Skip to content
Back to Calamus

Privacy

Privacy Policy

This policy states the categories of personal data processed by Calamus, the purpose and lawful basis for each, every processor engaged, the countries to which data is transferred, the period for which each category is retained, and the rights available to you. Read it in full.

Last updated 9 September 2026. This policy applies to the writing application at write.calamusapp.com, the macOS desktop application, the iPadOS and iOS applications, and the website at calamusapp.com. It describes the processing actually carried out by that software. It should be read together with the Cookie Policy and the data deletion notice.

1. Controller

Calamus LLC, 4539 N 22nd St, Ste N, Phoenix, AZ 85016, United States, is the controller of the personal data described in this policy and determines the purposes and means of its processing. We have not appointed a data protection officer, no statutory obligation to do so arising for an undertaking of this size. Correspondence concerning this policy should be sent to support at calamusapp dot com.

2. The website

2.1. calamusapp.com collects no personal data before you respond to the cookie banner, and none at all unless you submit an email address through the waitlist form. No session recording is performed and no first-party analytics technology is deployed.

2.2. Where you consent to the marketing category, the Pinterest tag is loaded and sets Pinterest’s cookies, for the purpose of measuring the effectiveness of paid advertising. Where consent is refused the tag is not loaded. Each category and the cookies within it are identified in the Cookie Policy.

2.3. An address submitted through the waitlist form is transmitted to Calamus and forwarded server-side to a Mautic mailing list instance operated by us at waitlist.calamusapp.com. The address is not transmitted from your browser to any third party. No name, referring page or tracking parameter is collected with it.

3. Account data

Registration requires an email address and a password, both processed by Supabase Auth. Calamus retains no copy of your password and does not receive it in plain form. A first name is stored where you supply one. Where two-factor authentication is enabled, the shared secret for your authenticator application is held by Supabase Auth and not by Calamus.

4. Content you create

4.1. Content created in the application is stored in a PostgreSQL database operated by Supabase. It comprises books, the Binder tree, chapters and scenes and their text, synopses and outlines, Codex entries and the relationships between them, research folders, sources and links, moodboard items, ideas, notes, to-dos, word bank entries, timeline beats, pen names, series, and per-book compile settings.

4.2. Snapshots constitute version history and store text, not word counts alone. Each capture records the text of the scene or chapter as it stood at the time of capture, in plain text, together with the timestamp, the word count, and any label you applied. Captures arise in three ways: automatically as you write, on your instruction, and on a restore, which captures the text it is about to replace.

4.3. The text within captures is subject to a cap. Per scene and per chapter, the 20 most recent captures retain their text, as do the 50 most recent captures taken on your instruction or created by a restore. Older captures retain their timestamp, word count and position in the history and cease to retain the text. A capture is deleted when the scene or chapter to which it relates is deleted, and with the book or the account, as part of the same cascade.

4.4. Row-level security is enabled on every table and scoped to your own user. Access across accounts is refused by the database itself rather than by application code.

4.5. Interface preferences, including editor font size, compile margins, theme and panel widths, are stored on the device on which they are set: in browser local storage in the web application, and in the system preferences store in each native application, as declared in their privacy manifests. They are not transmitted to a server and do not synchronize between devices.

5. Images you upload

5.1. Book covers, author photographs, character portraits, moodboard images, publisher logos and timer backgrounds are stored in a private Supabase Storage bucket named book-assets. No object in that bucket is retrievable by address.

5.2. In the web application, each image is requested through a Calamus route that verifies an authenticated session, verifies that the file is filed under your own user identifier, and only then issues a signed link valid for 60 seconds. In the native applications, each file is requested over an authenticated path that does not expire during a session, short-lived links having proved unreliable during scrolling. The verification is identical in both cases: a valid session and ownership of the file are required, or nothing is returned. Only the duration of the permission differs.

6. Support, feedback, and exports

6.1. A support ticket stores its subject, the messages exchanged, and any screenshots you attach. Attachments are stored in private Vercel Blob storage and are served only through a route that verifies ownership of the ticket. Feedback submitted from Settings stores a category, a title and your description. Both generate a notification to us by email through Resend.

6.2. Settings can deliver an export of all projects by email. The archive is uploaded to private Blob storage and the message contains a link bearing a random token that ceases to function 24 hours after issue. The token alone is not sufficient: retrieval requires an authenticated session, ownership of the export, and a recognized device. Each retrieval is recorded in the security log.

7. Payment

7.1. Purchases are processed by Stripe Checkout. Card details are collected by Stripe and are not received by Calamus. Calamus stores against your account the product purchased, the Stripe checkout session and payment intent identifiers, the amount and currency, the date, and whether the purchase was subsequently refunded or disputed. The email address is collected by Calamus before checkout, in order that the purchase may be attached to an account and that a previously refunded address may be declined without being charged. Stripe returns the name supplied to it during checkout.

