1. Introduction
Quibu ("we," "us," or "our") is a worldbuilding editor for fantasy authors and game masters. This Privacy Policy explains how we collect, use, and protect your information when you use our desktop application and cloud services (collectively, the "Service").
Our desktop application works fully offline with no account required. Cloud features (sync, sharing, and AI-powered tools) are optional and require a paid subscription and account creation.
2. Information We Collect
2.1 Account Information
If you create an account for cloud features, we collect your email address and a hashed password. We do not store your password in plain text.
2.2 Project Data
When you use cloud sync, your project files (stories, lore entries, maps, images, and other content you create) are uploaded to and stored on our servers. This data remains on our infrastructure and is associated with your account.
2.3 Payment Information
Payment processing is handled entirely by Stripe. We never receive, store, or have access to your full credit card number or payment details. We receive only a confirmation of your subscription status from Stripe.
2.4 Usage Data
With your consent, we collect basic analytics about how the web application is used (such as page views) through Vercel Analytics. Analytics is not loaded if you choose "Essential only." The desktop application does not collect any usage data when used offline.
2.5 Cookies & Local Storage
We use strictly necessary, HTTP-only cookies to authenticate users and protect account sessions. These include a short-lived access cookie and a refresh cookie used to keep you signed in securely. Our authentication provider may also set cookies required to complete and maintain authentication. Because these cookies are necessary to provide sign-in and account security, they are not disabled by the analytics choice.
We store your cookie-consent choice in your browser's local storage so the website can remember it on that device. You can clear the choice at any time by clearing this website's local storage in your browser.
3. How We Use Your Data
- Cloud Sync & Storage: Your project data is stored on our servers to enable cross-device synchronization and cloud backup.
- AI Features: When you use AI-powered features (lore checking, content generation, smart paste, or querying), relevant portions of your project content are sent to OpenAI for processing. When you generate concept art, the image prompt is sent to fal.ai for processing. OpenAI does not use API inputs or outputs to train or improve its models unless the API customer explicitly opts in to data sharing. Quibu does not opt in to that data sharing. Quibu also sends OpenAI Responses API requests with application-state storage disabled. Under OpenAI's standard API controls, prompts, responses, and embeddings may nevertheless appear in abuse-monitoring logs retained for up to 30 days. For approved OpenAI projects using Zero Data Retention or Modified Abuse Monitoring, customer content is excluded from those logs. The original content chunks remain stored on our servers for future queries. fal.ai request history is disabled for concept-art generation, and generated media is set to expire after one hour.
- Sharing: If you choose to share a project via a share link, the shared content becomes accessible to anyone with that link. You control when sharing is enabled or disabled.
- Email: We use your email address to send account verification emails and critical service notifications. We do not send marketing emails.
4. Data Storage & Security
Your project data is stored on our servers using industry-standard cloud infrastructure (Neon PostgreSQL for structured data, Cloudflare R2 for file storage). We use encryption in transit (HTTPS/TLS) for all data transfers between your device and our servers.
Authentication tokens are secured using JWT with strong signing secrets. Passwords are hashed using bcrypt before storage.
5. Third-Party Services
We use the following third-party services:
- Stripe — payment processing. Subject to Stripe's Privacy Policy.
- OpenAI — AI text generation and embeddings. API data is not used for model training unless Quibu explicitly opts in, which Quibu does not do. Responses application-state storage is disabled. Standard abuse-monitoring retention of up to 30 days may still apply unless enhanced OpenAI data-retention controls have been approved and enabled for the project.
- fal.ai — AI image generation using FLUX.1 Schnell. Request history is disabled and generated media is set to expire after one hour.
- Vercel — web application hosting and analytics.
- Resend — transactional email delivery.
- Cloudflare — DNS, CDN, and file storage (R2).
Unless you explicitly share your project, your project content is never shared with any third party beyond the AI inference described above.
6. Data Retention
Your project data remains on our servers for as long as your account is active. If you cancel your subscription, your data will be retained for 30 days to allow for re-subscription. After 30 days, your cloud-stored data may be permanently deleted.
The desktop application stores all data locally on your machine. We have no access to data that has not been synced to our cloud service.
7. Your Rights
You have the right to:
- Access and review the personal information we hold about you
- Request correction of inaccurate data
- Disable cloud sync at any time and continue using the app offline
- Delete your share links to stop public access to shared projects
- Contact us to request deletion of your account and associated data
To exercise any of these rights, contact us at the email address listed below.
8. Children's Privacy
Quibu is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on our website with a revised "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: support@quibu.app