Privacy Policy

Last updated: August 30, 2026

Who We Are

This Privacy Policy describes how FirstReader LLC ("we," "us," or "FirstReader") collects, uses, and protects information about you. FirstReader is a South Carolina limited liability company.

What We Collect

FirstReader collects the account information you use to sign in and other information you choose to provide through the site. When you upload a manuscript, we store the manuscript text, metadata you provide (title, genre, POV mode, character list), and the analysis results FirstReader generates. We may also collect the technical and usage information described below.

If an upload is rejected by a manuscript-content check, FirstReader may automatically retain a content-free diagnostic record linked to your account. It includes a random support reference, the rejection stage, file format and size, aggregate extraction and language measurements, and timestamps. It does not include the manuscript title, filename, manuscript text, excerpts, or a copy of the rejected file. After a rejection, you may separately and explicitly choose to share a private copy of that file with FirstReader support for diagnosis.

FirstReader may collect IP addresses, browser strings, page paths, clicks and visits, browser and session data, and date and time of visit from its website visitors. FirstReader uses Google Analytics on its website to collect visitor data, including sessions, views, events, conversions, changes in clicks and visits, session channel groups and visitor sources (i.e., how people find and access our website), page paths, date of visit, country, region, city, event names, day of week of visit, and level link clicks, as well as other information or data about use of our website. The information obtained by FirstReader through Google Analytics includes aggregated reporting and pseudonymous data, including browser and session identifiers, internal manuscript and analysis-related identifiers, transaction identifiers, analysis tier, and purchase value. These identifiers do not contain manuscript text or titles, although some can be associated with an account or manuscript using FirstReader's own records. Information obtained through Google Analytics is transmitted to Google and subject to Google's data privacy policies.

FirstReader also uses Microsoft Clarity on its public marketing pages to understand how visitors use the site, through aggregated heatmaps and session recordings of scrolling, clicks, and navigation. Clarity applies content masking, and it is not loaded on the pages that display your manuscripts or analysis reports. Information collected through Clarity is transmitted to Microsoft and subject to Microsoft's data privacy policies.

How We Use Your Data

  • Manuscript text is sent to Anthropic for analysis and is stored and processed by the infrastructure providers described below. We do not sell your manuscript. We disclose manuscript text or related metadata only to service providers needed to store, process, secure, deliver, or bill for FirstReader, as described in this policy.
  • Rejected-upload diagnostics help us identify upload and content-check problems. Administrators see anonymous aggregate rejection totals. They can retrieve an individual content-free record only with its exact support reference, unless you explicitly shared the rejected file. Access to a shared file is limited to authorized administrators and is logged. Support normally uses a bounded preview; downloading the full file is reserved for exceptional diagnosis.
  • Analysis results are stored so you can access your reports at any time while service remains available.
  • Email address is used for account access, password resets, and occasional product updates. We will never sell your email or share it with third parties for their marketing purposes.
  • Payment information is handled entirely by Stripe. We never see or store your credit card number.

Your Manuscript is Yours

To the extent permitted under applicable law, you retain full ownership and copyright of your manuscript at all times. Uploading to FirstReader does not grant us any rights to your work beyond the limited, process-only license described in our Terms of Service.

AI Training: Our Commitment

FirstReader does not use your manuscripts to train AI models — our own or any third party's — now or in the future, without your express separate written consent.

We also take reasonable steps to ensure our AI partners do not use API inputs (your manuscript text and our prompts) to train their models.

Data Storage, Retention, and Deletion

We store your manuscripts and analysis results so you can access them while the service remains available.

