Privacy
Effective 26 September 2026
This policy explains how personal data is handled by the website at teitha.com, the beta mailing list, and the teitha desktop application. Where the website and the application differ, each is addressed separately.
Summary
- You browse this site
- No personal data is collected. No cookies, no analytics, no third-party requests.
- You join the beta list
- We store your email address, the date you joined, and your answers to the three signup questions. Nothing else.
- You install the app
- It checks dl.twriter.sh for updates at each launch. Your work stays on your device.
- You enable AI features
- Your requests go directly to Anthropic under your own API key. We do not receive them.
Who we are
teitha.com and the teitha desktop application are operated by an independent software developer established in Uruguay, who is the data controller for the personal data described in this policy.
This policy covers the website, the beta mailing list, the download and update service, and the desktop application.
Personal data we collect
The website
Browsing this site collects no personal data. There is no account system, no cookie, no analytics, and no request to any third-party server.
If you join the beta mailing list, we collect your email address, the date and time of submission, and your answers to the three signup questions: the platform you would run teitha on, how much you have written, and what you write. The endpoint does not read or record your IP address, user agent, or referrer.
Cloudflare, our hosting provider, processes connection data including your IP address in order to deliver the site. We retain no server logs of our own.
Application downloads are served from dl.twriter.sh, our own storage. As with any download, that server receives your IP address and user agent.
Where a teitha.com link is shared on a third-party platform, that platform's servers request the preview image from us.
The application
The application collects no personal data and transmits nothing by default. Your manuscript, notes, and story data are files on your own device.
It makes three types of outbound connection.
- Update checks
- At each launch, the application requests the update manifest from dl.twriter.sh. That server receives your IP address, operating system, and application version. No document content is transmitted. There is currently no setting to disable update checks.
- AI features (optional)
- AI features are inactive until you supply your own Anthropic API key. When you invoke one, the application transmits the content that request requires directly to Anthropic under your own account: manuscript passages, the related story data, your direction notes, your conversation history, and file paths. This data is not routed through our servers.
- Spell check dictionaries
- On Windows and Linux, the application's browser engine downloads a dictionary from Google's servers on first use, disclosing your IP address and language. Text you type is checked locally and is not transmitted.
All other application data remains on your device, including error logs, token usage records, conversation history, and your API key. The key is encrypted using your operating system's secure storage and is not accessible to the application's interface layer.
Purposes and lawful bases
- Beta mailing list
- Purpose: to send a single notification when a release is available. The signup answers are used to decide which builds are prioritised and which testers are invited first. Lawful basis: consent, which you may withdraw at any time.
- Website hosting and delivery
- Purpose: to deliver the site and maintain its security. Lawful basis: legitimate interests.
- Update checks
- Purpose: to distribute security and functionality updates to installed software. Lawful basis: legitimate interests.
- AI features
- Data transmitted to Anthropic under your own API key is not processed by us and requires no lawful basis on our part. It is governed by your agreement with Anthropic.
We do not use personal data for profiling, advertising, or automated decision-making.
Third parties and disclosure
The following are the only third parties involved in the processing described in this policy.
- Cloudflare
- Hosting, the beta signup endpoint, storage of the mailing list, and distribution of downloads and updates. Acts as our processor under its data processing addendum.
- Anthropic
- Receives AI requests made under your own API key. Anthropic acts as your provider under your agreement with it, not as our processor. We do not receive, store, or have access to that data, and its use, including for model training, is governed by your agreement with Anthropic.
- Provides spell check dictionaries to the application on Windows and Linux, as described above.
- GitHub
- Builds and deploys the website. It processes no visitor data.
We do not sell or share personal data, including as those terms are defined under California law. We use no data brokers, no advertising networks, and no mailing list rental.
We may disclose personal data where required by law. For the beta mailing list, that consists of an email address, a date, and three multiple-choice answers.
Retention
Beta mailing list: retained until the release notification has been sent, and deleted no later than six months after that, or earlier on request. The list is stored in Cloudflare's key value storage, which is replicated across Cloudflare's global network.
Data stored on your device is under your control. Conversation history is deleted automatically after 90 days by default, a period you can change. Files deleted within the application are moved to your operating system's trash. Your API key is retained until you remove it.
We retain no download or usage records.
Your rights
We extend the following rights to all users regardless of location: access to the personal data we hold about you, rectification, erasure, restriction of processing, objection to processing, and portability. Where processing is based on consent, you may withdraw that consent at any time.
To exercise any of these rights, write to [email protected]. We respond within the period required by applicable law.
We cannot act on data transmitted to Anthropic under your own API key, as we neither receive nor hold it. Direct such requests to Anthropic. Data stored on your own device is likewise not accessible to us.
You may lodge a complaint with the supervisory authority in your jurisdiction. In Uruguay this is the Unidad Reguladora y de Control de Datos Personales.
Cookies and tracking technologies
This site uses no cookies, local storage, tracking pixels, fingerprinting, or analytics. No consent banner is presented because no such consent is required.
The site's content security policy permits no third-party origins, which prevents third-party scripts from loading.
Children
teitha is not directed at children. We do not knowingly collect personal data from anyone under 16, and we operate no age verification.
If you believe a child has submitted an email address, write to [email protected] and it will be deleted.
International transfers
The controller is established in Uruguay, which the European Commission recognises as providing an adequate level of data protection.
The beta mailing list is stored on Cloudflare's global network. Transfers are governed by Cloudflare's data processing addendum, which incorporates the standard contractual clauses.
AI requests made under your own API key are transmitted to Anthropic's infrastructure under your agreement with Anthropic.
Security
Data minimisation is the principal measure: we hold no accounts, no passwords, and no document content.
The site is served over HTTPS with strict transport security and a content security policy restricting resources to its own origin. The signup endpoint is implemented so that it cannot record identifying request metadata.
In the application, your API key is encrypted using operating system secure storage and is not exposed to the interface layer.
Windows builds are not currently code signed. Each release is published with a SHA-512 checksum for verification.
In the event of a personal data breach, we will notify affected individuals and the competent supervisory authority as required by law.
Changes to this policy
Revisions are published on this page with a revised effective date and take effect on publication. We do not send email notifications of changes to this policy.
Contact
For questions, requests concerning your rights, or complaints: [email protected].