Privacy Policy
Last updated: July 29, 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
WriteGeist.app, c/o Marco Bugno, Poststrasse 1, 5613 Hilfikon, Switzerland
Email: contact@writegeist.app
If you have any questions about data protection or wish to exercise your rights, you can contact us at any time using the contact details above.
2. Overview of Processing
WriteGeist is a browser-based SaaS platform for book authors. This privacy policy informs you about the nature, scope, and purpose of the processing of personal data in connection with the use of our platform.
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, email address, or usage data.
3. Legal Framework (revDSG and GDPR)
WriteGeist is operated by a provider based in Switzerland. The processing of personal data is therefore primarily subject to the Swiss Federal Act on Data Protection (revDSG / nFADP).
Because the Platform also serves users in the European Economic Area (EEA), the processing of personal data of those users is additionally subject to the EU General Data Protection Regulation (GDPR) by virtue of its extraterritorial scope (Art. 3 GDPR).
The data subject rights described in this policy are available to you under both the revDSG and the GDPR. Where this policy refers to the GDPR, the corresponding provisions of the revDSG apply mutatis mutandis.
4. Categories of Data Processed
When using WriteGeist, we process the following categories of personal data:
- Account data: email address, display name, avatar, bio (during registration and profile management).
- Authentication data: hashed passwords (email/password login) or OAuth identities (Google login).
- Project content: chapter texts (as Tiptap JSON), chapter snapshots, comments (including guest name), project metadata (genre, target audience, style notes, book metadata).
- Worldbuilding data: characters, locations, timeline events, whiteboard content (Excalidraw).
- Usage data: writing sessions (writing_sessions), credit transactions (credit_transactions), subscription status.
- Device/browser data: local storage of offline drafts (in localStorage), AI API keys (your own BYOK keys), editor preferences (font, zoom, text width).
Note: Your own AI API keys (BYOK) are stored exclusively in your browser's localStorage and are never sent to our server or logged by us.
5. Purposes of Processing
- Platform provision: storage and syncing of your projects, chapters, and worldbuilding data.
- Authentication & account management: registration, login, profile management, subscription management.
- Payment processing: subscription billing via Stripe (we do not store payment data – see Section 6).
- AI features (hosted Geist): text generation, improvement, analysis via Google Gemini API.
- Spell check: LanguageTool (self-hosted on Hetzner).
- Export features: generation of DOCX, EPUB, and PDF files from your manuscripts.
- Abuse prevention & security: detecting and preventing violations of our Terms of Service.
- Communication: transactional emails (e.g., password reset, payment confirmations).
6. Legal Bases
The processing of your personal data is based on the following legal bases of the GDPR:
- Art. 6(1)(b) GDPR (Contract performance): processing is necessary for the performance of the user contract with you (platform provision, storage of your content, export features).
- Art. 6(1)(f) GDPR (Legitimate interest): our legitimate interest lies in the security and stability of the platform, abuse prevention, and improvement of our services.
- Art. 6(1)(a) GDPR (Consent): if you have given us consent to process certain data (e.g., optional AI features), processing is based on this consent.
- Art. 6(1)(c) GDPR (Legal obligation): to fulfill statutory retention and accountability obligations (e.g., commercial retention periods for payment data).
7. Processors and Third-Party Services
In connection with the operation of the platform, we work with the following service providers, who act as processors (Art. 28 GDPR) or independent controllers:
Where data is transferred to third countries (particularly the USA), this is done on the basis of EU Standard Contractual Clauses (SCC) or an adequacy decision (e.g., EU-US Data Privacy Framework).
8. AI Usage Details
WriteGeist offers two types of AI usage, which differ from a data protection perspective.
7.1 Hosted Geist (Writer / Author / Publisher Tiers)
When using a paid tier, you can use the integrated Geist AI. Your request – consisting of the text you selected (or chapter) as well as the project's styleguide context (genre, target audience, time period, narrative perspective, writing style notes) and the current chapter's POV character – is sent to the Google Gemini API for inference.
