Back

Privacy Policy

Effective date: 2026-04-08

Summary: the service is for users aged 18 and over. We process account data, creative content, generated outputs, payment records, logs, and moderation data to operate the product, provide AI features, handle billing, and keep the service safe.

Introduction

This Privacy Policy explains how Talevo (individual operator, Australia) ("we", "us") collects, uses, discloses, and protects personal information when you use Talevo.

The service is operated by an individual based in Australia and is intended for users aged 18 and over. If you are under 18, do not use the service or provide personal information.

This Policy should be read together with our Terms of Service. Effective date: 2026-04-08.

The operator is an individual small business based in Australia. Under the Australian Privacy Act 1988, many businesses with annual turnover of AUD 3 million or less are exempt from the Australian Privacy Principles (APPs), unless an exception applies (for example, certain health records, contracted service providers, or other regulated activities). We aim to handle personal information transparently and consistently with APP expectations regardless, but your statutory rights may depend on whether the Privacy Act applies to us in your circumstances.

1. Information We Collect

Account and profile: email address, display name, authentication identifiers, invite/referral codes, referral relationships, and profile settings.

Authentication: when you sign in with Google OAuth or similar providers, we receive information permitted by your provider settings (such as email and basic profile data).

Terms acceptance: timestamp and version of Terms, Privacy Policy, and Billing Policy you accepted at registration or re-acceptance.

Creative content: prompts, drafts, novels, chapters, adventure worlds, characters, world settings, chat messages, generated text and images, uploads, publishing metadata, and moderation records.

Payments: purchase history, package selections, Echo balances, member status, and transaction references processed through Stripe. We do not intentionally store full payment card numbers on our servers.

Technical and usage logs: IP address, device and browser metadata, request timestamps, feature usage, error diagnostics, security signals, and abuse-prevention data.

Support and feedback: messages you send through in-app feedback or email contact channels.

2. How We Use Information

We use personal information to authenticate users, provide and personalize creative features, process Echo consumption, deliver purchases, operate referral and creator incentive programs, save sessions, publish and moderate community content, prevent fraud and abuse, maintain security, debug errors, comply with law, and respond to your requests.

We may use aggregated or de-identified data to understand product usage, improve reliability, and develop new features.

We do not use your private drafts or non-public creative content for unrelated advertising profiling.

3. AI and Model Providers

To fulfill writing, adventure, image, and related AI features, we may transmit prompts, context, generated outputs, and necessary metadata to large language model providers and image generation providers.

Providers process data according to their own terms and security practices. Data may be logged temporarily for abuse prevention, billing, or service quality.

Do not submit confidential, regulated, or highly sensitive personal information unless you accept that it will be processed to deliver the feature you request.

4. Third-Party Service Providers

We use third parties to help operate the service, including:

• Stripe — payment processing and fraud signals;

• Supabase — authentication and identity services;

• Cloud hosting, databases, object storage, and content delivery providers;

• Email delivery, analytics, and abuse-prevention tools where configured;

• LLM and image model API providers.

These processors handle information on our instructions and subject to contractual or legal safeguards appropriate to the service.

Current disclosed processing locations, based on our deployed provider configuration: Australia, United States, Singapore.

These locations cover payment processing, authentication and database services, cloud hosting and storage, content delivery, and LLM or image API providers. We review and update this list when deployment regions or material providers change.

We do not control every sub-processor location. Where required, we take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with applicable law.

5. We Do Not Sell Personal Data

We do not sell your personal information to data brokers or third parties for their independent marketing purposes.

We may share information with service providers as described above, when required by law, to protect rights and safety, or in connection with a business transfer subject to this Policy.

6. Public Content

If you publish novels, chapters, adventure worlds, images, or public profile information, that content may be visible to other users and may be indexed, shared, or copied according to product features.

Deleting or unpublishing content does not guarantee removal of copies already viewed, cached, exported by users, or retained for compliance, security, or dispute handling.

7. Retention

We retain information only as long as necessary for the purposes described in this Policy:

• Account and creative data: deleted or de-identified within approximately 30 days after confirmed account deletion, except where law or legitimate interests require longer retention;

• Payment and transaction records: up to 7 years for tax, accounting, and dispute purposes;

• Security and operational logs: generally up to 12 months;

• Backups: may persist until natural expiry on backup rotation cycles.

Some moderation, referral, and enforcement records may be retained longer where needed to prevent repeat abuse or comply with legal obligations.

8. Cross-Border Transfers

We are based in Australia. Based on our current deployment configuration, personal information may be stored or processed in: Australia, United States, Singapore.

Where personal information is transferred internationally, we take reasonable steps to ensure appropriate safeguards consistent with applicable privacy law, such as contractual protections with processors and access controls.

By using the service, you acknowledge that your information may be processed outside your home country, where privacy laws may differ from those in your jurisdiction.

9. Security and Data Breaches

We implement reasonable technical and organizational measures designed to protect personal information, including access controls, encryption in transit where supported, and monitoring for abuse.

No online service is completely secure. You are responsible for safeguarding your credentials and devices.

Notify us promptly if you believe your account has been compromised.

If we become aware of unauthorized access, loss, or disclosure of personal information that is likely to cause serious harm (or otherwise triggers notification duties under applicable law), we will investigate promptly and, where required, notify affected individuals and regulators such as the Office of the Australian Information Commissioner (OAIC) within timeframes required by law.

10. Your Rights and Privacy Complaints

Depending on your location, you may have rights to access, correct, delete, or export personal information, object to certain processing, or withdraw consent where processing is consent-based.

To exercise these rights or raise a privacy concern, contact us in writing at qinkunpeng2015@gmail.com or through in-app feedback. Include your account email, a clear description of your request, and enough detail for us to locate relevant records.

We will acknowledge privacy complaints within a reasonable time and aim to provide a substantive response within 30 days, subject to complexity and lawful exceptions. We may verify your identity before fulfilling requests.

If you are not satisfied with our response, and the Privacy Act 1988 (Cth) applies to your complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. Users in other jurisdictions may have additional rights to complain to their local privacy regulator.

Some data may be retained where required by law or for legitimate operational purposes even after a deletion request.

11. Cookies and Local Storage

We use browser local storage and similar technologies to operate the service, including:

• authentication token (`wa_token`) to keep you signed in;

• active session and stream-resume state for writing and adventure features;

• locale, UI preferences, and product configuration flags.

These technologies are functional rather than used for third-party advertising cookies. You may clear browser storage, but doing so may sign you out or reset preferences.

12. Minors

Talevo is not directed to individuals under 18. We do not knowingly collect personal information from anyone under 18.

If you believe a minor has provided personal information, contact us using the details in Section 14 and we will take appropriate steps to delete it.

13. Policy Updates

We may update this Privacy Policy from time to time. For material changes that are not urgently required, we will provide at least 15 days' notice before the updated Policy takes effect.

Continued use after the effective date means you acknowledge the updated Policy where permitted by law.

14. Contact

Email: qinkunpeng2015@gmail.com (personal contact address of the operator; suitable for privacy, billing, copyright, and refund requests).

You may also submit requests through in-app feedback.

Privacy Policy | Talevo