Privacy Policy
# Privacy Policy
Last updated: 14 July 2026
## About this policy
This is an interim Privacy Policy. It accurately describes how Branch Press handles information today, and it applies now. It is currently under review by legal counsel and may be refined for clarity and completeness; any material change will be handled as described under "Changes to this policy" below. If anything here is unclear, contact [email protected].
## The short version
Branch Press is a reading site and a private writing workspace. If you only read, we collect nothing about you beyond the ordinary technical logs any website produces. If you create an account, we store what the service needs to work: your email, your profile, and the things you write. Your notes are private by default and protected so that only your account can read them. We run no analytics, show no ads, send no marketing email, do not sell or share your data, and do not use your content to train AI models. You can export your writing and delete your account, and everything in it, at any time.
## Who operates Branch Press
Branch Press (branchpress.org) is an independent literary press and writing platform operated by Soulaiman B. Mershed, also writing as S B Mershed, an individual based in Muscat, Oman. In this policy, "Branch Press," "we," "us," and "our" refer to this project; "you" refers to any visitor or account holder. For anything concerning your data or this policy, contact [email protected]. General correspondence: [email protected].
## Scope
This policy covers branchpress.org and the account-based writing workspace within it, called Branchspace. It describes the system as it actually runs today. If we change what the system does with your data, we update this policy first.
## The two ways to use Branch Press
As a reader, without an account: the essays, books, graph, and public pages are readable without signing up, without consent-requiring cookies, and without identifying you. The only data involved is the technical minimum described under "Information processed automatically."
As a writer, with an account: Branchspace is a private writing workspace with notes, spaces, a knowledge graph, a reading tracker, and a public writer profile. Everything you create there is private by default. Some things become public only by your explicit choice, described under "What is public."
## What we collect from account holders, and why
We collect only what each feature needs to function.
To sign you in: your email address and a securely hashed password, held by our database and authentication provider, Supabase. We never store or see the password itself. If you sign in with Google, we receive the identity information Google's sign-in provides (your name, email, and avatar reference) and the tokens Google issues; we do not gain access to your Gmail, Drive, or any other Google data.
To give you a profile: an optional display name, handle, bio, and avatar image. The avatar is stored in our storage system.
To make the workspace work: the notes, spaces, and compositions you create, stored with database access rules so that only your account can read them; your reading-tracker entries; your reading positions, bookmarks, and highlights on Branch Press essays; and daily contribution counts used for your profile's contribution calendar. Those contribution records are numbers only, never the content, titles, or subject of what you wrote. Your private writing may contain anything you choose, and we treat all of it as private regardless of its subject.
If you email us, we receive your email address, your name if you give one, and your message, used only to read and respond to you.
## Information processed automatically for everyone
Like any website, Branch Press is served through hosting and content-delivery infrastructure. When you load a page, that infrastructure processes limited technical information as a normal part of delivering the site, protecting it from abuse, and diagnosing faults: your IP address, browser and device type, the page requested, timestamps, referring page, and security and error logs. Our hosting and content-delivery provider is Cloudflare, and our database provider keeps equivalent service logs. These logs are held for short rolling windows on the providers' standard schedules, typically measured in days to weeks, and are not used by us for any purpose. We run no analytics and no tracking, so we do not profile you.
## Fonts and page assets are served by us
All fonts and site assets on Branch Press are served from Branch Press's own hosting. Loading a Branch Press page does not send your IP address or any other information to third-party font or asset services. One exception exists by your own action: if you embed an image in your notes by pasting a link to an outside host, your browser fetches that image from that host when the note is displayed.
## What we deliberately do not do
Each of these is true of the system as it runs today:
- No analytics or tracking scripts of any kind.
- No advertising and no ad-tech.
- No sale or sharing of your personal data with anyone for their own purposes.
- No marketing email; we email you only about your account or the service when necessary.
- No cross-site tracking and no third-party cookies.
- No AI training on your content, and today no user content is sent to any AI provider at all.
If we ever wanted to change any of these, we would change this policy first and tell you.
## What is public, and only by your choice
Privacy on Branch Press works in one direction: things become public only through an explicit action of yours, and you can reverse the visible part of that action at any time.