7.2. Where a purchase is refunded, the account is deleted seven days later and one record is retained beyond that point: the email address, the payment reference, and the relevant dates. It evidences what was sold and refunded and gives effect to the restriction on repurchase. It contains no part of your content. The full sequence is set out in clause 7 of the Terms of Service.

7.3. Calamus Ideas is included for holders of a Calamus license. A separate subscription to it, for persons who do not hold one, is sold by Apple rather than by Stripe. Apple collects the payment, so no card details and no Apple ID identifier are received by Calamus. The record stored corresponds to that for a Stripe purchase: the existence of a subscription, the transaction identifier supplied by Apple, and whether it is currently active.

8. Technical data

8.1. Your IP address and user identifier are used as rate-limiting keys in Upstash Redis, within short sliding windows, on sign-in, checkout, the desktop download, account exports, password changes, two-factor verification, device verification, requests for a device code by email, and connection of a social account. These are counters rather than a record of activity and expire with their windows.

8.2. Calamus contains no analytics product, no advertising technology, and no session recording, and performs no tracking of what you write or when you write it beyond the word counts displayed to you. The security log described in clause 10 is the only record of use of an account, and it records access rather than content.

9. Device recognition

9.1. Sign-in from an unrecognized browser requires a code from your authenticator application, or, where none is configured, a six-digit code sent to the address on the account. An emailed code is stored as a keyed hash rather than in plain form, expires after ten minutes, is bound to the browser that requested it, and may be used once.

9.2. Successful verification causes that browser to be recognized for 30 days. Recognition is held by two means: a cookie carrying a random token, signed to prevent forgery, and a database record carrying a keyed hash of that token rather than the token itself, so that a copy of the database does not yield a working credential. The record also stores a label derived from the user-agent string, such as “Safari on iPad”, the user-agent string itself, and the IP address and resolved country at which the device was first and last seen.

9.3. Recognized devices are listed in Settings under Security and may be revoked there. Revoked and expired devices remain in the list, so that the history of access to the account remains available.

9.4. Where a recognized device is observed on a different network, Calamus records an entry in the security log and takes no other action. Re-verification is not required for travel, for use of a virtual private network, or for a change of country. A change of address within the same block, which is consistent with a router obtaining a new lease, is not recorded.

10. The security log

10.1. Calamus maintains a security audit log. It is the only component of the application that records actions taken in respect of an account rather than content created within it, and its contents are therefore set out here in full.

10.2. An entry is written on each of the following: a successful sign-in; a failed sign-in; the first observation of a device; the success or failure of a device verification; the revocation of a device; the appearance of a recognized device on a different network or in a different country; the retrieval of an emailed export; the connection or disconnection of a social account; the deletion of an account; and the refund or chargeback of a purchase.

10.3. Each entry records the originating IP address, the country resolved from it, the user-agent string, and, where the event concerns one, the device and its label. Certain entries record one further detail specific to the event: the handle connected, the export file retrieved, or the Stripe payment refunded. No entry contains any part of your content.

10.4. An entry for a failed sign-in records the reason for failure, distinguished in four cases: an incorrect password, no account existing at the address supplied, the attempt having been rate-limited, or an incorrect second factor. The interface does not disclose which of those occurred, disclosure being a means by which the existence of an account at a given address could be established. The distinction is recorded in the log and not in the response.

10.5. Entries are accordingly written in respect of failed sign-ins against addresses at which no account exists, which constitutes a record concerning a person who is not a user of the Service. For those entries the address is not stored. What is stored is a keyed hash of the address, computed with a secret held only on the server, which preserves the property required, namely that repeated attempts against one address group together, while retaining nothing legible. An investigator holding a specific address can hash it and match; the table alone yields no addresses. The IP address, the country and the user-agent string are stored as received.

10.6. Entries are retained for 24 months with the IP address intact, after which the address is truncated in place: an IPv4 address loses its final octet and an IPv6 address everything below its first 48 bits. The event, its time, the account and the outcome are retained, so that the log continues to serve its purpose, and what is removed is the capacity to associate an entry with a particular connection. Entries are not deleted. The table refuses deletion, and refuses any update affecting any column other than that one, at the database level and without exception for Calamus. Retention beyond that point is deliberate: a chargeback may be raised months after the event, and a record capable of being erased by the person it concerns does not serve its evidential purpose. This is also why the log survives deletion of the account, as stated in the data deletion notice.

10.7. No interface in Calamus displays this log, to you or to any other person. A request for the entries concerning your account may be made from the address on the account.

