Try

Privacy Policy

Last updated: September 29, 2026

Penpoint is built by Tophat Creative, LLC. We believe your writing is yours, and so is your data. This policy explains what we collect, why, and how you stay in control. By using Penpoint, you also agree to our Terms of Service.

This policy covers:

Your Writing Data

The Penpoint desktop app stores all of your projects, characters, notes, and other content locally on your computer. We do not have access to your writing data. If you use Penpoint only as a desktop application, no prose, manuscripts, or project files are ever transmitted to our servers. If you subscribe to Penpoint Cloud, your content is encrypted on your device and the encrypted copy is transmitted as described in the Penpoint Cloud section below.

Diagnostic logs generated on your device may include metadata such as entity names (e.g., a character's name), navigation paths, and error details. Logs do not contain a copy of your book, manuscript, or project database. However, certain user-initiated actions (such as searches, copy/paste operations, entity renames, or content edits) may cause small, incidental fragments of your writing or worldbuilding to appear in log entries as part of the diagnostic context. These fragments are limited in scope and are never a reproduction of your work.

Diagnostic logs are stored as plain-text files on your device and can be opened and reviewed in any text editor at any time. Logs remain on your computer unless you choose to share them with us for support purposes.

Optional Community Analytics

Penpoint includes an optional community analytics feature that helps us understand how writers use the app and powers aggregate community statistics (for example, "142 authors writing today"). This feature is disabled by default. It only activates if you explicitly opt in.

If you choose to enable it, Penpoint periodically sends a small pseudonymous usage report containing:

This data does not include your name, email address, IP address, or any writing content. The device identifier is derived from your computer's system ID using a one-way cryptographic hash combined with a Penpoint-specific key. It cannot be reversed to identify your device or linked to other applications. Under certain privacy frameworks (such as the GDPR), a persistent pseudonymous identifier may be considered personal data. We treat it accordingly and process it only with your explicit consent.

You can view exactly what data is being sent at any time in Settings > Community & Updates. You can disable analytics at any time. Doing so immediately stops all data collection and deletes your historical data from our active systems. Infrastructure-level backups maintained by our hosting provider may retain residual copies for a limited period consistent with their retention policies, after which they are automatically purged.

Aggregate community statistics derived from this data (such as total active authors or total words written) may appear within the app or on the Penpoint website. These statistics only ever represent broad totals and can never identify an individual user.

Anonymous Activation Count

Separately from the optional analytics above, the app sends a single anonymous signal that an installation exists, along with whether you are using the free trial or a purchased copy. This happens once per installation: when you first install Penpoint and accept these Terms, or, if you already had Penpoint installed, automatically the first time you open the update that introduced this. The signal contains no device identifier, no account, no name, and no writing content. Like the update check described below, it contacts our server directly, so the connection carries your device's IP address; the count we keep records only a date and a running total, with no IP address stored. It increments an aggregate daily total (for example, "8 installs today") and is never tied to a specific person, device, or session.

We use this only to understand how many people install Penpoint and how installations trend over time. Because it carries no identifier, it creates no per-device record and is not part of, or linked to, the opt-in community analytics described above. It is the same kind of anonymous, aggregate count we keep for website buttons (described below), and it is sent only once per installation. Because it records nothing about you as an individual, there is no separate on/off setting for it: in the same way the app's routine check for updates simply contacts a server, there is nothing here to collect about you and so nothing to turn off.

Community Dictionary Submissions

Penpoint includes a curated community spelling dictionary (the "Authors Dictionary") that helps writers' spellcheck recognize genre and fiction vocabulary. When you choose to submit a word to it (for example, by clicking the submit button next to a word in your custom dictionary), that single word is sent to us for review, together with an optional note you write, the word's language, and your app version and platform.

Submitting a word is a deliberate and voluntary action that you initiate. This feature is separate from the opt-in community analytics described above, and it has no additional setting to enable or disable, because no data is collected unless and until you choose to submit a word. Each submission is stored with a pseudonymous device identifier (the same one-way hashed identifier described above, and never your name, email address, or any content from your books) so that you can later view your own contributions. The information collected is limited to the individual word you submit and the optional note you attach to it; nothing else about your writing or your use of the app is collected by this feature.

Submitted words may be reviewed by us and, if suitable, added to the shared Authors Dictionary that ships to all writers. Please do not submit words that are private, sensitive, or that you do not wish to contribute to a public community resource. You can request deletion of your submissions at any time by contacting support@penpoint.app.

