Privacy Policy
Last updated: September 29, 2026
Penpoint is built by Tophat Creative, LLC. We believe your writing is yours, and so is your data. This policy explains what we collect, why, and how you stay in control. By using Penpoint, you also agree to our Terms of Service.
This policy covers:
- the Penpoint desktop app for Windows, macOS, and Linux;
- Minipen, the Penpoint phone app for iPhone and Android, described in its own section below;
- Penpoint Cloud, the optional encrypted backup and sync service; and
- the penpoint.app website.
Your Writing Data
The Penpoint desktop app stores all of your projects, characters, notes, and other content locally on your computer. We do not have access to your writing data. If you use Penpoint only as a desktop application, no prose, manuscripts, or project files are ever transmitted to our servers. If you subscribe to Penpoint Cloud, your content is encrypted on your device and the encrypted copy is transmitted as described in the Penpoint Cloud section below.
Diagnostic logs generated on your device may include metadata such as entity names (e.g., a character's name), navigation paths, and error details. Logs do not contain a copy of your book, manuscript, or project database. However, certain user-initiated actions (such as searches, copy/paste operations, entity renames, or content edits) may cause small, incidental fragments of your writing or worldbuilding to appear in log entries as part of the diagnostic context. These fragments are limited in scope and are never a reproduction of your work.
Diagnostic logs are stored as plain-text files on your device and can be opened and reviewed in any text editor at any time. Logs remain on your computer unless you choose to share them with us for support purposes.
Optional Community Analytics
Penpoint includes an optional community analytics feature that helps us understand how writers use the app and powers aggregate community statistics (for example, "142 authors writing today"). This feature is disabled by default. It only activates if you explicitly opt in.
If you choose to enable it, Penpoint periodically sends a small pseudonymous usage report containing:
- A pseudonymous device identifier (UUID) derived from your computer's system ID using a one-way cryptographic hash
- Date, platform, and app version
- Session duration, session count, and time spent in each section of the app
- Counts of entities created (characters, chapters, locations, etc.)
- Manuscript and worldbuilding word counts
- Number of books and total days used
- Writing timer usage (total minutes and number of timer sessions)
- Export counts by format, such as "exported 1 DOCX" (no file names or content)
- General time-of-day activity patterns
- Whether the app is running in trial or licensed mode
- Whether you subscribe to Penpoint Cloud and which tier (Backup or Sync), as a coarse indicator with no account identifier, email, or billing details
This data does not include your name, email address, IP address, or any writing content. The device identifier is derived from your computer's system ID using a one-way cryptographic hash combined with a Penpoint-specific key. It cannot be reversed to identify your device or linked to other applications. Under certain privacy frameworks (such as the GDPR), a persistent pseudonymous identifier may be considered personal data. We treat it accordingly and process it only with your explicit consent.
You can view exactly what data is being sent at any time in Settings > Community & Updates. You can disable analytics at any time. Doing so immediately stops all data collection and deletes your historical data from our active systems. Infrastructure-level backups maintained by our hosting provider may retain residual copies for a limited period consistent with their retention policies, after which they are automatically purged.
Aggregate community statistics derived from this data (such as total active authors or total words written) may appear within the app or on the Penpoint website. These statistics only ever represent broad totals and can never identify an individual user.
Anonymous Activation Count
Separately from the optional analytics above, the app sends a single anonymous signal that an installation exists, along with whether you are using the free trial or a purchased copy. This happens once per installation: when you first install Penpoint and accept these Terms, or, if you already had Penpoint installed, automatically the first time you open the update that introduced this. The signal contains no device identifier, no account, no name, and no writing content. Like the update check described below, it contacts our server directly, so the connection carries your device's IP address; the count we keep records only a date and a running total, with no IP address stored. It increments an aggregate daily total (for example, "8 installs today") and is never tied to a specific person, device, or session.
We use this only to understand how many people install Penpoint and how installations trend over time. Because it carries no identifier, it creates no per-device record and is not part of, or linked to, the opt-in community analytics described above. It is the same kind of anonymous, aggregate count we keep for website buttons (described below), and it is sent only once per installation. Because it records nothing about you as an individual, there is no separate on/off setting for it: in the same way the app's routine check for updates simply contacts a server, there is nothing here to collect about you and so nothing to turn off.
