AuthorAZ
Legal

How to Keep Your Manuscript Private in the Age of AI

What the terms of service actually say, which tools receive your file, and the six decisions that keep an unpublished manuscript yours.

Alexandru Filip
Aug 10, 2026
9 min read

Most advice about manuscript privacy is either a shrug or a panic. The shrug says nothing you do matters, because everything is scraped eventually. The panic says unplug entirely and write in a cave.

Neither is useful, and both skip the part that is actually within your control: which services receive a copy of your file, and what you agreed to when they did.

That is a short list of decisions. Here is how to work through it.


First, separate the two problems

Authors tend to blur two very different exposures, which makes the whole subject feel unmanageable. Pulled apart, each is tractable.

Problem one: your published books. Already out in the world, already in libraries and retailers and shadow libraries, already — in many cases — in training corpora that were assembled years ago. This is a legal and political problem. It is being fought in courts and legislatures, and it is very largely not something you solve at your desk. Registering copyright and joining an authors' organization are the meaningful moves here.

Problem two: the work that hasn't been published yet. The draft, the notes, the half-finished sequel, the outline for the series you haven't announced. This one is entirely different, because it has not left your hands yet. Every copy of it that exists on someone else's server got there because you put it there.

This article is about problem two. It is the smaller problem and the one that is still open.


The survey data is unusually consistent

It is worth knowing how widely this concern is shared, if only because the isolation is part of what makes authors quiet about it.

  • A December 2023 Authors Guild survey of more than 2,400 writers found 96% believed consent should be required, and authors paid, if their work is used to build an AI system.
  • A 2025 study from the University of Cambridge's Minderoo Centre for Technology and Democracy found that 59% of surveyed published novelists believed their work had already been used to train large language models without permission, 51% expected AI to replace their work entirely, and 93% said they would opt out of AI training if given the choice.

That last figure is the interesting one. Ninety-three percent would opt out. Almost none of them have been offered the option.

Which leads to the practical reframing: nobody is going to grant authors a global opt-out this quarter. But there is a much less satisfying, much more available version — don't put the manuscript somewhere that reads it.


The six decisions

1. Know which of your tools receive the file

Make an actual list. Not a mental one. For most working authors the list is longer than expected, and it includes tools they'd never think of as "AI tools":

  • The word processor (does it sync? to where?)
  • Cloud storage, including the automatic backup you set up once in 2019 and forgot
  • The notes app that holds your outline
  • Grammar and editing tools — these receive your full text by definition
  • Beta reader and critique platforms
  • The formatting tool
  • Anything with a browser extension that reads page contents
  • Email, if you send drafts to yourself or to editors

Being on that list is not an accusation. A grammar checker cannot work without receiving your sentences. The point of the list is that you can't make decisions about exposure you haven't inventoried.

2. Read one paragraph of the terms — the same paragraph, every time

This is the highest-value ten minutes available to an author this year, and almost nobody spends it. You are not reading the whole document. You are reading one section, usually titled Your Content, User Content, or License.

You're looking for what you grant, and how far it reaches. The words that matter:

worldwide · royalty-free · sublicensable · transferable · to reproduce, modify, adapt, publish, and create derivative works · to improve our services

Most of that is boilerplate a service genuinely needs in order to display your file back to you on another device. A license to "reproduce" your document is what makes the document appear on your screen.

The parts to actually weigh are narrower:

  • sublicensable — they can pass the right on to someone else
  • derivative works — the right extends past storage into making new things from it
  • to improve our services / develop our products — the phrasing that most often covers model training
  • and whatever the document says explicitly about training or machine learning

Then check two more things: whether any opt-out is on by default or off, and whether your setting survives a change of terms. Opt-outs that reset on the next policy update are common and are the reason a decision you made in 2024 may not still be in force.

This is not legal advice. Read your own terms, or ask someone qualified. But read them.

3. Decide per tool, not globally

The answer is not "no cloud services." That is unworkable and, for most authors, unnecessary. The answer is a deliberate split.

A workable division for most people:

Keep localCloud is usually fine
The unpublished draftPublished blurbs and descriptions
Unreleased series outlines and notesBuy links and retailer URLs
Anything under a pen name you haven't linked publiclyCover files already on retail pages
Manuscripts under submission or on exclusive termsYour public author bio

The test is simple: if this leaked tomorrow, would anything be lost? Your published blurb leaking costs you nothing. Book four of an unannounced series is a different category.

