Privacy by Design: How We Guard Your Legacy
1. Infrastructure & Legal Framework (The Foundation)
The privacy of user data is legally guaranteed through our downstream agreements with infrastructure providers. We do not use "free tier" APIs that claim rights to user content.
Intelligence Layer (Google Gemini API - Paid Commercial Tier)
- Protection Mechanism: We utilize the paid/commercial tier of the Google Gemini API (specifically Gemini 1.5 Pro and Flash models).
- Archival Grade Accuracy: For handwriting and historical documents, we employ high-fidelity "Archival Grade" models to ensure pixel-perfect transcription (< 0.2% error rate).
- Legal Guarantee: Under Google’s Cloud Data Processing Addendum, input and output data are NOT used to train their foundation models.
- Data Isolation: Customer data is processed statelessly and is not stored in shared model weights.
Hosting Layer (AWS - Commercial Terms)
- Protection Mechanism: Logic and databases reside on Amazon Web Services (AWS).
- Shared Responsibility Model: We inherit AWS's ISO 27017 compliant security. AWS does not access customer data for marketing or training.
Storage Layer & Public Hosting (Amazon S3 Site Service)
- Default Secure State: By default, all user uploads and generated dossiers are stored in private AWS S3 buckets and delivered via time-limited, cryptographically signed URLs.
- Opt-In Public Hosting ("Share with Family"): You have the option to host your generated dossier as a public site for easy sharing. Please be aware that this public hosting is NOT secure by default, as it creates an open URL accessible to anyone with the link.
- Hosting Lifecycle: This public hosting service is strictly opt-in (and you may opt-out at any time by cancelling). It is provided completely free for the first 7 days, after which it requires a subscription fee of $4.99 per month to maintain active public access. Cancelling the subscription will immediately revoke public access and seal the archive.
2. Architectural Design Practices (The "Vault")
Our system architecture is designed to minimize "data residency" risks. We treat user memories as sensitive artifacts, not a data lake.
Server-Side Proxying
All API interactions occur on a secure backend (AWS Lambda), ensuring API keys are never exposed and allowing PII stripping before data leaves our "vault".
Ephemeral Context
The Theirloom AI engine uses temporary context windows. Once a session ends, the AI's "active memory" is cleared. We simulate strict cross-tenant isolation.
No "Community" Training
We explicitly DO NOT aggregate user stories to train a master model. Your "Writer DNA" is kept separate from your personal "Memory Data".
3. Product Design & Output (The "Anti-Slop" Factor)
Our product roadmap enhances privacy by focusing on static, permanent digital artifacts rather than "always-on" digital surveillance.
The "Artifact" Strategy
The journey ends with a permanent digital archive. We are incentivized to archive and cold-store data, not keep it live for ad-targeting.
Private "Silo" Accounts
Accounts are single-user vaults. We do not offer public galleries by default. Sharing is intentional (handing someone a book), not algorithmic.
3.5 "Glass Vault" - Privacy-Preserving Analytics
We collect anonymous feedback to improve our service while maintaining strict separation between your creative content and operational data.
✓ What We Collect (Anonymous)
- • Satisfaction ratings (Happy/Neutral/Sad)
- • Page views (sanitized, no PII in URLs)
- • Purchase categories (e.g., "bought Digital")
- • Session IDs (ephemeral, memory-only)
✗ What We Never Access
- • Your manuscript content
- • Character names or story details
- • Uploaded photos or documents
- • IP addresses (resolved to region, then deleted)
🔒 The "Air Gap" Architecture
Our marketing systems are cryptographically separated from your creative content. The marketing Lambda functions have explicitDENY permissions on all content storage buckets.
Manuscripts, photos, AI context
Purchase history, email, preferences
4. Terms of Service
Intellectual Property Rights
You retain full ownership of the source documents you upload. Upon full payment, you are granted complete ownership rights to the generated novel and any associated output files (PDF, ePub, Scribus files).
Legal Basis: Consistent with Thaler v. Perlmutter (2023) and emerging AI authorship frameworks where the human creative direction determines ownership.
Prohibited Content
You may not upload content that is illegal, offensive, violates the rights of others, or infringes on third-party intellectual property. We reserve the right to refuse service for any content we deem inappropriate.
- Content promoting violence, hate speech, or illegal activity
- Copyrighted material you do not have rights to
- Private information of third parties without consent
Limitation of Liability
Theirloom.io is provided "as is". We are not liable for any damages arising from the use of our service, including but not limited to data loss, inaccuracies in generated content, or service interruptions.
Our maximum liability to you is limited to the amount you paid for the specific service. This limitation is consistent with industry standards for AI-generated content services.
AI-Generated Content Notice
Output is generated using AI models. While we strive for accuracy, AI may occasionally produce factual errors or "hallucinations." You are responsible for reviewing and verifying the final output before publication or distribution.
Data Retention Policy
For more on our "Digital Shredder" and 7-day auto-deletion policy, please consult our Security page.
View Security Standards →