Last updated · 30 July 2026

Privacy policy.

We are a research workspace, not an advertising company. The short version: your projects belong to you, we don't sell anything to anyone, and we collect the minimum we need to run the service.

The short version

Who is responsible for your data

Writium is an independent project run by a sole proprietor based in Los Angeles, California. Under data-protection law that operator is the “controller” of the data described here, and is the one who answers your requests. Every request reaches a real person through the contact form, which is the fastest route and the one we monitor. If you need our legal or postal details, for example to make a formal data request or to serve a notice, ask through that form and we will provide them.

What we collect

To run the service we need to know a few things about you.

Our analytics are first-party and cookieless: no tracking cookies, no third-party analytics service, and we never store your IP address. Your IP is used in memory to rate-limit abuse and to compute an anonymous visitor id, which is a one-way salted hash of your IP and browser string that changes every day. It cannot be reversed to an IP, and it can't follow you across days or across sites. When you are signed in, an event carries your account id as well, so we can tell your own sessions apart from a stranger's.

Why we're allowed to use it

If you're somewhere the law asks us to name a basis for each use, these are ours.

Where the law requires consent for something, we ask for it first and you can withdraw it at any time.

What we do not do

One honest caveat about “nobody can see your work.” No other user can. But the person who runs Writium holds the database credentials needed to operate it, so they technically can reach stored data, and will if they have to debug a fault or answer a lawful request. They don't read your projects for any other reason.

Who we send data to

To run Writium we send limited data to a few providers. We share only what a feature needs, and each provider handles it under its own terms and privacy policy. These are all the ones we use.

Where your data goes

Every provider above is based in the United States, so your data is processed there, and by their own infrastructure providers wherever those operate. If you are in the UK, the EU, or somewhere else with transfer rules, that is a transfer outside your country. We rely on the transfer terms in each provider's data-processing agreement, which is normally the European Commission's standard contractual clauses or an equivalent approved mechanism, together with the security measures described here. Ask us through the contact form if you want the specifics for a given provider.

How long we keep it

Backups kept by our database provider expire on their own schedule, so a deleted item can briefly survive in a backup before rolling off.

Cookies and browser storage

We use one essential cookie, and only one: the login session, set when you sign in. It is HTTP-only and, in production, Secure, so scripts on the page can't read it. Your browser may show it split across a couple of entries, because a session can be larger than a single cookie is allowed to be. It exists to keep you signed in and nothing else. There are no analytics cookies, no advertising cookies, and no third-party cookies, which is why you never see a consent banner here.

Three small things are stored in your browser rather than in a cookie: your theme choice (kept in local storage until you clear it), a per-tab id used to group the events of one visit, and any utm_ tags from the link you arrived on (both kept in session storage, and both erased when you close the tab). Only the per-tab id and the utm tags are ever sent to us, and only to our own servers.

Your rights

If you live somewhere with strong data laws (the EU, the UK, California, and plenty of other places), you have the rights below. Most people can use them without asking us. We don't charge for any of this, we don't treat you differently for using it, and we answer within 30 days. We may need to confirm you control the account before we act on a request sent by email.

California residents: we do not sell or share personal information as those terms are used in the CCPA, and we haven't in the last 12 months. If you're in the EU or UK and you think we've got something wrong, you can complain to your national data-protection authority, though we'd rather you told us first so we can fix it.

Children

Writium is for users aged 13 and up. It is not directed to children under 13, and we do not knowingly collect data from them. If we learn that an account belongs to a child under 13, we close it and delete the data.

If you are between 13 and 18, you need a parent, guardian, or teacher to agree to our terms for you. If you are a parent or guardian and you believe a child under 13 has given us data, write to us through the contact form and we will delete it. Parents and guardians can also ask to see, correct, or delete data held about their child, and can tell us to stop collecting more.

Keeping it safe

Passwords are salted and hashed, never stored in readable form, and checked against known breach lists when you set one. Everything travels over HTTPS. The login cookie is HTTP-only. Access to your rows is scoped to your account at the database level. Nothing is ever perfectly secure, and we won't pretend otherwise, but that is the standard we hold. If a breach ever puts your data at risk, we will tell you and the relevant authority as quickly as the law requires.

Changes to this policy

When something material changes here, we'll update the date at the top and email everyone with an active account at least 14 days before it takes effect. Smaller clarifications take effect when we post them.

Contact

Privacy questions go to contact form. We answer in plain English.