Privacy Policy
The short version
- Your writing belongs to you. We don't sell it, we don't train AI on it, and we don't read it for any reason other than to make Dormouse work for you.
- To provide the app, we use Firebase (Google) — accounts, a cloud database, and file storage — to host your stories and sync them across your devices, plus Google's Gemini API to power the AI features, all behind our own server so your data isn't exposed.
- You can delete your account from inside Dormouse at any time. Deleting it permanently erases your writing, recordings, and images from our systems.
- Dormouse is for writers aged 17 and over.
- Who we are
- What we collect
- How we use it
- Who we share with
- Where it's stored
- Retention
- Your rights
- International transfers
- Security
- Children
- Changes
- Contact
1. Who we are
Dormouse is a writing app for novelists, operated by CYBURON Ltd, a company registered in England and Wales (trading as "Dormouse"). For the purposes of UK GDPR and the Data Protection Act 2018, CYBURON Ltd is the data controller for the personal information processed through Dormouse.
How to contact us
- Privacy questions, data requests, deletion: privacy@cyburon.com
- Postal address: CYBURON Ltd, 66 Paul Street, London, EC2A 4NA
If you're not satisfied with how we've handled a privacy question, you have the right to complain to the UK Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.
2. What we collect
2.1 Account information
- Email address. Required to create an account and to verify you're real (every email/password account must verify their email before using the app).
- Password. Hashed and stored by Firebase Authentication. We never see your actual password.
- Display name. The name you give the app when you sign up (optional — defaults to blank).
- Identity colour. Cosmetic — for the avatar tint.
- Profile picture (optional). If you set one, it's stored only on the device that set it — it isn't uploaded to our servers.
- Sign in with Apple users: we receive your full name and email at first sign-in (or a private relay email if you chose that). Apple is the source of truth for these.
2.2 Your writing
- Notes (text, plus the original audio recording if you used voice capture).
- Ideas (unattached fragments not yet tied to a story).
- Projects (your novel or other writing project, with metadata like title, genre, audience, your one-line concept).
- Story elements: characters, places, items, scenes, threads, tags, and themes you've created.
- Moodboard images (photos you add from your camera or photo library as visual references for a story).
- AI-generated content: summaries, character/place/item dossiers, scene synthesis, theme and structure suggestions, and "Ask Dormouse" answers — all generated from your own writing.
2.3 Usage data we generate to operate the service
- Daily AI-call counter. One Firestore document per user (keyed by Firebase user ID) holds today's count of AI requests so we can enforce a fair daily cap. This document holds two numbers (a count and a date) and no content from your writing.
- Function logs. When you use AI features, our server logs the request's user ID, timestamp, model used, and token counts. These logs do not contain the content of your prompts or responses. They're retained for 30 days for debugging and abuse detection, then deleted.
- Verification email events. When we send a verification email through Resend, Resend records the delivery attempt and its outcome (delivered, bounced, or failed) for delivery troubleshooting.
2.4 What we don't collect
- No analytics. We don't use Firebase Analytics, Google Analytics, Mixpanel, or any other behavioural analytics in the app.
- No advertising IDs. We don't read the iOS advertising identifier (IDFA), don't use ad networks, and don't show ads.
- No location. We don't ask for location and don't read any location data from your device.
- No contacts, and no background access to your device. We use the camera or photo library only when you add a moodboard image or choose a profile picture, and the microphone only when you record a voice note — and only at that moment. We don't browse your photo library, read your contacts, or collect anything you don't actively give Dormouse.
3. How we use your information
We process your personal data for the following purposes, under the legal bases listed:
- Providing the service (contract — Article 6(1)(b) UK GDPR): hosting your writing and syncing it across your devices through your account, generating AI overviews when you ask for them, and sending verification emails so you can use the app.
- Operating the service safely (legitimate interests — Article 6(1)(f)): enforcing the daily AI-call cap, validating that requests come from a genuine Dormouse build, debugging failures, preventing fraud and abuse.
- Communicating with you (contract / legitimate interests): replying when you contact us, sending essential service notices like password resets and verification emails.
We do not use your writing or your account data for any other purpose. We don't sell it, share it for marketing, profile you, or train AI models on it (see below for a specific note about Gemini).
4. Who we share data with
We share data only with the processors who help us run the service. We've chosen each one for security, reliability, and a clean privacy posture, and we have data-processing agreements in place with each.
4.1 Google (Firebase + Gemini)
We use Google services for the core infrastructure of the app:
- Firebase Authentication stores your email, hashed password, and account metadata.
- Cloud Functions for Firebase runs our backend code (verification emails, the AI proxy).
- Cloud Firestore is where your writing lives — notes, ideas, projects, story elements, AI-generated content, and the daily AI-call counter — held in your own per-user space and protected by security rules so only your signed-in account can read it.
- Cloud Storage for Firebase stores your voice-note recordings and moodboard images, in the same per-user, rules-protected space.
- Google Cloud Secret Manager stores the API key our backend uses to call the Gemini API.
- Google Gemini API processes prompts we send (containing your notes and project metadata) and returns AI-generated text.
Gemini and training. We use Gemini on Google's paid tier, which contractually does not use API inputs or outputs to train Google's models. This is materially different from the free tier, where data can be used for training. Dormouse uses the paid tier specifically for this reason.
4.2 Apple (Sign in with Apple)
If you sign in with Apple, Apple authenticates you and passes us your name and email (or a private-relay address if you chose that) at first sign-in. We don't send Apple any of your writing, and your stories are not stored in iCloud — they live in your Firebase account (Section 4.1). Apple's handling of your sign-in is governed by Apple's own privacy policy.
