Legal
Effective September 9, 2026
This Privacy Policy explains how Subhead ("Subhead", "we", "us", or "our") collects, uses, discloses, and protects information when you visit subhead.org or use the Subhead writing community and related services (the "Service"). It applies to members, people invited to become members, and people whose personal information a member submits to the Service, including people named in Forum posts.
1. Who we are and how to contact us
Subhead is the controller of the personal information described in this policy and operates an invitation-only online community for writers. Questions, rights requests, content-review requests, and data protection complaints may be sent toprivacy@subhead.org. You do not need to be a member to contact us or exercise a right.
2. Information we collect
We may collect the following categories of information:
- Account information: name, email address, authentication records, account status, and the member who invited you.
- Invitation-recipient information: an invited person's email address, the inviter's identity, the personal note supplied by the inviter, delivery and expiry status, and related security records. We receive this information from the inviting member before the recipient becomes a member.
- Profile information: avatar, short name, pronouns, biography, location, timezone, languages, writing and reading genres, reading preferences, availability, and books you choose to list.
- Content and activity: manuscript metadata, workshop posts, submission materials, forum posts, comments, feedback, reactions, reading requests, commitments, writing-group activity, notifications, and sharing links you submit.
- Information about people who are not members: names, professional roles or affiliations, experiences and factual claims attributed to them, opinions about them, replies, supporting context, and moderation or rights-request records.
- Communications: support requests, personal invitation notes, and other messages you send through or about the Service.
- Technical information: IP address, browser and device information, request timestamps, security events, and diagnostic logs generated when you use the Service.
- Local browser information: interface preferences and draft responses stored locally in your browser.
3. Google Drive data
Subhead does not operate a Google Drive connection or file picker. If you choose to share a Google Drive file, you paste an HTTPS sharing link that you obtained from Google Drive.
- Subhead does not request Google OAuth permissions or receive a Google access token.
- Subhead does not download, copy, or store the selected file's contents.
- A pasted link can be stored with the public post or submission material where you choose to use it. A manuscript source link and private handoff carry the link only inside their encrypted packets.
- You control access to the underlying file through its Google Drive sharing settings. Removing a link from Subhead does not delete the file from Google Drive.
A file name and sharing link you post remain part of that public post or submission material until you remove the attachment, withdraw the content where that control is available, or request deletion.
4. Dropbox data
Subhead does not operate a Dropbox connection or chooser. If you choose to share a Dropbox file, you paste an HTTPS sharing link. Subhead does not copy or store the Dropbox file itself. A public post or submission can retain the pasted link; a manuscript source link and private handoff carry it only inside encrypted packets. You control access through Dropbox sharing settings.
5. Where information comes from and our lawful bases
We receive information directly from members and visitors, automatically from their use of the Service, from a member who sends an invitation, and from members who write about a named person in the Forum. We may also receive operational information from service providers.
We rely on the following lawful bases where UK or EU data protection law applies:
- Contract: to create and operate a member account and provide features a member requests under our Terms.
- Legitimate interests: to secure and administer the Service, prevent abuse, moderate content, preserve discussion integrity, administer an invitation requested by a member, and provide a forum in which writers can exchange attributed, firsthand professional experiences. These interests are balanced against the rights and reasonable expectations of members, invitees, and named people.
- Legal obligation: to comply with applicable law, respond to valid legal requests, and handle data protection rights and complaints.
- Consent: where we ask for consent for an optional technology or use, including non-essential analytics cookies where consent is required. Consent can be withdrawn at any time without affecting earlier lawful processing.
6. How we use information
We use information to:
- provide, maintain, secure, and improve the Service;
- authenticate members and manage invitations and profiles;
- display content to the audiences selected or described when it is posted;
- operate workshops, submission discussions, forums, writing groups, beta reads, notifications, and related features;
- send transactional emails, including sign-in links and invitations;
- respond to support, privacy, safety, and moderation requests;
- detect misuse, investigate incidents, enforce our Terms, and comply with law; and
- where enabled and lawfully permitted, analyze service reliability and aggregate usage without using Google user data for unrelated purposes.
