Epoch Studio

Privacy Policy

Effective 11 August 2026 · Epoch Works LLC, 118 Conemaugh Avenue, Jerome, PA 15937, USA · chriskantz@gmail.com

The short version. Epoch Studio is local-first. Your manuscripts and projects are stored on your device and are not sent to us. We do not operate a server that receives your creative work, we do not sell your data, and we do not train AI models on your manuscripts.

Your work leaves your device only when you choose to use an optional third-party service — such as a cloud AI provider whose key you enter — or for the narrow system functions listed below. Section C lists every destination the software can reach.

1. Who we are

Epoch Studio is published by Epoch Works LLC (118 Conemaugh Avenue, Jerome, PA 15937, USA). For privacy questions, contact chriskantz@gmail.com.

2. What we store, and where

DataWhere it livesSent to us?
Manuscripts, chapters, characters, analysis, images, project filesYour device — local browser storage and, in the desktop app, your operating system's user-data folderNo
App settings, including any API keys you enterYour device — local settings storageNo
Error logs, if a feature failsYour device — a local log file, rate-limitedNo
Session and writing statistics, goals, streaksYour deviceNo

We do not maintain accounts, and the software contains no analytics, advertising, or telemetry.

3. API keys

If you enter API keys for third-party providers, they are stored locally on your device and used only to call the provider you configured. We never receive your keys. Treat them as you would a password: anyone with access to your device could read them.

4. When your content leaves your device — and only then

Nothing about your work is transmitted off your device except in the cases below. These are summarised here and listed exhaustively in Section C.

5. Privacy mode is on by default

The software includes a setting to never send manuscript text to the cloud, and it is enabled by default. While it is on, AI features run only on a local model; if no local model is available, the feature is blocked rather than sent off your device. You can turn it off if you want to use a cloud provider.

6. We do not train on your work

We do not use your manuscripts or projects to train, fine-tune, or evaluate AI models. Any model training would require your explicit, separate, opt-in consent, which we do not currently request or collect.

7. We do not sell your data

We do not sell, rent, or share your personal information or creative work. There is no advertising.

8. Children

The software is not directed to children under 13, and we do not knowingly collect personal information from them.

9. Your rights

Because your data is stored locally and we do not hold it, you control it directly — you can view, edit, export, and delete your projects within the software at any time. For any personal data you believe we hold (for example, if you email us), you may request access or deletion at chriskantz@gmail.com.

10. Third-party services

When you use an optional third-party service, that service's privacy policy governs the data you send it. We do not control those services. The current set of services the software can reach is in Section C.

11. Security

Your data is stored locally under your operating system's protections. The software restricts file access to approved locations and validates external links before opening them. No system is perfectly secure; keep your device and accounts protected.

12. International users

Your data stays on your device wherever you are. If you choose a cloud provider, your content may be processed in the country where that provider operates, under their terms.

13. Changes

We may update this policy. Material changes will be communicated in the app or on next launch.


Section C — every destination the software can reach

Verified against the source code on 11 August 2026, and re-verified before each release.

DestinationTriggerData sent
A cloud text-AI provider you configure (Anthropic, OpenAI, Groq, OpenRouter, Google Gemini, xAI, Together, Cerebras, Pollinations)You enable it with a key and privacy mode is offThe manuscript or derived text for the feature you invoked
An image provider you configure (Pollinations, or fal.ai / Replicate / Stability / Ideogram with your key, or your own local installation)You generate an imageThe image prompt, built from metadata
Brave Search, or a SearXNG instance you nameYou turn web search on and run a searchOnly the search query you typed
WikipediaYou use the research lookupYour search term
Hugging Face, or its mirrorYou download a modelNothing — a file download
Update host (GitHub releases)Desktop app launch, and a download if you updateA version check
Your own local networkYou start local model discoveryA local probe only; it stays on your network

The software contains no analytics, advertising, or telemetry calls. Namespace identifiers that appear in exported files, such as EPUB XML namespaces, are not network requests.