Privacy / Effective October 5, 2026

A quiet product
should have a
plain policy.

Messy input is private material. Project Issue keeps it only to make the finite publication you asked for, and gives you a direct way to leave.

01

What Project Issue keeps

We store the account identifier and email used to sign in; URLs, text, images and files you deliberately save; source metadata; private extracted article text, captions, transcripts or on-device OCR; the structured Issues produced from those Saves; private reading highlights (source-text revision, selected positions and colors, without a second copy of the quotation); paired-device and push-delivery identifiers; and product events needed to understand whether capture and Issues work. If you apply to a Founding Editors cohort, we also keep the practice, weekly save range, publication preference, optional profile, short answer and cohort review permission you submit.

We also store your current Terms acceptance, optional AI-editor permission, any rights, privacy or safety request you submit, and—if you choose to answer it—the response and optional short note from the private editorial question at the end of an Issue. Follow, resave and creator-block relationships are stored only to provide those product and safety controls. We do not collect advertising identifiers, sell personal data, or track you across apps and websites.

During the private beta, capture events may include a random capture attempt identifier, the capture adapter, whether the attempt succeeded or failed, a bounded duration, and a coarse failure category. Those capture-reliability envelopes never include the saved URL, title, source text, image, or file contents. Founding Editors reports include only participants selected for that cohort; internal, unselected, declined, and withdrawn accounts are excluded.

02

Why it is used

Data is used to capture what you share, retrieve source material, remove duplicates, infer the patterns connecting that week's Saves, generate and deliver your Issues, render your archive and deliberate public publications, secure paired devices, respond to rights requests, and measure capture, reading and weekly retention. The optional AI editor is off until you give explicit permission. Platform audiovisual transcription remains off unless the relevant provider authorizes it and a specific disclosure and permission are added. The hosted transcription processor is also off in the current beta until its contract, retention, and cross-border processing have been reviewed. If you separately join a Founding Editors cohort and consent to personal review, an authorized cohort editor may inspect that private Issue output, its source titles and original links, and keep a bounded review note. Cohort reviewers do not receive the stored private source bodies, transcripts, OCR text or uploaded originals through the review desk. Your own end-of-Issue response is used to test whether the automatic edit revealed a useful pattern. Aggregate reporting counts only the categorical response; its optional note is not shown in the retention report and is never published automatically.

03

Private input, deliberate publication

Saves and unpublished editorial material are private by default. An Issue can be private, unlisted or public. Public and unlisted Issues expose the selected editorial object, source attribution, short permitted excerpts and original links—not the private full-text reader. Anything you publish may be copied or cached by recipients and third-party services outside our control.

04

Processors and transfers

Cloudflare hosts the Web application, database and private uploaded objects. OpenAI provides sign-in; only when you enable the optional AI editor does OpenAI also receive the selected source URLs, titles, publishers, saved or extracted text and Issue context required for one edit. Apple receives a device token and Issue-ready notification data for push delivery. These providers may process data outside Japan. Each receives only the information needed for its task, and private service credentials stay on the server.

05

Retention and deletion

Reading highlights are private to their owner and do not enter public Issues, editorial prompts or analytics. They are removed when the underlying saved body changes, expires or is restricted. Account and source data remains while the account is active. You can disconnect a device without deleting the account, or permanently delete the Project Issue account from Account & Privacy on the Web or inside the iOS app. Deletion removes the account record, Saves, extracted source content, uploaded objects, Issues, private reading highlights, relationships, cohort application, device credentials and linked analytics events, including linked editorial review records and end-of-Issue responses, from the live product. A rights, privacy or safety request and its review record may be retained separately when reasonably necessary to document and comply with that request. Security logs and infrastructure backups may persist temporarily under provider retention practices and are not used to recreate the account.

06

Your choices

You control Issue visibility, can revoke any capture device, can disable future AI-editor transfers, can block or unblock a public creator, can update or remove an end-of-Issue response, can stop saving at any time, and can delete the account without contacting support. Deleting Project Issue does not delete your ChatGPT account or content on the original source sites. For access, correction or privacy questions that cannot be completed in the product, review the public privacy choices, use the rights and privacy request form, or contact payphone1402@gmail.com.