7. Visibility and sharing within Subhead
Your name, avatar, biography, and other profile information you choose to provide may be visible to other members. Workshop, Perfect Pitch, and Forum content is shared with the Subhead community as indicated in the relevant interface. Writing-group and beta-reading material is limited to the relevant participants where the Service describes it as private. Replies, quotations, reactions, and contributor information may be shown alongside the content to which they relate.
A Google Drive or Dropbox link can be opened by anyone who receives it if its provider permissions allow that access. Review those permissions before posting a link.
8. People who are not members
A member may name an agent, editor, service provider, or other person in a Forum post. The member is the source of that information. Subhead processes the person's name, professional context, and the attributed contribution so members can exchange firsthand, factual information and so Subhead can moderate that exchange. We rely on the legitimate interests described in section 5 and limit visibility to the audience stated by the Service.
If you are named or identifiable in Subhead content, you may ask for access to the personal information about you, correction of an inaccurate factual statement, restriction while a dispute is reviewed, a response to be attached or otherwise made available, or deletion of personal information. Send the relevant name and, if known, the post URL toprivacy@subhead.org. No Subhead account is required. We will assess the request against applicable law and the rights of members, may temporarily restrict the content during review, and will explain the outcome.
Where UK or EU data protection law requires direct notice, we will provide it within the applicable period unless a documented exemption applies. If direct notice would involve a disproportionate effort, we will document that assessment and take appropriate measures to protect the person's rights. This policy is also the public notice for personal information members provide about other people.
9. People invited to Subhead
A member who invites you gives Subhead your email address and may add a note explaining how they know you and what you write. We use that information to send and administer the requested invitation, prevent abuse, and maintain an invitation record. We do not use an invitee's address for unrelated marketing. The invitation link expires after 7 days, although the invitation record may remain visible to the inviter for invitation administration and security.
If you did not expect the invitation, want to know its source, object to further invitations, or want the invitation information deleted, emailprivacy@subhead.org. We may keep the minimum information needed to record an objection, prevent repeated invitations, investigate abuse, or comply with law.
10. When we disclose information
We may disclose information:
- to other members and participants according to the visibility of the feature you use;
- to service providers that supply hosting, database, content delivery, email, storage, security, and operational support under appropriate obligations;
- when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or enforce agreements;
- in connection with a merger, financing, reorganization, or transfer of the Service, subject to appropriate safeguards; or
- with your direction or consent.
We do not sell personal information and do not use personal information for third-party targeted advertising.
11. Cookies, analytics, and local storage
Subhead uses essential session cookies to keep members signed in and protect authenticated requests. We may also use browser storage or cookies for interface preferences, sidebar state, drafts, and security features. We do not use these technologies for third-party advertising.
Subhead uses one optional analytics provider: Google Analytics 4, loaded through the Google tag and operated by Google. We use it for a single purpose — to see which parts of Subhead are used, so we can decide what to build and what to retire. We do not use it for advertising, and the advertising categories of Google’s consent settings are refused permanently rather than left to your choice.
What is collected: public page addresses, scroll depth, and clicks on links leaving the site, together with the approximate location, device, and browser that Google derives from the request. We do not measure authenticated pages or send the contents of manuscripts, critiques, notes, or messages. We do not send your name or email address.
Analytics event records are retained by Google for 14 months from collection, after which they are deleted automatically; aggregate reporting totals persist beyond that period.
Analytics are off until you allow them. Google’s consent settings default to refused for every visitor, so nothing is stored or measured before you choose, and declining changes nothing about how Subhead works. Your choice is kept in your browser’s local storage for six months and can be changed here or under Settings › Privacy; withdrawing takes effect immediately and does not affect processing that was lawful beforehand.
Analytics choices
These choices are about what stays private.
Help us see which parts get used
Public pages only. Your work, notes, and groups are never included.