Files too large for our ordinary upload route are transferred directly from your browser to private Supabase Storage under a time-limited, single-file authorization. An accepted file becomes the stored source for your manuscript. If validation rejects the file, FirstReader immediately requests deletion and verifies that the object is absent; failed attempts are retried, and automated cleanup repeats the check after the signed authorization expires. If an upload is abandoned before validation, it becomes cleanup-eligible when that authorization expires and is removed by the next daily cleanup, normally within 24 hours. Because a resumable provider transfer URL can remain technically usable after the signed authorization expires, the next daily cleanup after the provider's maximum transfer window performs a final deletion and absence verification; that window is conservatively treated as 26 hours after authorization. Content-free upload lifecycle metadata becomes eligible for deletion after 30 days.

Content-free rejected-upload diagnostic records become eligible for deletion after 30 days and are removed by daily automated cleanup. If you explicitly share a rejected file for diagnosis, support access ends seven days after upload authorization. The private Storage copy is then queued for the next daily cleanup, normally within 24 hours; failed cleanup attempts are retried daily. It may be deleted earlier by an administrator. Requesting account deletion also removes any account-linked shared diagnostic file before the account is deleted. A deleted shared file cannot be restored from FirstReader's database backups because Supabase Storage objects are not included in those backups.

When you delete a manuscript, FirstReader permanently deletes its stored source file and the application records that make up the manuscript and its reports, including manuscript text, scene content, analysis results, character data, generated reports, and any linked Perception Scan. Limited records maintained separately from the manuscript may remain, including payment and cost records and content-free security-event metadata. Where applicable, their manuscript link is removed, and any stored prompt-injection text excerpt is deleted.

When you request account deletion, we schedule deletion after a seven-day grace period. You may cancel during that period. After the grace period, we delete your sign-in account, profile, stored API key, manuscripts, source files, reports, and other account-linked application records.

Deletion from FirstReader's active systems does not necessarily delete records maintained independently for payments, accounting, security, legal compliance, email or comments, subscriptions, analytics, system logs, or service-provider operations. Deleted database records may also remain temporarily in restricted backups until those backups expire or are overwritten. See Third-Party Services below for provider-specific handling.

Your Rights

Regardless of where you live, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete manuscripts and your account using the controls in FirstReader, or contact us about independent records not covered by those controls.
  • Export your reports in a machine-readable format (available in-app).
  • Withdraw consent for processing where consent is the basis.
  • Object to or restrict processing in certain circumstances.

To exercise any of these rights, email privacy@firstreader.app.

If you are a resident of the European Union, the United Kingdom, or California, you have additional rights under the GDPR, UK GDPR, or CCPA, including the right to data portability and the right to lodge a complaint with a supervisory authority (such as your national data protection authority or the California Attorney General). If you wish to exercise any location-based privacy rights, please submit a request to FirstReader by contacting us directly. Please keep in mind that we may require additional information from you to verify that you are the rightful owner of the personal data you wish to access.

We do not sell your personal information. We do not share it with third parties for their independent marketing purposes.

Third-Party Services

FirstReader uses the following service providers to operate, secure, communicate about, and measure the service. Each provider processes data under its own terms and privacy practices. Deleting data from FirstReader does not necessarily delete provider-held records immediately. Provider retention may depend on the service used, FirstReader's account configuration or plan, backup cycles, legal obligations, and fraud or security needs.

