Privacy policy
Last updated: 12 July 2026
The short version. We do not sell, share, or train AI on your data. We do not store the content of your chats. We do not track you across the web. We collect the minimum we need to run your account and process payments — nothing more.
Who this covers
This policy applies to the WriterPi Chrome extension, the writerpi.com website, and the backend that powers both. It applies whether you use WriterPi for free, on a trial, or on a paid plan.
What we collect
- Email address — so we can sign you in with a one-time code and tell you about your account.
- Plan and usage counters — which plan you are on and how many messages you have used this cycle. Numbers only, never message text.
- Payment records from Paddle or Razorpay — the transaction id, amount, plan, and date of each payment. We need this to honour the plan you paid for and for tax records.
- Anonymous trial counter — a random device id stored in your own browser so the 10-message no-signup trial cannot be repeated forever. Not tied to any real identity.
- Signup and login IPs — kept for account security, so we can spot obvious abuse. Never shared, never used for advertising.
- Aggregated site visits — one anonymous count per day from writerpi.com to draw an internal growth chart. No individual visitor is identified.
What we do NOT store
- The content of your chat messages.
- The AI's replies to you.
- The contents of any page the extension reads on your behalf.
- Images you upload or scan from a page.
Chat content passes through our backend only long enough to get a reply from the AI provider. Once the reply is returned to your browser, the content is discarded. The database keeps a usage row (tokens, credits, model used) for cost accounting — but no message text.
Your data is not used to train AI
We do not use your data to train or fine-tune any AI model. We do not share your data with any AI provider for training purposes. Our AI provider contracts explicitly opt out of training on API traffic.
Third parties we work with
To deliver the service we send necessary data to a small set of processors:
- AI providers (OpenAI, Anthropic) — your messages and any page or image you attach are sent here so they can generate a reply. Data processing is per their published API terms, which prohibit training on API traffic.
- Paddle — global payments. Paddle acts as the merchant of record for international customers. Paddle sees the payment details directly. We only ever receive the transaction id and amount.
- Razorpay — payments for Indian customers, same arrangement.
- Resend — delivers your one-time sign-in code via email.
- Hetzner — our cloud hosting provider, where the backend runs.
We do not share your data with anyone else. We do not sell your data. We do not use it for advertising.
Cookies and local storage
- A single HttpOnly session cookie on writerpi.com (your sign-in JWT, 90-day expiry).
- A few small localStorage values in the extension: your chosen theme, tone, and selected mode.
- A sessionStorage entry that keeps your chat history within the current browser tab — wiped when you close the tab.
No tracking pixels. No analytics scripts. No third-party cookies. No advertising SDKs.
Your rights
Under GDPR (EU), CCPA (California), and India's DPDP Act, you have the right to:
- Access — request a copy of your account data. Email hello@writerpi.com from the address tied to the account.
- Delete — request account deletion. We remove your account and associated usage data within 7 days.
- Correct — ask us to fix any data that is wrong.
- Object — object to specific uses of your data. Since we do not do advertising or profiling, this is rarely relevant, but the right stands.
- Portability — export your payment history from your account page on writerpi.com.
- Withdraw consent — sign out at any time to end your session. Delete the extension to end all local storage.
To exercise any of these, email hello@writerpi.com. We respond within 7 days.
Data retention
- Account records: kept while your account is active, deleted within 7 days of an account deletion request.
- Payment records: kept for 7 years to satisfy Indian tax law requirements.
- Usage counters: reset each billing cycle. No historical usage-per-message data is stored.
- Signup / last-login IPs: kept for 90 days for security review, then discarded.
Data location
The backend runs in Germany (Hetzner). Payment data is processed by Paddle (UK / global) and Razorpay (India). AI requests are processed in the United States (OpenAI, Anthropic). If you are in the EU or India, your data will therefore be transferred outside your country to the extent needed to deliver the service. All transfers use encryption in transit.
Security
Session tokens use HttpOnly, Secure, SameSite=lax cookies. Passwords for the admin surface use constant-time comparison and IP-based lockout after failed attempts. All traffic is over HTTPS. Backend systems are patched regularly.
Children
WriterPi is not intended for users under 13. We do not knowingly collect data from children under 13.
Changes to this policy
If we change the policy in a way that materially affects you, we will email the address on file at least 30 days before the change takes effect. The "Last updated" date at the top always reflects the current version.
Contact
Questions about privacy or data requests: hello@writerpi.com.
Data controller: WriterPi (independent developer, India).