Website Analytics

Our marketing website (penpoint.app) uses Google Analytics to understand how visitors find and use the site. Google Analytics sets cookies on your device to measure page visits and session activity. This collects:

This data is aggregated and does not directly identify you. We use it to understand which features interest writers most and how to improve the site. Google's privacy policy applies to this data collection: policies.google.com/privacy. You can opt out site-wide using Google's browser opt-out add-on.

We also track anonymous aggregate click counts on certain website buttons (such as download and purchase buttons) to understand how visitors interact with the site. This tracking stores only a daily total count per button type. No cookies, identifiers, or personal information are collected or stored.

Auto-Update Checks and Announcements

The Penpoint desktop app periodically checks for new versions by contacting GitHub's servers. This is a standard HTTPS request that may transmit your IP address to GitHub. No personal data or usage information is included in these requests. Minipen does not check for updates itself; the App Store or Google Play handles that.

Both apps also download a public announcements file (news, tips, and service notices) from announcements.penpoint.app, which is hosted by GitHub. The request carries no account, device identifier, or usage information; like any web request, the connection reveals your IP address to GitHub.

Discord Rich Presence (Optional)

Penpoint includes an optional Discord Rich Presence feature that displays your writing activity in your Discord profile status (e.g., "Working on Characters" or "Working on the Manuscript"). This feature is disabled by default and only activates if you turn it on in Settings > Community & Updates.

When enabled, Penpoint communicates directly with the Discord desktop app running on your computer using Discord's local IPC protocol. The only information shared is:

No writing content, character names, project titles, or personal information is ever shared. The communication happens entirely on your device between Penpoint and the Discord desktop app, so no data is sent to Penpoint's servers. Discord's own privacy policy governs how Discord handles your presence status once it is displayed.

You can disable this feature at any time in Settings, which immediately stops all presence updates. The Discord desktop app must be running for this feature to work.

Minipen, the Penpoint Phone App

Minipen is Penpoint's free companion app for iPhone and Android. It lets you read and edit your books on your phone, and it works only with an existing Penpoint Cloud Sync subscription. Everything Minipen sends to us goes through Penpoint Cloud, so the Penpoint Cloud sections below apply to it in full. This section summarizes what is specific to the phone app.

Signing in. You sign in with the email address of your existing Penpoint Cloud account and a one-time code we email to you, then unlock your books with your Cloud password. Your Cloud password unlocks your encryption keys on your phone; we never receive it. Minipen cannot create an account or delete one. Those happen in the desktop app or by emailing support@penpoint.app (see Deleting your account).

What Minipen sends to Penpoint Cloud:

What stays on your phone. Your writing-activity statistics (such as words written per day) are stored only on your phone and are not uploaded. Signing out of Minipen, or a lapse in your subscription, removes the book copies stored on your phone; your cloud copy is not affected.

Announcements. Minipen downloads the same public announcements file as the desktop app, described in Auto-Update Checks and Announcements. No account information is sent.

What Minipen does not do. Minipen contains no advertising and no third-party analytics or tracking tools, and it does not track you across other apps or websites. It does not access your location, camera, microphone, or contacts. On Android it asks only for internet access and vibration (for haptic feedback). When you add a picture to a book, you choose it through your phone's own photo picker, and Minipen receives only the picture you pick. Minipen has no purchases of any kind: no prices, no checkout, and no links to buy.

App stores. Apple and Google distribute Minipen. Downloading it from the App Store or Google Play is governed by their own privacy policies (Apple, Google). Depending on your phone's settings, they may share aggregate statistics with us, such as install counts and anonymous crash reports; they do not share your name or email address with us.

Penpoint Cloud

This section applies only if you subscribe to Penpoint Cloud (either Penpoint Backup or Penpoint Sync), and to Minipen, which works only with Penpoint Cloud. If you use Penpoint only as a local desktop application, none of the data described in this section is collected, and nothing in your privacy experience changes.

What Penpoint Cloud Cannot Read

Penpoint Cloud uses zero-knowledge encryption. All of your book content (manuscripts, characters, locations, items, notes, arcs, and all other project data) is encrypted on your device before it ever leaves your computer. Tophat Creative stores the encrypted data but cannot decrypt or read it. Neither can anyone else, including our hosting providers.

When you delete a book from the cloud or erase your cloud data, the encryption keys are permanently destroyed (crypto-shredded), making all associated ciphertext unrecoverable even if residual copies exist in infrastructure backups.

