Legal

Privacy Policy

Last updated: 14 August 2026

Summary. We collect the email address you sign up with, what you choose to put on your profile, the poems, drafts and comments you post, and basic technical logs. We do not sell your data and we do not run advertising networks on the site. Poems are transmitted to an AI provider for the automated checks that run before publication; section 4 sets out exactly what is sent. You can delete your data from your account page. This summary is not part of the policy — the numbered sections are.

1. Who this is from

First Verse is a service of Webfront LLC ("First Verse", "we", "us"), which operates firstverse.app and is the controller of the personal information described here. This policy explains what personal information we collect, why, who else gets to see it, and what you can do about it. It applies to everyone who uses the site, whether or not you have an account.

2. What we collect

2.1 What you give us

  • Account details. Your email address. If you sign in with Google we receive your name, email address, profile picture and Google account identifier — never your Google password. If you sign in with an emailed link there is no password at all: we store only a one-way hash of the link's token, and each link works once and then expires. Accounts made before August 2026 may still carry a hashed password.
  • Profile information. Your name, a short bio or title, a profile photo, a city and country, and any website or social links, if you add them. All of this is optional except a name.
  • Your writing. The poems you post, their titles, the comments and replies you leave, and your drafts — which are stored on our servers so you can come back to them, and are visible to nobody but you until you publish them.
  • Messages. What you send us through the contact form, and our replies. Both sides of that thread are shown back to you on your account page.
  • Payment details. If you buy evaluation credits or pay to expedite a poem, Stripe collects and holds the card details. We receive a customer reference, the amount, and whether it succeeded. We never see or store your full card number.

2.2 What we record as you use the site

  • Activity. Which poems you star, who you follow, which poems you save, and which poem and poet pages you have opened. Poets see a count of readers on their own poems and on their page, never who those readers were.
  • Reports. If you report a comment we record that you did so, to prevent the same comment being reported repeatedly by one member. We do not disclose the identity of a reporter to the person reported.
  • Tip clicks. We count uses of a poet's tip control and report the count to that poet. We do not receive the payment, the amount, or the identity of the payer; those are handled entirely by the payment provider, off the Service.
  • Technical logs. Your IP address, browser and device type, and the pages you request, in ordinary web-server logs. We store the IP address attached to a contact-form message as an anti-abuse measure.
  • Email delivery records. For each email we send you, we log what kind it was, the address, the subject and whether it was accepted for delivery. We do not use tracking pixels to record whether you opened it.
  • Referrals. If you arrive through someone's referral link, we record who referred you.

2.3 What we don't collect

We don't ask for your postal address, your phone number, your date of birth, or your government ID. We don't buy personal data about you from data brokers, and we don't build advertising profiles on you.

3. Why we hold it

  • To give you an account and keep you signed in.
  • To publish your poems and show them to readers.
  • To run the automated checks described in section 4, and so to prevent the publication of unlawful material and of other people's work.
  • To email you about things that happen to your account and your poems (section 7).
  • To take payment for the optional paid features, and to keep records of those payments.
  • To answer you when you write to us.
  • To keep the Service running, to detect and prevent abuse, and to measure how it is used.

If you are in a jurisdiction that requires a legal basis for each of these (such as the UK or EU), ours are: performance of a contract for running your account and publishing your work; legitimate interests for security, abuse prevention, moderation and basic analytics; consent for optional marketing email; and legal obligation for payment and tax records.

4. AI processing of your poems

Every human submission goes through automated checks before it can publish. Those checks look for content that breaks our posting rules, and for work that appears to be somebody else's.

Those checks are carried out by a third-party AI service — currently Anthropic's Claude API. To run them, we transmit the poem's title, text and the author name attached to it to that provider. We do not send your email address, your account identifier, or your IP address with it.

The same applies if you request a craft evaluation in the Studio: the poem is sent to the same provider to generate the evaluation, which is returned to you and shown to nobody else.

Drafts are not transmitted to any AI provider. The checks run at the point of posting, not while you write; unpublished work remains on our servers only.

Comments may be screened in the same way. Where comment screening is enabled, the text of the comment is transmitted to the same provider, on the same terms, and is likewise not used to train their models.

Under our agreement with the provider, this content is processed to return a result and is not used to train their models. We keep the check outcomes (scores, flags, a short note) attached to the poem in our own database so a person can review a decision later.

These checks are a condition of publication and cannot be waived. If you do not want your writing transmitted to an AI provider on these terms, do not post it on the Service.

