Legal
Privacy Policy
Last updated July 6, 2026
Overview
Write to Stick is an AI word processor: the AI drafts, you edit, and you can invoke the AI on any passage. This policy describes what data the service actually handles, where it goes, and why. It is written to match how the product works, not as boilerplate.
Questions or requests about your data can be sent to hello@writetostick.com.
What we collect when you sign in
Signing in with Google gives us your email address and your Google account’s stable identifier. We store these in our database (hosted on Supabase) alongside your credit balance and lifetime spend and top-up totals. This record exists for one reason: to identify your account and meter usage-based billing. New accounts are seeded with a small free credit balance tied to this record.
Legacy users who joined with an email invite code are stored the same way, keyed by the invite code and the email address it was issued to. During the legacy signup flow, a short-lived verification token linked to your email is stored and expires after 24 hours.
We do not collect names, profile photos, contacts, or anything else from your Google account beyond email and the account identifier.
Your documents stay on your device
Documents you write, your context library, voice profiles, edit history, and preferences are stored locally in your browser (IndexedDB). They are not uploaded to or stored on our servers, and they do not sync across devices. If you clear your browser data, they are gone — we cannot recover them, because we never had them. You can export documents at any time as Markdown or Word files.
The two exceptions are the ones you trigger yourself: invoking an AI operation (described below) and linking or saving a document to Google Docs (also below).
AI processing (Anthropic)
This is the core data flow, so we want to say it plainly: when you invoke an AI operation — drafting, editing a selection, analysis, document chat, voice emulation — the relevant document content, your instruction, and any context items you have enabled are sent through our server to Anthropic (the maker of Claude) for processing. Our server relays this content in transit and does not store it.
Anthropic processes this data under its API terms and, by default, does not train its models on data submitted through the API.
If you approve a web search during an AI operation (the service always asks first), the search query derived from your request is sent to Anthropic’s web search tool. If you add a URL as reference material, our server fetches that page’s content on your behalf and passes it into the AI operation; it is not stored.
Google Docs access (optional)
Google Docs features are entirely optional and only activate when you use them (importing a doc, linking a doc for sync, or saving to Google Drive). When you do, the app asks Google for two permissions: “drive.file”, which lets it read and write only the specific files you pick or that the app creates, and “drive.readonly”, which is used solely so Google’s file picker can display thumbnails and previews of your files while you choose one.
Outside of rendering that picker, the app reads and writes only the documents you explicitly select. Linked documents live in your own Google Drive under your own account — they are never copied to our servers. Your document content flows directly between your browser and Google’s APIs. The Google access token is cached in your browser’s local storage and expires automatically.
Payments (Stripe)
Credit top-ups are processed by Stripe. Your card details go directly to Stripe and never touch or get stored on our systems. After a successful payment, Stripe notifies our server, which records the payment session identifier (to prevent double-crediting) and updates your credit balance.
Email (Resend)
We send transactional email only — currently, the verification email in the legacy invite-code signup flow — via Resend. There is no marketing list and no newsletter.
Hosting and operational logs (Vercel)
The service runs on Vercel. Like any web service, our server writes operational logs: your account key, the type of AI operation, token counts, computed cost, and errors. These logs do not include your document content. If you submit in-app feedback, that feedback is written to these logs. Logs are used for debugging, billing verification, and abuse prevention.
Fonts are served from Google Fonts, which means your browser makes a request to Google’s servers (disclosing your IP address to Google) when the page loads.
What we don’t do
We do not sell your data. We do not share it with third parties beyond the processors named above. We do not serve ads. We do not use tracking cookies or third-party analytics. We do not store your documents on our servers.
Your rights and data deletion
Your documents and local data: delete them at any time by clearing your browser’s site data — they exist nowhere else.
Your account record (email, Google identifier, credit balance, spend history): email hello@writetostick.com from the address on the account and we will delete it. Note that deleting the account record forfeits any remaining credit balance, and operational logs age out of our hosting provider’s retention window on their own schedule.
Documents in your Google Drive are yours to manage in Google Drive; revoking the app’s access can be done from your Google account’s security settings at any time.
Changes to this policy
When the product’s data practices change, this page changes with them and the “Last updated” date at the top is bumped. Continued use of the service after changes constitutes acceptance.