The Unwritten Prompt

Legal

Privacy Policy — Development Draft

How The Unwritten Prompt handles prompts, generated stories, purchases and reports.

Version draft-2026-09-10 · Updated 2026-09-28T22:03:37.892Z

DEVELOPMENT DRAFT — replace every [PLACEHOLDER] before store submission.

1. Controller

The data controller is [LEGAL NAME OR COMPANY], tax identifier [TAX ID], with address at [REGISTERED ADDRESS]. Privacy contact: [PRIVACY EMAIL].

2. Data we process

The app creates a pseudonymous account from a one-way keyed transformation of a random installation identifier. We process the story premise and chosen language, technical generation metrics, gameplay achievement progress, entitlement and purchase records supplied by Apple or Google, and content excerpts that you explicitly submit through the reporting tool. If you enable a platform gaming profile, Apple or Google separately processes that profile under its own terms. We do not intentionally request your real name, contacts, precise location or advertising identifier.

3. Why we use it

We use this information to provide and secure the game, generate and recover campaigns, prevent duplicate charges and abuse, verify purchases, respond to reports, meet legal obligations and maintain the service. The principal legal bases are performance of the service contract, legitimate interests in security and reliability, and compliance with legal obligations. Optional processing will use consent where required.

4. AI processing

Your premise is sent by our server to the AI provider selected for the service. Depending on configuration and region, this may be [CURRENT AI PROVIDERS AND REGIONS]. Do not enter personal, confidential or sensitive information. International transfers, where applicable, must be covered by [TRANSFER SAFEGUARD].

5. Retention

Pending premises and completed campaign packages are encrypted and automatically erased no later than 24 hours after the relevant job or completion. Technical generation records exclude prompt and story text. Explicitly reported excerpts are retained for up to 12 months. Purchase, accounting and fraud-prevention records are retained for [STATUTORY RETENTION PERIOD]. Operational security logs are retained for [LOG RETENTION PERIOD].

6. Sharing and portable stories

Data is disclosed only to infrastructure, AI and store-payment providers needed to operate the service, and to authorities where legally required. Current processors: [HOSTING PROVIDER], [AI PROVIDERS], Apple and Google as applicable. We do not sell personal data or use prompts for advertising. You may deliberately export a signed story and send it through a service of your choice; we do not receive that transfer merely because you export the file. If you use in-app friend delivery, our server temporarily stores the package encrypted at rest for up to 7 days and deletes it after collection or rejection. The server processes imported packages to verify integrity and safety status, without adding them to a public story library. If either party explicitly reports one, the reported content and its share identifier are processed under section 5. Copies already delivered outside our systems cannot be remotely deleted.

7. Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and complain to your local supervisory authority. Contact [PRIVACY EMAIL]. A deletion mechanism and response procedure must be finalized before release.

8. Children and security

The service is not directed to children below [MINIMUM AGE]. We use transport encryption, access controls and encrypted temporary job storage, but no system can guarantee absolute security.

9. Updates

Material revisions are versioned and shown in the app. Effective date: [EFFECTIVE DATE].