ForkBar Privacy Policy
Effective Date: [Launch Date — to be set] Last Updated: 2026-05-26
⚠️ Draft note for review: This draft reflects ForkBar's specific data-handling design (immediate hard delete + tombstone, 16-entity export, 2-tier cookie consent). Before launch, recommend running it past a privacy lawyer for jurisdiction-specific compliance review. Placeholders marked
[…]need to be filled in.
1. Who we are
ForkBar (the "Service") is an AI-assisted collaborative fiction platform. Users create story projects, generate chapters with AI assistance, and "fork" other users' public chapters to write alternate narrative branches. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights.
The data controller is [Entity Name], [Jurisdiction]. Contact: [privacy@forkbar.app or substitute].
2. Data we collect
We collect only the data we need to operate the Service. Categories:
2.1 Account data (provided by you)
- Email address
- Username (you choose, must be unique)
- Password hash (only for email/password accounts; we never see your plaintext password)
- Optional: bio, avatar URL
2.2 Authentication-provider data
When you sign in with Google, we receive from Google:
- Your email address and email-verified status
- Your Google account identifier (
subclaim) - Your display name and profile picture (used for default avatar)
We do not receive your Google password. We do not access your Google contacts, calendar, drive, or any other Google product data.
2.3 Content you create
- Story projects (title, premise, genre, tone, language, rating, cover image)
- Chapters (text content you write or generate with AI assistance)
- Character sheets, world bibles, and other story assets
- Chat messages exchanged with the in-product AI assistant
- Forks (when you fork another user's chapter to start a branch)
2.4 Usage data
- Pages visited within the Service
- Actions taken (e.g., project created, chapter published, fork created)
- Browser type, operating system, screen size
- Approximate location derived from IP address (country-level only)
- Session recordings of your interactions with the UI (see Section 4 on cookies and Section 6 on PostHog session replay; user-authored prose, chat content, and asset JSON are masked from these recordings)
2.5 Technical / error data
- Error messages and stack traces when something goes wrong
- Request metadata (URL path, timestamp, response status) with personal identifiers (email, IP, auth tokens) scrubbed
- LLM-generation telemetry (tokens used, cost, model selected, duration) — not the prompt or response content
2.6 Payment data
If you subscribe to a paid plan, payment is processed by Stripe. We do not see or store your full card details. We retain only:
- Stripe customer ID and subscription ID (opaque identifiers)
- Subscription status (active, past_due, canceled, etc.)
- Subscription period end date (for renewal display)
3. How we use your data
We use your data only for the purposes listed below.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Operate the Service (display your stories, save your chapters, etc.) | Account data, content, auth-provider data | Contract performance — Article 6(1)(b) |
| Detect and fix bugs / maintain Service stability | Error data, technical data | Legitimate interest — Article 6(1)(f) |
| Process payments | Payment data | Contract performance — Article 6(1)(b) |
| Product analytics (understand which features users engage with, fix activation funnel issues) | Usage data | Consent — Article 6(1)(a); you control via cookie banner |
| Send transactional emails (password reset, email verification, payment receipts) | Email address | Contract performance — Article 6(1)(b) |
| Comply with legal obligations (tax, anti-fraud, law-enforcement requests) | Any data as required | Legal obligation — Article 6(1)(c) |
We do not:
- Sell your data to third parties
- Use your content to train external AI models (your prompts/responses go to LLM providers under the contract terms described in Section 6)
- Use your data for advertising or behavioral profiling
- Share your data with marketing affiliates
4. Cookies and similar technologies
ForkBar uses cookies in two tiers. You control the second tier via our cookie consent banner.
4.1 Necessary cookies (always active)
These are required for the Service to function and cannot be disabled.
- Session cookie (
forkbar_session): keeps you logged in - CSRF token cookie: protects against cross-site request forgery
- Consent state cookie: remembers your cookie choices
- Locale cookie (
forkbar_locale): remembers your language preference
4.2 Analytics cookies (require your consent)
These are not active until you opt in. If you opt out (or never opt in), no analytics or session-replay data about you is collected.
- PostHog cookies: product analytics, session replay, funnels (see Section 6.3)
We do not use Marketing or Advertising cookies. We will update this Policy and add a third "Marketing" consent tier before introducing any such cookies; you will be re-prompted when this happens.
5. How long we keep your data
| Data category | Retention |
|---|---|
| Active account data + content | Indefinitely while your account is active |
| Deleted account data | Immediately and permanently deleted when you request account deletion (see Section 7). Your public chapters and forks remain visible but are anonymized to [deleted]. We do not retain a recovery window. |
| Sentry error data | 90 days (Sentry-side retention) |
| PostHog analytics data | 1 year (PostHog-side retention) |
| Email logs (sent via Resend) | 30 days |
| Stripe billing records | 7 years (retained by Stripe per tax-record requirements; we hold only references) |
| Backups | Up to 30 days in encrypted point-in-time backups maintained by GCP Cloud SQL. Deleted-account data is purged from backups within 30 days of deletion. |
6. Who we share your data with (sub-processors)
We share your data only with the following third-party service providers, and only to the extent necessary to operate the Service. Each is bound by a data processing agreement (DPA).