Community Dictionary Submissions
Penpoint includes a curated community spelling dictionary (the "Authors Dictionary") that helps writers' spellcheck recognize genre and fiction vocabulary. When you choose to submit a word to it (for example, by clicking the submit button next to a word in your custom dictionary), that single word is sent to us for review, together with an optional note you write, the word's language, and your app version and platform.
Submitting a word is a deliberate and voluntary action that you initiate. This feature is separate from the opt-in community analytics described above, and it has no additional setting to enable or disable, because no data is collected unless and until you choose to submit a word. Each submission is stored with a pseudonymous device identifier (the same one-way hashed identifier described above, and never your name, email address, or any content from your books) so that you can later view your own contributions. The information collected is limited to the individual word you submit and the optional note you attach to it; nothing else about your writing or your use of the app is collected by this feature.
Submitted words may be reviewed by us and, if suitable, added to the shared Authors Dictionary that ships to all writers. Please do not submit words that are private, sensitive, or that you do not wish to contribute to a public community resource. You can request deletion of your submissions at any time by contacting support@penpoint.app.
Website Analytics
Our marketing website (penpoint.app) uses Google Analytics to understand how visitors find and use the site. Google Analytics sets cookies on your device to measure page visits and session activity. This collects:
- Pages visited and time spent
- Referring website or search engine
- General geographic region (country/city level)
- Browser and device type
This data is aggregated and does not directly identify you. We use it to understand which features interest writers most and how to improve the site. Google's privacy policy applies to this data collection: policies.google.com/privacy. You can opt out site-wide using Google's browser opt-out add-on.
We also track anonymous aggregate click counts on certain website buttons (such as download and purchase buttons) to understand how visitors interact with the site. This tracking stores only a daily total count per button type. No cookies, identifiers, or personal information are collected or stored.
Auto-Update Checks and Announcements
The Penpoint desktop app periodically checks for new versions by contacting GitHub's servers. This is a standard HTTPS request that may transmit your IP address to GitHub. No personal data or usage information is included in these requests. Minipen does not check for updates itself; the App Store or Google Play handles that.
Both apps also download a public announcements file (news, tips, and service notices) from announcements.penpoint.app, which is hosted by GitHub. The request carries no account, device identifier, or usage information; like any web request, the connection reveals your IP address to GitHub.
Discord Rich Presence (Optional)
Penpoint includes an optional Discord Rich Presence feature that displays your writing activity in your Discord profile status (e.g., "Working on Characters" or "Working on the Manuscript"). This feature is disabled by default and only activates if you turn it on in Settings > Community & Updates.
When enabled, Penpoint communicates directly with the Discord desktop app running on your computer using Discord's local IPC protocol. The only information shared is:
- That you are using Penpoint
- Your current mode (Worldbuilding or Manuscript)
- A general description of which section you are working in (e.g., "Working on Characters", "Working on Locations")
No writing content, character names, project titles, or personal information is ever shared. The communication happens entirely on your device between Penpoint and the Discord desktop app, so no data is sent to Penpoint's servers. Discord's own privacy policy governs how Discord handles your presence status once it is displayed.
You can disable this feature at any time in Settings, which immediately stops all presence updates. The Discord desktop app must be running for this feature to work.
Minipen, the Penpoint Phone App
Minipen is Penpoint's free companion app for iPhone and Android. It lets you read and edit your books on your phone, and it works only with an existing Penpoint Cloud Sync subscription. Everything Minipen sends to us goes through Penpoint Cloud, so the Penpoint Cloud sections below apply to it in full. This section summarizes what is specific to the phone app.
Signing in. You sign in with the email address of your existing Penpoint Cloud account and a one-time code we email to you, then unlock your books with your Cloud password. Your Cloud password unlocks your encryption keys on your phone; we never receive it. Minipen cannot create an account or delete one. Those happen in the desktop app or by emailing support@penpoint.app (see Deleting your account).
What Minipen sends to Penpoint Cloud:
- Your account email address, used to sign you in and to send one-time codes.
- Device information: a device name, the platform (iOS or Android), and the Minipen version. We use this to list your devices in Settings, manage your device limit, and keep sync working across app versions.
- Book identifiers and version metadata: internal IDs, version numbers, timestamps, and file sizes, used to sync the right version of each book.
- Your writing, the pictures you add, and your synced preferences, all end-to-end encrypted on your phone before upload. We store only the encrypted copy and cannot read it.
