Privacy Notice
In one paragraph
SceneWeaver keeps your writing on your own computer. The app never sends us your manuscript — the words you've written, your character names, your notes, your citations, or anything you've typed — under any circumstance. If the app crashes, it prepares a bug report for you to look at and decide whether to send us (by opening it in your email client or copying it) — it is never sent on its own. Two things are sent automatically and you cannot turn them off. The first time you run a newly installed version, SceneWeaver tells us three things — your operating system, the version you installed, and a random identifier for that install. Nothing else, once per version, and never a word of your writing; it is how we know how many people actually installed a release. Separately, a licensed copy checks periodically that its licence is still valid. We say so here rather than leave you to find out. There are also two settings in Preferences you can turn on if you want to help us improve the app: anonymous usage information (which features people use, at app start / quit) and local performance profiling (how long common operations take). Both are off by default, neither includes a word from your book, and performance timings only reach us when both are switched on. This website only sees the basic technical details our hosting provider needs to send you the page and stop attackers — we don't set cookies, we don't run analytics, we don't use tracking pixels. Two companies see your IP address when you load this site: Cloudflare (who hosts the site) and Google Fonts (who supplies the typefaces).
Who's responsible for your data
The person legally responsible for sceneweaver.uk and the SceneWeaver app is Shane M Lee, based in the United Kingdom. In UK data-protection law he's called the "data controller".
If you have any privacy question — you want to use one of your legal rights (listed further down), you're worried about something, or you just want to know how a piece works — email privacy@sceneweaver.uk.
What we collect, why, and on what legal basis
Here's every piece of personal information we deal with, where it goes, and the legal basis we rely on to use it. The "legal basis" column names one of the categories the UK data-protection law (UK GDPR, Article 6) allows; each is explained in the row.
| What | Where | Why | Legal basis |
|---|---|---|---|
| Your IP address and the basic technical details of each page request (which browser, which page, whether it worked, how long it took) | Cloudflare's server logs while you browse sceneweaver.uk |
To send you the page; to stop abuse and rate-limit attackers; to spot problems when things break. | "Legitimate interests" — the law lets us process data when we have a good reason and it doesn't override your rights. Keeping the site up and secure is that reason here. |
| Your IP address, briefly | Google's Fonts server, when your browser fetches the two typefaces the site uses (Playfair Display and Inter) | Your browser has to ask Google's server for the font files because we link to them there rather than storing our own copies. | "Legitimate interests" — the site needs its typefaces to display correctly. See Data going overseas below. |
| Bug-report contents (only if you actively choose to send one) | When the app crashes it prepares a report showing the technical details of what went wrong (the error trace, app version, your operating system, what you were doing when it broke) — never anything from your manuscript. The report sits in a dialog for you to look at. It only reaches us if you actively send it (through your email client or by copying it into a message to us). If you close the dialog, nothing goes anywhere. | To work out what broke and fix it. | "Consent" — you make the decision fresh for each crash. There's no automatic sending and no preferences toggle to change; if you don't send it, we don't get it. |
| Install count (automatic — there is no setting to switch this off) | The first time you run a newly installed version, the app sends exactly three things: your operating system (for example "Windows"), the version you installed, and a random identifier generated for that install. It is sent once per version, so upgrading sends it again. Nothing else goes with it — no usage, no features, no session, and never a word of your manuscript. It uses the same random install ID described in the row below — a random identifier generated on first launch and stored on your own computer, which tells us nothing about who you are. | To know how many people install each release on each operating system. Downloads don't tell us this: a download may never be installed, and one download may be installed on several machines. | "Legitimate interests" — knowing how many installations a release has is how we decide which versions to keep supporting and testing. We've kept it to the smallest thing that answers that question, and it carries nothing that identifies you. |
| Anonymous usage information (only if you turn on "Send anonymous usage information" in Preferences) | Small events at app start and app quit — app version, operating system, session length, and short labels for which features you've used (for example, that you exported to DOCX). Each install is identified by a random identifier we call the install ID. It's generated once on the first launch of a fresh install and stored in a settings file on your own computer — the same identifier is used whenever you have this setting on, even across turning it off and back on again, so any events we do receive can be grouped by install without ever telling us who you are. The install ID is never sent unless this setting is on; when the setting is off it just sits in your local settings file. Never contains a word of your manuscript. | To see which features people actually use and which sit unused, so we can make the app better. | "Consent" — you actively choose to enable this, and can switch it off at any time in the app's Preferences. |
| Performance timings (only if BOTH "Enable local performance profiling" AND "Send anonymous usage information" are on) | How long common operations took — loading a manuscript, exporting, running a report, and so on. Sent as event name + duration in milliseconds; still tagged with the same anonymous install identifier as the usage-information row above. Never contains a word of your manuscript. With profiling on but usage information off, the timings only get written to a local log file on your own computer and never leave it. | To spot which operations are slow across the range of computers people run the app on, so we can prioritise the right things to speed up. | "Consent" — you actively choose to enable both settings, and can switch either off at any time in the app's Preferences. |
| Student ID / enrollment letter (Student tier only, and only if you choose the upload route) | If you buy a Student-tier licence AND choose to prove you're a student by uploading an ID or letter through the app, the file goes to our licensing server and is stored briefly. | To check you're entitled to Student pricing. | "Fulfilling our contract with you" — you're asking us to give you Student pricing, so we need to check you qualify. You can prove your status other ways (academic email, honour system) so this upload is never the only option. |
We do not set our own cookies, run analytics, embed tracking pixels, or show targeted ads. There are no user accounts on this site.
Your manuscript
This gets its own section because it's the promise SceneWeaver is built on. The app never sends the contents of your manuscript to us, to Cloudflare, to Google, or to anyone else. That covers your prose, your chapter and scene titles, your character / item / location / organisation names, your citations, your notes, your comments, your exports, and anything else you've typed. This promise doesn't depend on what you have or haven't switched on — it's the same whether both opt-ins are off, both are on, or anything in between.
The other companies we rely on
Data-protection law calls these "sub-processors": companies that store or handle data on our behalf. There are two:
- Cloudflare, Inc. — hosts the website (Cloudflare Pages), runs the licensing service (Cloudflare Workers), stores licence records (Cloudflare D1), and stores any Student verification uploads (Cloudflare R2). Cloudflare also handles the domain name lookup, page caching, and HTTPS security. Their privacy policy: cloudflare.com/privacypolicy.
- Google LLC — supplies the two web fonts (Playfair Display and Inter) via the free Google Fonts service. Their privacy policy: policies.google.com/privacy. If you'd prefer not to connect to Google at all, you can block
fonts.googleapis.comandfonts.gstatic.comin your browser and the site will fall back to whatever fonts your device has installed.
If we ever add another company (say, an email-list provider for release notifications), we'll update this page to list them.
Data going overseas
Cloudflare and Google are both American companies, and they run servers all over the world. When one of those overseas servers handles your request, your IP address leaves the UK for a moment. Both companies are covered by the UK–US Data Privacy Framework, which is the UK government's official approval that data sent to the US under this arrangement gets the same protection it has here. Both companies also offer their own contractual safeguards; the details are in their privacy policies above.
How long we keep information
- Cloudflare's server logs: Cloudflare keeps these for the length of time they've set for the free Pages plan we use — usually a few days for the detailed logs, longer for the counted totals. We don't download or keep our own copies.
- Google Fonts: Google's own retention policy applies; we never see or store this data.
- Bug reports (only the ones you've chosen to send): kept only long enough to investigate and fix the issue, plus a short window afterwards to catch anything that comes back. Deleted routinely after that.
- Anonymous usage information (when you've enabled it): the raw records are short-lived; the totalled figures stay so we can spot trends.
- Performance timings (when both settings are on): same retention as anonymous usage information — raw records short-lived, aggregated figures kept for trend analysis. If profiling is on but usage information is off, the timings sit in a local log file on your computer (capped in size, oldest entries dropped as new ones arrive) and never reach us.
- Student verification uploads: the file itself sits in Cloudflare's storage until it's been reviewed, plus up to 30 days after review in case there's a dispute over the decision. Any upload that hasn't been reviewed within 90 days is automatically rejected and the file wiped. After the file is deleted, we keep a short administrative record ("a submission arrived on this date, we decided it this way") tied only to the licence ID and a hashed version of the email — never the file itself.
Your rights under UK data-protection law
You have the right to:
- See the personal information we hold about you.
- Correct anything that's wrong or incomplete.
- Have it deleted (the "right to be forgotten"), with a few exceptions the law recognises.
- Restrict or object to us using it for certain things.
- Take it with you — get a copy in a format another service could read.
- Change your mind at any time on anything you chose to enable in the app. Turning it off in Preferences stops further sending immediately.
- Complain to the UK Information Commissioner's Office (ico.org.uk) if you think we've mishandled your data.
To use any of these rights, email us at the address in Who's responsible for your data above. We aim to reply within a month, which is the deadline the law sets us.
Children
SceneWeaver is a writing tool for adults. It's not aimed at children under 13, and we don't knowingly collect personal information from them.
When this page changes
We'll update this page as the app and the site change — for example, when a new opt-in appears, or if we add a release-notification mailing list. The Effective from date below moves whenever there's a real change, and any big change will be flagged on this page for a reasonable stretch of time so you can see it.
Effective from: 2026-07-06. Previous version: 2026-05-31 (added the Student-tier verification upload row, named Cloudflare D1 and R2 explicitly, and set the 30-day-after-review / 90-day-pending retention rules).