scriber.

Your words, handled with care

Privacy at Scriber

This notice explains what Scriber stores, what your assistant can read, and how to ask for help with your data.

Effective September 14, 2026 · Operated by MARTIN NICOLAS AUSILIO

What we collect and why

We use your email address to create your account, send sign-in codes, and respond to support requests. We store the writing you add: manuscripts and their version history, imports, story-bible entries, writing briefs, notes, prompts, reviews, generated files, narration, and related project information. Optional submission tracking can include contact details you enter for agents or other recipients.

We also store preferences, provider settings, usage and estimated-cost counters, and connection records. Hosting and security systems process technical information such as IP addresses, timestamps, request details, and errors to operate and protect the service. Please avoid including passwords or provider keys in manuscripts or support messages.

When text goes to an AI service

When you ask Scriber to generate or review something, the text and context needed for that request go to the provider selected for that feature. Depending on your settings, this can include OpenAI, Anthropic, OpenRouter and its selected model provider, or a narration provider such as ElevenLabs, Fish Audio, Google, Groq, or Microsoft’s Edge speech service. Some features use a shared provider account when available; the interface describes whether a connected account is needed.

For a direct ChatGPT or Claude connection, you explicitly choose one story. The assistant can read all its chapters, your writing brief, and confirmed story-bible entries, including confirmed facts from an owned shared universe. It also receives Scriber’s review methods and computed prose statistics. It cannot use these tools to edit your writing or call paid generation in Scriber. Reviews produced in the assistant are not automatically saved back to Scriber.

Copying or downloading a review package does not send its manuscript text to ChatGPT or Claude. Sharing it there is a separate action. Opening an assistant from Scriber does not put your manuscript in the link.

Third-party services apply their own privacy, retention, and model-training policies and your account settings. Scriber does not operate a model-training pipeline or sell manuscript content. Connecting an assistant does not transfer your ChatGPT or Claude subscription into API credit.

Infrastructure and credentials

Scriber runs on Vercel. Account and project records are stored in the application’s PostgreSQL database; uploaded and generated files use configured application storage, including Vercel Blob. Resend delivers sign-in and feedback emails. These providers process information needed to provide their services. Infrastructure and AI providers may process data outside your country.

Optional provider keys are encrypted in application storage and decrypted on the server when needed. OAuth access tokens and refresh tokens for Scriber’s assistant connection are stored as hashes. Optional ElevenLabs account authorization uses separate access and refresh tokens encrypted under your profile. The server uses them only for the speech access you approve. Disconnecting removes those credentials from Scriber and requests revocation at ElevenLabs. Speech you explicitly generate is sent to ElevenLabs and uses your workspace allowance. Browser read-aloud uses your browser’s voices; voices marked as a browser service may send text to that service. New file uploads are private and served through an ownership check. Older files and provider-held copies may have different retention or access characteristics; contact us about historical uploads.

Downloaded natural voices

Kokoro narration runs on your device, without sending the text being spoken to an AI provider. A voice download retrieves model and voice files from Hugging Face on the web, and GitHub on iOS; those hosts receive the normal connection information needed to deliver a download. Downloaded files remain in browser storage or app storage until you remove them or the device clears them. They are not account credentials. The public listening page does not send its text to Scriber or save it.

When you save a Kokoro audiobook, its audio and chapter labels are stored on this device, scoped to your signed-in account. They stay on the device unless you choose Save to Scriber. That action uploads a private copy, available to your signed-in account on other devices. Completed passages are retained to resume interrupted work. You can remove individual recordings, download a WAV or compressed MP3 chapter package, or explicitly share a copy to another app. Files saved to your account share its 1 GB allowance with manuscripts, revisions, reviews, images and other content. Remove account files in Library; a deleted upload reservation can take up to 16 minutes to release its space. Save to Files uses your device’s file providers, including cloud folders you have configured. It does not authorize background access to those cloud accounts. Browser copies disappear if you clear site data; iOS copies are excluded from backup and removed when the app is deleted. Device storage is not a private vault against someone who has access to your browser or unlocked device.

Browser voices are a separate option, and some use the browser vendor’s network service. Your manuscript’s normal Scriber storage and synchronization still apply when you use the writing desk.

Cookies and browser storage

Scriber uses secure session cookies for sign-in and temporary cookies for login and connection flows. Your browser also stores preferences such as theme and recovery copies of unsaved writing. Google Fonts may receive your IP address and ordinary browser request information when fonts load. Scriber does not include advertising trackers in the application.

Retention, deletion, and your choices

Project data stays available while your account and projects remain in Scriber. Moving a story or chapter to Trash is a soft deletion: it can be restored, and versions or backups may remain. Revoking an assistant connection stops future access; it does not erase content already shared with that assistant. Connections expire after at most 30 days unless you reconnect.

You can export your writing, remove provider keys in your profile, and revoke assistant access in Assistant connections. Delete your account from Profile on the website or Account → Delete account in the iOS app. We verify ownership with a separate email code. Access closes immediately, saved provider credentials are removed, and assistant connections are revoked. Your cloud content is queued for permanent removal, normally within 48 hours; interrupted cleanup is retried. Exported copies, other devices’ offline copies, backups and third-party conversations may remain under their own retention controls. For help, access or correction, contact contact@scriber.studio. We will explain any remaining legal or security retention.

Review accounts and updates

Directory reviewers use a separate account containing an original fictional sample. It does not unlock the normal writing studio or private user accounts. The sample and its connection records may be shared between reviewers, so reviewers should not enter personal writing there.

We update this notice when data handling changes and show the effective date above. Questions about this notice can be sent to contact@scriber.studio.