- Crash and sync-failure reports: fixed status codes, counts, opaque identifiers, the app version, the platform, and timestamps. They never contain writing, titles, file names, or any free text. They are sent automatically while you are signed in and are used only to find and fix problems.
What stays on your phone. Your writing-activity statistics (such as words written per day) are stored only on your phone and are not uploaded. Signing out of Minipen, or a lapse in your subscription, removes the book copies stored on your phone; your cloud copy is not affected.
Announcements. Minipen downloads the same public announcements file as the desktop app, described in Auto-Update Checks and Announcements. No account information is sent.
What Minipen does not do. Minipen contains no advertising and no third-party analytics or tracking tools, and it does not track you across other apps or websites. It does not access your location, camera, microphone, or contacts. On Android it asks only for internet access and vibration (for haptic feedback). When you add a picture to a book, you choose it through your phone's own photo picker, and Minipen receives only the picture you pick. Minipen has no purchases of any kind: no prices, no checkout, and no links to buy.
App stores. Apple and Google distribute Minipen. Downloading it from the App Store or Google Play is governed by their own privacy policies (Apple, Google). Depending on your phone's settings, they may share aggregate statistics with us, such as install counts and anonymous crash reports; they do not share your name or email address with us.
Penpoint Cloud
This section applies only if you subscribe to Penpoint Cloud (either Penpoint Backup or Penpoint Sync), and to Minipen, which works only with Penpoint Cloud. If you use Penpoint only as a local desktop application, none of the data described in this section is collected, and nothing in your privacy experience changes.
What Penpoint Cloud Cannot Read
Penpoint Cloud uses zero-knowledge encryption. All of your book content (manuscripts, characters, locations, items, notes, arcs, and all other project data) is encrypted on your device before it ever leaves your computer. Tophat Creative stores the encrypted data but cannot decrypt or read it. Neither can anyone else, including our hosting providers.
When you delete a book from the cloud or erase your cloud data, the encryption keys are permanently destroyed (crypto-shredded), making all associated ciphertext unrecoverable even if residual copies exist in infrastructure backups.
What Penpoint Cloud Does Collect
While your writing content is encrypted, Penpoint Cloud necessarily processes certain clear-text metadata to operate the service:
- Account email address: used for sign-in codes, subscription notifications, and support.
- Device information: a display name for each device (by default your computer's or phone's name, e.g., "My Laptop"; you can change it), visible only to you in the app, plus the device's platform (Windows, macOS, Linux, iOS, or Android), which app it is (desktop or Minipen), the app version, and when it last connected.
- Book identifiers: internal UUIDs that identify your books in the cloud. Book titles are NOT stored in clear text; they live inside the encrypted blob.
- Version metadata: version numbers, timestamps, and file sizes associated with each backup, used to manage version history and syncing.
- Subscription status and history: your current plan, billing period, and entitlement state, plus a record of subscription lifecycle changes over time (for example subscribe, cancel, or resubscribe events) used for aggregate service and retention analytics.
- IP addresses: recorded in server logs by Supabase and Resend as part of normal HTTPS request processing. We do not use IP addresses for tracking or profiling.
- Operational service data: anonymized usage patterns (such as sync frequency, backup sizes, and connection timing) used to ensure the service is working correctly. Because your content is encrypted, we see operational patterns, not your data.
- Sync health reports and crash reports: sent automatically only while you are signed in to Penpoint Cloud on a device (including Minipen), stored with your account's internal ID (never your email), and used solely to keep the service working and to fix crashes. A sync health report notes that one sync operation hit a known failure class, using a fixed status code, a count, and the book's internal UUID. A crash report notes that the app crashed, with an opaque fingerprint of the code location. These reports contain no writing, titles, file names, or error message text: every field is a fixed code, a number, an opaque identifier, the app version, the platform, or a timestamp. If you use Penpoint only as a local desktop application, none of these reports are sent.
How We Use Cloud Data
We use the metadata described above to:
- Provide and operate the sync and backup service (deliver your encrypted books to your devices, manage version history, handle device registration).
- Send you transactional emails: sign-in codes, subscription confirmations, payment failure notices, and pre-purge warnings. These are service emails, not marketing; no separate consent or unsubscribe is required.
- Monitor for abuse and ensure fair use (egress logging, usage diagnostics).
- Respond to support requests related to your cloud account.