What Penpoint Cloud Does Collect

While your writing content is encrypted, Penpoint Cloud necessarily processes certain clear-text metadata to operate the service:

How We Use Cloud Data

We use the metadata described above to:

The legal basis for processing this data is contract (to provide the sync service you subscribed to) and legitimate interest (abuse prevention and service reliability).

Cloud Data Retention

Penpoint Cloud retains data according to the following schedule:

Disaster-recovery backups. So that a failure at our hosting provider can't lose your books, we keep an encrypted offsite backup with Backblaze B2 in the European Union. Nightly copies of account records (including account email addresses, which are separately encrypted) are kept for about 60 days, then deleted automatically, so a deleted account can remain in these backups for up to that long. The backup also mirrors the encrypted book files. Those copies can outlast your account, but once your account is deleted or your data is erased, the keys that could decrypt them are gone, so no one, including us, can ever read them. Our hosting provider's own infrastructure backups work the same way and are purged on their schedule.

Cloud Data Location & Transfer

Penpoint Cloud data is hosted on Supabase infrastructure in the European Union. Your encrypted book content and account metadata are stored in the EU. Some metadata (such as email addresses for transactional email delivery and payment data for billing) is processed by subprocessors that may operate in the United States. These transfers are governed by Standard Contractual Clauses (SCCs).

Cloud Subprocessors

The following services process data on our behalf to operate Penpoint Cloud:

Each subprocessor is bound by its own data protection terms to protect your data to a standard at least as protective as this policy. We will notify Cloud subscribers before adding or replacing a subprocessor.

Your Cloud Data Rights

In addition to the rights described in the "Your Rights" section below, Penpoint Cloud subscribers have the following rights:

Email & Support

If you contact us at support@penpoint.app, we'll have your email address and whatever you include in your message. We use this only to respond to you and won't share it with anyone.

Data Retention

Community analytics data is retained for up to 18 months, after which it is automatically deleted. If you opt out of community analytics, all of your data is deleted from our servers immediately.

We do not retain website analytics data ourselves. Google's retention policies apply to that data. Support correspondence is retained for up to 24 months after the inquiry is resolved, then deleted. You may request earlier deletion of your support correspondence at any time by contacting us.

Data Security & Location

Community analytics data is transmitted over HTTPS (TLS) and stored on Supabase infrastructure hosted in the United States. The underlying database uses AES-256 encryption at rest. For users in the EEA or United Kingdom, data is transferred to the United States under Standard Contractual Clauses.

Third Parties

We do not sell your data. We do not share it with third parties except as described below, where services process data on our behalf to operate Penpoint (except where noted as an independent controller):

Only Tophat Creative, LLC has access to the raw community analytics data stored in Supabase. No other individuals, contractors, or services have access.

Your Rights

Regardless of where you live, you have the right to:

If you are located in the European Economic Area (EEA) or United Kingdom, you also have rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. For the purposes of the GDPR, the data controller is Tophat Creative, LLC, contactable at support@penpoint.app. The legal basis for processing community analytics data is your explicit consent (opt-in).

Children's Privacy

Penpoint is a general-purpose writing tool. It is not directed at children under the age of 13 (or 16 in jurisdictions where GDPR applies). We do not knowingly collect personal information from children. If a parent or guardian becomes aware that their child has opted into community analytics, they may contact us at support@penpoint.app to have the data deleted, or simply disable the feature in the app.

Penpoint Cloud requires you to be at least 13 years old (or 16 in jurisdictions where GDPR applies) to subscribe. If you are between 13 and 18 (or the age of majority in your jurisdiction), you must have permission from a parent or guardian.

The same age rules apply to Minipen, the phone app: you must be at least 13 (or 16 where GDPR applies), with a parent's or guardian's permission if you are under 18.

Business Transfers

In the event that Tophat Creative, LLC or Penpoint is acquired, merged, or sold, anonymous community analytics data and Penpoint Cloud account data (including encrypted book data) may be transferred to the successor entity. Any such transfer will remain subject to the commitments made in this privacy policy, including the zero-knowledge encryption guarantee. If a new owner materially changes how your data is handled, we will notify users through the app or this policy before those changes take effect.

Changes

We may update this policy from time to time. When we do, we'll update the date at the top. For material changes (such as changes to what data is collected, how it is used, or who it is shared with), we will notify you within the app and provide at least 30 days' notice before the changes take effect. For any questions, reach us at support@penpoint.app.