| Sub-processor | Purpose | Data accessed | Where data is processed |
|---|---|---|---|
| Google LLC | Sign-in via OAuth; Google Cloud Platform hosting | Email, OAuth identifier (sign-in); all platform data (hosting) | United States |
| Stripe Inc. | Payment processing | Email, billing address, card details (Stripe sees, we don't), purchase records | United States |
| PostHog Inc. | Product analytics, session replay, funnels | Usage events with structured properties (no prose, chat content, or asset content) | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | Error stack traces with personal identifiers scrubbed | United States |
| Vercel Inc. | Web frontend hosting | Request traffic to apps/web (no persistent storage of personal data) | United States |
| Resend (Resend Inc.) | Transactional email | Email address, message content (verification links, password resets) | United States |
| OpenRouter / xAI / Anthropic / OpenAI / Google AI | LLM generation | Prompts and generated responses passed through; each provider's own terms govern (we use their API contract, not their training data terms) | United States |
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, your data is transferred to the United States. Each sub-processor relies on the EU–US Data Privacy Framework or Standard Contractual Clauses (SCCs) for such transfers.
We will update this list and notify you of material changes before adding a new sub-processor.
7. Your rights
You have the following rights regarding your personal data. Most can be exercised directly from the Service; for any you cannot exercise yourself, contact us at [privacy@forkbar.app].
7.1 Right to access
You can download all data we hold about you at any time:
- Go to
/settings→ Data export - We will email you a machine-readable JSON file (or generate a download link if the export is large) containing all data described in Sections 2.1–2.5 (excluding LLM-intermediate state and Stripe-managed billing records, which you can request from those providers directly)
7.2 Right to deletion ("right to be forgotten")
You can permanently delete your account at any time:
- Go to
/settings→ Delete account - You will be asked to confirm by typing
DELETE - On confirmation, your personal data is immediately and permanently deleted. Your public chapters and forks remain visible but anonymized to
[deleted], preserving the experience of other users who built on or read your work. - This action is final and cannot be undone. There is no grace window. If you contact support claiming to have deleted your account by mistake, recovery may be possible only via emergency database backup within 30 days; this is not a guarantee.
7.3 Right to rectification
- Update your email, username, bio, avatar, and other profile fields at
/settings→ Profile - Email changes require re-verification via a link sent to your new email address
7.4 Right to portability
The export at /settings → Data export is provided in JSON format suitable for porting to any system that accepts it. The structure is documented at [link to data-format doc, to be added].
7.5 Right to object / withdraw consent
- Opt out of analytics at any time via the cookie banner footer (or
/settings→ Privacy preferences) - After opt-out, PostHog stops collecting new data immediately; previously collected data is deleted from PostHog within 30 days
7.6 Right to lodge a complaint
If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first; please contact [privacy@forkbar.app] before doing so.
7.7 Right not to be subject to automated decision-making
We do not make automated decisions with legal or significant effects about you. AI-assisted content generation operates only on your explicit prompts and does not affect your legal rights.
8. Children
The Service is not intended for use by anyone under 13 (or under 16 in the EEA, where applicable). We do not knowingly collect data from children. If you believe a child has provided data to us, please contact us and we will delete it.
9. Security
We protect your data with reasonable technical and organizational measures:
- Encryption in transit (HTTPS / TLS 1.2+ on all connections)
- Encryption at rest (GCP Cloud SQL + GCS managed encryption)
- Password hashing with bcrypt (12 rounds)
- Session cookies marked HttpOnly + Secure + SameSite=Lax
- Strict Content Security Policy headers
- Access to production systems limited to authorized personnel using least-privilege IAM roles
- Regular dependency updates and security patches
No security system is perfect. If we become aware of a breach affecting your data, we will notify you and (where required) the relevant data protection authority within 72 hours.
10. International users
ForkBar is operated from the United States. By using the Service, you understand that your data may be processed in the United States and other countries where our sub-processors operate. Where required (EU/UK/CH), we rely on EU–US Data Privacy Framework or Standard Contractual Clauses for such transfers.
For users in California, you have additional rights under the California Consumer Privacy Act (CCPA): rights of access, deletion, correction, and non-discrimination for exercising those rights. The mechanisms in Section 7 fulfill these rights.
For users in China, ForkBar's launch market is EN-primary; we do not currently operate dedicated infrastructure in China and have not filed PIPL local-storage compliance. Future ZH-market expansion will be accompanied by a Policy update.
11. Changes to this Policy
We will update this Policy from time to time. If we make material changes that affect how we collect, use, or share your data, we will:
- Update the Last Updated date at the top
- Notify you via email at least 14 days before the changes take effect (for material changes)
- Display a prominent notice in the Service when you next visit
You can review previous versions of this Policy at [link to version history, to be added].
12. Contact us
For any privacy questions or to exercise your rights, contact us at:
- Email: [privacy@forkbar.app]
- Postal: [Entity Name, Address — to be filled]
If you are an EEA resident and need a data protection representative, [our representative is X / we do not yet have one — to be confirmed].
ForkBar is built by a small team. We do our best to make this Service trustworthy, but we are not a law firm and this Policy is not legal advice. If you have legal questions about your rights, consult a qualified privacy lawyer.