account status, outstanding matters and legal obligations; signing out is not a deletion request.
Privacy deletion requires identity verification and scope confirmation. Working copies, published works, search caches and backups are distinct. Deleting something in the interface does not immediately erase every backup. When data must remain, we explain the categories, reasons and available handling arrangements in the request response. Archiving a manuscript is not account deletion or withdrawal from publication.
15. Making a privacy request
Email support@evoronai.com with your account email, request type and scope to request access, correction, export or deletion. We may require identity checks proportionate to the request, but not your password. Applicable law may also provide rights to object, restrict processing, withdraw consent, portability, appeal or complain to an authority; applicability depends on your circumstances.
We handle requests within applicable deadlines and explain necessary extensions, inability to fulfill a request or lawful retention. Withdrawing consent does not affect lawful processing based on consent before withdrawal. A privacy request does not automatically cancel an order or refund a payment; you can submit the corresponding payment request as well.
16. Objecting and withdrawing consent
Where applicable law provides a right to object to processing based on legitimate interests, email support@evoronai.com with the relevant processing and your circumstances to request review. You may withdraw consent for consent-based processing through the same email. Withdrawal does not affect lawful processing before withdrawal or records that must continue to be processed on another lawful basis.
17. Minors
This service is not designed for children; paid creation and credit purchases are subject to the terms’ age-18 requirement. Other access and data processing involving minors remain subject to applicable law. Do not submit children’s personal information without a lawful basis. Parents or guardians who believe such information was improperly submitted can contact support with the circumstances and relevant location for review.
18. Policy updates
This page displays the effective date, and earlier public policies remain available for reference. Material changes to features, data flows or applicable requirements are communicated through appropriate product notices or contact channels. Uses requiring separate consent still require that consent. Existing acceptance records retain the policy and time actually confirmed.