Privacy Policy
Last updated 7 September 2026.
Proselon is made by Holstein Creations LLC. This policy covers this website and the Proselon app. The short version is that your manuscripts never reach us, being plain files in a folder of your own choosing, and what we do hold is the small set of things an account and a subscription require.
What we never collect
Your writing. When Proselon first runs it asks where your books should live, and it offers four answers: a folder in iCloud Drive, Dropbox, Google Drive, or OneDrive. Under Advanced it will also keep them on this computer and nowhere else. Wherever you point it, the books remain plain files in a folder you can open yourself. Proselon does not upload them, back them up to us, index them, or train anything on them. We hold no copy of a manuscript anywhere. If your library sits in a synced folder, the service that syncs it can read those files as it reads anything else you keep there, under its terms rather than ours. If you delete Proselon, your books are still sitting there in plain files.
What we do collect
- Your email address and password, to make the account work. The password is stored hashed by our authentication provider, and we never see it in the clear.
- Your IP address and browser/app user agent, recorded when you sign up and when you sign in, and also when an attempt to do either is refused — a wrong password, a confirmation code that does not match, a request for a reset. The refusals are recorded because they are what a limit has to be counted from: too many of them against one address, or from one place, and we make the next attempt wait. We keep all of it to spot abuse of the free trial and to investigate suspicious sign-ins. It is not used for advertising or profiling, and the password itself is never written down, whether it was right or wrong.
- The address you write from, when you send us a message. Writing through the form on our contact page leaves a line recording that a note arrived from your IP address, and writing through the help form inside Proselon leaves one recording that a note arrived from your account. The note itself is stored in neither case: it becomes an email to us and the request is over. What the line is for is the same limit as above, since each of those forms sends mail from our own domain and a cap on how often it may do so has to be counted from something. The email address typed into the contact form travels in the message so that we can reply to it, and is not written into our database.
- Your agreement to the Terms of Service, recorded when you create your account, meaning the date and which version of the terms you accepted. This is the record that the agreement was made.
- How you found us, recorded once at signup. If you arrived through a campaign link, a tagged link, or from another site, that channel’s label and the campaign’s name are stored with your account, and a first-touch cookie holds the label for up to ninety days beforehand so the signup can record it. Channel labels only, never your browsing history. This record is separate from the usage counts below and their switch, because it is made once at signup rather than counted over time.
- Subscription state, meaning which plan you are on, whether you are trialing, active, past due or cancelled, and the relevant dates. Your card number is never sent to us or stored by us. It goes directly to Stripe.
- A device list. Each computer you sign in on registers itself with your account, recording whether it is a Mac or a Windows machine, its OS and app version, its computer name, and when it was last seen. This is what enforces the five-device limit and what lets you sign out a device remotely from your account page on the web.
- The moment you last ended your sessions. Changing your password, or resetting one you have forgotten, now signs out every browser and every computer the account was signed in on, and the time it happened is stored so that any session older than it is refused. It is one date and time, kept only for accounts that have changed a password, and it exists so that a password change is a real remedy if you ever believe somebody else has reached your account.
- Usage counts from the app: how often Proselon is opened, how long sessions last, whether the opening setup was finished, which writing engine, theme, export formats and library storage provider get used, and which kind of Framework a project carries when you open it. Counts and choices only, sent to PostHog, the same measurement service this website uses. See the next section for exactly what this can and cannot contain, and for the off switch.
- Website analytics. This site uses PostHog to count visits, to see which pages are read, and to record which element a visit clicked through on its way to a download or an account. That last measurement runs on the pages that describe and sell Proselon, where the words a click passes through are our own published copy. It is dropped on your account page and on the sign-up, verification and password forms, where what stands on the screen is yours rather than ours. The site sets cookies and sends that record to PostHog, whose servers are in the United States. The record includes the approximate place, at the level of a city, from which your connection reached the site. Pages are counted by their address, and whatever in an address identifies you is replaced before the count is sent: a password-reset token, a confirmation code, the email address the verification page is opened with. When you create an account, the visit that led to it is joined to the account by the account’s own identifier, which is a string of characters and not your email address, and the channel that brought you is kept beside it. Nothing on this site records your screen, and nothing reads what you type into it.
- A record of the mail we send to your account. Whenever Proselon emails you, we record which message it was, and afterwards whether it reached you, bounced, or was reported as spam. That record goes to PostHog, the same measurement service named above, and is attached to your account. It holds the message’s name from a short fixed list of our own, the identifier our mail service gives that one message so we can trace it if you tell us nothing arrived, and the time. We never record the subject line, and never a word of what the message said. It exists so that we can see what Proselon has already written to you before we write to you again. Nothing in it records whether you opened a message or followed a link, because we do not measure either.
Usage counts from the app
The app tells us when it is opened, how long a session lasts, which writing engine you picked and whether its setup finished, when you reached the end of the opening setup, which theme you chose, which export format you ran, and which storage provider you keep your library in. While the app is open it reports that length as the session goes along rather than only once you have quit, so a session still counts when the app is closed abruptly or never closed at all. What it measures is the time the window is in front of you and you are working in it. A Proselon window left open behind something else adds nothing. The provider is a name from a short fixed list, never a folder or a path. Two of the engines are configured inside Proselon itself, and for those the app also reports which model you chose. The Local model engine sends the model’s name, and the API Key engine sends that name along with the service the key points at. A model name is a setting of the same kind as your theme, and it is all that reaches us — never a word of what you asked the model to write. The subscription engines take that choice inside their own window, where Proselon cannot see it, so for those we report nothing and guess nothing. When you set an engine working, the app reports which of the two co-writer surfaces you were working in, the Proselon chat window or the Terminal. That is one of two fixed words, and it tells us nothing of what you asked for or what came back. When you open a project, the app reports that it happened and which kind of Framework the project carries, meaning a Fiction Book or Series, a Nonfiction Book or Series, an Essay or Article Collection, no Framework at all, or one you installed yourself, which is reported as your own and never by name. That category is all of it. Nothing about the writing travels with it: not the project’s name, not its files, not its length, not how many projects you have, and no identifier of any kind that would let one opening be matched to another, so these counts cannot be gathered into a picture of any book of yours. Each count is a named event with a timestamp and, at most, a short value drawn from a fixed list — values outside those lists are dropped before anything is sent, so this channel cannot carry prose, chat, titles or paths even by accident. We use it to answer questions such as how many writers are on Windows, which engines get used in practice, and whether people come back. These counts go to PostHog, whose servers are in the United States, and the record kept there includes the IP address they were sent from. Nothing here is sold, shared, or used for advertising. It is on by default and disclosed here. If you would rather not send it, turn it off at proselon.com/account/privacy, which the app’s Settings point to. The switch governs the whole account rather than any particular computer, and the app reads your answer again each time it starts, so a computer already running keeps to the answer it had until you open it again. Turning it off records when you did, so we can prove we stopped.
Email we send you
Most of what we send is what the account requires: the verification code, a password reset you asked for, and the billing notices described in the Terms. There is one other kind. If your account was made and the app has never run, or if the app ran and no writing engine was ever set up, Megan writes to ask what happened and whether she can help. Those notes are decided by the two things this page has already described, meaning whether a computer of yours ever registered itself and whether the setup counts show an engine finished, and they stop of their own accord once you get going. Every one of them carries a link that ends them for good, and using it leaves the account mail untouched. If telemetry is off, we cannot tell where anyone stopped, so those accounts are written to about nothing except the account itself.
Your preference about those notes is kept by Resend, our email provider, rather than by us, so that it holds whichever way a message is sent. When you confirm your address it is stored there as a contact, which is what the preference attaches to; the record is your email address and the categories you have or have not turned off, and nothing else. Deleting your account deletes it, along with everything described under “Deleting everything” below.
Your preference about those notes is kept by Resend, our email provider, rather than by us, so that it holds whichever way a message is sent. When you confirm your address it is stored there as a contact, which is what the preference attaches to; the record is your email address and the categories you have or have not turned off, and nothing else. Deleting your account deletes it, along with everything described under “Deleting everything” below.
