Privacy Policy
Last updated: 18 August 2026
This policy explains what personal data I Wrote It collects, why, and what you can do about it. We have tried to write it in plain language rather than legal padding.
1. Who is responsible
The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], registration number [REGISTRATION NUMBER].
For any privacy question or request, write to hello@iwroteit.org. We answer within 30 days, usually much sooner.
2. What we collect
- Account data — your email address, and a password hash. We never store your password itself.
- Document content — the text of documents you choose to record, stored as a series of timestamped snapshots so that a diff can be produced later.
- Writing-process metadata — timing of edits, session length, pauses, the size and origin of pasted blocks, and the sequence of revisions. This is the substance of the record; without it the Service has no product.
- Billing data — handled by our merchant of record, Paddle. We receive a subscription status and a transaction reference. We never see or store your card details.
- Basic technical data — IP address, browser and device type, and pages visited, used for security and aggregate analytics.
3. What we deliberately do not do
- We do not use your documents to train machine-learning models — ours or anyone else's.
- We do not sell personal data, and we do not share it for advertising or profiling.
- We do not read your documents except where you explicitly ask us to investigate a technical problem, or where we are legally compelled.
- We do not publish anything. A record becomes visible to another person only when you generate a verification link yourself.
4. Why we may process your data (legal bases)
- To perform our contract with you — creating your account, recording your writing, producing reports, taking payment.
- Legitimate interests — keeping the Service secure, preventing abuse and fraud, and understanding aggregate usage so we can improve it.
- Legal obligation — tax, accounting and responses to lawful requests.
- Consent — where we ask for it, such as optional product emails. You can withdraw consent at any time.
5. How long we keep it
- Document snapshots and process metadata — for as long as your account is active, because the record's value is precisely its history. You can delete any individual document at any time, and deletion is permanent.
- After you close your account — deleted within 30 days, except where we must keep transaction records for tax and accounting purposes.
- Technical logs — 90 days.
6. Who we share it with
Only with service providers who need it to run the Service, under contract and on our instructions:
- Paddle.com Market Ltd — merchant of record: payments, invoicing, tax, billing support.
- Hosting and database providers — storage and delivery of the Service.
- Privacy-respecting web analytics — aggregate traffic measurement.
- Email delivery — transactional messages such as password resets.
We may also disclose data where legally required, or to establish or defend legal claims.
7. International transfers
Our providers may process data outside your country. Where data leaves the European Economic Area or the United Kingdom, transfers rely on adequacy decisions or Standard Contractual Clauses.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent. You also have the right to complain to your local data-protection authority.
To exercise any of these, email hello@iwroteit.org. We will not charge you or make the Service worse for asking.
9. Security
Data is encrypted in transit and at rest. Access to production systems is restricted and logged. No system is perfectly secure, and we will not claim otherwise; if a breach affects your data and poses a risk to you, we will notify you and the relevant authority as required by law.
10. Cookies
We use strictly necessary cookies to keep you signed in and to protect against abuse. Analytics is configured to avoid cross-site tracking. We do not run advertising cookies.
11. Children
The Service is not directed at children under 16. If we learn that we hold data from a child under 16 without appropriate consent, we delete it.
12. Changes
If we change this policy in a way that materially affects you, we will notify you by email or in the Service before the change takes effect.