Privacy Policy
Effective date: June 19, 2026
Last updated: June 19, 2026
The short version
WIP Inbox turns the AO3 update emails you forward into an organized reading dashboard. To do that, I store your email address, the metadata from the fic-update emails you forward, and the reading data you create inside the app.
Here's what I want you to know first, because it's the whole point:
- No ads. Ever. WIP Inbox has never run ads and never will.
- I don't sell your data. Not to advertisers, not to data brokers, not to anyone.
- I don't train AI on your content. None of your emails, reading data, notes, or anything else is used to train machine-learning models — mine or anyone else's.
- No AI summarizing of fic. WIP Inbox never generates or rewrites story content. Where you see chapter summaries, those are the author's own words, taken straight from the AO3 email.
- No scraping AO3. WIP Inbox never touches AO3's servers. It only reads the emails you choose to forward.
The rest of this page is the detail behind those promises.
Who runs WIP Inbox
WIP Inbox is operated by WIP Inbox LLC ("WIP Inbox," "I," "me," "my"), a limited liability company based in Virginia, USA. For privacy-law purposes, WIP Inbox LLC is the data controller for the information described here. You can reach me anytime at hello@wipinbox.com.
WIP Inbox is not affiliated with, endorsed by, or connected to the Archive of Our Own (AO3) or the Organization for Transformative Works (OTW). "Archive of Our Own," "AO3," and "OTW" are names belonging to the OTW; they're used here only to describe what WIP Inbox works with.
What I collect
Account information. Your email address. WIP Inbox uses passwordless "magic link" sign-in, so I don't store passwords. I also assign you a private forwarding address (like updates+[your-id]@inbound.wipinbox.com) so your forwarded emails reach your account and no one else's.
Forwarded AO3 email content. When you set up forwarding, AO3's notification emails arrive at your private WIP Inbox address. WIP Inbox reads each one and extracts the details it needs to build your dashboard — story title, author, fandom, relationships, rating, warnings, tags, chapter numbers and titles, chapter word counts, the author's own chapter summaries (when included), and the AO3 link. That extracted metadata is stored in your account. The raw email itself is discarded. The inbound handler parses the message in memory to pull out those structured fields and writes only the parsed fields to the database. The original email body and the inbound payload are never written to the database or to storage — once parsing finishes, they're gone on my end. (Postmark, the email processor described below, retains inbound messages on its own side according to its retention settings; that's outside WIP Inbox's database and governed by Postmark.)
Reading data you create. Your reading progress (which chapter you're on), shelf placements (Currently Reading, On Deck, Library, DNF), and — if you're on the Fanatic plan — personal notes, tags, custom shelves, and any cover-art images you upload.
Payment information. If you subscribe to Fanatic, payments are handled by Stripe. WIP Inbox does not receive or store your full card number. I receive only what Stripe shares to manage your subscription (such as your subscription status and the last four digits / card brand for your reference).
Basic technical data. Standard server logs needed to operate and secure the service (such as IP address and request information). WIP Inbox does not run any third-party analytics.
How forwarded emails are handled
This is the unusual part, so it gets its own section.
You forward AO3 notification emails to WIP Inbox using a filter you set up in your own email account. WIP Inbox receives those messages through Postmark, our inbound email processor, parses out the fic metadata listed above, and stores it against your account. WIP Inbox does this only for messages sent to your private forwarding address.
WIP Inbox does not read your wider inbox, cannot see emails you don't forward, and never contacts AO3 directly. Parsing is done with simple pattern-matching on the email text — there is no AI model reading, interpreting, or summarizing your fic.
How I use your information
I use the information above to:
- Build and maintain your reading dashboard and library;
- Detect chapter updates, completion, and dormancy, and resurface stories you've shelved;
- Operate magic-link sign-in and keep your account secure;
- Process and manage your Fanatic subscription (via Stripe);
- Send you transactional and (if you opt in) digest emails (via Postmark);
- Respond to you when you contact support;
- Diagnose problems, prevent abuse, and keep the service running.
I do not use your information for advertising, profiling for third parties, or AI training.
What I never do
To be unambiguous:
- I never sell, rent, or trade your personal information.
