WriteGeist

Privacy Policy

Last updated: July 29, 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

WriteGeist.app, c/o Marco Bugno, Poststrasse 1, 5613 Hilfikon, Switzerland

Email: contact@writegeist.app

If you have any questions about data protection or wish to exercise your rights, you can contact us at any time using the contact details above.

2. Overview of Processing

WriteGeist is a browser-based SaaS platform for book authors. This privacy policy informs you about the nature, scope, and purpose of the processing of personal data in connection with the use of our platform.

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, email address, or usage data.

4. Categories of Data Processed

When using WriteGeist, we process the following categories of personal data:

  • Account data: email address, display name, avatar, bio (during registration and profile management).
  • Authentication data: hashed passwords (email/password login) or OAuth identities (Google login).
  • Project content: chapter texts (as Tiptap JSON), chapter snapshots, comments (including guest name), project metadata (genre, target audience, style notes, book metadata).
  • Worldbuilding data: characters, locations, timeline events, whiteboard content (Excalidraw).
  • Usage data: writing sessions (writing_sessions), credit transactions (credit_transactions), subscription status.
  • Device/browser data: local storage of offline drafts (in localStorage), AI API keys (your own BYOK keys), editor preferences (font, zoom, text width).

Note: Your own AI API keys (BYOK) are stored exclusively in your browser's localStorage and are never sent to our server or logged by us.

5. Purposes of Processing

  • Platform provision: storage and syncing of your projects, chapters, and worldbuilding data.
  • Authentication & account management: registration, login, profile management, subscription management.
  • Payment processing: subscription billing via Stripe (we do not store payment data – see Section 6).
  • AI features (hosted Geist): text generation, improvement, analysis via Google Gemini API.
  • Spell check: LanguageTool (self-hosted on Hetzner).
  • Export features: generation of DOCX, EPUB, and PDF files from your manuscripts.
  • Abuse prevention & security: detecting and preventing violations of our Terms of Service.
  • Communication: transactional emails (e.g., password reset, payment confirmations).

7. Processors and Third-Party Services

In connection with the operation of the platform, we work with the following service providers, who act as processors (Art. 28 GDPR) or independent controllers:

ServiceProviderPurposeLocationDPA/Safeguards
Hosting & InfrastructureHetzner Online GmbHServer hosting of the platformGermany (EU)EU Standard Contractual Clauses
Database & AuthSupabase (Supabase Inc.)PostgreSQL database, authentication, Storage for whiteboard assetsUSA / EU (Multi-Region)DPA in place, SCC
Payment ProcessingStripe (Stripe Inc.)Subscription payments, invoicingUSAPCI-DSS Level 1, DPA, SCC
Google OAuthGoogle LLCSocial Login (Sign in with Google)USADPA, SCC
Google Gemini API (Geist AI)Google LLCHosted AI features (paid tiers only)USA / EUDPA (Google as processor), Paid Services – no training use
ElevenLabsElevenLabs Inc.Text-to-Speech (TTS) for character voicesUSADPA in place
LanguageToolSelf-hosted (Hetzner)Spell and grammar checkingGermany (EU)No data shared with third parties
Cloudflare R2Cloudflare Inc.Image storage (character/location images)Global (Edge)DPA in place, SCC

Where data is transferred to third countries (particularly the USA), this is done on the basis of EU Standard Contractual Clauses (SCC) or an adequacy decision (e.g., EU-US Data Privacy Framework).

8. AI Usage Details

WriteGeist offers two types of AI usage, which differ from a data protection perspective.

7.1 Hosted Geist (Writer / Author / Publisher Tiers)

When using a paid tier, you can use the integrated Geist AI. Your request – consisting of the text you selected (or chapter) as well as the project's styleguide context (genre, target audience, time period, narrative perspective, writing style notes) and the current chapter's POV character – is sent to the Google Gemini API for inference.

