Who we are
Maldric is a fiction writing desk run by Intrepid Developer, operated by Chris Vanderplank in the United Kingdom. For privacy questions, write to chris@intrepid-developer.com. You can use that address to leave the waitlist or ask about your data.
The author desk is a separate host from this marketing site. A waitlist row is not a desk account.
What this site collects (the waitlist)
Registering interest stores your email address, and — if you give them — a name and whether you ticked “I’m writing a series”. We also store a short source tag (this site) and when you joined.
We use that list to write when we have an invite for you. Joining also sends one transactional “you’re on the list” message through AhaSend. It is not a newsletter, not a drip campaign, and not an account. Joining does not create a login and does not reserve a paid plan. Invitations are sent individually when a beta place is available.
The lawful basis is consent. You ask us, on this form, to contact you about a desk invite. A separate, optional tick stores whether you want product news later. We do not send product news today. You can withdraw waitlist consent by emailing chris@intrepid-developer.com — we will delete the waitlist row. The same email twice stays one row. We do not sell waitlist addresses.
Desk accounts (invite-only, separate)
A desk login is an Identity account on the author site, not this marketing site. It is created only with a personal invite. The waitlist does not become that account. Desk accounts hold the name and email you register with, password or passkey details, optional authenticator 2FA, appearance and spelling preferences, account About the author copy, billing status, remaining credits, whether you opted in to product news, when you accepted these terms, and the manuscripts you write.
New accounts Activate by confirming the email through a transactional letter. Until that is done, the library stays closed.
Manuscripts belong to the author. We do not sell drafts. On the desk you can download a local working copy of the live draft whenever you like — during a trial, after it ends, or if a paid plan is paused. That download is not on this site. Pause, cancel, past due, or trial end turns the desk download-only. We do not delete the library.
Authors can send us product feedback from the desk. Those notes are for triage. We do not email them on, and they are not a manuscript.
Beta / ARC readers
On the desk, an author can open a beta / ARC round and add a reader. We store that person’s name and, if the author gives it, their email, plus a hashed invite token and any comments they leave on a snapshot of the book. That is the author’s invite list, not our waitlist, and not a newsletter.
The author can copy a link, and we also send the reader an invite through AhaSend. Revoking a reader or a round stops the token. Readers do not get a Maldric account. We watermark the reader’s EPUB/PDF, not the author’s own files.
Cookies and local storage
This marketing site uses essential cookies only — an anti-forgery cookie so the waitlist form can be posted safely. We do not run advertising, analytics, or social-media trackers here, and we do not drop a marketing cookie when you only read the page. Page-load counts for this site are first-party on our API: path, method, and status, not your email, IP, or user-agent.
The author desk (a different host) uses an Identity sign-in cookie and related security cookies, plus small preference cookies for appearance and spelling. The browser also keeps a short-lived IndexedDB cache of recent chapter edits so a flaky connection does not eat a sentence — that cache is on your machine, and it is not the local working-copy zip. The desk sends a one-session client id in memory for those page counts; it is not stored as a cookie.
Where data is hosted
Maldric is hosted on Railway, in an EU region. Waitlist rows and desk data sit in that EU deployment. Manuscript files, covers, import assets, and export packs are stored in Railway object storage in that same setup. This describes storage on our hosting deployment. Optional AI requests, payments and other processor services are separate, as described below; we do not claim all processing stays in the EU.
Who else processes data
We use a short list of processors. None of them get a licence to sell your book.
- Railway — hosting and storage, EU region, as above. Privacy policy.
- Stripe — card payments, Customer Portal, invoices, and webhooks on the signed-in desk when an author picks a paid plan or credit pack. The waitlist is free and does not take a card. We will not charge you from this page. Stripe holds the card; we keep subscription status and remaining credits. Privacy policy.
- Grok, provided by SpaceXAI (SpaceX’s AI division, formerly xAI) — optional desk tools, listed below. The author writes the book. Suggestions are never applied unless the author accepts them. We do not send the waitlist form through Grok. Privacy policy.
- AhaSend (EU, Netherlands) — transactional mail and optional writing reminders the author controls on Settings: the waitlist acknowledgement, desk email confirmation, password reset, ARC invite, send-to-Kindle of the finished EPUB, a quiet-return letter when a book has had no chapter save, and an opt-in daily writing time. Not a newsletter and not a campaign tool. Writing reminders name a book title only — never the manuscript. Turn them off from the letter or on Settings → Reminders. Open and click tracking stay off. We do not send manuscript bodies by mail. Kindle mail is the finished EPUB to an address the author typed — never the markdown zip. Privacy policy.
- Sentry (EU ingest) — errors, traces, logs, and product metrics for the API, the operator console, and the signed-in author desk. This marketing waitlist site does not load Sentry. It does not receive author manuscripts, chapter or bible request bodies, or emails as telemetry. Privacy policy.
- Google Fonts — only on the signed-in Style page, when you pick or preview a pack typeface from the curated catalogue. The writing desk does not load Google Fonts; it uses cached or uploaded faces, or the system stack. Desk chrome, this marketing site, and the operator console self-host Source Sans 3 and Source Serif 4 (latin and latin-ext) and do not call Google for that. Cached faces for EPUB/PDF are fetched on the server and embedded in the pack. Privacy policy.
When draft text goes to SpaceXAI
These desk features send writing to Grok (SpaceXAI) when you run them. They are optional. Nothing is applied unless you accept it.
- Chat (Talk) — the selected span, or the chapter if there is no selection, plus neighbouring titles and bible summaries.
- Review — a full book pass against the series bible (plot, characters, places, lore) plus pacing and prose.
- Character chat and converse — the character sheet, your voice notes, and short quoted lines from the draft. Chat may update the sheet or Imagine a portrait when you ask; converse stays in-character.
- Timeline chat and suggest — the board, and markdown from a chosen book or chapter, to propose event drafts you still have to accept.
- Ideas chat — the series ideas board. It drafts bible cards when you ask, never a chapter.
- Style talk — the book’s style rules and the passage you ask about. It does not rewrite the manuscript unless you apply a change.
- Import extract — the assembled markdown after an import. That can go to SpaceXAI even if you never used Chat, review, or converse. The original upload file is not sent.
- Book overview cards — character sheets, world, and timeline event proposals from a book you choose. You still accept each card.
Imagine covers send your cover prompt and, if you ground it, the book title, a short synopsis, and bible names. That is jacket art, not chapter bodies.
If you never run those tools, we do not send the draft to SpaceXAI for them.
How long we keep waitlist details
We keep your waitlist email until we have written with an invite, or until you ask us to remove it — whichever comes first. If you later create a desk account, that account is a separate record.
Your rights (UK GDPR)
If you are in the UK, you can ask us what we hold, have it corrected, ask us to delete it, restrict or object to our using it, or ask for a copy in a portable form. Those rights are not absolute — we will say so if a legal reason applies.
To use them, email chris@intrepid-developer.com. You can also complain to the Information Commissioner’s Office (ICO) if you think we have mishandled your data.
Children
Maldric is aimed at adult authors. Do not join the waitlist on behalf of a child if you are not that child’s parent or guardian.
Changes
We may update this policy as the product changes. The date at the top is when this version was last changed. Material changes will be reflected on this page.