Who we share it with
Only the services that make Proselon run, and only what each one needs:
- Stripe, for payments and subscription management. It receives your email and payment details directly.
- Supabase, for account storage and authentication.
- Resend, for sending the account and billing emails described in the Terms, and the notes from Megan described above. It also holds your address as a contact, so that your preference about those notes survives however a message is sent.
- PostHog, for measuring how the website and the app are used. Your email address is attached there to the account it belongs to, sent when you confirm the address and again whenever you sign in or reset your password, so that a person in our measurements can be matched to a person in our records rather than to a bare identifier nobody can look up. PostHog also holds a copy of the billing record Stripe keeps for you — the same address, your subscription and your invoices — which it collects from Stripe directly rather than from us, so that what Proselon earns can be read beside how it is used. Deleting your account removes both: the address and the measurements attached to it are erased on request, and the billing copy goes at the next refresh, within six hours. Cancelling a subscription does not: your billing record stays with Stripe, and so does PostHog’s copy of it.
- Vercel, for hosting this website and the account service.
- GitHub, which holds the nightly backup of our database. It is encrypted before it leaves us, with a key GitHub does not have and cannot obtain, so what is stored there is unreadable to anyone but us.
Your AI provider is separate from us
Proselon’s co-writer runs on an AI account you sign into yourself, or on a model running locally on your machine. When you use it, what you send goes to that provider under their privacy policy rather than through us. We never receive it. If you use a local model, nothing leaves your computer at all.
How long we keep it
Account and subscription records last as long as your account does. Sign-in records (IP and user agent, whether the attempt succeeded or was refused), and the single line kept when a message is sent through the contact form or the help form, last while they are useful for abuse investigation. Usage counts from the app are held by PostHog for a year, after which PostHog deletes them. The record of the mail we sent you is held there on the same terms and goes the same way. The counts collected before 24 August 2026 are in our own database instead, kept for 13 months, then reduced to anonymous monthly totals and deleted. A device you sign out stays in the registry, marked signed out, for up to 12 months and is then removed. Stripe keeps its own payment records for as long as tax and financial rules require, independently of us. A backup of our database is taken nightly and kept, encrypted, for thirty days before it is deleted, so a record removed today leaves the backups within a month.
Deleting everything
You can delete your account at proselon.com/account/delete, which Settings inside the app links to. Doing so cancels any subscription immediately, deletes your Stripe customer record, deletes your rows in our database, sign-in records — refused attempts among them — and device list and usage events and consent records included, deletes the contact record and email preferences held by Resend, asks PostHog to erase the person your account identifier names together with the usage counts and the record of mail attached to it, and deletes the sign-in itself. PostHog carries that erasure out as a queued job rather than in the moment you press the button. Where the request cannot be made or does not arrive, what stands is the person that request would have erased, your address among it, since 28 August 2026 when we began attaching it there. PostHog deletes the counts a year after they reach it in any case, and we will have the whole person removed sooner if you ask us to — by email, to the address at the foot of this page, and it is a thing a person does rather than a job that runs. The copy of your billing record that PostHog holds is a separate thing and goes a separate way: deleting your Stripe customer record, which the same routine does first, removes it from PostHog at the next refresh within six hours, without anyone having to ask. The nightly backups are the one thing that does not go at once. A deleted account stays in whichever of them were taken before you asked, and goes when each of those reaches thirty days of age and is deleted with it. Deletion does not touch your books. Those are yours, on your machine. If you would rather we did it, email hello@proselon.com.
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, correct it, have it deleted, or object to how it is used. Email hello@proselon.com and we will act on it. If you are in the UK or EU, you also have the right to complain to your local data protection authority.
Children
Proselon is not intended for children under 13, and we do not knowingly collect their information.
Changes
If we change what we collect or who we share it with, we will update this page and change the date at the top. Material changes are emailed to the address on your account.
Contact
Questions, requests, or complaints: hello@proselon.com.
Proselon