11. Artificial intelligence and model training

Calamus contains no artificial intelligence or machine-learning functionality. Your content is not transmitted to any model provider, and is not used to train any model, by us or by any third party.

12. Connected social accounts

12.1. Calamus can publish extracts of your own manuscript to social accounts you connect. Bluesky is operative. Threads is implemented against the same interface but is not enabled and cannot be connected pending approval by Meta.

12.2. Connection is made per pen name, in Settings under Social. For Bluesky you generate an app password in Bluesky’s own settings and supply it to Calamus. An app password is distinct from your account password: it permits posting and reading on your behalf and may be revoked in Bluesky at any time without altering your account password or terminating other sessions.

12.3. Calamus verifies the credential against the platform before storing it, then encrypts it with AES-256-GCM before writing it to the database. Each record is assigned its own 12-byte initialization vector, stored alongside the ciphertext, and the authentication tag is appended to the ciphertext, so that a tampered value fails on decryption rather than decrypting to a value that would then be transmitted to a platform. The encryption key is held in a server environment variable and not in the database. Each record identifies the key version used to encrypt it, so that keys may be rotated without re-encrypting all records simultaneously.

12.4. Alongside the encrypted credential, the record stores the platform, the handle, the display name, a token expiry where the platform issues one (Bluesky app passwords do not), and whether the account is active or requires reconnection.

12.5. The credential is decrypted only on the server and only within the scheduled process that publishes. No component returning data to your browser handles the plaintext; interfaces receive the handle, the display name and the status only.

12.6. What is published is text taken from your own manuscript, edited by you where you chose to edit it, and expressly approved by you, to accounts you connected. Calamus does not read your timeline, your followers, your messages or your engagement metrics. It publishes nothing you have not approved, and it does not publish as Calamus.

12.7. Where a platform rejects a stored credential, the account is marked as requiring reconnection and notice is sent to you by email through Resend. Failed posts remain in the queue with the error returned by the platform.

12.8. If Threads publishing is enabled, its access token will be stored in the same encrypted form, refreshed on the schedule the platform requires, and used solely to publish a post you have approved to your own Threads account.

13. Processors

  • Supabase. The PostgreSQL database, authentication, and the image storage bucket. Hosted in us-east-1.
  • Vercel. Hosting for the application and this website, and private Blob storage for support attachments and account exports. Vercel’s network additionally resolves an IP address to a country, which is the country recorded in the security log.
  • Stripe. Payment processing. Card details are received by Stripe and not by Calamus.
  • Resend. Transactional email, including support notifications, export links and reconnection notices.
  • Upstash. Redis, used solely for rate limiting.
  • Mautic, operated by us at waitlist.calamusapp.com. The launch waitlist mailing list.
  • Bluesky, and Threads if enabled. Recipients of the posts you approve, and of nothing else.
  • Apple. Processes payment for the Calamus Ideas subscription and reports its status. Apple has no part in a purchase processed by Stripe.
  • Pinterest. Advertising measurement on the website only, and only where you consent to the marketing category. The tag is not present in the application and receives no part of your content.

That list is exhaustive. No data broker and no analytics vendor is engaged. The sole advertising undertaking is Pinterest, it appears on the website only, and only on consent. We do not sell personal data and we do not share it for the marketing purposes of any third party.

14. Retention

Retention periods applied by the software
CategoryRetention periodNotes
Content you createFor the lifetime of the accountDeleted with the book or the account
Text within snapshotsThe 20 most recent captures per scene or chapter, plus the 50 most recent taken on your instruction or created by a restoreOlder captures retain timestamp and word count only
Deleted chapters and scenes30 days in Trash, then 30 days in ArchivePermanently deleted thereafter
Deleted books30 daysPermanently deleted with all content filed under them; no Archive tier
Deleted research sources30 daysPermanently deleted thereafter; Research has no Archive tier
Drafts and IdeasUntil deleted by youNot subject to automatic purging
Emailed export archivesLink ceases to function 24 hours after issueThe file itself is retained until removed on request
Support ticket attachmentsRetained after account deletionRemoved on request
Stored social credentialsUntil you disconnect the accountDeleted with the initialization vector
Purchase recordsAs required for accounting and tax purposesStripe retains its own records under its own policies
Refund recordsIndefinitelyEmail address, payment reference and dates; contains no content
Rate-limiting countersMinutes to hoursExpire with their own windows
Recognized devicesRecognition expires 30 days after verification, or on revocationThe record is retained, marked expired or revoked
Emailed device codes10 minutesMarked used on acceptance
Security log entriesIndefinitely; IP address truncated after 24 monthsDeletion is refused at the database level

15. International transfers

Calamus LLC is established in the United States, and your data is stored and processed in the United States by the processors identified in clause 13. The database holding your account and your content is operated in Virginia. If you are located in the United Kingdom, the European Economic Area or Switzerland, your data is therefore transferred outside your jurisdiction. Each processor is engaged under a data processing agreement, and the transfers rely on the European Commission’s Standard Contractual Clauses or on the processor’s certification under the EU-US Data Privacy Framework.

