LogoPepys
  • Features
  • Pricing
  • Print guide
Sign up
LogoPepys
LogoPepys

Turn your own photos into journal pages you can print and keep.

support@pepys.page
Product
  • Features
  • Pricing
  • FAQ
  • Photo Sticker Maker
  • Printable Journal Pages
  • Printable Planner Pages
  • Free Weekly Planner
  • Online Scrapbook Maker
Resources
  • Journal Prompts
  • AI Prompt Generator
  • Journal Sizes
  • Scrapbook Layout Ideas
  • How to Start Journaling
  • Print guide
Company
  • Contact
Legal
  • Acceptable Use Policy
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
© 2026 Pepys. All Rights Reserved.

Privacy Policy

How Pepys collects, uses and protects your data

2026/08/01

Introduction

This Privacy Policy explains how Pepys handles information when you design and print journal pages. Pepys supports three different storage contexts: a signed-out Guest Draft, an authenticated local Project, and an authenticated cloud Project. They do not have the same retention or cross-device behavior. Use of the service is also subject to the Acceptable Use Policy.

Pepys is operated by Chao Wang as an individual operator. The service is for people who are at least 18 years old.

Information We Collect

  • Account data: email address, name, login credentials, or the identity provided by Google or GitHub sign-in.
  • Project data: measured page configuration, text, layout, crop and placement parameters saved for an authenticated Project. Whether processed Print Materials are sent to Pepys depends on that Project's storage mode.
  • Cloud Print Materials: standardized JPEG or PNG materials uploaded only for a cloud Project or after an explicit local-to-cloud transition. Pepys does not save your original photo file.
  • Export records: Project export status and billing facts, or a content-free local-export receipt after an authenticated browser export.
  • Payment data: handled by Waffo Pancake, our Merchant of Record. We store references such as customer and invoice identifiers, never card numbers.
  • Starter-kit delivery data: if you request the PDF starter kit, we use the email address you provide to send its download link.
  • Technical data: basic request metadata used for rate limiting and abuse prevention. IP addresses used for rate limiting are stored only as salted one-way hashes.
  • AI guest identity and protection data: a server-issued opaque guest Cookie identifies a visitor, and the server stores only its one-way hash. AI quota and rate-limit metadata includes hashed subject identifiers, weekly success and verification state, active reservation state, request counts, and timestamps. IP addresses used for minute-level protection are represented by secret-salted one-way hashes; Pepys does not create a User-Agent fingerprint or use IP geolocation for this feature.
  • AI moderation metadata: a content-free record may contain the Waffo request ID, stage, action, reason code, matched categories, subject hash, local ruleset version, and timestamp. These records are retained for 90 days and then handled by scheduled cleanup. They never contain a raw IP address, Waffo request body, selections, background, or generated Prompt.

AI Prompt Generation and Safety Processing

Pepys does not store your AI category, mood, duration, optional background, generated Prompt, or generation history as user content. The current result exists in browser state until you copy it, replace it, leave the page, or hand it to the browser-local editor.

For each generation attempt, Waffo performs an input scan of the selections and optional background and an output scan of the candidate Prompt before it can be displayed. OpenRouter sends the request to the DeepSeek V4 Flash model through an upstream inference provider. These processors receive the data needed for their role even though Pepys does not retain the input or output.

OpenRouter is instructed to keep data collection denied where supported. This preference limits eligible routing but does not guarantee an upstream provider's retention behavior. Do not include names, contact details, health information, financial information, or other sensitive personal data in the optional background.

Depending on where you are and where these providers operate, Waffo Pancake, OpenRouter, its upstream inference provider, and other disclosed service providers may process information through international transfers. Their names identify independent service roles; they do not sponsor, endorse, or officially operate Pepys.

Original Photos and Print Materials

Pepys processes a selected original photo in your browser. Background removal, cropping and print normalization also run locally. We do not save the original photo file. The processed result is a Print Material: it may remain local or be uploaded according to the Project storage mode.

Browser-local processing does not make local data durable. Keep original photos somewhere you control so you can select them again if the browser clears site data or a device is lost.

Guest Drafts

A Guest Draft is the signed-out working state used on Pepys's eight local-content pages. Its page configuration and processed photo or background blobs are stored in IndexedDB in the same browser and device. A tab-scoped session marker lets that tab restore its draft after a reload and lets an opaque handoff ID restore it after authentication in the same browser. The URL does not contain photos, answers, arbitrary Prompt text, or Project JSON.

