Legal

Privacy Policy

How 2Novel collects, uses, and protects your data.

Last updated: 9/23/2026

1.Data we collect

  • Account: your email, name, profile photo and Google account identifier. We do not receive your Google password. If you set a separate 2Novel login password, we store an argon2id hash, not the plain password.
  • Content you create: books, source text, translations, glossaries and translation settings.
  • Usage and payments: translated character counts, costs, balance, top-up and refund history, plan and workspace members.
  • Technical data: IP address, browser, server error logs and, only after you accept optional analytics, aggregate traffic statistics from Google Analytics 4.

We do not collect sensitive personal data as defined by Vietnam’s Decree 13/2023/ND-CP.

2.How we use data

  • Account data — sign-in, workspace permissions and service notices.
  • Content — storing it for you to read, edit and publish, and sending it to an AI provider for translation.
  • Usage and payments — billing, reconciliation, refunds for failed chapters and preventing abuse.
  • Technical data — system security and troubleshooting.

Translation requires sending chapter text to an AI provider. This is a technical requirement and cannot be turned off while using translation.

We do not use your works to train our own models. Whether an AI provider uses data for training depends on that provider’s policy; use your own API key (BYOK) to manage this under your provider account.

3.Your API key (BYOK)

Your key is encrypted in your browser before leaving your device, using PBKDF2-SHA256 with 600,000 iterations and AES-256-GCM with a passphrase you choose. The server stores the encrypted key.

By default, your passphrase stays in your browser and is not stored on the server. For each translation, it is sent to the server to decrypt the key in server memory. The plain key is not written to the database or logs.

Exception: if you enable server-side passphrase storage for automated translation through the API, the passphrase is sealed with a server secret and used only for your workspace. You can turn this off at any time.

There is no feature to show a forgotten passphrase. If you lose it, you need to enter and save your API key again with a new passphrase. The optional server sealing described above allows the server to open the passphrase for automated translation.

4.2Novel browser extension (ChatGPT relay)

The extension is optional. It lets you translate through your own signed-in chatgpt.com session instead of entering an API key. Other features work without installing it.

The extension runs only on chatgpt.com, to compose requests and read replies, and 2novel.app, to receive tasks and return results. It does not read other pages or your browsing history.

  • Pairing: you paste a pairing code into the extension. It stores a device token in your browser’s local storage, used only to receive your workspace’s tasks. You can revoke it in Settings at any time.
  • Data sent: chapter text to be translated goes from 2Novel to the ChatGPT tab, and the resulting translation goes back to 2Novel.
  • Activity logs: device identifier, event name, time, duration, book and translation identifiers, the URL of the ChatGPT conversation created by the extension, and error details when applicable. These are used to diagnose relay problems.

The extension does not request permission to read cookies or passwords. It cannot see your OpenAI login credentials and does not read ChatGPT conversations other than those it creates for translation.

Data collected by the extension is used only to run translation and troubleshoot problems. It is not sold, shared with advertisers or used to train models.

Diagnostic data also includes call records containing request text and page-state snapshots when the relay encounters a block. Each category has its own cleanup schedule: the defaults are 24 hours for completed call records, 72 hours for activity logs and 7 days for page-state snapshots. Actual retention depends on the storage configuration.

5.Sharing with third parties

We do not sell or trade your data. We share it only with parties needed to run the service:

  • Google — sign-in through OAuth and optional traffic measurement through Analytics 4 after you accept analytics.
  • The AI provider you select — chapter text and translation context needed to produce the translation, processed under that provider’s policies.
  • SePay — domestic payments, and Polar — international payments. 2Novel does not see or store your card number.
  • Google Cloud (Singapore) — server and database infrastructure.

Otherwise, we disclose data only in response to a lawful written request from a competent authority.

6.Retention

  • Books and translations: kept until you delete them. Deleting a book also deletes its chapters and translations.
  • If deletion is allowed, deleting your account deletes your profile, workspaces you own, books, encrypted API keys and associated invitations. A completed deletion cannot be undone.
  • Backups: deleted data may remain in backups for a short period before being overwritten.
  • Technical logs: rotated on short cycles. Extension diagnostics are cleaned up by category as described in section 4; not all data is deleted after 72 hours.

Export translations as .docx or .txt before deleting if you want to keep them.

Deleting your account does not cancel renewal with an external payment provider. Before deleting, the server checks for retained provider billing evidence. If potential external billing needs review, it pauses deletion and keeps your account, data and sign-in available; use the customer portal when offered and contact support for recovery. A local canceled or expired plan may still require this review. This safeguard does not cancel a subscription or issue a refund.

7.Your rights

Under Vietnam’s Decree 13/2023/ND-CP, you have rights to be informed, access, correct and delete data; restrict or object to processing; withdraw consent; request a copy of data; and complain.

You can edit your profile, export translations, delete individual books and request account deletion in the app. The server may pause account deletion for a billing review as described above. A book export is not a complete copy of all personal data. Email us to request account data or exercise other rights.

Send other requests to [email protected] from the email address you use to sign in. We respond within 72 hours.

Include your sign-in email, the relevant workspace and your specific request: access, correction, deletion, a copy, restriction, objection or withdrawal of consent. If you no longer have access to your sign-in email, explain this in your message. Do not send passwords, API keys or identity documents in your initial message.

8.Cookies

  • Sign-in session cookies (httpOnly) — required for the service to work; deleting them signs you out.
  • Google Analytics 4 cookies (_ga, _ga_*) — optional traffic statistics. Analytics starts off: Google Analytics is not loaded and no Analytics request is made until you choose “Accept analytics”. Choosing “Reject analytics” saves analytics as off.

The “Privacy choices” control in the footer and the privacy-choices button available on the site reopen these settings. Choose “Turn off analytics” to withdraw later; withdrawal disables analytics and removes the _ga and _ga_* cookies owned by 2Novel. Sign-in, language, market and appearance storage is essential and separate from optional analytics. If this browser cannot save your choice, analytics remains off. 2Novel does not set advertising cookies.

9.Security

  • All connections use HTTPS.
  • Google handles your Google password. If you set a separate 2Novel password, we store an argon2id hash, not the plain password.
  • BYOK API keys are encrypted in the browser (see section 3).
  • Sign-in sessions use httpOnly cookies and protection against cross-site request forgery (CSRF).
  • Data is separated by workspace; queries check membership permissions.

If a personal-data breach occurs, we notify affected people and the competent authority within 72 hours of discovery.

10.Policy changes and contact

When this policy changes, we update the date at the top of the page. Changes that significantly affect your rights will be announced at least 7 days in advance.

For any personal-data request: