InsideHow it worksStudioPricingFAQ
Legal

Privacy policy

What we collect, why we collect it, who else sees it, how long we keep it, and how to make us delete it. No dark patterns and nothing sold.

Last updated 2 August 2026

Accounts are still being connected. Right now a guide you build is saved in your own browser and never reaches a server, which is why the app says so on the dashboard. The sections below describe what happens once accounts are live.

01The short version

  • We collect what is needed to run the service and nothing beyond it.
  • We do not sell your data and we do not share it for advertising.
  • We do not run third-party advertising or tracking pixels.
  • Your guides are yours. Ask and we delete them, and your account with them.

02What we collect

Account details. Your email address, and a password we never see in plain text because our authentication provider hashes it.

What you make. The niches you search, ideas you save, guides you build, edits you make, and the exports you generate. This is the product; without it there is nothing to show you when you come back.

Billing details. Your plan, billing period, and renewal date. Card numbers never touch our servers. Payment is handled by Stripe, which sends us a customer reference and the last four digits, nothing more.

Technical logs. IP address, browser and device type, timestamps, and errors. Ordinary server logs, used to keep the thing running and to find out why something broke.

We do not ask for your date of birth, your phone number, your address, or anything else the service does not need.

03Why we are allowed to hold it

  • To perform our contract with you: your account, your guides, your plan.
  • Legitimate interest: keeping the service working, secure, and free of abuse.
  • Legal obligation: tax and accounting records for payments.
  • Consent: product email, which you can withdraw at any time without losing anything.

04Who else sees it

Only the companies we need to run the service, each doing one job:

  • Anthropic: your prompts and guide text are sent to the Claude API to write and revise. Anthropic does not train on API data by default.
  • Supabase: accounts, database, and file storage.
  • Stripe: payments. They hold the card details, we do not.
  • Vercel: hosting and server logs.
  • Pexels: photo search. We send the search terms, not anything about you.

Nobody on that list gets your data for their own marketing. We will hand data to law enforcement only where the law actually requires it.

05Where it is held

Our providers run infrastructure in the United States and the European Union, so your data may be processed outside your country. Where that involves data leaving the UK or EEA, the transfer relies on Standard Contractual Clauses.

06How long we keep it

  • Account and guides: while your account is open.
  • After you delete your account: removed within 30 days, apart from backups, which roll off within 90.
  • Payment records: kept as long as tax law requires, usually 6 to 7 years.
  • Server logs: 30 days.

07Your rights

Wherever you are, you can ask us to show you what we hold, correct it, export it, or delete it. In the UK, the EEA, and several other places these are legal rights rather than courtesies, and they also include objecting to processing and asking us to restrict it.

Email contactnashdeen@gmail.com and we will act within 30 days. There is no charge. If you are in the UK or EEA and you are not satisfied, you can complain to your data protection authority.

08Cookies

Octavo sets a session cookie so you stay signed in, and stores your local preferences in your browser. That is all. There is no advertising cookie, no analytics pixel, and no cross-site tracker, so there is no consent banner to dismiss.

09Children

Octavo is not for under-18s and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

10If something goes wrong

If a breach happens and it puts you at real risk, we will tell you and the relevant authority within 72 hours of finding out, and we will say what happened rather than dressing it up.

11Changes and contact

Material changes to this policy get notice before they take effect, and the date at the top always reflects the current version. Anything you want to ask goes to contactnashdeen@gmail.com. See also the terms of service.