Astor Press est. MMXXVI Download · Mac
A note on privacy

What we collect.

Written plainly, in eight short articles. The short answer is: very little, and only what the volume needs to write itself.

Effective · 11 July MMXXVI
Articles of the policy i — viii
i.

Who you are, to us.

Astor signs you in with Sign in with Apple. Apple sends us a stable, opaque identifier that does not include your real Apple ID. If you choose to share an email, Apple may give us a relay address ending in privaterelay.appleid.com; we use it only to reach you about your account.

The web press does not ask for an Apple account. It assigns that browser a random pseudonymous identifier and keeps the signed session in a secure, HTTP-only cookie for up to one year. The browser also keeps a separate, signed recovery credential in Astor’s local storage for up to ten years, renewed when you next use the press. It represents only that random identifier, contains no name, email, or essay text, and is sent only to Astor’s same-origin session endpoint. It lets Astor restore the same pseudonymous identity — including ownership of staged plates — if only the cookie is cleared, expires, or must be re-signed.

Clearing Astor’s full site data removes both the browser-local library and that recovery credential; clearing cookies alone does not remove local storage. When a new web identity is created, the server uses a keyed digest of the network address for a short-lived abuse-limit bucket; the raw address is not placed in that Redis key.

If you submit the Fellowship form, we store the name, email, work, and optional first commission you deliberately enter, together with a keyed pseudonymous digest of the submitting network for abuse control. The raw network address and browser user-agent are neither stored with the application nor written to our application logs.

That identifier is what we store as you. We do not read your contacts, calendar, photos, location, or other documents. Lecture Mode may ask for microphone access, but only after you choose Enable voice; you may instead listen or type, and you may mute or end voice at any time.

ii.

What gets sent when you read.

When you ask Astor to write a volume, the topic, your level/voice/length choices, and the chapter text it generates pass through our HTTPS proxy at marginalia-api-three.vercel.app. The proxy fans those requests out to two upstream model providers:

  • Anthropic — for the prose, chapter structure, margin replies, and the teaching plan that turns a finished essay into a private lecture.
  • OpenAI — for the engraved-style plates, the generated lecture narration and word timing, and the live AI professor in Lecture Mode.

Your highlights and the questions you put to the margin pass the same way, along with the surrounding paragraph so the reply can stay in the voice of the page. When you prepare a lecture, the finished essay and up to eight rendered figure plates are sent to Anthropic to compose its objectives, explanations, examples, checks, and visually grounded annotations; each resulting narration beat is sent to OpenAI to produce the professor’s voice and word timing.

Newly prepared web lectures include server-signed bindings for their authored checks. When you submit a written answer for feedback, Astor sends that answer to Anthropic together only with the bound objective, check, rubric, retry hint, and immediately preceding lesson context. The full essay is not included in that feedback request, and the request cannot become an open-ended conversation. Older and hand-authored lecture printings keep the written answer on the page and offer their authored hint and follow-up without claiming adaptive evaluation.

Experimental Lecture Mode voice office hours are disabled on the public production site. In a private testing build that offers voice, enabling it sends microphone audio, a transcript, the full open essay, and the current lecture place to OpenAI over an encrypted realtime connection. Choosing Just listen keeps the microphone off; a typed question or tap on a professor’s mark in that testing build still sends the full essay and current context, but no microphone audio unless you explicitly enable it.

We do not send your name, email, or account identifier to either model provider. OpenAI requests do carry a stable, pseudonymous safety code derived from your account so abuse can be investigated without revealing who you are.

iii.

How long it stays.

Your library lives on your Mac or, when you use the web press, in that browser’s local storage. Before a public-link request is sent, the browser also journals that one exact request in IndexedDB so a timeout or reload can retry the same bytes under the same operation identifier. Because a timed-out request may still commit, the journal remains through unsuccessful or ambiguous replies and is removed only after the link result is safely written back to your shelf, or when you clear Astor’s site data. The web recovery credential described above may remain in local storage for up to ten years unless you clear Astor’s site data. Apart from material you deliberately share or submit through the Fellowship form, we hold the small server-side pseudonymous record needed to sign you back in, plus quota and aggregate cost counters used to prevent abuse. Fellowship applications remain in our application inbox until reviewed or deleted; repeat submissions from the same email are not inserted as new rows.

