Draft for legal review. This text was written by the product team and has not been reviewed by a lawyer. It is not legal advice. The fields in double square brackets name the legal entity and are filled in once it is decided; the notes marked Lawyer to confirm are decisions a lawyer must confirm or change before any live sale. Both disappear in the reviewed version.
1. What this statement covers
This statement supplements the Privacy Policy of [[SERVICE_NAME]] ([[SERVICE_DOMAIN]], the "Service"), operated by [[SELLER_LEGAL_NAME]], [[SELLER_ADDRESS]] ("we", "us"). It describes two things the Privacy Policy does not cover in detail: what we store about creators who write for the Service, and what we store when someone reports a problem with a Report. Everything in the Privacy Policy, including the companies that process data for us and how to reach us, continues to apply.
For buyers: what a purchase stores (your organization, the account that paid, the product, the amount, and Stripe's identifiers of the session and the payment, never your card number) is described in the Privacy Policy and in the purchase terms.
Lawyer to confirm: that a supplement to the Privacy Policy is the right form, and which US state privacy laws apply to the Service (for example the California Consumer Privacy Act) given its size and audience.
2. Creators
2.1 Your application
When you apply to write for the Service we store what you enter: the byline you want, your expertise, your disclosures, the links you give, and the account you apply from. We add the decision (approved, declined, or revoked), who made it, when, and a note explaining it.
Who sees it: the reviewers and editors of the publishing organization, and administrators of the Service. An application is never public. A declined application is kept so that you can apply again from the same account.
How long: as long as your account exists. Deleting your account deletes the application with it.
2.2 Your author profile
When your application is approved we make an author profile, which is public by design: your byline, a short biography, your expertise, your disclosures (employers, investments, clients, and anything else a reader should know about your interests), and a public address at /authors/<your-name>. Readers see it next to every Report you write, and search engines may index it. The editorial team keeps the profile for you from what you applied with; ask them to change it, and keep your disclosures complete and truthful while you write for the Service.
The editorial team can set a profile to not public, which removes the page; the byline stays on the Reports.
How long: a published Report keeps its author's byline. If you delete your account, the link between the account and the profile is removed, but the profile and the Reports you published stay, because readers rely on the attribution and the disclosures of a published work. Ask us at [[SUPPORT_EMAIL]] if you want a profile taken offline.
Lawyer to confirm: that a published author profile and byline may be kept after the creator deletes their account, and what a creator may demand to be removed.
2.3 Your drafts and submissions
Your drafts, the documents you import or save through the authoring tools (including the MCP server, which acts under one of your API keys), the illustrations you upload, and every submission for review are stored with the time and the account that made them. The editorial team's review notes are stored with the revision. A log of publishing actions (who submitted, approved, published, delisted or withdrew what, and when) is kept for every edition and cannot be edited.
Who sees it: you, the editorial team of the publishing organization, and administrators. A draft is never public. A published Report is public in the parts its edition makes free, and readable by buyers in full.
How long: drafts are not deleted; if your creator role is revoked, your open drafts are frozen. Published revisions and the log are kept for as long as the Report exists. If you delete your account, your name is removed from drafts, revisions and log entries, and the work stays.
2.4 Your agreement and your ledger
If you write paid Reports, a creator agreement is recorded for you: your share of each sale in basis points, the dates it applies, a reference to where the signed document is kept (outside the Service), and a note. For every sale, refund, and dispute of one of your paid editions, the Service writes an entry to your ledger: the kind (accrual or reversal), the amount in cents, the edition, and the time. Payments made to you outside the Service are recorded with the amount, the date, a reference and who recorded them. Ledger entries are never edited; a change is a new entry.
The ledger links each entry to the purchase line it came from. You do not see who bought your Reports: your ledger shows the edition, the amount and the time, never the buyer.
Who sees it: you (your agreement's existence, your balance, your entries and payouts), the commerce staff of the publishing organization, and administrators.
How long: agreements, ledger entries and payouts are financial records. They are kept for at least seven years after the last entry, also after you delete your account, in which case they are no longer linked to an account.
Lawyer to confirm: the retention period of the creator financial records (drafted as seven years), and what tax information (for example a Form W-9 or 1099) we must collect from US creators and where it is stored, since the Service does not store it.
2.5 Your API keys
If you connect an AI tool to the Service through the MCP server, you do so with an API key made in your settings. We store the key's name and first characters, a hash of the key (never the key itself), when it was made, when it expires or was revoked, and when it was last used, as well as the drafts the tool saves. What you send to your own AI tool, and what that tool keeps, is between you and that tool's provider.
3. Reports of a problem
Anyone, logged in or not, can report a problem with a Report (a factual error, a wrong source, a problem with an illustration, a rights problem, or something else).
What we store: the Report and the revision you read, the category, your message (up to 2,000 characters), the contact detail you may leave (optional, up to 200 characters), and, if you were logged in, your account. We add the time, and later the status, the editorial note and who handled it. To limit abuse, the Service counts reports per network address for one hour in a short-lived cache; the address is not stored with the report. Our servers also keep ordinary access logs for security, for a short time.
Who sees it: the editors of the publishing organization and administrators. Nothing of a report is public, and authors do not see who reported a problem: a correction that follows a report does not name the reporter. We use your contact detail only to answer you about the report.
Please do not put personal information about others, or sensitive information about yourself, in a report.
How long: a report is kept with the Report it concerns, so that the history of corrections stays understandable. If you delete your account, the link to your account is removed. To have the contact detail you left removed earlier, write to [[SUPPORT_EMAIL]] and name the Report and the approximate date.
Lawyer to confirm: the retention of resolved problem reports (drafted as kept with the Report, with removal of the contact detail on request) and whether a fixed deletion period for the contact detail is needed.
4. Your choices and your rights
You can see your application, your profile, your ledger and your API keys in the Service, and revoke a key at any time. You can delete your account as the Privacy Policy describes; what that does to each kind of data is stated above. For anything else, including a copy of the data we hold about you as a creator, write to [[SUPPORT_EMAIL]]. We answer within 45 days.
Lawyer to confirm: the response time (drafted as 45 days, the California rule) and whether rights of access, deletion and correction must be offered to all users or only where state law requires them.
5. Changes
We may change this statement by publishing a new version on this page with a new effective date. If a change affects what we do with data we already hold about you as a creator, we tell you by email before it applies.
6. Contact
[[SELLER_LEGAL_NAME]], [[SELLER_ADDRESS]]. Privacy questions: [[SUPPORT_EMAIL]].