Privacy Policy

Last updated: March 4, 2026

1. Introduction

Gable Digital Solutions, Inc. ("we," "our," or "us") operates FictionMaker.ai and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service, including our website and mobile applications (collectively, the "Service"). Please read this policy carefully.

This Privacy Policy applies to all users of the Service, including residents of California, Virginia, Colorado, Connecticut, Texas, Delaware, and other U.S. states with privacy laws, as well as users in the European Union, United Kingdom, and other countries. Your specific rights vary by jurisdiction and are detailed in the applicable sections below.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Name, email address, username, and password when you register.
  • Profile Information: Profile picture, bio, and other optional profile details.
  • Payment Information: Billing address and payment card details (processed by Stripe; we do not store full card numbers).
  • User Content: Stories, characters, worlds, and other creative content you create using our platform.
  • Communications: Messages, support requests, and feedback you send to us.
  • Survey Responses: Information provided in optional surveys or research activities.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, click patterns, and interactions with AI tools.
  • Device and Technical Information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
  • Log Data: Access times, referring URLs, error logs, and server activity.
  • Cookies and Tracking Technologies: We use cookies, web beacons, pixels, and similar technologies as described in Section 7.
  • Location Information: Approximate geographic location derived from your IP address.

2.3 Information from Third Parties

  • Social Login Providers: If you register using a social media account (e.g., Google), we receive basic profile information from that provider, subject to your privacy settings there.
  • Payment Processors: Transaction status and limited billing information from Stripe.
  • Analytics Providers: Aggregated usage statistics from analytics services.

3. How We Use Your Information

We use your personal information for the following purposes:

  • To provide, operate, maintain, and improve the Service
  • To create and manage your account
  • To process transactions and send related information (receipts, invoices, subscription notices)
  • To send technical notices, security alerts, and administrative messages
  • To respond to your comments, questions, and support requests
  • To send marketing communications (subject to your preferences and applicable opt-out rights)
  • To analyze usage patterns and improve user experience and platform features
  • To detect, investigate, and prevent fraudulent transactions and other illegal activity
  • To enforce our Terms of Service and other policies
  • To comply with applicable legal obligations
  • To protect the rights, property, or safety of us, our users, or others

4. Legal Basis for Processing (EU/UK Users)

If you are located in the European Union or United Kingdom, we process your personal data on the following legal bases under GDPR/UK GDPR:

  • Contractual Necessity (Art. 6(1)(b)): Processing necessary to perform our contract with you, including providing the Service, managing your account, and processing payments.
  • Legitimate Interests (Art. 6(1)(f)): Processing for our legitimate business interests, including fraud prevention, security, product improvement, and direct marketing (where you would reasonably expect it), provided these do not override your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable laws, regulations, and legal processes.
  • Consent (Art. 6(1)(a)): Processing based on your specific consent, including for non-essential cookies, marketing communications, and optional features. You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. AI and Your Content

Important: We do not use your personal creative content (stories, characters, worlds) to train our AI models without your explicit, separate consent. AI features process your content only within your own projects to provide relevant suggestions and assistance.

We may use anonymized, aggregated, and de-identified data derived from platform interactions (not your specific content) to improve our AI capabilities and service quality. Such data cannot be used to identify you.

If you choose to participate in optional AI training programs, we will seek your explicit consent and provide full details about how your content will be used, with the ability to withdraw consent at any time.

6. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: Third-party companies that perform services on our behalf, such as cloud hosting (Cloudflare, AWS), payment processing (Stripe), email delivery, analytics, and customer support. These providers are contractually bound to process data only for the specified purpose and to maintain appropriate security measures.
  • Legal Requirements: When required by law, court order, subpoena, or other legal process, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a government request.
  • Business Transfers: In connection with a merger, acquisition, bankruptcy, reorganization, or sale of all or substantially all of our assets. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
  • With Your Consent: When you give us explicit consent to share your information with a specific third party.
  • Aggregate/De-identified Data: We may share aggregated or de-identified information that cannot reasonably be used to identify you.
  • Protection of Rights: To enforce our Terms of Service, protect the security or integrity of the Service, or protect the rights, property, or safety of us, our users, or others.

