Privacy Policy
The short version. Epoch Studio is local-first. Your manuscripts and projects are stored on your device and are not sent to us. We do not operate a server that receives your creative work, we do not sell your data, and we do not train AI models on your manuscripts.
Your work leaves your device only when you choose to use an optional third-party service — such as a cloud AI provider whose key you enter — or for the narrow system functions listed below. Section C lists every destination the software can reach.
1Who we are
Epoch Studio is published by Epoch Works LLC (PO Box 514, Jerome, PA 15937, USA). For privacy questions, contact epochworksllc@gmail.com.
2What we store, and where
| Data | Where it lives | Sent to us? |
|---|---|---|
| Manuscripts, chapters, characters, analysis, images, project files | Your device — local browser storage and, in the desktop app, your operating system's user-data folder | No |
| Voice-reference recordings or audio files you previously chose to save | Your device — local browser storage; retained until you delete them | No |
| App settings, including any API keys you enter | Your device — local settings storage | No |
| Error logs, if a feature fails | Your device — a local log file, rate-limited | No |
| Session and writing statistics, goals, streaks | Your device | No |
The Epoch Studio app does not maintain accounts, and the software contains no analytics, advertising, or telemetry. The optional Epoch Field Notes mailing list described below is separate from the app and never receives your manuscript or project.
2AThe website and Epoch Field Notes
The website loads no analytics, advertising, newsletter scripts, or tracking pixels. If you choose to join Epoch Field Notes, the signup form sends your email address directly to Buttondown, our newsletter service provider. Buttondown sends a confirmation message, and you are not added to the active list unless you confirm.
Epoch Works can access the confirmed address in Buttondown and uses it only to send Epoch Field Notes: product demonstrations, development notes, playtest invitations, and related Epoch Studio news. Every issue includes an unsubscribe path. We use the address for active delivery until you unsubscribe, ask us to delete it, or the newsletter service is closed. After an unsubscribe, Buttondown may retain limited records after unsubscribe as described in its privacy policy. Buttondown processes the signup under its privacy policy.
3API keys
If you enter API keys for third-party providers, they are stored locally on your device and used only to call the provider you configured. We never receive your keys. Treat them as you would a password: anyone with access to your device could read them.
4When your content leaves your device — and only then
Nothing about your work is transmitted off your device except in the cases below. These are summarised here and listed exhaustively in Section C.
- You enable a cloud AI provider. If you configure a third-party text or image provider and the "never send manuscript text to the cloud" setting is off, the relevant text or prompt is sent to that provider to produce the feature you invoked. It goes to the provider you chose, under their privacy policy — not to us.
- You use the research lookup. A search term you enter is sent to Wikipedia to fetch a summary.
- You configure or use web search. Web search is off by default and requires you to supply either a Brave Search API key or the address of your own SearXNG instance. Testing that connection sends the fixed phrase "Epoch Studio connection test," even while web search is off. When you run a search, only your search query is sent to that provider. Manuscript text is never included.
- You download a model. The software fetches the model file from the model host (Hugging Face, or its mirror) and verifies it by checksum. No personal data is sent.
- The desktop app checks for updates. A version check, and if you update, a download, from the update host (GitHub releases).
- You start local-network discovery. If you ask the software to find a model server on your own network, it probes local addresses. This stays on your network; nothing goes to the internet.
4AMicrophone, dictation, and local speech tools
Epoch asks for microphone access only after you start a recording. For dictation, the temporary recording is held in memory, sent only to the transcription service running on your own device, and discarded after the transcript is returned. Epoch Works LLC does not receive or retain that recording.
Earlier builds also allowed you to record or import a voice-reference sample with your permission. Any sample you chose to save remains in local browser storage on your device until you delete it. Local narration and transcription services receive text or audio at a local address — by default, a loopback address on your device, or a service you deliberately configure on your own local network. They do not send it to Epoch Works LLC.
5Privacy mode is on by default
The software includes a setting to never send manuscript text to the cloud, and it is enabled by default. While it is on, AI features run only on a local model; if no local model is available, the feature is blocked rather than sent off your device. You can turn it off if you want to use a cloud provider.
6We do not train on your work
We do not use your manuscripts or projects to train, fine-tune, or evaluate AI models. Any model training would require your explicit, separate, opt-in consent, which we do not currently request or collect.
7We do not sell your data
We do not sell or rent your personal information or creative work. We disclose personal information only to a service provider needed for a feature you deliberately use—for example, Buttondown when you join Epoch Field Notes—or when legally required. There is no advertising.
8Children
The software is not directed to children under 13, and we do not knowingly collect personal information from them.
9Your rights
Because your data is stored locally and we do not hold it, you control it directly — you can view, edit, export, and delete your projects within the software at any time. For any personal data you believe we hold (for example, if you email us), you may request access or deletion at epochworksllc@gmail.com.
10Third-party services
When you use an optional third-party service, that service's privacy policy governs the data you send it. We do not control those services. Buttondown handles the optional website newsletter as described in Section 2A. The current set of services the Epoch Studio software can reach is in Section C.
11Security
Your data is stored locally under your operating system's protections. The software restricts file access to approved locations and validates external links before opening them. No system is perfectly secure; keep your device and accounts protected.
12International users
Your data stays on your device wherever you are. If you choose a cloud provider, your content may be processed in the country where that provider operates, under their terms.
13Changes
We may update this policy. Material changes will be communicated in the app or on next launch.
CEvery destination the software can reach
| Destination | Trigger | Data sent |
|---|---|---|
| A cloud text-AI provider you configure (Anthropic, OpenAI, Groq, OpenRouter, Google Gemini, xAI, Together, Cerebras, Pollinations) | You enable it with a key and privacy mode is off | The manuscript or derived text for the feature you invoked |
| A cloud image provider you configure (Pollinations, or fal.ai / Replicate / Stability / Ideogram with your key) | You generate an image while privacy mode is off | The image prompt, which can include scene and character descriptions drawn from your manuscript |
| A local speech service you configure (transcription and narration) | You start dictation, narration, or a voice preview | A temporary microphone recording, narration text, or a locally stored voice reference, sent to a local address — by default loopback on your device, or an address you choose on your own local network; never sent to Epoch Works LLC |
| Brave Search, or a SearXNG instance you name | You test the connection, or turn web search on and run a search | The fixed phrase "Epoch Studio connection test," or the search query you submit; never manuscript text |
| Wikipedia | You use the research lookup | Your search term |
| Hugging Face, or its mirror | You download a model | Nothing — a file download |
| Update host (GitHub releases) | Desktop app launch, and a download if you update | A version check |
| Your own local network | You start local model discovery | A local probe only; it stays on your network |
The software contains no analytics, advertising, or telemetry calls. Namespace identifiers that appear in exported files, such as EPUB XML namespaces, are not network requests.