We use a Google Gemini API key tied to an active Cloud Billing account. Google classifies this as its "Paid Services" tier. Under the Gemini API Additional Terms of Service (effective March 2026):

  • Google does not use your prompts (including associated system instructions, cached content, and uploaded files) or responses to improve its products or train its models.
  • Processing occurs in accordance with the Data Processing Addendum (Google as a data processor).
  • Google logs prompts and responses for a limited period solely for detecting and preventing violations of the Prohibited Use Policy (abuse monitoring). This data may be transiently cached in any country where Google or its agents maintain facilities.

Users in the European Union, the European Economic Area, Switzerland, or the United Kingdom automatically receive paid-tier data protection treatment from Google, even if they would otherwise be on a free quota.

7.2 BYOK – Bring Your Own Key (Hobby Tier)

On the Hobby (free) tier, no Geist credits are available. However, you can enter your own API keys for OpenAI, Anthropic, Google, Groq, or DeepSeek in your settings. These keys are stored exclusively in your browser's localStorage (key: wortgeist_ai_v3_settings).

When you invoke an AI feature, your browser sends the key together with your prompt to our server (/api/ai/generate). Our server forwards the request to the third-party provider you selected. Your API key is held in server memory only for the duration of the request, is not persisted to disk or database, and is not logged.

WriteGeist is not responsible for the data processing by the third-party provider in BYOK mode. The privacy policy of the respective provider (OpenAI, Anthropic, Google, Groq, DeepSeek) applies. You should check whether your tier (free vs. paid) affects how your data is used for training purposes.

7.3 No Automatic Transmission

Manuscript content is never sent to AI providers automatically or in the background. AI calls occur only through your explicit action: you select text (or refer to a chapter) and click an AI action (Improve, Summarize, Translate, Continue, Synonyms, Extract Characters, send a chat message) or start a speech synthesis (TTS) or image generation. Context (styleguide, POV) is only transmitted if required for the selected action.

9. Retention and Deletion

We store your personal data only as long as necessary for the respective processing purposes or as required by statutory retention periods.

Chapter Snapshots (Version History):

  • Automatic snapshots: Hobby tier = 7 days, Writer = 30 days, Author/Publisher = 365 days. After expiry, they are automatically deleted.
  • Manual snapshots: Unlimited retention, capped at 50 per chapter.

Project deletion: Deleted projects are soft-deleted (deleted_at column) and permanently removed from the database after 30 days.

Account deletion: You can delete your account at any time via the account settings. Your personal data will be deleted within 30 days, unless statutory retention obligations conflict (e.g., commercial retention of payment data: 6–10 years).

Local data: Data stored in your browser's localStorage (offline drafts, AI settings) remains there until you actively delete it or your browser removes it. We have no access to this locally stored data.

10. Your Rights

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR): you have the right to request information about the personal data we process.
  • Right to rectification (Art. 16 GDPR): you have the right to have inaccurate data corrected.
  • Right to erasure (Art. 17 GDPR): you have the right to request the deletion of your data, unless statutory retention obligations conflict.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR): you have the right to receive your data in a machine-readable format.
  • Right to object (Art. 21 GDPR): you have the right to object to the processing of your data.
  • Right to withdraw consent (Art. 7(3) GDPR): you can withdraw consent at any time with effect for the future.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you have the right to file a complaint with the competent data protection authority.

To exercise your rights, please contact us using the contact details provided in the "Controller" section.

11. Security Measures

We take appropriate technical and organizational measures to protect your personal data:

  • SSL/TLS encryption for all data transmission.
  • Row-Level Security (RLS) in Supabase: data is isolated per tenant.
  • Password hashing (bcrypt) for email/password authentication.
  • Server-side session management with httpOnly cookies.
  • Regular security updates and dependency audits (npm audit, Dependabot).

12. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy as needed to reflect changes in the legal situation or changes to the platform. The current version is available at /privacy. We will notify you of material changes by email or by a notice on the platform.

13. Contact

If you have any questions, suggestions, or complaints about data protection, you can contact us at any time (contact details at the top).