Privacy

Your writing stays yours.

Five Rooms is built so that the people who make it can't read what you write. This notice says what the apps keep, what leaves your device and when, what the web version's servers can and can't see, and what you can do about it.

Draft: not yet reviewed. This notice hasn't been reviewed yet and may change before it's final.

Last updated 11 October 2026

Who we are

Five Rooms, the apps and fiverooms.app, is made and run by Mark Perry in Australia ("we"). We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can reach us at privacy@fiverooms.app.

The apps keep your work on your devices

Your projects live in the app's own library on your Mac, iPad or iPhone, and in daily backups beside it. The apps have no account, no analytics and no tracking, and send nothing about you to us. Features that use Apple's on-device models (a one-line summary of where you left off, the style checks' judgement of your own rules) run on the device and send nothing anywhere.

What leaves your device, and only when you choose

  • iCloud. Projects sync between your devices through your own iCloud account, encrypted with a key each project keeps in your Keychain, so Apple stores sealed data. Pen names, your name for bylines and your personal dictionary sync through iCloud too. Checkpoints you share for review go through iCloud sharing to the people you invite.
  • Five Rooms on the web. Only the projects you put on the web go to our servers, encrypted on your device first; the section below says what the servers can see.
  • Storyteller Workbench. If you connect a project to Workbench, each compile sends it a record of the build (the preset, the time and a checksum of the file), never the text.
  • ElevenLabs. If you add your own ElevenLabs key to narrate an audiobook, the text of that book is sent to ElevenLabs to be read, under their terms. Without a key, audiobooks are read by the voices on your device.
  • Assistants you connect. An AI assistant connected to the app through MCP reads what you allow it to and can comment and suggest; it is off until you turn it on in Settings, and what it reads goes to that assistant under its own terms.
  • Web clips and citations. Clipping a web page fetches that page; importing from Zotero talks to Zotero on your own computer.

Five Rooms on the web: end-to-end encrypted

Projects you put on the web are encrypted on your own devices (your browser, Mac, iPad or iPhone) before they're sent, with keys that only your devices hold. Each project has its own key; those keys are themselves locked with a vault key that is opened by your passkey, a device you've paired, or your recovery key. Our servers store only the locked copies.

So our servers never see your text, your titles, your notes, your comments, the names in your story, your project keys, your vault key, your recovery key, or the secret your passkey gives your browser to unlock them.

What the servers can see

  • Your account name, the name you typed when you joined. It's shown in your passkey manager and to the operator.
  • Device names, such as "Chrome on Windows" or the name you gave a Mac, so you can see and sign out your devices.
  • Sizes, counts and timing: how many projects and documents you have, how big each encrypted piece is, and when each was saved or fetched. From these someone could tell roughly how much and when you write, but not what.
  • Passkey records: each passkey's public key and identifier, whether it is synced, and when it was added and last used. There are no passwords.
  • An activity record of sign-ins, devices added and removed, and similar account events, which you can see on your account page.
  • Usage against your account's limits: storage used, projects, reader links and connected agents.
  • Your IP address, which every web request carries. It is used briefly to limit repeated attempts (for example at signing in) and isn't stored with your account.

The honest limit of encryption on the web

In a web browser, the server that stores your encrypted projects also sends the program that holds your keys. If that server, or the hosting account or build process behind it, were ever compromised, it could send a changed program that copies your keys. We reduce that risk with a strict content security policy, no third-party scripts, and deploying only from our own source code. The Mac, iPad and iPhone apps don't have this limit: their program comes from the App Store.

Projects you make readable to agents

If you turn on Agents on the web for a project, you choose to let our server read that project so that an assistant you connect (such as Claude) can work with it. For that project only, the server keeps a copy of its key, locked with a server key, and opens the project in memory while an agent works on it. At rest it stays encrypted. What an agent reads is sent to that agent under its own terms. Turn it off and the server's copy of the key is deleted and the project's key is changed.

Reader links

When you share a checkpoint with beta readers, the reading copy (the manuscript's text only, never notes or research) is encrypted with a key that is part of the link itself, after the "#", which browsers never send to the server. Readers don't have accounts. The server sees how many links you made, when each was opened and active, and how many notes came back and their sizes; the notes themselves are encrypted with the link's key.

Shared projects

When you share a project with a co-writer or a commenter, your device gives them the project's key, locked so only their account can open it. From then on they hold that key, just as your own devices do, and can read everything in the project. Our server sees who shares which project with whom, in what role and when, but not the project or its key. Removing someone changes the project's key.

Who hosts it

Five Rooms on the web runs on Cloudflare (Cloudflare, Inc., of the United States), which hosts the app and stores the encrypted data for us as our service provider and sees the same request information any host does. Data is stored in Cloudflare's Oceania region where the product allows a choice, and may be processed elsewhere as Cloudflare operates.

How long

Your encrypted projects stay until you remove them from the web or delete your account; removed data is cleared within a day. Activity records are kept for 90 days. Deleting your account deletes everything the servers hold for it, at once.

The operator's view

Five Rooms on the web is open by invitation. The operator can see each account's name, when it joined and was last seen, its usage, the invites they made and who used them, and can suspend or resume an account. The operator can't read anyone's projects.

Children

Five Rooms on the web isn't intended for children under 16, and we don't knowingly invite them.

Your choices

  • Access and correction: the apps show you everything they keep; your account page on the web shows your account name, devices, passkeys, activity and usage. Ask us for anything else we hold about you, or to correct it.
  • Export: every project is a package the apps export and import, and Export everything on the web saves every project on the web the same way.
  • Deletion: delete a project, a backup, or your web account, and it's gone from where you deleted it; your other devices keep their own copies until you delete those too.

Changes

If this notice changes in a way that matters, the apps and the web version will say so before the change applies.

Complaints

Write to privacy@fiverooms.app. We'll reply within 30 days. If you're not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).