FOLD: STORIES TOGETHER
Privacy policy
Your story, your choices.
Effective September 12, 2026. Fold: Stories Together and foldandpass.com are operated by Gregory Joseph Shipley. Contact support@foldandpass.com about privacy, access, corrections, or deletion.
What Fold stores
- Your account: username, internal account ID, creation date, passkey public credentials, hashed recovery codes, and, if you choose password sign-in, a password hash and verified email address. We do not receive your fingerprint, face scan, device unlock code, or passkey private key.
- Your games: room membership, invitations, settings, starting prompts, saved drafts, contributions, turn history, publication choices, emoji awards, blocks, and reports. We use these to run the game, restore progress, and prevent abuse.
- Devices and security: session identifiers and timestamps, a basic device/browser label, request-limit counters, and notification endpoints or device tokens when you opt in. Our hosting services necessarily receive network information such as IP addresses and basic request diagnostics. Fold’s application logs exclude passwords, session tokens and manuscript text.
- Support: messages and contact information you choose to send us. Reports are shared with the operator for investigation.
Who can read a story?
Rooms require an invitation. The server limits which paragraph each player can see during play; blurring is also a visual effect. After a reveal, participants can read the completed private manuscript. Room members see usernames and room/story information. The service is encrypted in transit, but it is not end-to-end encrypted: authorized service operators can access stored content when needed to operate the service or investigate abuse.
Publishing is optional and requires every participant’s consent. A completed story is reviewed by AI or a person before it appears on the public shelf. Anyone can then read the approved story, including its title, prompt, paragraphs and usernames. Any contributor can withdraw it. Other people may have saved or shared copies that Fold cannot recall.
Service providers and optional AI
We do not sell personal information, serve advertisements, use advertising identifiers, or track you across other companies’ apps and websites. We do not include a third-party behavioral analytics SDK.
- Render hosts the application and PostgreSQL database in the United States, including operational logs and restricted backups.
- Resend delivers account verification, recovery and security email. It receives the recipient address and message needed for delivery.
- Apple’s Push Notification service, or your browser’s push provider, receives a device token/endpoint and a short notification when you enable alerts. Alert payloads exclude story titles, paragraphs, usernames and room invitation codes. You can turn alerts off in Account or device settings.
- AI is optional. Currently, Anthropic supplies starting-prompt suggestions. Before sending, Fold asks for permission and identifies the provider. For starting-prompt suggestions, only the optional inspiration you entered and our generation instructions are sent; account details, gameplay paragraphs and handoff fragments are not included. Cancel to avoid sharing, or use local sample ideas. The provider may retain submitted inspiration and generated suggestions under its API privacy and safety policies. Avoid entering personal information in inspiration.
- Optional AI publication review: each writer separately chooses whether Anthropic may review the completed public submission. Only after reveal and every writer’s agreement do we send its complete title, starting prompt, paragraphs and writer usernames to Anthropic. No account IDs, email addresses, session credentials, unsent drafts or other private stories are sent. Clear submissions may publish automatically; flagged, uncertain or failed reviews stay private for Fold’s operator. Without everyone’s permission, the story stays private and is not submitted for AI or routine human publication review. Existing publication consent does not imply AI consent. You can withdraw publication before review; information already sent cannot be recalled from the provider. Anthropic’s API retention and safety policies apply to submitted text and results.
- Support mail is forwarded by Porkbun to the operator’s Google email inbox. These providers process messages for routing and delivery. Apple separately processes TestFlight installation, diagnostic and feedback information under its own policies.
We use service providers for these stated purposes and require them to protect personal data through their applicable service terms and data-processing safeguards. Information may be processed outside your country. We may disclose information when legally required, to investigate abuse or protect users, or with your permission. We do not use your manuscripts to train our own AI model.
Storage on your device
The website uses necessary sign-in cookies. The iPhone app stores session credentials in the device Keychain. Local storage keeps your theme choice; device storage can keep an unsent draft for reconnecting. No private story or authentication response is cached by our service worker. Sign-out and account deletion clear drafts from the device performing the action. A connected device using a deleted session is instructed to clear its drafts; an offline device or an expired session may require you to clear its app/browser data yourself.
Retention and deletion
Accounts, memberships and contributions remain while the account and stories are in use. Sessions expire after 30 days or seven days of inactivity. Inactive recovery drafts are removed after seven days, while the current unfinished turn’s draft can remain until it is finished or deleted. AI request counters are kept for up to 30 days. Expired sign-in/email challenges are regularly removed. Reports and detailed moderation results are kept for up to 90 days; the publication’s review status remains with its record; an active suspension record remains until the account is deleted or the suspension is lifted.
Delete your account in Account → Privacy & safety → Delete account. Verify your identity if asked, enter your username, and confirm. No support email is required. This immediately removes the account, sign-in methods, email, sessions, notification registrations, drafts and your contributed paragraphs from the active database. Public editions you helped write are removed. Remaining turns are passed. Other writers’ paragraphs remain in private rooms; hosting transfers to another member or an empty room is deleted. Your authored titles and prompts are cleared; older stories with unknown authorship may also have these fields cleared.
Restricted database backups can temporarily retain deleted data for their recovery window (up to seven days under our hosting backup configuration). They are not used for ordinary access. Independently saved copies and service-provider security or legally required records may follow their own retention rules. We retain only an irreversible hash of a deleted session token until that session’s original expiry (no more than 30 days) to help other devices clear local drafts; it cannot be used to sign in. Support email may remain while your request or a related follow-up is being handled; contact us to request removal of correspondence.
Your choices
You can use passkeys without supplying an email, opt out of notifications, skip AI, keep stories private, withdraw publication, block writers, and delete your account. Public reading does not require signing in. You can request a copy or correction of your personal data at our support address; we may verify ownership before disclosing data.
Children and updates
Fold is not intended for children under 13. If you believe a child has supplied personal information, contact us so we can remove it. We will update this page when our practices change and provide an in-app notice or other appropriate notice for material changes.