16. Lawful bases for processing

Data protection law requires a lawful basis to be identified for each purpose of processing. They are not uniform across the categories described in this policy, and are as follows.

  • Your account, your content, and synchronization. Performance of the contract entered into on registration. Without this data the Service cannot be provided.
  • Purchases and refunds. Performance of the contract, and thereafter compliance with a legal obligation, tax and accounting law requiring a seller to retain a record of what was sold.
  • The waitlist and marketing email. Consent, given on submission of the address. Every message carries a means of unsubscribing, by which consent is withdrawn.
  • Analytics, advertising measurement, and embedded video. Consent, given through the cookie banner and withdrawable at any time using the Cookie settings link in the footer of any page.
  • Security, device recognition, and prevention of abuse. Our legitimate interest in preventing unauthorized access to accounts and content, balanced against the limited nature of the data processed and the fact that it comprises no part of your content.

17. Your rights

Where the UK GDPR or the EU GDPR applies to you, the rights set out below are available. Most may be exercised directly within the application without a request to us.

  • Access. Settings exports all content you have created, in archive form, at any time and without a request.
  • Rectification. Content you created may be edited directly. Write to us in respect of anything you cannot reach.
  • Erasure. Individual items, a whole book, or the account in its entirety. Each route is set out in the data deletion notice.
  • Portability. The same export constitutes a machine-readable copy suitable for transfer to another service.
  • Restriction and objection. You may require us to restrict a particular use, including any processing carried out on the basis of legitimate interest.
  • Withdrawal of consent. Unsubscribe from any message, or vary your cookie choices from the footer of any page. Withdrawal does not affect the lawfulness of processing carried out beforehand.

Requests are answered within one month. No fee is charged, and no detriment follows from making a request. The security log described in clause 10 and the refund record described in clause 7.2 are the two categories that cannot be erased on request, for the reasons stated in those clauses. All other categories can.

18. Complaints

A complaint may be made to us in the first instance, which is ordinarily the faster route, but you are not required to do so. If you are in the European Economic Area you may complain to the supervisory authority in your country of residence. In the United Kingdom, the supervisory authority is the Information Commissioner’s Office, at ico.org.uk. A complaint costs nothing and has no effect on your account.

19. Children

The Service is not directed at children under 13 and we do not knowingly collect personal data from a child under 13. Where a user is under 16 and resident in the European Economic Area or the United Kingdom, consent to the processing of their data is given by a parent or legal guardian rather than by the user. If you believe a child under 13 has supplied us with personal data, write to us and we will delete the account and its contents.

20. Processing on your devices

Calamus for Mac and iPad, and Calamus Ideas for iPhone, operate against the same account and the same data as the web application, and everything above applies to them. The following describes processing carried out on the device itself.

Local cache of work in progress. Before each save, the application writes the current text to a file on your device and deletes it once the server confirms the save. The file does not leave the device and is not transmitted. Its purpose is to limit the loss caused by a crash, a loss of power, or a forced quit to a few seconds of work.

Photograph access, iPhone only. Calamus Ideas requests access to photographs at the point you select an image to accompany a note. It reads only the image you select, does not enumerate your library, and does not request access before a feature requiring it is used. The remainder of the application functions if access is refused.

Font enumeration, Mac only. On compiling a book, the application reads the fonts installed on your computer in order to list them and to determine the embedding permissions granted by each designer, some fonts being embeddable in a print PDF but not in an editable Word file. This processing occurs entirely on your device. No font, and no list of your fonts, is transmitted to us.

Credential storage. Your sign-in credential is held in the system Keychain, the store provided by macOS and iOS for that purpose, which we cannot read. Signing out removes it.

Device naming. On verifying a new device we store a name for it, taken from the name the device reports, so that the list in your settings is legible. Any device may be revoked from that list with immediate effect.

No tracking or analytics. Neither application contains an advertising identifier, an analytics SDK, or any technology that follows you into the applications or websites of other undertakings. This corresponds to the privacy manifest declared by each application to Apple.

21. Amendments

This policy describes the processing carried out by the software as it currently operates, and is amended when that processing changes. The date stated at the head of this document is the date of the current revision.

22. Contact

Correspondence concerning this policy, including a request to exercise any right described in clause 17, should be sent to support at calamusapp dot com, or to Calamus LLC at the postal address stated in clause 1.