Privacy policy.
We are a research workspace, not an advertising company. The short version: your projects belong to you, we don't sell anything to anyone, and we collect the minimum we need to run the service.
The short version
- Your projects, sources, and notes are yours. We do not sell them, share them, or train models on them.
- Your work is stored in your account and scoped to it. No other user can reach it.
- Passwords are stored only as a salted hash, so nobody here can read yours. The login cookie is HTTP-only, so page scripts can't read it either.
- No advertising trackers, no tracking cookies, and no data shared with ad networks. We collect our own privacy-friendly usage analytics (see below) to improve Writium, and nothing else.
- Running the app means sending small, specific pieces of your work to a few processors. Exactly which pieces, and to whom, is listed below in plain terms.
Who is responsible for your data
Writium is an independent project run by a sole proprietor based in Los Angeles, California. Under data-protection law that operator is the “controller” of the data described here, and is the one who answers your requests. Every request reaches a real person through the contact form, which is the fastest route and the one we monitor. If you need our legal or postal details, for example to make a formal data request or to serve a notice, ask through that form and we will provide them.
What we collect
To run the service we need to know a few things about you.
- Account info. Your email and a hashed password; or, if you choose “Continue with Google,” the basic profile Google shares (your name, email address, and profile picture) in place of a password.
- Project data. The projects, theses, claims, sources, source notes, highlights, and documents you create. Scoped to your account.
- Plan and usage counters. Your plan, your search-credit counters per period, and any extra credits you've bought, so plan limits work.
- Billing info. If you subscribe, we store the customer and subscription identifiers our payment processor gives us, your plan, its status, and when the period renews. We never see or store your card number.
- Usage analytics. We record product events on our own servers. Each event carries: what happened (a pageview, a search, a project created, an error), the page path, where you arrived from (referrer and any utm_ tags in the link), your device type, operating system, browser, screen and window size, language, timezone, approximate location (country, region, and city) derived by our host from the connection, your plan, and a per-tab session id. Some events carry extra detail: a search event records the search tier, how long it took, how many results came back, and your search query, stored as typed and truncated to 200 characters. Error events record a truncated error message.
- Feedback. If you use the in-app feedback button we keep what you sent: the rating, the category, your note, and which page you were on, plus your account id and email if you were signed in.
- Support correspondence. If you write to us through the contact form, we keep the topic, the name and email you give us, and your message, so we can pick up where we left off.
Our analytics are first-party and cookieless: no tracking cookies, no third-party analytics service, and we never store your IP address. Your IP is used in memory to rate-limit abuse and to compute an anonymous visitor id, which is a one-way salted hash of your IP and browser string that changes every day. It cannot be reversed to an IP, and it can't follow you across days or across sites. When you are signed in, an event carries your account id as well, so we can tell your own sessions apart from a stranger's.
Why we're allowed to use it
If you're somewhere the law asks us to name a basis for each use, these are ours.
- To provide the service you asked for (your account, projects, searches, billing): performing our contract with you.
- To keep it working and honest (analytics, error reports, rate limits, preventing abuse of free-plan limits, security): our legitimate interest in running and improving a service people can rely on, balanced against the fact that we keep this data minimal and don't use it to profile or advertise to you.
- To answer you (feedback and support messages): our legitimate interest in supporting our users, and your consent when you choose to write to us.
- To meet legal duties (tax and accounting records for payments): compliance with a legal obligation.
Where the law requires consent for something, we ask for it first and you can withdraw it at any time.
What we do not do
- We do not sell your data: not to advertisers, not to AI companies, not to anyone.
- We do not use your projects to train AI models. We do not permit our providers to train on your work either, and we rely on the API terms they publish rather than on any special arrangement.
- We do not embed third-party trackers (no Google Analytics, no Facebook pixel, no Hotjar). Our usage analytics run on our own servers and are never shared with or sold to anyone.
- We do not build advertising or behavioural profiles, and we don't make automated decisions about you that have a legal or similarly significant effect.
- We do not require a .edu email. We do not verify that you are a student. The free tier is yours either way.
One honest caveat about “nobody can see your work.” No other user can. But the person who runs Writium holds the database credentials needed to operate it, so they technically can reach stored data, and will if they have to debug a fault or answer a lawful request. They don't read your projects for any other reason.
Who we send data to
To run Writium we send limited data to a few providers. We share only what a feature needs, and each provider handles it under its own terms and privacy policy. These are all the ones we use.
- Hosting (Vercel, US). Serves the site and app. Sees your IP address, browser, and the requests you make, and derives the approximate location we described above.
- Database and sign-in (Supabase, US). Stores your account, projects, sources, documents, analytics events, feedback, and contact messages, and handles password hashing and login sessions.
- Web search (Exa, US). Receives your search query so it can return real web results.
- AI vetting (Anthropic, US). Receives the search results, your query, and a small slice of project context: your essay title, your thesis, and the titles of sources you have already saved. It then picks and classifies the best results. The body of your document and your private notes are not sent.
- Embeddings (OpenAI, US): not currently enabled. Writium contains a semantic recall feature that would search your own saved sources by meaning. It is switched off, and no data has been sent to OpenAI. We are listing it so the disclosure is already here if we turn it on: it would receive the text of each saved source (title, author, your notes on that source, and any highlights you kept) plus your recall query. Your document body would not be sent. We will update this page before enabling it.
