Mythwrites

Privacy Policy

Effective date: 7 August 2026 · Written with India’s Digital Personal Data Protection Act, 2023 (DPDP) in mind
Last updated: 6 September 2026

Mythwrites is a writing and worldbuilding tool operated by Vishal Kundar, trading as Myrmidon Studio (a sole proprietorship registered in India), and published at mythwrites.com. In this policy “Mythwrites”, “we” and “us” mean that operator, and “you” means the person using the service. On a Paddle receipt or payment statement you may see the account name Myrmidon Studios: that is the same business.

The short version

Your manuscripts are yours. We store them so you can reach them from any device, and for nothing else. We do not sell your data, we do not read your writing for product or marketing purposes, we run no advertising or analytics trackers, and we never send your work to an AI model on our own initiative. A run happens only when you start one: Included Mythic AI goes through our server to Together AI, while bring-your-own-key AI goes directly from your browser to the provider you picked. We never see your card details: payments are taken by Paddle, our merchant of record. Delete your account and we delete your projects, your profile and your login, with two exceptions on projects owned by other people that are set out in full below.

What we collect, and why

We do not collect your date of birth, government ID, location, contacts, or any biometric data. We set no advertising or analytics cookies. Your sign-in session is held in host-scoped Supabase SSR cookies. In production they are Secure and SameSite=Lax; they are intentionally not HttpOnly because the browser Supabase client maintains the session. Legacy Supabase localStorage auth data is cleared during migration; local demo/project state may still use browser storage.

Where your work is stored

Project content is stored as structured data in a Postgres database hosted by Supabase in the Northeast Asia (Tokyo) region, protected by row-level security so that only you and the collaborators you invited can read it. Images go into a private bucket and are served through short-lived signed links rather than public URLs. The application is served through Fly.io in production.

That region is in Japan, so your data is stored and processed outside India. We are telling you plainly rather than leaving it to be inferred: if you would rather your writing not leave the country, this is the point to decide, and you can export everything and close your account at any time. As at the effective date of this policy the Indian government has not restricted transfers to any country under the DPDP Act. If we move the database to another region we will say so here before the move.

Who else touches your data

This is the complete list of processors we use. We name them individually, rather than by role, so you can go and check them yourself.

There is no other payment processor in this list, and no second one is taking your money today. If we ever add or change one we will name it here before it receives anything, and an existing subscription stays with the provider that created it.

We use no advertising networks, no analytics platforms, no session recording tools and no data brokers. We do not sell, rent or share your personal data or your writing with anyone for their own purposes.

AI features: exactly what leaves your device

AI assistance runs one of two ways, and which one you pick changes where your writing goes. The provider selector on the AI page is where you choose, and it is set per project.

Included with Mythic. A run on the Mythwrites AI provider goes to our server, which forwards it to Together AI on our own key and hands you back the answer. Together AI is in the United States and processes it under its own API terms. Our server does not store what it forwards or what comes back: neither the context nor the answer is written to a database, a log or an error report, and nothing of the run survives the response.Mythic includes fifteen of these runs a day.

Your own key. Right now that means OpenAI or Anthropic: you paste an API key for one of them. The AI settings page also has a local/custom-endpoint field, but our current browser security policy (the Content-Security-Policy that limits which addresses this browser may call) only allows OpenAI, Anthropic and our own processors, so a custom endpoint there does not work in production today. That key stays in this browser session, is cleared when the session ends or you sign out, is stripped out of every save, sync and export, and is never sent to Mythwrites’s servers. On this path your browser calls the provider directly: the request does not pass through our servers, so we cannot see, store or log your prompts or the model’s replies. Mythwrites does not apply the fifteen-runs-a-day Included-AI quota to this path; your provider’s own rate limits, usage limits and charges apply instead. You may need to enter the key again after the browser session ends. This is the path to use if you would rather we were not in the middle of it at all.

For assistant, continuity-review, and chat runs, the request carries a bounded context from the project you have open:

A short selected chapter can therefore be sent in full; a longer one is clipped at the stated limit, and the total context is also capped. Author-note bodies are excluded. Smart Import sends numbered source paragraphs, up to its displayed context limit, only when you explicitly choose Extract lore; the original file is not retained. If part of your work is confidential or under embargo, review the displayed scope and provider before starting a run. The classic consistency, plot-hole and description tools can use a local heuristic when a bring-your-own-key provider has no key; continuity review, chat, and lore extraction do not send anything and ask you to add a key or choose Included AI.

On training. We never use your manuscripts, worlds or characters to train any AI model, and we never grant anyone else a licence to them for that purpose. On the included path, what Together AI may do with what we forward is governed by Together AI’s own API terms, not by this policy. On your own key, what the provider you chose does with your text is governed by your contract with that provider, not by this policy. OpenAI and Anthropic both state that content submitted through their APIs is not used to train their models by default, but that is their promise to you rather than ours, and you should read their current terms before sending anything sensitive.

