How Pepys collects, uses and protects your data
2026/08/01
This Privacy Policy explains how Pepys handles information when you design and print journal pages. Pepys supports three different storage contexts: a signed-out Guest Draft, an authenticated local Project, and an authenticated cloud Project. They do not have the same retention or cross-device behavior. Use of the service is also subject to the Acceptable Use Policy.
Pepys is operated by Chao Wang as an individual operator. The service is for people who are at least 18 years old.
Pepys does not store your AI category, mood, duration, optional background, generated Prompt, or generation history as user content. The current result exists in browser state until you copy it, replace it, leave the page, or hand it to the browser-local editor.
For each generation attempt, Waffo performs an input scan of the selections and optional background and an output scan of the candidate Prompt before it can be displayed. OpenRouter sends the request to the DeepSeek V4 Flash model through an upstream inference provider. These processors receive the data needed for their role even though Pepys does not retain the input or output.
OpenRouter is instructed to keep data collection denied where supported. This preference limits eligible routing but does not guarantee an upstream provider's retention behavior. Do not include names, contact details, health information, financial information, or other sensitive personal data in the optional background.
Depending on where you are and where these providers operate, Waffo Pancake, OpenRouter, its upstream inference provider, and other disclosed service providers may process information through international transfers. Their names identify independent service roles; they do not sponsor, endorse, or officially operate Pepys.
Pepys processes a selected original photo in your browser. Background removal, cropping and print normalization also run locally. We do not save the original photo file. The processed result is a Print Material: it may remain local or be uploaded according to the Project storage mode.
Browser-local processing does not make local data durable. Keep original photos somewhere you control so you can select them again if the browser clears site data or a device is lost.
A Guest Draft is the signed-out working state used on Pepys's eight local-content pages. Its page configuration and processed photo or background blobs are stored in IndexedDB in the same browser and device. A tab-scoped session marker lets that tab restore its draft after a reload and lets an opaque handoff ID restore it after authentication in the same browser. The URL does not contain photos, answers, arbitrary Prompt text, or Project JSON.
Pepys keeps one active Guest Draft in each tab. Reset, Clear local content, and a successfully recorded authenticated export remove the relevant draft and its local materials. Records carry a 24-hour expiry check, but a closed tab or browser may leave inaccessible site data until Pepys encounters the expired record or the browser clears it. Browser storage is not a backup. On a shared device, use Clear local content and, when appropriate, clear browser site data before leaving the device.
A local Project is authenticated and saves its Project configuration to Pepys, while its processed photo and background bytes remain in IndexedDB under that user and Project on the current device. New Projects use local Print Materials by default. Pepys may ask the browser for persistent storage, but the browser can decline and persistence is still not a backup.
Signing out does not erase local Project materials. Another device can receive the saved configuration but cannot receive those local bytes; missing materials require relinking on that device. Deleting a Project through the Journal list clears its local namespace on the device where deletion is performed. Pepys cannot remotely erase local materials from another device. Account deletion removes server-held account and Project data, but it cannot reach IndexedDB on a device; clear local site data separately on every shared or previously used device.
A cloud Project saves both Project configuration and processed Print Materials to Pepys-controlled storage so the Project can work across signed-in devices. It still does not upload or retain the original photo file. Existing cloud Projects remain cloud Projects. Moving a local Project to cloud mode uploads and verifies all required processed materials before committing the new mode. Moving from cloud to local first downloads and verifies the materials, and cloud deletion requires confirmation.
Removing a cloud Print Material releases it from user material usage and places the stored object in a 7-day cleanup grace period. Account deletion removes server-held Projects and cloud Print Materials without waiting for that grace period. Server export files are generated for the response and are not kept as a reusable photo backup.
Google or GitHub sign-in can continue immediately. Email registration requires verification. After following the email verification step, return to the original device and browser so Pepys can use the opaque handoff ID to recover the Guest Draft and local photos. Opening verification on another device does not transfer browser-local content.
Authentication does not automatically create a Project or start a download. After the draft returns, you confirm the requested watermark-free PNG, PDF, or Print output.
After a successful authenticated browser export, Pepys stores a content-free receipt containing the user ID, search job ID, template ID, page preset, output kind, locale, optional stable Prompt ID or layout ID, signed acquisition enums, and a timestamp. The signed acquisition record is limited to approved source, search-engine, landing, locale and first-touch values. It does not store a raw search query or full referrer.
The receipt never includes photo bytes, arbitrary Prompt or answer text, Project JSON, diary content, or arbitrary search queries. Custom product measurement must follow the same stable ID and enum boundary.
Third-party analytics and session replay are disabled on the eight local-content pages, Journal editor routes, and every AI Prompt Generator route where local journal content or generated results can render. Other pages may load configured analytics providers in production, so Pepys does not make a site-wide claim that a provider can never observe page content. Current provider configuration and privacy-path exclusions must be audited before changing this statement. See the Cookie Policy for cookie details.
First-party AI Prompt Generator product measurement follows a content-free boundary: it is limited to stable event names and enums and must not include the optional context, generated Prompt, raw provider response, Cookie value, or IP address. This first-party measurement does not create a site-wide claim about configured analytics.
Pepys does not add a starter-kit request address to a marketing audience or lead database. Resend processes the delivery message on our behalf and may retain operational delivery logs under its service retention controls.
We use information to operate the service, save the storage mode you choose, render and export pages, enforce quotas and rate limits, process payments, and send essential account messages. A starter-kit request results in one delivery email and does not subscribe you to marketing emails. We do not sell your personal information.
We use encrypted transport and access-controlled server storage. Browser-local materials rely on browser and operating-system isolation and are not application-level encrypted by Pepys. No method of transmission or storage is 100% secure.
Depending on your location, you may have rights to access, correct, export or delete personal data held by Pepys. You can delete your account and its server-held data from Settings, request help exercising applicable rights, or appeal an AI safety decision by contacting us. Browser-local data must be cleared on each relevant device because Pepys cannot remotely inspect or erase another device's IndexedDB.
We may update this policy from time to time. Material changes will be announced on this page with an updated date.
The same monitored address handles support, privacy, billing, safety reports, and appeals: support@pepys.page. Severe safety reports target review within 24 hours; ordinary reports and appeals target review within five business days. These are review targets, not guaranteed outcomes.