The legal basis for processing this data is contract (to provide the sync service you subscribed to) and legitimate interest (abuse prevention and service reliability).
Cloud Data Retention
Penpoint Cloud retains data according to the following schedule:
- Book version history: retained according to your plan's version-history policy for as long as your subscription is active.
- After subscription lapses: all cloud data (encrypted books, metadata, version history) is kept for 30 days, then permanently deleted (crypto-shredded). Warning emails are sent before deletion.
- Account deletion (full erasure): your encryption keys are destroyed (crypto-shredded) and your account email and sign-in record are deleted immediately; your stored encrypted books, device list, and other account data are removed within 24 hours. A few non-personal records are kept: an opaque tombstone identifier (to prevent account-ID reuse), internal records of storage clean-up, and your subscription history (plan and dates, with no email address) for our business records. See Deleting your account.
- Account email after cancellation: if you cancel your subscription but do not delete your account, we retain your account email so you can resume without re-registering. You can delete your account at any time.
- Service records (download logs, integrity-check results, and receipts of which service emails were sent, none of which contain your writing): kept while your account exists and deleted along with it.
- Sync health and crash reports: kept for up to 90 days, and deleted along with your account.
- Server logs (Supabase infrastructure): these include IP addresses and internal account and device IDs, and are kept for a limited period set by Supabase (currently a few weeks to a few months), then deleted automatically.
- Email delivery logs (Resend): retained according to Resend's standard retention policies.
Disaster-recovery backups. So that a failure at our hosting provider can't lose your books, we keep an encrypted offsite backup with Backblaze B2 in the European Union. Nightly copies of account records (including account email addresses, which are separately encrypted) are kept for about 60 days, then deleted automatically, so a deleted account can remain in these backups for up to that long. The backup also mirrors the encrypted book files. Those copies can outlast your account, but once your account is deleted or your data is erased, the keys that could decrypt them are gone, so no one, including us, can ever read them. Our hosting provider's own infrastructure backups work the same way and are purged on their schedule.
Cloud Data Location & Transfer
Penpoint Cloud data is hosted on Supabase infrastructure in the European Union. Your encrypted book content and account metadata are stored in the EU. Some metadata (such as email addresses for transactional email delivery and payment data for billing) is processed by subprocessors that may operate in the United States. These transfers are governed by Standard Contractual Clauses (SCCs).
Cloud Subprocessors
The following services process data on our behalf to operate Penpoint Cloud:
- Supabase (EU hosting): stores encrypted book data, account metadata, and authentication records. Supabase privacy policy.
- Lemon Squeezy (Merchant of Record): processes subscription payments and handles tax compliance. Lemon Squeezy acts as an independent data controller for payment and tax data. Lemon Squeezy privacy policy.
- Resend: delivers transactional emails (sign-in codes, subscription notifications). Resend privacy policy.
- Backblaze B2 (EU hosting): stores the encrypted offsite disaster-recovery backup described above. Backblaze privacy policy.
- GitHub: runs the automated nightly job that creates the disaster-recovery backup. Data passes through this job in transit and is not stored at GitHub. GitHub privacy statement.
Each subprocessor is bound by its own data protection terms to protect your data to a standard at least as protective as this policy. We will notify Cloud subscribers before adding or replacing a subprocessor.
Your Cloud Data Rights
In addition to the rights described in the "Your Rights" section below, Penpoint Cloud subscribers have the following rights:
- Access (DSAR): you can request a copy of all data we hold about your cloud account by contacting support@penpoint.app. We will respond within one month.
- Portability: your books are always available as local
.penpointfiles on your computer. You can export them at any time without contacting us. - Rectification: you can update your device names in the app. To change your account email, use the email-change feature in Settings.
- Erasure: in the Penpoint desktop app's Cloud settings, "Permanently erase all cloud backups" crypto-shreds your encryption keys and deletes all cloud data while keeping your account, and "Close my Penpoint Cloud account entirely" deletes the account itself, including your email and sign-in record. You can also ask us to delete your account by emailing support@penpoint.app from your account's email address. Minipen cannot delete accounts; signing out of it only removes the copies on your phone. Full steps are on the Deleting your account page. Note that Lemon Squeezy retains billing records under its own legal obligation as Merchant of Record.
- Restriction & objection: you can contact us to request restriction of processing or to object to specific processing activities. We will respond within one month.