Our lawful basis

In practice, we process your personal data on the consent you give when you create an account and accept our terms, and to act on requests you make to us or meet a legal obligation, such as keeping payment and tax records. India's DPDP Act sets out a framework for lawful processing along these lines. The Digital Personal Data Protection Rules, 2025 were notified in November 2025 and bring the Act into force in stages: the Data Protection Board provisions started first, and the substantive rules on notice, consent and a data fiduciary's duties are scheduled to commence later. We describe our actual practice here rather than asserting that a specific not-yet-commenced provision already governs us. You can withdraw consent at any time by deleting your account. Withdrawal does not undo processing that already happened, and it does not erase records the law requires us to keep.

Your rights

India's DPDP Act sets out rights along these lines in Sections 11 to 14, and the Act is being brought into force in stages: not every substantive provision is operative yet. Rather than wait for commencement, we give every user the practices below now, wherever you live. Export and portability in particular are capabilities we built into the product, not a claim about what any specific law currently requires of us.

Billing records are the one place to ask twice. Paddle holds your payment details as the seller, so a request to see or erase those goes to Paddle as well as to us, and we will tell you what we hold and point you at them for the rest.

The Act also places duties on you, including not raising false or frivolous complaints and not impersonating anyone else when you give us personal data.

What deleting your account actually does

In cloud mode, deleting your account:

Two honest exceptions for somebody else’s project. If you accepted an invitation, your name and email stay on its collaborator list until the owner removes you or deletes the project. Images you uploaded into that project stay with its work too. Ask us and we will remove either for you.

Deleting your Mythwrites account does not by itself erase the records Paddle keeps as the seller of your subscription, which it holds for its own tax and accounting obligations. Ask Paddle directly about those.

If any part of the deletion fails, we tell you so on the spot rather than reporting success. Should the subscription cancellation be the part that fails, your account is still deleted and we say so, and you should contact us or Paddle so the subscription is stopped.

Deletion is immediate and cannot be undone, so export anything you want to keep first. In browser demo mode there was never a server copy, and deleting simply clears that browser’s storage.

Retention

We keep your account and project data for as long as your account exists, because that is the service. After deletion we retain nothing except records the law requires, principally payment and tax records for the period Indian tax law prescribes, and any correspondence needed to defend a legal claim. What we hold of a payment is the plan, the dates and the Paddle reference; the transaction record itself is Paddle’s and is kept by Paddle. Database backups may hold residual copies for a short period before they roll off.

Security

Everything travels over HTTPS. Database rows are protected by row-level security policies, so one account cannot read another’s projects. Uploaded images sit in a private bucket reached only through expiring signed links. AI keys never reach our servers. Card details never reach them either, because the checkout is Paddle’s and not ours. If a personal data breach happens we will tell you and the Data Protection Board of India without waiting to be asked, consistent with the breach-notification approach in the DPDP Act regardless of which of its provisions have come into force at the time.

Being straight with you: this is a small independent product, not a bank. We offer no security guarantee, and you should keep your own copies of anything you cannot afford to lose. The Export page is there for exactly that.

Children

Mythwrites is for adults. You must be 18 or older to create an account. We do not knowingly collect data from children, we do not track or profile children, and we run no advertising directed at anyone. If you believe a child has created an account, tell us and we will delete it.

If you are outside India

Mythwrites is operated from India and this policy is written to India's DPDP framework, which stays our home privacy framework no matter where you live. That does not shrink your rights: if you are in the European Economic Area, the United Kingdom, California, or anywhere else with its own data protection statute, we extend the same voluntary rights described above to you, regardless of whether that statute has commenced or applies to us: access, correction, deletion, portability, and the right to complain. Beyond that, we do not claim to comply with every country's privacy law, and nothing in this policy should be read as a certification that we do. Where mandatory privacy law applicable to you in your own country gives you a right this policy does not already describe, that mandatory right is not affected by anything here: write to the contact below and we will handle it. We do not sell personal information as California law uses that term.

Changes to this policy

If we change this policy in a way that materially affects you, we will email the address on your account and show a notice in the app at least 14 days before the change takes effect, so you have time to export your work and leave if you disagree. The effective date at the top always tells you which version is current.

Contact and grievances

Grievance officer under the DPDP Act: Vishal Kundar, reachable at support@mythwrites.com. Write there for any privacy question, to exercise any right above, or to complain. We acknowledge within 3 working days.

If we do not resolve your complaint to your satisfaction, you may take it to the Data Protection Board of India.

Terms of Service · Refund Policy