  • Anthropic (Claude API) processes manuscript text and FirstReader prompts to generate analysis. Anthropic states that commercial API inputs and outputs are not used to train its models by default and are normally deleted from its backend within 30 days. If content is flagged by its trust-and-safety systems, Anthropic states that it may retain flagged inputs and outputs for up to two years and related safety-classification scores for up to seven years. Different features, agreements, safety requirements, or legal obligations may also change retention.
  • Supabase provides authentication, database, and private source-file storage. Database backups may temporarily retain deleted database records until the applicable backup expires. Supabase states that database backups do not contain Storage objects, so restoring a database backup does not restore a deleted source file.
  • Stripe provides checkout and payment processing. Stripe receives payment and transaction information. FirstReader also sends internal account and manuscript identifiers, the manuscript title in the checkout description, analysis type and tier, applicable billable word count, and available analytics identifiers. FirstReader does not receive or store your complete card number. Stripe retains information independently for payment, fraud, legal, and regulatory purposes and states that, in most jurisdictions, it generally keeps personal data received from business users for five or more years after the business relationship or last transaction, whichever is later.
  • Vercel hosts FirstReader's website, authenticated application, and API routes. It may process request information, IP addresses, URLs, and application or runtime logs. Runtime-log retention follows FirstReader's active Vercel plan and enabled observability features.
  • Resend delivers and receives FirstReader email. It processes sender and recipient addresses, subjects, message content, and delivery metadata for account and report notifications, support messages, and opted-in updates. Report notifications may include your manuscript title and a FirstReader link. Resend states that customer data is processed while FirstReader's service agreement remains active and deleted within 90 days after FirstReader terminates its Resend account, subject to its terms and legal obligations. That provider-account period is separate from deleting an individual FirstReader account.
  • Google Analytics measures use of FirstReader's public and authenticated pages through cookies, pseudonymous browser and session identifiers, and the analytics information described above. Retention of user-level and event-level data depends on FirstReader's Analytics property settings. Google states that deleting a user's Analytics data does not delete associated aggregate data, such as visited page URLs.
  • Microsoft Clarity provides heatmaps and session playback on public marketing pages. It is not loaded on pages that display manuscripts, reports, account settings, jobs, administrative data, or Perception Scan results. Microsoft currently documents 30-day retention for playback data and nine-month retention for click data, heatmaps, and labeled or favorited sessions.
  • Google Cloud runs FirstReader's manuscript-analysis worker and stores operational logs. Manuscript text and analysis data are processed there. Logs can contain internal identifiers, manuscript titles, chapter headings, and error or operational context. FirstReader's current Google Cloud configuration retains ordinary application logs for 30 days and required audit logs for 400 days.
  • Sentry provides application and worker error and performance monitoring. Error messages, stack traces, breadcrumbs, and operational context may be sent to Sentry. FirstReader disables Sentry session replay and applies credential-pattern scrubbing before events are sent. Event retention follows FirstReader's active Sentry plan; Sentry currently documents 30 days for its Developer plan and 90 days for paid plans.
  • Upstash provides Redis-based API rate limiting. FirstReader uses an IP address as a short-lived identifier for one-minute sliding-window rate limits and does not enable Upstash's optional rate-limit analytics.

International Data Transfers

FirstReader is a US-based company, meaning your data may be internally transferred, stored and processed within the United States as well as any other locations where FirstReader operates and/or performs services. Further, FirstReader may transfer, process or store your data to its service providers, contractors or vendors which may be located within the United States or elsewhere around the world. This means that FirstReader may transfer, store and/or process your personal data outside of your country of residence (or outside of the European Economic Area ("EEA") for individuals living within the EEA, UK or Switzerland). Any such data transfers shall be made in compliance with any applicable laws as they apply to FirstReader in its collection, use or transfer of your personal data. FirstReader has implemented adequate safeguards to protect your personal data in accordance with this Policy and such applicable laws.

Cookies

We use essential cookies for authentication (keeping you logged in) and session management. We also use cookies to help understand how visitors use our website so that we can improve our offerings, make our website more accessible, and for tracking analytics.

Children's Privacy

FirstReader's Terms of Service require users to be at least 16. If we learn that we have collected information from a child under 16, we will delete it promptly.

Copyright Matters

For DMCA takedown notices and copyright-related inquiries, see our Copyright & DMCA Policy.

Changes to This Policy

We may update this policy as the service evolves. Significant changes will be communicated via email at least 14 days before they take effect, where practicable. The "last updated" date at the top of this page reflects the most recent revision.

Contact

Questions about this policy? Contact us at privacy@firstreader.app.

FirstReader LLC
6650 Rivers Ave., Suite 100
Charleston, SC 29406