Your profile page, at a public address based on your handle, shows your display name, handle, bio, avatar, your public spaces, your public activity, and your contribution calendar. The profile is public by default, because Branch Press is a press and writers are its public face, but a single switch in your profile settings makes it fully private.
Marking a note or space public exposes it at a share link that anyone can read, and that search engines can index, cache, and quote. Unsharing removes it from Branch Press going forward, but cannot recall copies others may already have made. Publish deliberately.
Reading-tracker entries are private unless you mark an individual entry public. Nothing else you create is ever visible to anyone but you.
## Images you embed from elsewhere
The workspace lets you place images in notes by pasting a direct link to an image you host elsewhere. Branch Press stores only the link. The image stays with, and is served by, the host you chose, under that host's own privacy practices. Choose hosts you trust, especially for images in notes you make public.
## Your private notes stay private
We designed Branch Press so that reading your private notes forms no part of ordinary operation: database access rules restrict each note to its owner's account, and no feature of ours reads private content for analytics, recommendations, training, or curiosity. We have no interest in inspecting private notes. We will not access your private content except where the law recognizes a narrow need: where we are legally compelled to by a valid legal order, or where it is strictly necessary to investigate a specific, credible report of abuse of the service or harm to others, and then only to the minimum extent required. We prefer this honest statement to an absolute promise that a single legal order could turn into a falsehood.
## Retention and deletion
Your content persists until you delete it. Deleting a note deletes it; unsharing a note removes it from public view immediately. You can delete your entire account from your account settings; account deletion removes your authentication record, profile, avatar, notes, spaces, readings, annotations, bookmarks, reading positions, and contribution history, and residual copies in operational backups are purged within 30 days. You can also request deletion by email at [email protected], and we will complete it within 30 days of verifying that the request comes from the account holder. Server and security logs follow the short provider schedules described above.
## Your rights
You can, at any time: access the personal data we hold about you, most of which is simply visible to you in your account; correct it, since profile fields are self-serve; export your content and take it elsewhere, which currently works per item, for compositions and notes, as a single full-account archive does not exist yet; delete individual content or your entire account; and object or complain, first to us at [email protected] and also to a data protection authority. The precise set of statutory rights that applies to you depends on where you live; if you contact us, we will honor the rights the law gives you.
## Where data lives and international transfers
Branch Press operates from Oman, and its infrastructure providers are international. Your account data is stored with Supabase in Singapore (AWS ap-southeast-1) and transits Cloudflare's global content-delivery network. If you sign in with Google, Google processes the sign-in. This means your data crosses borders as an inherent part of the service. The formal safeguards that govern these transfers are provided through our providers' data-processing terms; the exact contractual wording is being finalized with legal counsel.
## Artificial intelligence
Today, no user content is sent to any AI provider, for any purpose, and there is no AI feature in the product. Branch Press intends to eventually offer an optional AI writing assistant. If that happens, the provider will be named in this policy before the feature activates; it will process your content only when you invoke it; your content will never be used to train AI models, ours or a provider's; and if you never use the feature, your notes will never touch any AI system.
## Information stored in your browser
Branch Press stores a small amount of data in your browser: your sign-in session, theme choice, reading positions, and editor preferences. This is functional storage the service needs to work; it is not used for tracking, and we do not use third-party cookies. You can clear it at any time through your browser's site-data settings, which signs you out and resets preferences.
## Security
Private content is protected by database access rules that make each record readable only by its owner's authenticated account; public data is exposed only through deliberately restricted read paths; passwords are hashed by the authentication provider; and all traffic is encrypted in transit. No system is invulnerable, and we do not claim ours is, but its privacy boundaries are enforced in the database itself, not merely in the interface. If a data breach affects your personal information, we will notify you and any authority the law requires.
## Age
Branch Press is a general-audience service for adults and is not directed at children. You must be at least 16 years old to create an account.
## Changes to this policy
We may update this policy as Branch Press evolves. When we do, we will update the "Last updated" date above, and for material changes, meaning anything that changes what we collect, what becomes public, or what we promise under "What we deliberately do not do," we will post a clear notice on the site and in the workspace before or when the change takes effect, and email account holders where a change materially affects them. Continued use of Branch Press after a change takes effect means the updated policy applies to you.
## Contact
Questions, requests, or complaints about privacy: [email protected]. We aim to respond within 14 days and to resolve verified data-subject requests within 30 days.