Writely beta
Back to WritelyPrivacy Notice
How the Writely beta collects, uses, stores, shares, and deletes personal data, in plain language.
Last updated: 27 July 2026
Who this notice is for
Writely is an independent, free, non-commercial beta writing project based in Singapore. It is not currently operated by a registered company or ACRA-registered business. This notice uses Singapore's Personal Data Protection Act (PDPA) as its primary privacy framework.
Writely does not currently charge users, display advertising, accept donations, or sell personal data.
Information Writely handles
Google account and authentication information
Google Sign-In is configured with the standard openid, email, and profile scopes. Writely receives and stores your Google account identifier, name, email address, email verification status, and profile-image URL. Better Auth also stores the OAuth tokens and scope information needed to establish and manage your account. New or refreshed OAuth tokens are encrypted before they are stored.
Documents and preferences
Writely stores document titles, writing and supported formatting, writing mode, document version, creation and update times, and save information. It also stores account preferences such as whether the leave-editor reminder is disabled. Theme and interface-language preferences are kept in your browser.
AI usage
Writely stores daily AI token totals and short-lived request-lock information used to enforce the daily allowance and prevent duplicate AI requests. Writely does not store selected AI text, instructions, or AI responses in its own database as separate AI records.
Feedback
If you submit beta feedback, Writely stores the message, your account identifier, and the submission time. Feedback is optional.
Sessions and technical information
Better Auth stores session identifiers, expiry and update times, and may store the IP address and browser user-agent associated with a session. Service providers may also generate necessary request, security, reliability, and error logs containing information such as IP address, browser details, request path, and timestamps. Writely has not found analytics, advertising trackers, an email provider, or an error-monitoring SDK in the repository.
Why Writely uses this information
- To sign you in and keep your account and sessions secure.
- To create, save, synchronize, display, export, and delete writing.
- To recover recent unsaved changes after a failed save or interruption.
- To provide an AI action only when you deliberately request it.
- To enforce product limits and reduce automated or repeated abuse.
- To receive beta feedback, investigate problems, and protect Writely.
- To respond to privacy, correction, deletion, or legal requests.
Browser recovery copies
While you edit, Writely may keep a temporary recovery copy in this browser's local storage. It contains the document identifier, title, writing and formatting, the saved document version, and a timestamp. It stays on the device and browser profile where it was created; it is not a server backup.
A recovery copy is cleared after a confirmed save or deliberate discard. Copies older than 30 days are removed automatically when Writely next performs recovery cleanup. You can clear all Writely recovery copies from Settings & Help, or remove Writely site data through your browser settings.
Selected-text AI and Groq
AI runs only after you deliberately select text and choose an AI action. The server verifies that you own the document before it calls Groq. Writely sends Groq:
- the selected text and its supported formatting;
- the built-in action or custom instruction for that request;
- the selected writing mode;
- system instructions needed to produce and safely format the result; and
- ordinary API metadata generated by the request.
The code does not retrieve or send the rest of the document. It sends only the selected passage, not the document title or account email. Groq returns the generated text and token-usage totals.
Groq states that it always retains usage metadata that does not contain customer inputs or outputs. Groq may temporarily retain inputs and outputs for reliability or abuse investigation under its standard data controls. Groq's documentation says retained customer data is stored in the United States.
Writely intends to use Groq Zero Data Retention, but the repository cannot confirm whether Global ZDR and the Inference API setting are enabled for the production Groq account. Until that setting is manually confirmed, users should assume Groq's standard inference retention rules may apply. See Groq's current data documentation.
An AI response remains temporary unless you choose to insert or accept it. Once inserted, it becomes part of your stored document and is handled like the rest of that document.
Service providers and overseas processing
Writely currently relies on these confirmed providers:
- Google for identity and Google Sign-In.
- Neon for the PostgreSQL database that stores account and document data.
- Groq for selected-text AI processing.
These providers may process personal data outside Singapore. Groq documents United States storage for retained customer data. The production Neon region and the application-hosting provider and region are not confirmed in the repository. They must be confirmed before public beta. More detail is available on the Subprocessors page.
Cookies
Writely uses essential authentication and security cookies so Google Sign-In and account sessions work. Better Auth configures session cookies as HttpOnly and SameSite=Lax, and uses Secure cookies in production. Writely does not currently use advertising or analytics cookies in the repository, so it does not show a non-essential cookie banner or maintain a separate Cookies page.
Security
Writely uses server-side authentication and ownership checks, document and request size limits, AI usage limits, structured-content validation, unsafe-link checks, sanitized AI HTML, encrypted OAuth tokens, restricted authentication cookies, same-origin checks on authenticated API posts, production-safe errors, and browser security headers. Sensitive document and AI request bodies are excluded from application logging.
No online service can promise complete security. If you believe your Writely account or personal data is at risk, contact the privacy email below promptly.
Retention and deletion
Active account information, documents, preferences, feedback, session records, and AI usage totals remain in the live database while needed to operate your account, unless you delete them or ask Writely to do so. There is not currently a separate automatic deletion schedule for feedback or historical daily AI totals.
Deleting a document permanently removes it from the live application database and clears its recovery copy in the current browser. Deleting your account removes the live user record and linked documents, preferences, sessions, connected OAuth-account records, AI usage totals, and feedback through database cascade deletion. It also clears Writely recovery copies in the browser used for deletion.
Provider backup retention and deletion timing are not controlled by this repository and remain to be confirmed. Copies may remain in protected provider backups until those backups expire. See the Data Deletion page for steps and limitations.
Your choices and requests
You can download a JSON copy of your Writely data, delete documents, clear browser recovery copies, and delete your account from Settings & Help. You may also ask to access or correct personal data, or withdraw consent, by emailing code.dreamer666@gmail.com. Writely may ask for reasonable identity verification before disclosing or changing account data.
Withdrawing consent does not affect processing that occurred before the withdrawal. If Writely can no longer use information necessary to authenticate you or store your documents, the practical result may be account deletion or loss of access to those features.
Personal-data incidents
Writely will investigate suspected personal-data incidents, contain the issue, assess affected data and users, and consider whether notification to Singapore's Personal Data Protection Commission and affected individuals is required. Writely will provide notices as soon as practicable when the PDPA requires them.
Privacy contact
Privacy questions, requests, and complaints can be sent to code.dreamer666@gmail.com. The public title “Privacy Contact” is used until the appropriate DPO designation and registration approach are manually confirmed.
Changes to this notice
Writely may update this notice as the beta changes. The updated date will be shown here. Material changes will also be communicated through a prominent notice in Writely before or when they take effect where reasonably possible.