Pepys keeps one active Guest Draft in each tab. Reset, Clear local content, and a successfully recorded authenticated export remove the relevant draft and its local materials. Records carry a 24-hour expiry check, but a closed tab or browser may leave inaccessible site data until Pepys encounters the expired record or the browser clears it. Browser storage is not a backup. On a shared device, use Clear local content and, when appropriate, clear browser site data before leaving the device.

Local Projects

A local Project is authenticated and saves its Project configuration to Pepys, while its processed photo and background bytes remain in IndexedDB under that user and Project on the current device. New Projects use local Print Materials by default. Pepys may ask the browser for persistent storage, but the browser can decline and persistence is still not a backup.

Signing out does not erase local Project materials. Another device can receive the saved configuration but cannot receive those local bytes; missing materials require relinking on that device. Deleting a Project through the Journal list clears its local namespace on the device where deletion is performed. Pepys cannot remotely erase local materials from another device. Account deletion removes server-held account and Project data, but it cannot reach IndexedDB on a device; clear local site data separately on every shared or previously used device.

Cloud Projects

A cloud Project saves both Project configuration and processed Print Materials to Pepys-controlled storage so the Project can work across signed-in devices. It still does not upload or retain the original photo file. Existing cloud Projects remain cloud Projects. Moving a local Project to cloud mode uploads and verifies all required processed materials before committing the new mode. Moving from cloud to local first downloads and verifies the materials, and cloud deletion requires confirmation.

Removing a cloud Print Material releases it from user material usage and places the stored object in a 7-day cleanup grace period. Account deletion removes server-held Projects and cloud Print Materials without waiting for that grace period. Server export files are generated for the response and are not kept as a reusable photo backup.

Authentication and Same-Device Recovery

Google or GitHub sign-in can continue immediately. Email registration requires verification. After following the email verification step, return to the original device and browser so Pepys can use the opaque handoff ID to recover the Guest Draft and local photos. Opening verification on another device does not transfer browser-local content.

Authentication does not automatically create a Project or start a download. After the draft returns, you confirm the requested watermark-free PNG, PDF, or Print output.

Local-Export Receipts and Analytics

After a successful authenticated browser export, Pepys stores a content-free receipt containing the user ID, search job ID, template ID, page preset, output kind, locale, optional stable Prompt ID or layout ID, signed acquisition enums, and a timestamp. The signed acquisition record is limited to approved source, search-engine, landing, locale and first-touch values. It does not store a raw search query or full referrer.

The receipt never includes photo bytes, arbitrary Prompt or answer text, Project JSON, diary content, or arbitrary search queries. Custom product measurement must follow the same stable ID and enum boundary.

Third-party analytics and session replay are disabled on the eight local-content pages, Journal editor routes, and every AI Prompt Generator route where local journal content or generated results can render. Other pages may load configured analytics providers in production, so Pepys does not make a site-wide claim that a provider can never observe page content. Current provider configuration and privacy-path exclusions must be audited before changing this statement. See the Cookie Policy for cookie details.

First-party AI Prompt Generator product measurement follows a content-free boundary: it is limited to stable event names and enums and must not include the optional context, generated Prompt, raw provider response, Cookie value, or IP address. This first-party measurement does not create a site-wide claim about configured analytics.

Starter-Kit Email

Pepys does not add a starter-kit request address to a marketing audience or lead database. Resend processes the delivery message on our behalf and may retain operational delivery logs under its service retention controls.

How We Use Information

We use information to operate the service, save the storage mode you choose, render and export pages, enforce quotas and rate limits, process payments, and send essential account messages. A starter-kit request results in one delivery email and does not subscribe you to marketing emails. We do not sell your personal information.

Data Security

We use encrypted transport and access-controlled server storage. Browser-local materials rely on browser and operating-system isolation and are not application-level encrypted by Pepys. No method of transmission or storage is 100% secure.

Your Rights

Depending on your location, you may have rights to access, correct, export or delete personal data held by Pepys. You can delete your account and its server-held data from Settings, request help exercising applicable rights, or appeal an AI safety decision by contacting us. Browser-local data must be cleared on each relevant device because Pepys cannot remotely inspect or erase another device's IndexedDB.

Changes to This Policy

We may update this policy from time to time. Material changes will be announced on this page with an updated date.

Contact

The same monitored address handles support, privacy, billing, safety reports, and appeals: support@pepys.page. Severe safety reports target review within 24 hours; ordinary reports and appeals target review within five business days. These are review targets, not guaranteed outcomes.