Staying signed in, remembering your preferences and keeping your drafts safe need a little storage on this device, so those cannot be switched off. The privacy policy sets out what each one is for.
12. Retention and deletion
Single-use sign-in links expire after 15 minutes. A member session expires after 30 days without renewal and cannot continue beyond 90 days without a new sign-in. Emailed invitation links expire after 7 days; shareable community invitation links remain active until revoked. Expiry prevents further use of a link or session; related records may be retained where needed for security, abuse prevention, invitation administration, or legal compliance.
We retain account information while an account is active. We retain contributions and reading records while they remain part of the Service and afterwards only where needed to preserve the integrity of other people's contributions, resolve a dispute, establish or defend legal claims, comply with law, or protect the community. Operational logs are retained according to their security and diagnostic purpose and are deleted or de-identified when no longer needed. Backups are overwritten according to the applicable backup cycle and are not used to restore content that has been deleted from active systems unless required for disaster recovery or law.
You may remove or withdraw content where the Service provides that control. You may also request access, correction, deletion, or account closure by emailingprivacy@subhead.org. We may retain information where required by law or needed for security, fraud prevention, or the rights of other members.
13. Security and encryption
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections, access controls, and protected session tokens. No system is completely secure, and we cannot guarantee absolute security.
A manuscript source link saved for a work is encrypted and signed in the member's browser before it reaches Subhead. Current source-link records and backups made from them contain only the encrypted signed packet; Subhead staff and infrastructure cannot decrypt the provider URL. The member's browser pins the signing key after setup and rejects a changed key or stale signed revision. The member's browser decrypts the link locally to display or edit it and to prepare an authorized manuscript handoff. First setup and a newly restored browser establish that pin by trust on first use, so this is not an active-server identity-verification system. This protection does not apply to other private content unless the relevant feature explicitly says it is end-to-end encrypted.
Private Query Ledger details are also encrypted and signed in the member's browser. This includes the member-to-agent relationship, submission materials and routes, private URLs, notes, nudge notes, rejection language and referrals. Subhead retains the operational project and pitch references, dates, lifecycle and response states, nudge dates, and a random private-record identifier so it can run the Ledger without reading those private details. Agent profiles belong to a shared canonical directory and are not encrypted. The browser decrypts the private Ledger locally, and Subhead staff and infrastructure cannot decrypt its encrypted packet.
The migrations cannot erase source links or earlier Query Ledger details from database backups, write-ahead logs, or service logs created before encryption. We must expire, rotate, or delete those historical copies under our operational retention process before treating the historical backup estate as sanitized.
14. International transfers
Subhead and its service providers may process information in countries other than the one where you live, including the United States. For transfers covered by UK or EU data protection law, we rely on an applicable adequacy regulation or decision where available. Where adequacy does not apply, we use applicable contractual safeguards, which may include the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with any required transfer assessment. You may request information about the safeguard applicable to your information by contacting us.
15. Your rights and complaints
Whether or not you are a member, and depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, withdraw consent, or complain to a data protection authority. To exercise a right or make a data protection complaint, contact us atprivacy@subhead.org. We may need to verify your identity before completing a request. We will respond to rights requests without undue delay and normally within one month. We will acknowledge a data protection complaint within 30 days, investigate it appropriately, keep you informed, and communicate the outcome.
Right to object: You may object to processing based on our legitimate interests, including processing of information that identifies you in a Forum contribution or invitation. Email us with enough information to identify the processing. We will stop unless applicable law permits us to demonstrate compelling legitimate grounds or the processing is needed for legal claims.
If you are in the United Kingdom and remain dissatisfied after contacting us, you may complain to the Information Commissioner's Office atico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You may also contact the supervisory authority where you live or work, or where an alleged infringement occurred.
16. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us.
17. Changes to this policy
We may update this Privacy Policy as the Service or law changes. We will post the updated version here, change the effective date, and provide additional notice when a change is material.