4.3 Resend
Our transactional emails — the verification email when you create an email/password account, and password-reset emails — are sent from noreply@dormouse.app through Resend, Inc., a US-based email delivery provider. Resend receives your email address in order to deliver the message, and records standard email-delivery telemetry. It doesn't receive your display name or any of your writing. Resend's privacy policy lives at resend.com/legal/privacy-policy.
4.4 We will never sell your data
We do not sell personal data, and we do not share it with third parties for their own marketing or advertising purposes. The only sharing we do is with the processors listed above, and only to the extent needed to run Dormouse.
5. Where your data is stored
- Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, and Secret Manager: Google Cloud servers in the United States (region: us-central1). This is where your writing, voice recordings, and moodboard images are stored.
- Resend (verification and password-reset emails): sent from noreply@dormouse.app through Resend, Inc.'s infrastructure in the United States. Only your email address and the message itself pass through it.
- Gemini API: Google's Gemini service infrastructure, primarily in the United States.
- Your device: your profile picture (if you set one) is stored only in Dormouse's local sandbox on your phone and is never uploaded. Voice transcription also happens on your device.
6. How long we keep your data
6.1 While your account is active
We keep your account data and your writing for as long as your account exists. Your writing stays in your account until you delete it, or until you delete your account.
6.2 When you delete your account
Deleting your account from Dormouse → Profile → Delete Account permanently erases your data:
- All of your writing in Firestore — every note, idea, project, story element, and AI-generated overview — is deleted.
- All of your files in Cloud Storage — voice-note recordings and moodboard images — are deleted.
- The daily AI-call counter document is deleted.
- Your Firebase Authentication record is deleted (email, hashed password, display name).
- Your profile picture and the "last signed-in user" marker on the device are cleared.
Your cloud data is erased first, while you're still signed in, and your account record is removed afterwards — so a completed deletion leaves no copy of your writing on our systems. If you'd rather clear your content without closing your account, Profile → Delete all data does the same wipe but keeps the account.
6.3 Backups and logs
- Function logs (request timestamps, user IDs, no content) are retained for 30 days, then auto-purged.
- Resend delivery telemetry (the record that an email to your address was sent and whether it arrived) is retained by Resend under its own retention policy — see resend.com/legal/privacy-policy. We don't copy it into our own systems.
- Your writing is stored in Google Cloud (Firestore + Cloud Storage), which provides encrypted, redundant storage. We don't keep separate copies outside that.
7. Your rights
Under UK GDPR and the Data Protection Act 2018 you have the following rights in respect of your personal data:
- Access. You can request a copy of the personal data we hold about you. Most of it (your writing, story structure, AI outputs) is already readable directly in the app. Email privacy@cyburon.com for anything else.
- Rectification. Correct inaccurate data. You can edit everything in your account directly in the app.
- Erasure. Delete your account at any time from Profile → Delete Account — this permanently erases your writing, recordings, and images from our systems (see Section 6.2). You can also clear your content without closing your account via Profile → Delete all data.
- Portability. The right to receive your data in a structured, machine-readable format. Honest disclosure: Dormouse does not yet have a built-in export feature. Email privacy@cyburon.com with a portability request and we'll arrange a manual export within 30 days.
- Restriction and objection. You can ask us to pause processing your data, or object to a specific use of it. Email us with the details.
- Withdraw consent. Where we rely on consent (e.g. verification emails), you can withdraw it by deleting your account.
- Complaint to the ICO. You always have the right to complain to the UK Information Commissioner's Office (see Section 1).
We'll respond to any rights request within 30 days of receiving it, and at no charge unless the request is manifestly unfounded or excessive.
8. International transfers
Some of the processors we use are based in the United States (Google, Resend). When your personal data is transferred to the US, the transfer is protected by one of the following safeguards:
- The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under that framework.
- Standard Contractual Clauses (UK addendum) between us and the recipient, where the recipient is not certified.
These mechanisms are recognised by the UK government as providing an adequate level of protection. You can ask us for details of which mechanism applies to a specific processor.
9. How we secure your data
- Encryption in transit: all connections between the app, our backend, and the third-party processors use TLS.
- Encryption at rest: Firebase Authentication, Firestore, Cloud Storage, and Cloud Functions all encrypt stored data at rest by default.
- API key protection: our Gemini API key never ships in the app binary. It's stored in Google Cloud Secret Manager and only readable by our backend.
- Authentication: we use Firebase Authentication with required email verification (or Sign in with Apple, which Apple has already verified).
- Genuine-build verification: AI features are gated by Apple's App Attest, which prevents anyone from calling our backend from outside a legitimate Dormouse install.
- Account deletion: available in-app at any time (Profile → Delete Account), as required by App Store guidelines.
No system is perfectly secure. If we ever discover a personal-data breach affecting you, we'll notify you and the UK Information Commissioner's Office within 72 hours as required by UK GDPR.
10. Children
Dormouse is intended for writers aged 17 and over. We do not knowingly create accounts for users under 17, and we don't market the app to children. If you believe a child has created an account, please email privacy@cyburon.com and we'll investigate and, if confirmed, delete the account and any associated data.
11. Changes to this policy
We may update this Privacy Policy from time to time — to reflect new features, changed processors, regulatory requirements, or simply to make the wording clearer. When we make a material change we'll:
- Update the "Last updated" date at the top of this page.
- Email registered users at least 7 days before the change takes effect.
- Surface a notice in the app on the next launch after a material change.
Continued use of Dormouse after the effective date constitutes acceptance of the updated policy. If you don't accept the changes, you can delete your account at any time.
12. Contact
Privacy questions, data subject requests, and complaints:
privacy@cyburon.com
Postal address:
CYBURON Ltd
66 Paul Street, London, EC2A 4NA