Effective 29 July 2026
Privacy policy
This policy explains what Mythic Studio collects, why it is needed, where AI processing happens, and the choices you have.
1. Who is responsible for your data
Mythic AI operates Mythic Studio and is the controller of personal data described in this policy. For privacy questions or requests, email [email protected].
2. Information we collect
Account information
We collect your email address, display name, password hash, verification status, account role, and the dates associated with your account and sign-ins. We never store your password in plain text.
Creative content
We store the worlds, works, characters, lore, relationships, scene setups, scene messages, model responses, manuscripts, revisions, review comments, and invitations you create.
Technical and security information
Our servers may process IP addresses, request times, browser and device information, route and status information, model and token usage, and security events. We use this to deliver the service, diagnose faults, prevent abuse, and protect accounts. We do not need to put manuscript text into routine application logs.
3. How we use information
- to create and secure your account;
- to save, retrieve, and synchronise your creative work;
- to generate scene responses using the context you select;
- to send verification, password, and service messages;
- to provide invitations and editorial review;
- to maintain, troubleshoot, and protect the service; and
- to comply with law and enforce our terms.
Our main legal basis is performance of our contract with you: the processing needed to provide Mythic Studio. We also rely on legitimate interests to secure and improve the service, and on legal obligations where the law requires processing. If we introduce optional marketing or non-essential tracking, we will ask for consent where required.
4. How Scene Lab processes your writing
For each generation, Mythic builds a prompt from relevant parts of the current scene, participating characters, pinned or triggered lore, and recent scene history. It does not need to send every world or every manuscript to answer a scene request.
Generation normally runs through a privately operated vLLM model service. If that service is unavailable, Mythic may send the prompt needed for that request to OpenRouter, which routes it to a model provider. OpenRouter and the selected provider process that prompt under their own data terms and may operate outside the UK. Do not put another person’s sensitive personal information into a scene unless you have a lawful reason to do so.
Read OpenRouter’s privacy policy and provider data guidance. Provider practices can vary, so we do not promise that third-party model processing is zero-retention or never used for model improvement unless the configured route expressly guarantees it.
5. Who else receives information
We share information only where needed with:
- infrastructure, database, email, monitoring, and security providers that help us operate Mythic;
- OpenRouter and downstream model providers when third-party generation is used;
- people you deliberately invite to review a work, limited by their access; and
- authorities or advisers where disclosure is required by law or necessary to protect legal rights and safety.
We do not sell your personal data.
6. Cookies and browser storage
Mythic uses first-party authentication and security cookies to keep you signed in and defend against forged requests. The access cookie lasts up to 15 minutes and the refresh and security cookies last up to seven days unless you sign out or they are revoked. These cookies are necessary for the service and are not used for advertising.
The app also uses browser storage to remember navigation context and may cache account-scoped creative data for performance and resilience. Anyone with access to your browser profile may be able to inspect locally stored data. Signing out ends the server session but may not remove every cached browser record; clear site data on a shared device.
We do not currently use advertising cookies or third-party analytics cookies. If that changes, we will update this policy and provide controls where consent is required.
7. Retention and deletion
We keep account and creative content while your account is active and for as long as reasonably needed to provide the service. Security records, deletion records, and backups may remain for a limited period where needed for fraud prevention, recovery, disputes, or legal obligations.
You can edit account details in Studio. To request account closure, deletion, access, or a portable copy of personal data, email us. We may ask you to verify your identity before acting on a request.
8. Security
We use measures designed to protect your information, including password hashing, secure cookies, access controls, encrypted network transport, and account-scoped data checks. No online system can guarantee absolute security, so keep independent copies of important work and use a unique password.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, and to object to some processing. Where processing relies on consent, you can withdraw it. These rights may have legal exceptions.
Contact us first so we can try to resolve a concern. If you are in the UK, you can also complain to the Information Commissioner’s Office.
10. Children
Mythic is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account without the permission required by law, contact us.
11. Changes to this policy
We may update this policy as the service, providers, or law changes. The effective date at the top will show the latest revision. We will give reasonable notice of material changes where appropriate.