7. Cookies and Tracking Technologies

7.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Service to function (session management, authentication). Cannot be disabled.
  • Functional Cookies: Enable personalized features and remember your preferences (language, theme).
  • Analytics Cookies: Help us understand how users interact with the Service (Google Analytics). These are subject to your consent.
  • Marketing/Advertising Cookies: Used to deliver relevant advertisements and measure their effectiveness. Subject to your consent.

7.2 Cookie Consent

We obtain your consent before setting non-essential cookies. You may withdraw consent or adjust preferences at any time via our Cookie Preference Center, accessible in the footer of our website.

7.3 Browser Controls

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service. For information about managing cookies, visit www.allaboutcookies.org.

8. Targeted Advertising and Opt-Out

We may work with third-party advertising partners to display interest-based advertisements. You may opt out of targeted advertising by:

We recognize and honor the Global Privacy Control (GPC) signal. If your browser sends a GPC opt-out signal, we will treat it as a request to opt out of the sale and sharing of your personal information for targeted advertising purposes.

9. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, loss, alteration, or disclosure. These measures include:

  • Encryption of personal data in transit (TLS) and at rest (AES-256)
  • Access controls and role-based permissions for personnel
  • Regular security assessments, penetration testing, and audits
  • Incident response procedures
  • Employee data protection training

However, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with applicable law.

10. Data Retention

We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Account and profile data: Retained for the duration of your account, plus up to 30 days after account deletion for recovery purposes.
  • User Content: Retained while your account is active. Deleted within 30 days of account deletion, unless subject to a legal hold.
  • Transaction records: Retained for 7 years to comply with financial and tax regulations.
  • Server logs: Retained for 12 months for security purposes.
  • Support records: Retained for 3 years.
  • Marketing preferences: Retained until you opt out or withdraw consent.

11. Children's Privacy (COPPA Compliance)

Our Service is not directed to children under 13 years of age. We do not knowingly collect, use, or disclose personal information from children under 13. If you are under 13, you may not create an account or use the Service.

If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take immediate steps to delete that information and terminate the child's account. Parents or legal guardians who believe their child has provided us with personal information should contact us immediately at privacy@fictionmaker.ai. We will:

  • Verify your identity as the parent or guardian
  • Provide access to and a description of the personal information collected
  • Allow you to request deletion of the child's personal information
  • Allow you to request that we refrain from further collection from the child
  • Respond to verified parental requests within 30 days

For EU/UK users: Users between ages 13 and 16 (or the applicable age under your country's laws) require verifiable parental consent to use the Service in accordance with GDPR Article 8.

12. Your Privacy Rights

12.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to applicable legal requirements.
  • Opt-out of Marketing: Unsubscribe from marketing emails at any time.
  • Data Portability: Request your personal information in a commonly used, machine-readable format.

12.2 California Residents — CCPA/CPRA Rights

California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: Request the categories and specific pieces of personal information collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share information. We will respond within 45 days (extendable by 45 days with notice).
  • Right to Delete: Request deletion of personal information we collected from you, subject to certain exceptions (e.g., completing a transaction, security, legal obligations).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not currently sell your personal information. We may share certain information with advertising partners for cross-context behavioral advertising. You may opt out by clicking "Do Not Sell or Share My Personal Information" (available in our website footer) or by emailing privacy@fictionmaker.ai.
  • Right to Limit Sensitive Personal Information: You may request that we limit our use of sensitive personal information (e.g., account login credentials, precise geolocation) to purposes necessary for providing the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
  • Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and verification of your identity.

Categories of Personal Information We Collect (past 12 months): Identifiers (name, email, IP address), commercial information (transaction records), internet or network activity (usage data), geolocation data (IP-based), inferences drawn from usage data.