4. Turn off the sync you didn't choose

Most exposure is not a decision anyone made. It's a default. Worth checking once, properly:

  • Your OS-level cloud backup, which may be sweeping your entire Documents folder
  • The word processor's autosave-to-cloud, often on by default on mobile
  • Phone photo backup — which captures screenshots of pages, cover proofs and contracts
  • Any "smart features," "connected experiences," or "cloud-enhanced" toggle
  • Browser extensions with read-page permissions, on the sites where you draft

None of this requires new software. It requires forty-five minutes with the settings screens you have been ignoring.

5. Fix your backups so privacy doesn't cost you the manuscript

Here is the failure mode nobody warns about: an author becomes privacy-conscious, pulls everything off the cloud, and eleven months later loses a laptop with the only copy of a novel on it.

Privacy and durability are not opposed, but you have to deliberately solve both. The minimum viable arrangement:

  • Three copies, on two different kinds of media, with one off-site.
  • The off-site copy can be encrypted before it ever leaves your machine. Encrypted-at-rest by the provider is not the same thing as encrypted by you — if the provider holds the key, the provider can read the file. If you hold the key, they cannot.
  • Test a restore once. An untested backup is a rumour.

A physically off-site encrypted drive at a relative's house is unglamorous and completely sufficient.

6. Watch what your marketing tools leave behind

This one is newer, and most authors haven't hit it yet.

Image files can carry content-provenance metadata describing which tools touched them. Major platforms now read that metadata and apply "made with AI" labels based on what they find. Cloud design tools often write it automatically — sometimes for edits that have nothing to do with generative AI at all, like a background removal or a routine export.

The result is an ordinary, human-made graphic arriving with a machine-made label on it. Once that label is attached, readers scrutinise the post and reach can suffer. For an author whose entire credibility rests on having written the book themselves, being algorithmically filed under "made with AI" is not a small annoyance.

You can strip metadata manually before every upload. Or you can make the asset somewhere that never adds it.


What this does and doesn't buy you

Worth being precise, because overclaiming here is its own kind of dishonesty.

It does: stop new copies of unpublished work from accumulating on servers you don't control. Reduce the number of terms-of-service documents that govern your draft from eleven to two. Give you an answer when an agent or editor asks how you handle confidentiality.

It doesn't: retroactively remove anything from a corpus assembled in 2021. Protect your published books, which are a legal question, not a storage question. Stop someone from scanning a physical copy. Substitute for registering copyright.

The honest summary is that this is the part you control, done properly — not a solution to the industry-level problem. A policy fix would be better. It is also not arriving this quarter.


Where AuthorAZ fits

AuthorAZ is made by the author of this site, so treat this section accordingly.

Most of the six decisions above need no new software at all. Decisions 1, 2, 4 and 5 are inventory, reading, settings and discipline.

Where a tool helps is the part where an author's operational material — the metadata, covers, quotes, review excerpts, buy links, pen-name assets and manuscript snapshots — is currently scattered across cloud documents and note apps because there was nowhere else to put it. AuthorAZ is a local-first vault for exactly that: everything stays on the device, with encrypted export/import for your own backups, no account, no cloud, no AI processing. It's free for one book and one pen name, and a one-time purchase for the full vault.

It is not a writing app, and it is not trying to be. Write wherever you write.


Sources

  • Authors Guild, Survey of 2,470+ writers on AI and consent, December 2023.
  • University of Cambridge, Minderoo Centre for Technology and Democracy, survey of published novelists, 2025.

Facts verified 9 August 2026. Terms of service and platform policies change; re-read your own before relying on any summary, including this one.

Key Takeaways

Separate the published-backlist problem from the unpublished-draft problem; only one is still in your hands.

Read one section of every tool’s terms: Your Content, or License.

Fix backups before going local, or you trade an exposure risk for a data-loss risk.

Free · No account · 79 lessons

Read the free Publishing Course

The whole Publishing Manual, free and online: checklists, templates and decision trees for every stage, with platform figures verified against the Publishing Database.