- Payments (Stripe, US). Handles checkout, cards, and subscriptions. Card details go to Stripe directly and never touch our servers. We receive back the identifiers and status described above.
- Email (Resend, US). Delivers account and notification email, so it processes your email address and the contents of the message. Contact-form and feedback submissions, and a note that a new account was created (with the email address), are emailed to the operator this way.
- Sign-in with Google (optional). If you use “Continue with Google,” Google verifies who you are and sends us your basic profile (name, email, and profile picture) to create or match your account. We never receive your Google password.
- Breached-password check (Have I Been Pwned). When you set a password we check it against known breach lists, using a method that sends only the first five characters of a hash of it. The password itself never leaves our server, and the service can't tell what you chose or who you are.
Where your data goes
Every provider above is based in the United States, so your data is processed there, and by their own infrastructure providers wherever those operate. If you are in the UK, the EU, or somewhere else with transfer rules, that is a transfer outside your country. We rely on the transfer terms in each provider's data-processing agreement, which is normally the European Commission's standard contractual clauses or an equivalent approved mechanism, together with the security measures described here. Ask us through the contact form if you want the specifics for a given provider.
How long we keep it
- Account and project data: for as long as your account exists. When you delete the account it goes immediately, apart from the three narrow exceptions listed under your rights below.
- Usage analytics: up to 24 months, then deleted or reduced to aggregate counts. On account deletion these events stay but are unlinked from you at once.
- Feedback and contact messages: up to 24 months after the conversation ends. Feedback is anonymized immediately if you delete your account.
- Billing records: kept for as long as tax and accounting law requires, which is typically six to seven years. Stripe keeps its own records under its own policy.
- The free-plan abuse record: the one-way hash of your email plus your usage counters is kept indefinitely, because that is the only way it can do its job. It contains no email address and no name.
Backups kept by our database provider expire on their own schedule, so a deleted item can briefly survive in a backup before rolling off.
Cookies and browser storage
We use one essential cookie, and only one: the login session, set when you sign in. It is HTTP-only and, in production, Secure, so scripts on the page can't read it. Your browser may show it split across a couple of entries, because a session can be larger than a single cookie is allowed to be. It exists to keep you signed in and nothing else. There are no analytics cookies, no advertising cookies, and no third-party cookies, which is why you never see a consent banner here.
Three small things are stored in your browser rather than in a cookie: your theme choice (kept in local storage until you clear it), a per-tab id used to group the events of one visit, and any utm_ tags from the link you arrived on (both kept in session storage, and both erased when you close the tab). Only the per-tab id and the utm tags are ever sent to us, and only to our own servers.
Your rights
If you live somewhere with strong data laws (the EU, the UK, California, and plenty of other places), you have the rights below. Most people can use them without asking us. We don't charge for any of this, we don't treat you differently for using it, and we answer within 30 days. We may need to confirm you control the account before we act on a request sent by email.
- See what we hold. Ask via the contact form.
- Take it with you. Settings, then Data, then Export gives you a single JSON file with your account email, your plan, and every project in full: sources, notes, claims, and documents. For a copy of the other categories on this page, such as your analytics events or support messages, ask through the contact form.
- Correct it. Project data is editable in the app. For anything else, write to us and we'll fix it.
- Object or restrict. You can object to the uses we base on legitimate interests, and ask us to pause processing while a dispute is sorted out.
- Withdraw consent for anything we asked consent for, at any time. That doesn't undo what was already done.
- Delete it. Settings, then Data, then Delete account. The deletion is immediate and permanent: your account, projects, sources, and documents are erased, and any subscription is cancelled at that moment. Three narrow things are kept, none of which identify you: usage analytics in anonymized form (no longer linked to any account), feedback you submitted with the email and account link stripped, and, to prevent abuse of free-plan limits, a one-way hashed record of your usage counters and cycle start date that cannot be turned back into your email. If you sign up again with the same email, your plan allowances resume where they left off rather than resetting.
California residents: we do not sell or share personal information as those terms are used in the CCPA, and we haven't in the last 12 months. If you're in the EU or UK and you think we've got something wrong, you can complain to your national data-protection authority, though we'd rather you told us first so we can fix it.
Children
Writium is for users aged 13 and up. It is not directed to children under 13, and we do not knowingly collect data from them. If we learn that an account belongs to a child under 13, we close it and delete the data.
If you are between 13 and 18, you need a parent, guardian, or teacher to agree to our terms for you. If you are a parent or guardian and you believe a child under 13 has given us data, write to us through the contact form and we will delete it. Parents and guardians can also ask to see, correct, or delete data held about their child, and can tell us to stop collecting more.
Keeping it safe
Passwords are salted and hashed, never stored in readable form, and checked against known breach lists when you set one. Everything travels over HTTPS. The login cookie is HTTP-only. Access to your rows is scoped to your account at the database level. Nothing is ever perfectly secure, and we won't pretend otherwise, but that is the standard we hold. If a breach ever puts your data at risk, we will tell you and the relevant authority as quickly as the law requires.
Changes to this policy
When something material changes here, we'll update the date at the top and email everyone with an active account at least 14 days before it takes effect. Smaller clarifications take effect when we post them.
Contact
Privacy questions go to contact form. We answer in plain English.