01Scope and operator
This policy applies to the Wenmai website, accounts and the AI writing workflow. The data controller and service operator is Wenmai; contact email: wenpath@foxmail.com. We process data on a lawful, legitimate and minimal basis and never sell personal data or user works.
02Account and security data
Registration and login process your email address, verification-code hashes, password hashes and salts, session-token hashes, login and security-verification timestamps, and the IP addresses and rate-limit records necessary to keep the service safe. Verification codes expire within 10 minutes; sessions usually last 30 days. The server never stores plaintext passwords, plaintext verification codes or complete session tokens.
03Works and keys stay on your device by default
Projects, outlines, event packages, character sheets, manuscripts and versions are stored in your current browser by default. The provider, endpoint, model and API key you bring (BYOK) are also stored locally. Keys never enter works, cloud backups, the wish board or runtime logs. Clearing browser site data deletes this local information.
04How model tasks are processed
When you run a task, the Wenmai server temporarily processes the instruction you confirmed, the necessary excerpt of your work, the selected model and output settings, and forwards them to the model provider you chose. Your API key passes through the server only for that single request to reach the provider's endpoint; it is never written to the database or runtime logs.
05Task records keep no plaintext
For delivery, recovery, accounting and debugging, the server records the task type, model role, status, timestamps, token counts, error messages and a request digest — never the plaintext prompt or manuscript. Task results are encrypted with a temporary key generated by your browser for that session, usable for 24 hours to recover from interruptions; the recovery key is not persisted.
06What third-party services receive
Model tasks may be sent to DeepSeek, OpenRouter (which routes to Anthropic, OpenAI and other providers) or any compatible endpoint you configure yourself. Verification emails are sent through our email service provider, which processes the recipient address and message. When you open the third-party sponsorship page, payment and billing information is handled independently by that platform under its own rules.
07Membership and feature requests
The server stores your access expiry, grant records, subscription status and task usage to fulfil the service, reconcile orders and handle exceptions. We never collect payment passwords or card PINs. Feature requests store the title, description and category you submit, for review only; your original text is not published as-is.
08Optional encrypted cloud backup
Cloud backup is uploaded only after you actively enable it in Settings. Works are encrypted inside your browser first; the server stores only the ciphertext plus the backup time, size, device name, revision and project count. The recovery key and API keys are never uploaded. Turning backup off or deleting your account deletes the cloud ciphertext.
09Cookies, local storage and network logs
Login uses strictly necessary security cookies; works, settings, API connections and recovery keys use browser local storage. The server may log access time, request path, IP address, browser type or error information for security, troubleshooting and legal obligations — never for advertising profiles.
10Retention
Accounts, access rights, task usage and billing records are kept while the account exists; verification codes and sessions are cleaned per their validity and security needs; cloud backups are kept until you turn backup off or delete your account; feature requests are kept until processed or no longer necessary. Where law requires longer retention, we retain data for the statutory period and restrict it to that purpose.
11Your data rights
In Settings you can view your account, access and task usage; export or clear local works; delete local API connections; turn cloud backup on or off; and delete your account after password verification. To access, copy, correct, supplement or erase your personal data, or to withdraw non-essential consent, contact us at the email below. Where the GDPR or a similar law applies to you, these requests are handled under that framework.
12Security, minors and updates
We apply access controls, hashing, transport encryption, client-side encryption and log minimization, but no internet service can promise zero risk. Children under 14 (or the minimum digital-consent age in your jurisdiction) should use the service only with a guardian's consent. Material changes to these rules are announced on this page with an updated date and, where significant, by email.