Categories of Personal Information Sold or Shared: We do not sell personal information. We may share identifiers and internet/network activity with advertising partners for cross-context behavioral advertising purposes.

To submit a CCPA/CPRA request, contact us at privacy@fictionmaker.ai with subject line "California Privacy Request," or call our designated toll-free number. We will verify your identity before processing your request.

12.3 EU and UK Residents — GDPR/UK GDPR Rights

If you are located in the European Union or United Kingdom, you have the following rights under GDPR (EU 2016/679) and/or the UK GDPR:

  • Right of Access (Art. 15): Obtain confirmation of whether we process your personal data and access to that data, along with supplementary information.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data and completion of incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your personal data in certain circumstances (e.g., data no longer necessary, consent withdrawn, unlawful processing).
  • Right to Restriction of Processing (Art. 18): Request that we restrict processing of your personal data in certain circumstances (e.g., while accuracy is disputed).
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we demonstrate compelling legitimate grounds.
  • Rights Related to Automated Decision-Making (Art. 22): Not to be subject to solely automated decisions that produce legal or significant effects, unless you have given explicit consent or it is necessary for a contract. You may request human review of any such decisions.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority. In the EU, contact your national data protection authority (see edpb.europa.eu). In the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise your GDPR rights, contact us at privacy@fictionmaker.ai. We will respond within one month, extendable by two additional months for complex or numerous requests (we will notify you of any extension).

12.4 Other U.S. State Privacy Rights

Residents of certain U.S. states have additional privacy rights under applicable state laws:

  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Delaware (DPDPA), and other applicable states: You have the right to access, correct, and delete personal data we hold about you; the right to data portability; the right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing significant legal or similarly significant effects; and the right to appeal our response to your privacy request.
  • Nevada (SB 220): Nevada residents may opt out of the sale of personal information by emailing us at privacy@fictionmaker.ai.

To submit a request or appeal, contact us at privacy@fictionmaker.ai with "State Privacy Request" in the subject line. We will respond within the timeframes required by applicable state law (generally 45–60 days). If we deny your request, you have the right to appeal by contacting us at the same email address.

12.5 How to Exercise Your Rights

To exercise any privacy right, you may:

  • Email us at privacy@fictionmaker.ai with the subject line identifying your request type and jurisdiction
  • Use the data management tools available in your account settings
  • Submit a written request to our postal address below

We will verify your identity before processing requests. For most requests, we will require confirmation of the email address associated with your account. For sensitive requests, additional verification may be required. We do not charge a fee for responding to requests unless requests are manifestly unfounded or excessive.

13. International Data Transfers

Gable Digital Solutions, Inc. is based in the United States. Your personal information may be transferred to and processed in the United States and other countries, which may have data protection laws that differ from your home country.

For transfers of personal data from the EU or UK to the United States, we rely on appropriate transfer mechanisms including:

  • The EU–U.S. Data Privacy Framework (DPF) and UK Extension (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTA)
  • Adequacy decisions issued by the European Commission

A copy of our data transfer safeguards is available upon request by emailing privacy@fictionmaker.ai.

14. Do Not Track and Global Privacy Control

We recognize and honor the Global Privacy Control (GPC) signal. If your browser or device sends a GPC opt-out signal, we will treat it as a request to opt out of the sale and sharing of your personal information for cross-context behavioral advertising. We process GPC signals in accordance with applicable law.

We do not currently respond to browser "Do Not Track" (DNT) signals because there is no industry-standard mechanism for DNT compliance.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on this page with a new "Last updated" date and, where required by law or where changes are significant, by sending you an email or prominent in-Service notification. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Gable Digital Solutions, Inc.
Attn: Privacy Team
388 South Main St Ste 440
Akron, OH 44311
United States

Email: privacy@fictionmaker.ai

For EU/UK data protection inquiries specifically, please use the subject line "GDPR Request" or "UK GDPR Request" and include your country of residence.