- I never share your information with advertisers, and WIP Inbox shows no ads.
- I never use your content (emails, reading data, notes, uploads) to train, fine-tune, or improve any AI or machine-learning model.
- I never use AI to summarize, rewrite, or generate fanfiction content.
- I never reproduce AO3 works or divert traffic, hits, or kudos away from AO3 — links always point back to the original on AO3.
Legal bases for processing (UK/EU users)
Where the UK GDPR or EU GDPR applies, I rely on these legal bases:
- Contract — to provide the service you signed up for (your dashboard, parsing your forwarded emails, running your subscription).
- Legitimate interests — to keep the service secure, prevent abuse, and operate it reliably, balanced against your rights.
- Consent — where you opt in to something specific, such as digest emails. You can withdraw consent at any time.
- Legal obligation — where I must keep certain records (for example, limited billing records).
Who I share data with (sub-processors)
I keep this list short on purpose. These providers process data only to deliver the service, under their own contractual and security obligations:
| Provider | What it does | Data involved |
|---|---|---|
| Lovable / Lovable Cloud | App hosting and managed backend | Account data, reading data |
| Supabase | Database and storage (via Lovable Cloud) | Account data, reading data, uploaded cover art |
| Postmark | Inbound email parsing, plus transactional and digest email | Forwarded AO3 emails, email address, message content |
| Stripe | Subscription payments | Payment and subscription data (card details held by Stripe, not me) |
| Zoho Mail | hello@ and authors@ mailboxes | Anything you email those addresses |
I may add or change providers as the service evolves; if so, I'll update this list.
Cookies, analytics, and browser storage
WIP Inbox doesn't use advertising or cross-site tracking cookies, and doesn't run third-party analytics. The only browser storage it sets is the session token that keeps you signed in, stored in your browser's local storage.
Data retention
I keep your information for as long as your account is active. If you delete your account, I delete your personal data and reading data within 30 days, except for the limited records I'm required to keep (such as basic billing/tax records) or anonymized data that can't identify you. Residual copies may remain in routine encrypted backups for up to a further 7 days, after which they're overwritten on the normal backup rotation.
Your rights
Depending on where you live (including under the GDPR and California's CCPA/CPRA), you have rights over your data. WIP Inbox honors these for everyone, regardless of location:
- Access — get a copy of the data I hold about you.
- Export / portability — WIP Inbox offers a built-in export of your completed library; email me for a fuller export of your account data.
- Correction — fix inaccurate data.
- Deletion — delete your account and associated data.
- Object / restrict — object to or limit certain processing.
- Withdraw consent — for anything you opted into, like digests.
California residents specifically: the categories of personal information I collect are your identifiers (email address), commercial information (your Fanatic subscription status and payment metadata, via Stripe), internet/activity information (your reading progress, shelves, notes, and the fic metadata parsed from emails you forward), and technical data (server logs). I do not sell or "share" personal information as those terms are defined under California law, and I won't discriminate against you for exercising your rights.
To exercise any of these, email hello@wipinbox.com. I'll respond within the timeframe the law requires. If you're in the EU/UK and unhappy with my response, you may also complain to your local data protection authority.
Children's privacy
WIP Inbox isn't directed to children. You must be at least 16 years old (or the minimum digital-consent age in your country, if higher) to use it. I don't knowingly collect data from anyone under that age; if I learn I have, I'll delete it.
International data transfers
WIP Inbox and its providers may process data in countries other than yours, including the United States. Where required, transfers are covered by appropriate safeguards (such as Standard Contractual Clauses) offered by the providers above.
Security
I take reasonable measures to protect your information, including encrypted connections, passwordless sign-in, and access controls on the backend. No system is perfectly secure, but I treat your reading life as private and design accordingly.
Data breaches
If a security breach affects your personal data and is likely to put your rights at risk, I'll notify the relevant data protection authority within 72 hours of becoming aware of it, as the GDPR requires, and I'll tell affected users without undue delay where the law requires it.
Changes to this policy
If I change this policy, I'll update the date at the top and, for material changes, give notice in the app or by email. Continuing to use WIP Inbox after a change means you accept the updated policy.
Contact
Questions, requests, or concerns: hello@wipinbox.com.
— KT
