Auteur Intelligence — Privacy Policy
Last updated: 2026-09-22
In plain words. Auteur Intelligence sells software for making things — writing, film, games, software, and release work. Some features run locally; connected providers, optional hybrid features, and Auteur Cloud may transmit selected data. The hosted service has a limited staging deployment and is not generally available. When you use a hosted account, we process account details, billing status, content you choose to upload, and operational records. Provider routes vary by product and offer: some use your own account, while others may use a managed provider. Our public website sets no cookies of its own and runs no analytics. If you fill in the founding-beta application form, your answers are emailed to our company mailbox. This policy says what we collect, why, how long we keep it, and how to make us delete it.
1. Who we are
Saucer Century LLC, trading as Auteur Intelligence ("we", "us", "our").
- Louisiana limited liability company. Business address: 1048 Williams Ave, Suite A, Natchitoches, LA 71457.
- Contact for anything in this policy: hello@auteurintelligence.com
We are the controller of the personal data described in this policy. Where you use Auteur Cloud to process personal data contained inside your own project files, you are the controller of that data and we act as your processor.
2. The two ways our software runs
This distinction decides almost everything else in this policy.
| Shape | What it means | What reaches us |
|---|---|---|
| Local | Software on your computer. Local-only features keep project files there; connected providers, licence activation, and optional cloud or hybrid routes can send selected data outward. | Account or pairing data for activation; content sent to connected services according to the route you choose. |
| Hosted (Auteur Cloud) | An account for sign-in, entitlements, pairing, hosted coordination, and offered features. | Account data, billing status, uploaded content, operational records, and stored provider credentials or connected-service data needed for your selected feature. |
Status. Auteur Cloud has a limited staging deployment on Hetzner, with Supabase, Cloudflare R2, and supporting services. The hosted worker and customer billing are not approved for general availability. Hosted processing terms apply when a hosted feature is offered to you and used.
3. What we collect
3.1 The public website (auteurintelligence.com)
- Server logs. Our website host records the ordinary technical details of a request: IP address, timestamp, page requested, user agent. We do not use them to build a profile of you.
- No cookies of our own. The site sets no first-party cookies and uses no browser storage. We checked the site templates before publishing this policy.
- No analytics, no tracking pixels, no advertising tags. There are none on the site.
- Web fonts. The site uses font files hosted on its own domain.
3.2 The founding-beta application form
If you apply at /founding-beta/apply/, the form collects exactly these fields:
your name; your email address; your organization (optional); which products you are applying for; a description of the project you would bring; the AI tools and harnesses you already use; the model providers and subscriptions you hold; how you prefer to connect (OAuth, API keys, browser workflows, pay-as-you-go); your hardware; any privacy requirements you have; and any other notes you add.
The form does not accept file uploads. It includes one hidden field that real applicants never see; it exists only to catch automated spam, and its contents are discarded.
Where your answers go. Your answers, plus the time of submission, are formatted as a
plain-text email and sent over SMTP to our company mailbox at
hello@auteurintelligence.com. The message's reply-to address is set to the email address
you gave, so that we can reply to you. Our mailbox is hosted by Purelymail. If the direct send fails, the page offers you an
ordinary mailto: link instead, which sends the same answers from your own email program.
We do not store applications in a database, a CRM, or a marketing list. They live in the mailbox.
3.3 Hosted accounts (Auteur Cloud, limited staging)
- Account data: your name, email address, sign-in identifiers, organization and project membership, plan and subscription status.
- Billing data: subscription state, invoices, and tax records. We never see or store your card number. Payment details are handled entirely by Stripe.
- Your content: the projects, manuscripts, scripts, media, research, and files you upload or create in the hosted service, and anything derived from them (search indexes, embeddings, caches). Derived data is treated as though it were the content it came from.
- Operational records: receipts and audit rows describing what ran, what changed, what was approved, what it cost, and what verified it. These records reference your content; they are designed not to contain it.
- Provider key ciphertext: see §4.
- Device pairing: when you pair a computer with your hosted account, we hold the pairing and entitlement records that let that machine prove what it is licensed to do.
3.4 Local installations
Local-only features do not send project content to us as hosted content. Licence activation and pairing exchange account and device data with us; connected provider, cloud, and hybrid features may send selected content to external endpoints.
Some features do keep analytics on your own machine — for example, the learning features record your practice results in a file inside your own workspace folder, so the software can tell which lessons are giving you trouble. That data is written to your disk, is intended to remain on your disk, and you can turn it off per workspace. It is yours in the same way the rest of your files are.
When a local installation activates a licence or pairs with a hosted account, it exchanges an activation or pairing token with us. That exchange identifies the account and the machine; it does not carry your project files.
3.5 Support and correspondence
If you email us, or send us a bug report, we hold what you sent. If you send us a file to reproduce a problem, we hold that file until the problem is closed and then delete it.
3.6 The community platform
Skool access is included only where the applicable Auteur Learning or product offer says so. Skool is a separate service under its own terms and privacy policy. Separately priced premium products and services are not included merely because you have a founding seat.