We use a Google Gemini API key tied to an active Cloud Billing account. Google classifies this as its "Paid Services" tier. Under the Gemini API Additional Terms of Service (effective March 2026):
- Google does not use your prompts (including associated system instructions, cached content, and uploaded files) or responses to improve its products or train its models.
- Processing occurs in accordance with the Data Processing Addendum (Google as a data processor).
- Google logs prompts and responses for a limited period solely for detecting and preventing violations of the Prohibited Use Policy (abuse monitoring). This data may be transiently cached in any country where Google or its agents maintain facilities.
Users in the European Union, the European Economic Area, Switzerland, or the United Kingdom automatically receive paid-tier data protection treatment from Google, even if they would otherwise be on a free quota.
7.2 BYOK – Bring Your Own Key (Hobby Tier)
On the Hobby (free) tier, no Geist credits are available. However, you can enter your own API keys for OpenAI, Anthropic, Google, Groq, or DeepSeek in your settings. These keys are stored exclusively in your browser's localStorage (key: wortgeist_ai_v3_settings).
When you invoke an AI feature, your browser sends the key together with your prompt to our server (/api/ai/generate). Our server forwards the request to the third-party provider you selected. Your API key is held in server memory only for the duration of the request, is not persisted to disk or database, and is not logged.
WriteGeist is not responsible for the data processing by the third-party provider in BYOK mode. The privacy policy of the respective provider (OpenAI, Anthropic, Google, Groq, DeepSeek) applies. You should check whether your tier (free vs. paid) affects how your data is used for training purposes.
7.3 No Automatic Transmission
Manuscript content is never sent to AI providers automatically or in the background. AI calls occur only through your explicit action: you select text (or refer to a chapter) and click an AI action (Improve, Summarize, Translate, Continue, Synonyms, Extract Characters, send a chat message) or start a speech synthesis (TTS) or image generation. Context (styleguide, POV) is only transmitted if required for the selected action.
9. Retention and Deletion
We store your personal data only as long as necessary for the respective processing purposes or as required by statutory retention periods.
Chapter Snapshots (Version History):
- Automatic snapshots: Hobby tier = 7 days, Writer = 30 days, Author/Publisher = 365 days. After expiry, they are automatically deleted.
- Manual snapshots: Unlimited retention, capped at 50 per chapter.
Project deletion: Deleted projects are soft-deleted (deleted_at column) and permanently removed from the database after 30 days.
Account deletion: You can delete your account at any time via the account settings. Your personal data will be deleted within 30 days, unless statutory retention obligations conflict (e.g., commercial retention of payment data: 6–10 years).
Local data: Data stored in your browser's localStorage (offline drafts, AI settings) remains there until you actively delete it or your browser removes it. We have no access to this locally stored data.
10. Your Rights
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15 GDPR): you have the right to request information about the personal data we process.
- Right to rectification (Art. 16 GDPR): you have the right to have inaccurate data corrected.
- Right to erasure (Art. 17 GDPR): you have the right to request the deletion of your data, unless statutory retention obligations conflict.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR): you have the right to receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR): you have the right to object to the processing of your data.
- Right to withdraw consent (Art. 7(3) GDPR): you can withdraw consent at any time with effect for the future.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you have the right to file a complaint with the competent data protection authority.
To exercise your rights, please contact us using the contact details provided in the "Controller" section.
11. Security Measures
We take appropriate technical and organizational measures to protect your personal data:
- SSL/TLS encryption for all data transmission.
- Row-Level Security (RLS) in Supabase: data is isolated per tenant.
- Password hashing (bcrypt) for email/password authentication.
- Server-side session management with httpOnly cookies.
- Regular security updates and dependency audits (npm audit, Dependabot).
12. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy as needed to reflect changes in the legal situation or changes to the platform. The current version is available at /privacy. We will notify you of material changes by email or by a notice on the platform.
13. Contact
If you have any questions, suggestions, or complaints about data protection, you can contact us at any time (contact details at the top).
