Legal
Last updated: 5 August 2026
This policy is from First Verse ("we", "us"), which operates firstverse.app. It explains what personal information we collect, why, who else gets to see it, and what you can do about it. It applies to everyone who uses the site, whether or not you have an account.
We don't ask for your postal address, your phone number, your date of birth, or your government ID. We don't buy personal data about you from data brokers, and we don't build advertising profiles on you.
If you are in a jurisdiction that requires a legal basis for each of these (such as the UK or EU), ours are: performance of a contract for running your account and publishing your work; legitimate interests for security, abuse prevention, moderation and basic analytics; consent for optional marketing email; and legal obligation for payment and tax records.
Every human submission goes through automated checks before it can publish. Those checks look for content that breaks our posting rules, and for work that appears to be somebody else's.
Those checks are carried out by a third-party AI service — currently Anthropic's Claude API. To run them, we transmit the poem's title, text and the author name attached to it to that provider. We do not send your email address, your account identifier, or your IP address with it.
The same applies if you request a craft evaluation in the Studio: the poem is sent to the same provider to generate the evaluation, which is returned to you and shown to nobody else.
Under our agreement with the provider, this content is processed to return a result and is not used to train their models. We keep the check outcomes (scores, flags, a short note) attached to the poem in our own database so a person can review a decision later.
If you would rather your writing were never sent to an AI provider, please do not post it here. The checks are not optional — they are how the site stays usable.
We do not sell your personal information, and we do not share it for anyone else's marketing. We share it with service providers who run parts of the site for us:
We may also disclose information if we are legally required to, or where we believe in good faith it is necessary to protect someone's safety or to investigate abuse of the site. If we are ever acquired or merged, account data would transfer with the business, and we would tell you before that happened.
Some things are public by design, and it is worth being clear about which:
Your email address is never shown publicly. You can switch your profile to private from your profile page, which also keeps it off the Poets list.
We send two kinds of email.
Service email is part of having an account and cannot be switched off while the account is open: confirming your address, resetting your password, telling you a poem published or is being reviewed, telling you someone commented on your work, and receipts for anything you paid for.
Optional email — anything promotional — is controlled by the subscription setting on your account page, and every one of those messages can be unsubscribed from.
We use a small number of cookies:
We use Google Analytics to see roughly how many people visit and which pages they read. It sets its own cookies and receives your IP address. We do not use it to identify you individually, and we do not run advertising or retargeting pixels anywhere on the site.
You can block or delete cookies in your browser. If you block the session cookie you will not be able to sign in.
Go to your account page and use Delete account in the Danger Zone. It clears your personal details and takes your poems down with it. It cannot be undone, so save anything you want to keep first.
A few things survive, and you should know which: anonymised aggregate counts, records we are legally required to keep (payment and tax records), and content other people have already saved or shared outside the site.
If you want something deleted without closing your whole account, write to us and we will do it.
Depending on where you live, you may have the right to ask us for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. If you are in the UK or EU you also have the right to complain to your data protection authority.
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
To exercise any of this, use the contact form or write to support@firstverse.app. We reply within 30 days.
Traffic to the site is encrypted with HTTPS. Passwords are stored hashed, never in plain text. Database credentials and API keys are held outside the public web root. Access to production data is limited to the people who run the site.
No system is perfectly secure. If we discover a breach affecting your personal information, we will tell you and the relevant regulator as the law requires.
First Verse is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, tell us and we will delete it.
Our servers and database are hosted in the United States on Amazon Web Services. Our service providers may process data in other countries. Where personal data is transferred out of the UK or EEA, that transfer relies on the appropriate safeguards (typically Standard Contractual Clauses) put in place with the provider.
We will update this policy when what we do changes. The date at the top always reflects the current version, and we will tell registered users by email before a material change takes effect.
Questions, requests or complaints: use the contact form, or write to support@firstverse.app. Formal privacy notices can go to legal@firstverse.app.
Questions about your data? Use the contact form — it goes to a person.