Email & Support
If you contact us at support@penpoint.app, we'll have your email address and whatever you include in your message. We use this only to respond to you and won't share it with anyone.
Data Retention
Community analytics data is retained for up to 18 months, after which it is automatically deleted. If you opt out of community analytics, all of your data is deleted from our servers immediately.
We do not retain website analytics data ourselves. Google's retention policies apply to that data. Support correspondence is retained for up to 24 months after the inquiry is resolved, then deleted. You may request earlier deletion of your support correspondence at any time by contacting us.
Data Security & Location
Community analytics data is transmitted over HTTPS (TLS) and stored on Supabase infrastructure hosted in the United States. The underlying database uses AES-256 encryption at rest. For users in the EEA or United Kingdom, data is transferred to the United States under Standard Contractual Clauses.
Third Parties
We do not sell your data. We do not share it with third parties except as described below, where services process data on our behalf to operate Penpoint (except where noted as an independent controller):
- Lemon Squeezy: acts as Merchant of Record for purchases. When you buy Penpoint, Lemon Squeezy collects your name, email address, billing address, and payment information to process the transaction. Tophat Creative does not have access to your full payment details. Lemon Squeezy privacy policy.
- Supabase: hosts pseudonymous community analytics data (if you opt in), the anonymous activation count described above, community dictionary submissions, and Penpoint Cloud account and encrypted book data (if subscribed). Supabase privacy policy.
- Resend: delivers transactional emails for Penpoint Cloud (sign-in codes, subscription notifications), if subscribed. Resend privacy policy.
- Google Analytics: collects anonymous visitor data on the Penpoint website. Google privacy policy.
- Backblaze B2: stores Penpoint Cloud's encrypted disaster-recovery backup (if subscribed). Backblaze privacy policy.
- Apple and Google: distribute Minipen through the App Store and Google Play. Apple privacy policy, Google privacy policy.
- GitHub: serves desktop app update checks and the announcements file, and runs Penpoint Cloud's nightly backup job. GitHub privacy statement.
- Discord: receives presence status via local IPC when Discord Rich Presence is enabled (opt-in). Communication occurs locally between Penpoint and the Discord desktop app on your device. Discord privacy policy.
Only Tophat Creative, LLC has access to the raw community analytics data stored in Supabase. No other individuals, contractors, or services have access.
Your Rights
Regardless of where you live, you have the right to:
- Opt out at any time. Disabling community analytics in Settings immediately stops data collection and deletes all of your data from our servers.
- See what's collected. The Settings > Community & Updates panel shows you exactly what data is being sent.
- Request access to your data. You can contact us at support@penpoint.app to request a copy of any data we hold associated with your device.
- Request deletion. You can contact us at support@penpoint.app to request deletion, or simply toggle off community analytics to delete your data automatically.
If you are located in the European Economic Area (EEA) or United Kingdom, you also have rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. For the purposes of the GDPR, the data controller is Tophat Creative, LLC, contactable at support@penpoint.app. The legal basis for processing community analytics data is your explicit consent (opt-in).
Children's Privacy
Penpoint is a general-purpose writing tool. It is not directed at children under the age of 13 (or 16 in jurisdictions where GDPR applies). We do not knowingly collect personal information from children. If a parent or guardian becomes aware that their child has opted into community analytics, they may contact us at support@penpoint.app to have the data deleted, or simply disable the feature in the app.
Penpoint Cloud requires you to be at least 13 years old (or 16 in jurisdictions where GDPR applies) to subscribe. If you are between 13 and 18 (or the age of majority in your jurisdiction), you must have permission from a parent or guardian.
The same age rules apply to Minipen, the phone app: you must be at least 13 (or 16 where GDPR applies), with a parent's or guardian's permission if you are under 18.
Business Transfers
In the event that Tophat Creative, LLC or Penpoint is acquired, merged, or sold, anonymous community analytics data and Penpoint Cloud account data (including encrypted book data) may be transferred to the successor entity. Any such transfer will remain subject to the commitments made in this privacy policy, including the zero-knowledge encryption guarantee. If a new owner materially changes how your data is handled, we will notify users through the app or this policy before those changes take effect.
Changes
We may update this policy from time to time. When we do, we'll update the date at the top. For material changes (such as changes to what data is collected, how it is used, or who it is shared with), we will notify you within the app and provide at least 30 days' notice before the changes take effect. For any questions, reach us at support@penpoint.app.