Privacy Policy
Effective date: [DATE] · Version 1.0 · Draft pending attorney review
1. Who we are
Threadright is the brand of [Legal entity name — e.g., Threadright LLC], located in [City, State], providing editorial analysis reports for fiction manuscripts. Contact: orders@threadright.ink.
2. What we collect
Order and intake information: your name, email, product selection, and the manuscript details you give us on the intake form. Your manuscript: the text you send us for analysis. Payment: handled entirely by our payment processor; we never see or store full card numbers. Correspondence: emails you exchange with us. Our services are for persons 18 and over. This website currently sets no analytics cookies and no advertising trackers; if we ever add privacy-respecting analytics, we will update this policy first.
3. How we use it — and what we never do
We use your information solely to produce your report, calibrate the analysis to your book, correspond with you, process payment, and meet legal obligations. We do not sell your information. We do not use it for advertising. Your manuscript is never used to train AI models — not by us, and not by our AI provider, whose commercial terms prohibit training on customer inputs.
4. Who processes it
Anthropic (AI analysis via commercial API, under no-training terms) · [Stripe] (payments) · [hosting/email provider] (website and email) · [storage provider] (encrypted file storage). Each receives only what its function requires. We share nothing else with anyone, except as required by law.
5. How long we keep it
Manuscripts and working analysis files are deleted [30] days after final delivery — or sooner on request; email us and we will confirm deletion in writing. Deliverables, intake records, invoices, and correspondence are retained as business records for up to [7] years. Revision re-audit customers may ask us to keep their analysis baseline between versions; we do so only on request.
6. How we protect it
Manuscripts and working files are stored encrypted with access limited to the operator; transmission to processors is encrypted. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you promptly at the email on file.
7. Your rights
Request access, correction, or deletion any time by email; we respond within 30 days. California residents have the rights described in the CCPA/CPRA; we do not sell or share personal information as defined there, and we never discriminate for exercising rights.
8. Changes
Updates will be posted here with a new effective date; material changes are emailed to customers with active engagements.