Privacy notice
Core promise: RQAI does not receive your local draft library by default, use it to train AI, sell it or monitor your writing. Content leaves your device only when you choose a connected feature.
Controller and scope
RQAI Ltd, United Kingdom, is controller for personal information it actually receives through Chapbook sales, trials, support, website operations and RQAI-operated functions. Contact support@rqai.co.uk with “Chapbook privacy” in the subject. A provider you connect may be an independent controller under its own notice. If you use Chapbook for an organisation or process other people's information, you may be a controller and are responsible for your own lawful basis and notices.
What stays on this device
Drafts, writing-partner sessions, snapshots, saved ideas and profile data are stored in IndexedDB. Provider configuration, your GitHub token, AI keys, optional R2 credentials, licence and legal-acceptance record are stored in browser local storage (including helm.studio.config.v1) or equivalent app storage. RQAI cannot retrieve local-only data. On a shared or compromised device, browser storage can be exposed; use device access controls and least-privilege tokens.
Optional data flows you control
- GitHub: publishing and repository operations go from your browser to your repository. The device-login relay forwards the GitHub handshake, applies abuse-rate limiting and stores no token or draft.
- AI: prompts, relevant draft/profile context, images or requested source material go directly to the active Anthropic, OpenAI, Google Gemini or Groq account using your key. Provider retention, training controls, locations and terms apply.
- Private dictation: recorded audio is transcribed by a self-hosted Whisper model on this device after the model download. Live dictation instead uses the browser/operating-system speech service, which may send audio to its vendor.
- Cloudflare R2: optional media goes to your bucket, directly or through a Worker you configure. RQAI does not operate your bucket.
- Crossref and external media: DOI lookups and assets you deliberately fetch reveal normal request metadata to the destination.
Information RQAI receives, purpose and lawful basis
- Purchase/licence details: name, email, Stripe event/customer/payment references, product and licence status — to perform the contract, deliver and support a licence, meet accounting/legal obligations and prevent fraud.
- Trial request: typed email, product and request time in a private GitHub queue; a one-way canonical-email hash prevents repeat trials. The function temporarily uses an IP address for rate limiting — contract steps and legitimate interests in abuse prevention.
- Operational request data: Netlify and its infrastructure may process IP address, URL, time, browser and security metadata to deliver and secure the site — contract and legitimate interests in reliability/security.
- Support: email address, message and attachments you send — contract steps, legitimate interests in support/claims and legal obligation where applicable.
- Anonymous totals: per-day visit/install/activation counters in Netlify Blobs contain no IP, token, licence or user identifier — service measurement and legitimate interests.
- Optional consent: only where specifically requested for future non-essential storage or marketing. Consent can be withdrawn as easily as given.
Accepting the Terms is contractual. Acknowledging this notice is not consent to all processing and does not activate AI or publishing.
Recipients and international transfers
RQAI's relevant supplier categories are Netlify (hosting/functions/blobs), GitHub (private fulfilment queue and optional user publishing), Stripe (payments), email/communications suppliers and professional advisers or authorities where legally required. Optional AI, GitHub and Cloudflare recipients are selected by you. Providers may process outside the UK/EEA; their adequacy mechanism, UK IDTA/Addendum or standard contractual clauses and transfer-risk controls should be reviewed before confidential/personal data is sent. We do not sell personal information or share it for behavioural advertising.
Retention
- Local data: until you delete it, clear site/app data or uninstall; remote copies follow the destination's retention.
- Trial queue and fulfilment records: for the trial/anti-abuse period and then only as needed for support, fraud prevention or legal claims.
- Purchase, licence and accounting records: for the applicable tax and limitation periods (commonly up to six years after the relationship ends in the UK).
- Support correspondence: normally up to 24 months after closure, longer for an unresolved dispute or legal duty.
- Hosting/security logs: for Netlify's configured operational/security period; incident extracts may be retained while an investigation or claim is active.
- Anonymous daily counters: may be retained for longitudinal product measurement because they contain no user identifier.
Sensitive information and children
Chapbook does not ask for special-category data. Avoid sending health, biometric, political, religious, sexual-orientation or other sensitive information to AI unless you have an Article 6 basis and, where applicable, an Article 9 condition. Do not record people covertly. Chapbook is not directed to children under 16; younger use requires parent/legal-guardian acceptance and supervision.
Your rights
Subject to legal conditions, UK/EU rights may include access, correction, erasure, restriction, portability, objection, withdrawal of consent and safeguards for significant solely automated decisions. Chapbook does not make such decisions about users. Most drafts are only on your device, so use Export or Settings → Sign out & forget this device. For information RQAI holds, email support. We may verify identity and respond within the statutory period.
Right to object: you may object to processing based on legitimate interests. You have an absolute right to object to direct marketing; Chapbook performs no behavioural advertising.
You may complain to the UK Information Commissioner's Office at ico.org.uk or, where EU GDPR applies, your local supervisory authority.
Security, deletion and changes
Controls include HTTPS/HSTS, restrictive CSP, local-first storage, sandboxing/sanitisation, self-hosted local transcription, scoped provider calls, rate limits and signed licences. No system is perfectly secure. Revoke provider tokens if a device is lost. A material notice change receives a new version and renewed acknowledgement where appropriate.