Security
How Entangled Text protects accounts and manuscripts when you write books with AI.
Included AI credentials
Free, Pro, and Ultra generation uses platform-managed Kestrel pools. You do not need to bring a personal provider key. Platform credentials are stored securely and used only to fulfill generation requests you initiate.
Internal operator tooling may manage encrypted platform keys for site operations; that is not a customer plan feature.
Application security
- HTTPS for all production traffic
- CSRF tokens on state-changing forms and many authenticated POSTs
- Password hashing suitable for modern web apps (not reversible storage)
- Optional two-factor authentication for accounts that enable it
- Rate limiting on login, registration, and sensitive API-style endpoints
- Brute-force protections with lockouts and security event logging
- Security-focused HTTP headers (including Content-Security-Policy and frame controls where configured)
Manuscript & project data
Your projects live in our application database so the studio can show outlines, chapters, diffs, and exports. Access is scoped to your account (and to people you explicitly share with — for example beta-reader links). Staff access for support or abuse investigation is limited and audited.
Browser-only writing tools under /tools that analyze text locally do not upload manuscript content for those scans. Features that intentionally save or generate on the server (cloud save, signed-in AI tools) only process what you submit.
Third-party AI providers
Generation requires sending prompts and context to the model provider selected by included Free / Pro / Ultra routing. Those providers process data under their own security and privacy terms. Choose plans and practices you trust.
Audit logging & abuse response
We log security-relevant events such as logins, lockouts, and privileged admin actions. Logs are used for operations and investigation, not marketing. We may suspend accounts that abuse shared Free AI pools, attack the service, or violate the Terms.
If you believe you found a vulnerability, contact us via the contact form with enough detail to reproduce. Please avoid testing that degrades service for other authors.
What you can do
- Use a unique password and enable 2FA when available
- Keep your account email current for security notices
- Unpublish public stories you no longer want indexed
- Request account deletion when you leave the service
Security FAQs for AI book writers
Who can read my manuscript?
Projects are scoped to your account (and people you explicitly share with, such as beta-reader links). Staff access for support or abuse investigation is limited and audited. Public stories you choose to publish can be indexed — unpublish when you no longer want them public.
Is included AI safer than connecting my own provider?
Customer plans use included Free/Pro/Ultra AI under our operational controls. Generation still requires sending text to a model provider — pick a plan and practices you trust. Personal provider keys are not a Pro / Ultra customer feature.
Do free browser tools upload my novel?
Local analyzers under /tools process text in your browser for those scans. Cloud save and signed-in AI features only process what you intentionally submit.