5. Who else sees it

We do not sell your personal information, and we do not share it for anyone else's marketing. We share it with service providers who run parts of the site for us:

  • Our hosting provider — a commercial web host in the United States, which operates the servers, database and file storage holding your account, poems and drafts. We identify the provider on request; we do not publish its name, for security reasons.
  • Amazon Web Services — Amazon SES, which sends every email we send you, and which therefore receives your email address.
  • Anthropic — the AI checks and evaluations described in section 4.
  • Stripe — card payments for evaluation credits, expedited publishing, featured poems and poet handles.
  • Cloudflare — the challenge that runs when you ask for a sign-in link, to keep bots from mailing links to other people's addresses, and the CDN that serves some of our JavaScript. Both see your IP address.
  • Google — Sign-In (if you use it), Google Analytics (section 8), and Google Fonts, which receives your IP address as part of loading the page's typefaces.
  • Content delivery networks (Google Hosted Libraries, cdnjs, unpkg) that serve a handful of JavaScript libraries, and which therefore see your IP address.

The tip providers are deliberately not on that list. Using a poet's tip control takes you off the Service and into Venmo, Cash App or PayPal, where you transact under those companies' own terms and privacy policies. We disclose nothing about you to them, and we receive nothing about the payment.

We may also disclose information if we are legally required to, or where we believe in good faith it is necessary to protect someone's safety or to investigate abuse of the site. If we are ever acquired or merged, account data would transfer with the business, and we would tell you before that happened.

6. What is public

The following are public by design and visible to anyone, whether or not they have an account:

  • Your published poems, their titles, and the star and comment counts on them.
  • Your display name, profile photo, bio and any links you added.
  • Comments and replies you leave, with your name and photo attached.
  • Who follows you, and how many people you follow.
  • Badges you have earned, any awards you have won, and your position in public rankings.
  • Your handle, if you claimed one, and the tip handles you chose to publish.

Your email address is never shown publicly. You can switch your profile to private from your profile page, which also keeps it off the Poets list.

7. Email we send you

We send two kinds of email.

Service email is part of having an account and cannot be switched off while the account is open: confirming your address, resetting your password, telling you a poem published or is being reviewed, telling you someone commented on your work, and receipts for anything you paid for.

Optional email — the digest of what's new, and anything promotional — is controlled by the subscription settings on your account page, and every one of those messages carries a one-click unsubscribe link that works without signing in.

The same notifications are available on the site under Alerts, independently of email.

8. Cookies and analytics

We use a small number of cookies:

  • a session cookie, so the site knows you are signed in;
  • a "remember me" cookie, so you stay signed in between visits;
  • a dismissal cookie, recording that you closed the "install the app" prompt so we stop asking.

We use Google Analytics to measure how many people visit and which pages they read. It sets its own cookies and receives your IP address. We do not use it to identify individual members, and we do not run advertising or retargeting pixels anywhere on the site.

You can block or delete cookies in your browser. If you block the session cookie you will not be able to sign in.

9. How long we keep it

  • Account and profile data — while your account exists.
  • Poems, drafts and comments — until you delete them or your account.
  • Sign-in link tokens — the hash only, and only until the link is used or expires.
  • Contact messages — up to 3 years, so we have the history of a conversation if you write again.
  • Moderation records — for the life of the poem, plus a short period after, so a decision can be reviewed.
  • Email delivery logs — 12 months.
  • Server logs — typically 90 days.
  • Payment records — as long as tax and accounting law requires, usually 7 years.
  • Backups — deleted data can persist in routine backups for a short period before those rotate out.

10. Deleting your data

Go to your account page and use Delete account in the Danger Zone. This clears your personal details and removes your poems, drafts and comments. It cannot be undone; save anything you want to keep first.

Three categories survive deletion: anonymised aggregate counts, records we are legally required to retain (payment and tax records), and content other people have already saved or shared outside the Service, which we cannot recall.

To have specific data deleted without closing your account, contact us.

11. Your rights

Depending on where you live, you may have the right to ask us for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. If you are in the UK or EU you also have the right to complain to your data protection authority.

If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.

To exercise any of this, use the contact form or write to support@firstverse.app. Where the law sets a deadline for responding to a request of this kind, we answer within it — one month under UK and EU rules, 45 days under California's.

12. Security

Traffic to the site is encrypted with HTTPS. Current accounts hold no password: we store only a one-way hash of a single-use sign-in token, which cannot be replayed. Where a legacy password exists it is stored hashed, never in plain text. Database credentials and API keys are held outside the public web root. Access to production data is restricted to the people who operate the Service.

No system is perfectly secure. If we discover a breach affecting your personal information, we will tell you and the relevant regulator as the law requires.

13. Children

First Verse is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, tell us and we will delete it.

14. Where your data is held

Our servers and database are in the United States. Our service providers — those listed in section 5 — may process data in other countries. Where personal data is transferred out of the UK or EEA, that transfer relies on the appropriate safeguards (typically Standard Contractual Clauses) put in place with the provider.

15. Changes and contact

We will update this policy when what we do changes. The date at the top always reflects the current version, and we will tell registered users by email before a material change takes effect.

Questions, requests or complaints: use the contact form, or write to support@firstverse.app, which also receives formal privacy notices and data-subject requests.

Questions about your data: use the contact form or write to support@firstverse.app.