Privacy Policy
Last updated: May 11, 2026
1. Overview
All Your Universes ("we", "us") respects your privacy. This policy explains what data we collect, why we collect it, and how we protect it.
2. Data We Collect
Account Data
- Email address and display name
- Hashed password (bcrypt)
- Language and locale preferences
Story Personalization Data
- Narrative DNA preferences (genres, themes, style)
- Memories and personal details you choose to share
- Uploaded photos and media
- Connector data (Spotify, Instagram) — only with your explicit consent
Usage Data
- Pages visited, features used, session duration
- Device type, browser, and operating system
- IP address (anonymized after 30 days)
3. How We Use Your Data
- Story Generation: Your personalization data is sent to AI providers (Anthropic, OpenAI) solely to generate your stories. We do not share your raw personal data with these providers — only anonymized narrative context.
- Account Management: Email for authentication, notifications, and support.
- Service Improvement: Aggregated, anonymized usage patterns to improve the platform.
4. AI Provider Data Handling
We use Anthropic (Claude) and OpenAI as AI providers. When generating stories:
- We send narrative context (not raw personal data) to generate content
- AI providers process data under their respective data processing agreements
- We do not allow AI providers to use your data for model training
- Generated content is stored on our servers, not retained by AI providers beyond the generation request
5. Data Storage and Security
- Data is stored in encrypted PostgreSQL databases
- All connections use TLS/HTTPS
- Passwords are hashed with bcrypt
- File uploads are stored in encrypted object storage (S3/R2)
- JWT tokens with short expiration for authentication
- Rate limiting and content safety filters
6. Data Retention
- Account data: retained while your account is active
- Generated stories: retained until you delete them or your account
- Upload files: retained until you delete them
- Usage logs: anonymized after 30 days, deleted after 90 days
- After account deletion: all personal data is permanently deleted within 30 days
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data in Settings
- Deletion: Delete your account and all associated data
- Portability: Export your stories in PDF or ePub format
- Withdraw Consent: Disconnect connectors or revoke data sharing at any time
8. Connectors
When you connect third-party services (Spotify, Instagram), we access only the data you explicitly authorize. You can disconnect at any time, and we will delete the associated data within 24 hours.
9. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If we learn we have collected such data, we will delete it promptly.
10. Third-Party Services
- Stripe: Payment processing (PCI DSS compliant)
- Sentry: Error monitoring (anonymized data only)
11. International Transfers
Your data may be processed in jurisdictions outside your country of residence. We ensure appropriate safeguards are in place for international data transfers.
12. Changes
We may update this policy. Material changes will be communicated via email. The "last updated" date will reflect the latest revision.
13. Contact
For privacy inquiries, contact privacy@allyouruniverses.com.