To make lecture preparation and retries idempotent, short-lived backend caches retain the validated lecture plan — including narration and check text — and per-beat timing and audio-URL metadata for seven to eight days. The source essay is represented in those caches by a cryptographic digest used to bind the request and result; the essay request itself is not kept there as a durable copy.

A written lecture-check answer is processed transiently by Anthropic. Astor does not place the raw answer in cache keys or application logs. A keyed one-way digest of the exact answer and its bounded verdict may remain in a short retry cache for up to one hour, so a timeout or exact retry does not pay for or process the same answer twice.

Generated plates and lecture narration are placed in Vercel Blob storage under long, unlisted public URLs so the reader can display and play them without exposing a provider key. Lecture audio is removed on a rolling schedule within ninety-two days; Astor refreshes an older local lecture before its audio is due for removal. A plate successfully placed in your browser library is receipt-claimed and retained so the illustration does not disappear from that local volume. Uploads that are never claimed by a local volume or public share are removed after about eight days. Deleting a volume from your local shelf removes its local essay and lecture plan immediately, but it does not currently delete that volume’s claimed plate blobs; short-lived retry caches expire on their own schedule.

Choosing Share is different: Astor stores a frozen, full essay snapshot in Neon Postgres, including the public Blob URLs for its plates. Receipt-verified plates claimed by that committed public share are retained; there is currently no automatic deletion of claimed plate blobs when a share is revoked. Anyone who has the link can read the snapshot. Shares do not expire automatically. You can use Revoke link in the local reader’s Share panel; the public endpoint then returns Gone. The database keeps the soft-revoked snapshot and revocation timestamp, and deleting the local volume by itself does not revoke a link.

Anthropic and OpenAI process prompts, generated content, and — when you enable it — lecture audio under their API terms and retention policies. We do not use your prompts, reading, or conversations to train our own model. See:

iv.

Things we don't do.

  • No advertising SDKs, client analytics SDKs, or cross-site advertising profiles. Astor does not load third-party analytics JavaScript anywhere on astor.press; this keeps the origin that holds a browser-local library and recovery credential free of analytics code. Our hosting and API providers still process the ordinary request metadata needed to deliver and protect the service, as described above.
  • No advertising identifiers (IDFA, IDFV). Astor does not request them and does not link them.
  • No selling of personal information. There is no buyer to sell to and never will be.
  • No reading of your other documents. Astor never asks the system for files outside the volumes it wrote.
  • No training on your reading. Your prompts and highlights are not used to improve any model.
v.

Your rights, in plain.

You can ask us, by writing to yask@astor.press, to:

  • Show you everything we hold about your account.
  • Correct anything that looks wrong.
  • Delete your account and the server-side record entirely. We will do this within fourteen days and confirm by email.

If you use the web press and ask us to delete its pseudonymous record, clear Astor’s site data as well. Otherwise the recovery credential left in that browser can recreate the same pseudonymous record when you next use the press.

If you are in the EU, UK, or California, the rights afforded by GDPR, the UK GDPR, and the CCPA apply to your data. We treat every reader as if those rights applied, regardless of where they read.

vi.

Readers under thirteen.

Astor is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has registered an account, write to us and we will delete the record.

vii.

If this changes.

If the policy materially changes — if we ever begin collecting something we don't collect today — we will say so on this page and, for changes that affect existing accounts, by email before they take effect. The effective date at the top of this page reflects the current version.

viii.

Write to us.

Editor Yask Srivastava
Letters yask@astor.press — response within one business day
House Astor Press — an atelier for the patient reader
Questions or corrections? Write to the editor.