Fount StoriesLast updated · June 26, 2026
Legal

Privacy Policy

Your data, our responsibility. This policy describes what we collect, why, and the controls you have over it.

1. Overview

This Privacy Policy explains how Fount Stories ("Fount", "we", "us") collects, uses, and protects your personal information when you use our website and services. By using Fount you consent to the practices described below.

2. Information We Collect

We collect the minimum information needed to operate Fount. This includes: (a) account information you provide (email address, display name, hashed password), (b) your creator profile (niche, genre, storytelling method, voice notes, categories of interest), (c) usage data (number of generations per month, saved packets, generated calendars), (d) payment metadata when you subscribe (we never store full card numbers — Stripe handles all payment data), (e) device and log data (IP address, browser type, request timestamps) for security and abuse prevention.

3. How We Use Your Information

We use your information to (a) provide and improve the service, (b) personalize talking points, hooks, and calendars to your stated niche and voice, (c) deliver the Daily Brief and account emails you've signed up for, (d) process subscription payments and prevent fraud, (e) communicate service updates and respond to your support requests, and (f) protect Fount and our users from abuse.

4. AI Processing

When you generate a story packet or weekly calendar, Fount sends the story metadata and your creator profile to Anthropic's Claude language model via a secure API. Anthropic processes this data to generate the response and may retain it briefly for abuse-prevention purposes per their own policies. Fount does not use your generated content to train any AI model. You can review Anthropic's privacy practices at anthropic.com.

5. Third-Party Services

We rely on a small set of trusted vendors to deliver Fount. These include Stripe (payment processing), Resend (transactional email delivery), Anthropic (AI generation), and our infrastructure provider for MongoDB hosting. Each vendor receives only the data necessary to perform its function and is bound by its own privacy and security commitments.

6. Cookies and Authentication Tokens

We use a secure HTTP-only authentication cookie (and an Authorization header fallback for API clients) to keep you signed in. Your session token is never stored in browser local storage. We do not use third-party advertising trackers or analytics cookies. Signing out clears your session immediately.

7. Email Communications

If you subscribe to the Daily Brief, we send a personalized digest at 06:00 UTC daily. You can unsubscribe at any time by replying to any Fount email or by disabling Brief in your account settings. Transactional emails (verification links, password resets, payment receipts) are required to operate the service and cannot be opted out of while your account is active.

8. Data Sharing

We do not sell your personal information. We share it only with the vendors listed above, when required by law (e.g., a valid subpoena), to prevent fraud or harm, or with your explicit consent. If Fount is involved in a merger, acquisition, or asset sale, your information may transfer as part of the transaction; we will notify you before such a transfer takes effect.

9. Data Retention

We retain your account data for as long as your account is active and for a reasonable period afterward to support audit, legal, and recovery needs. Email-verification tokens automatically expire after 24 hours and password-reset tokens after 1 hour, after which they are purged automatically. You may request deletion of your account and personal data at any time (see Your Rights below).

10. Your Rights

Depending on your jurisdiction, you may have the right to (a) access the personal information we hold about you, (b) correct or update it, (c) request deletion, (d) export your saved content, (e) restrict or object to certain processing, and (f) lodge a complaint with a supervisory authority. To exercise any of these rights, email brief@fountstories.com — we'll respond within 30 days.

11. Security

Passwords are hashed with bcrypt. Auth tokens are signed JWTs with a short lifetime. Communications between your browser and Fount are encrypted in transit (HTTPS). We rate-limit sensitive endpoints (login, password reset, verification) and lock accounts after repeated failed sign-ins. No system is perfectly secure, but we work continuously to protect your data.

12. Children's Privacy

Fount is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will delete it.

13. International Transfers

Fount is operated from the United States. If you access Fount from outside the US, your information will be transferred to and processed in the US (and potentially other countries where our vendors operate). Where required by law, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) to safeguard your data.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or via a notice in the app at least seven (7) days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

15. Contact

Privacy questions, requests, or concerns? Email brief@fountstories.com.