4. Your AI provider keys
Some features use AI model or media provider accounts you connect and pay directly. Other features may use a provider arranged by us, or compute on a node you control. The applicable product or offer identifies the route and charges. A provider, including an upstream model host reached through a gateway, may receive prompts, source files, media, and related metadata needed for a request. Its terms and privacy practices also apply.
If you store a provider key with the hosted service:
- It is encrypted before it is written down, using envelope encryption with a key held outside the application database.
- The ciphertext is cryptographically bound to your organization, the key record, its version, and the provider, so a stored key moved to another tenant or another record cannot be decrypted at all.
- Application code is designed to restrict plaintext key access to the outbound provider call. This is not a claim that no person with infrastructure access could ever obtain plaintext; production access controls require separate verification.
- Keys are never included in exports or backups. Deleting a key removes the record and revokes its encryption key in the same operation.
You remain responsible for your provider accounts, your spend with them, and your compliance with their terms.
5. Why we process data, and on what basis
| What | Why | Basis, if GDPR/UK GDPR applies |
|---|---|---|
| Account and sign-in data | To give you an account and let you use it | Performance of a contract |
| Billing data | To charge you and keep required financial records | Contract; legal obligation for tax records |
| Content you upload | To provide the service you asked for | Contract; and your instruction, where we act as your processor |
| Operational records and receipts | To show what ran, resolve disputes, detect abuse, and keep the service honest | Legitimate interests |
| Provider key ciphertext | To run generation on your own accounts at your request | Contract |
| Application form answers | To decide admission to the founding beta and plan your onboarding | Steps taken at your request before a contract |
| Support correspondence | To answer you | Contract; legitimate interests |
| Server logs | To keep the site running and secure | Legitimate interests |
6. What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not use your content to train our own models. Provider training and retention depend on the selected route and that provider's terms.
- We do not read your content except as needed to run the service, when you ask us to (for example in support), or where the law requires it.
- Processing may use your local hardware, a connected provider, an optional hybrid node, or a managed provider route where offered.
7. Where your data is processed, and who else touches it
The providers we use for the public site and limited staging are listed in SUBPROCESSORS.md, which forms part of this policy. In summary:
- Live or provisioned for staging: our website and mail providers, Hetzner hosting, Supabase authentication/database, Cloudflare DNS and R2 storage, and Brevo email relay. Stripe billing remains in test mode. The subprocessor list distinguishes services used for the public site from staging services and from customer-directed providers.
We will update the provider list as required by the applicable agreement and law.
International transfers. Availability may extend worldwide where legally and operationally supportable. Your selected processing route may involve providers outside your country, subject to applicable law and the terms disclosed for that route.
8. How long we keep things
| Data | How long |
|---|---|
| Founding-beta applications | While needed to review and administer the application, subject to deletion requests and legal obligations. |
| Account data | For the life of the account, plus the deletion schedule below |
| Your content | Until you delete it, or until your account closes and the deletion schedule runs |
| Data derived from your content (indexes, embeddings, caches) | Follows source-content deletion and backup schedules. |
| Provider keys | No retention window at all: until you replace or delete them |
| Operational records and receipts | While needed for audit, service integrity, and dispute resolution. |
| Billing and tax records | As required by applicable tax and accounting law. |
| Product telemetry | Any new collection will be described before it begins. |
| Website server logs | As set by our hosting provider. |
Deletion. When you delete content or close your account, we process the request under our data lifecycle procedures and applicable law. We retain records needed to document what was deleted and what was kept. Backups rotate, so a deleted record can survive in backup for a bounded further period under our backup schedule. Some records — billing and tax records, and the proof that a deletion happened — are kept afterwards because the law or the integrity of the record requires it; we will tell you which.
Deletion never reaches your own machine. If you run the software locally, your files are yours; we cannot delete them, and we will not try.
9. Your rights
Depending on where you live, you may have the right to ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and — where we rely on consent — to withdraw that consent. We will not treat you worse for exercising any of these rights.
How to exercise them: email hello@auteurintelligence.com and say what you want. We will check that you are the person you say you are before acting on a request about an account. We will respond within the period required by applicable law.
Where in-product export and deletion paths are available, you may use them. You can also email us to request access to or deletion of your data.
If you think we have handled your data badly, please tell us first. You also have the right to complain to a supervisory authority.
10. Children
Ordinary independent account holders must be at least 18. A minor may participate in Auteur Learning through an account held and supervised by a parent, guardian, or other appropriate adult, subject to the safeguards of that offering. A minor may not hold an ordinary independent account. If you believe a child has provided personal data outside that supervised arrangement, email us at hello@auteurintelligence.com.
11. Changes to this policy
We will post any change here with a new date. If a change materially affects how we use your personal data, we will tell account holders in advance. The hosted sections of this policy take effect for you when you first use the hosted service.
12. Contact
hello@auteurintelligence.com
Saucer Century LLC, trading as Auteur Intelligence Business address: 1048 Williams Ave, Suite A, Natchitoches, LA 71457