Privacy policy
Wrifo keeps a record of how documents are written, so this policy has to be specific about what that record contains. This page says what we collect, what we deliberately do not, who can see your work, and how to take it with you or delete it.
The short version
- We store your account details, the documents written in your workspaces, and the record of how they were written.
- We never record which keys you press. The record keeps the kind of key - a letter, a space, a backspace - and its timing, never the character itself.
- Wrifo sees nothing outside its own documents: not your files, your screen, your other applications or your browsing.
- Your work is visible to the people in your workspace, and to anyone you give a share link to. Nobody else.
- You can export your documents, and you can delete your account and the work it owns.
Who this is from
Wrifo provides the writing application at app.wrifo.com, the Windows desktop application, and this website. If you write in a workspace belonging to your employer or client, they decide who is in that workspace and what happens to the work; we hold it on their behalf.
Questions, requests and complaints: [email protected].
What we collect
Your account
- Your name and email address.
- Your password, held by our sign-in provider. We never see or store it, and it never reaches our servers in readable form.
- Which account and workspaces you belong to, and your role in each.
- Invitations you send or accept, and the subscription your account is on.
Your work
- Documents: their text, titles, briefs, labels, dates, images and comments.
- Who a document is assigned to, its status, and the notes written when it moves through review.
- Version history and a log of workspace changes: who invited, assigned, approved, deleted.
The record of the writing
This is the part that makes Wrifo what it is, so it is worth stating exactly:
- Every change to a document, with the time our server received it, so the writing can be replayed.
- Where a change came from: typing, the toolbar, undo, or text moved from elsewhere in the same document.
- Key classes and their timing - that a letter was typed, that a backspace was pressed, and when - and never which letter. The words themselves are in the document, which you wrote; the keystroke record holds no text.
- Attempts to paste text in from outside, which are refused and counted.
- When the writer had the document open and was working in it, so time spent can include reading it back. This is recorded only for the person assigned to write the document, only while the window is in front of them, and only while it is being used.
Technical information
- Our servers log requests, including IP addresses, to run the service, find faults and stop abuse such as repeated sign-in attempts.
- The desktop application writes a diagnostic log to a temporary file on your own computer. It stays there and is not sent to us unless you send it to us yourself.
- On this website only, Google Analytics tells us how many people visit and which pages they read. It sets cookies and records an approximate location from the IP address. The application itself has no analytics.
- If you use the enquiry form, we receive your name, email address and message by email. It is not stored in the application.
What we do not collect
- The characters you type, as explained above.
- Anything outside Wrifo: no files, no screenshots, no other windows, no browsing history, no camera or microphone.
- Any tracking of writers across other websites, and no advertising of any kind.
In the desktop application the editor window is given no network access of its own. Everything it sends goes through the application, to our server and nowhere else.
Why we use it
- To run the service: storing documents, syncing them, showing them to the right people.
- To show how work was written: the replay, the work summary and the integrity read are the product, and they are built from the record described above.
- To tell people what needs their attention: notifications inside the application when work is assigned, submitted, approved or commented on, and emails for invitations and account matters such as confirming your address or resetting your password.
- To keep accounts secure: rate limits, refusing suspicious sign-ins, and the audit log.
- To support and improve the product: answering your questions, fixing faults, and the website analytics.
Where the GDPR applies, we rely on the contract with you to provide the service, our legitimate interest in keeping it secure and working, your consent for website analytics, and legal obligations where they apply.
Who can see your work
- People in your workspace. Everyone in a workspace can read the documents in it. What differs is who can change what: writers write the documents assigned to them, editors and admins run the work.
- Anyone you give a share link to. Publishing a document creates a link that needs no account. It carries that document and its record, and nothing else from your workspace. You can revoke it at any time, but a copy somebody already made cannot be recalled.
- Us, only as far as running the service requires: maintaining the servers, restoring backups, and looking into a problem you have reported. We do not read customers' documents otherwise, and we never sell anything.
- Authorities, if we are legally required to, and only to the extent required.
Services we use
| Provider | What it does | What it sees |
|---|---|---|
| Hetzner | Our servers and database, in Germany | Everything the application stores |
| Supabase | Sign-in and passwords | Your name, email address and password |
| Bunny.net | This website, the download, and images in documents | Images you add to documents; website requests |
| Resend | Sends our emails | The address and content of those emails |
| Google Analytics | Visitor statistics for this website only | Website visits; never the application |
| Microsoft | Distributes the app if you install it from the Microsoft Store | Your Store installation, under Microsoft's own privacy policy |
Spelling and grammar checking runs on a server we host ourselves. The text being checked stays on our own infrastructure and is not sent to any third-party service.
Our servers and database are in Germany. Some of the providers above operate internationally and may process data outside your country; where the GDPR applies, such transfers are covered by the safeguards those providers offer, including standard contractual clauses.
How long we keep it
- Your work: for as long as the workspace exists. Deleting a document puts it in the bin, and deleting it from there removes it and its record permanently.
- Your account: until you delete it.
- Server logs: a short period, for diagnosis and security.
- Backups: deleted data can persist in backups for a limited time before those are rotated out.
What deleting your account does
Deleting your account deletes the workspaces you own, and with them their documents and the whole record of how they were written. That cannot be undone. Your ability to sign in is removed and your sign-in identity is deleted from our sign-in provider.
One thing stays on purpose: if you wrote in somebody else's workspace, that work stays theirs, and your name stays on it. The record of who wrote what is the product, and rewriting authorship on the way out would falsify it for everyone else. Your entry is marked closed so it is clear you have left. If you want your name removed from work in a workspace you do not own, ask the people who run that workspace, or write to us.
Your rights
Depending on where you live you have some or all of these rights: to know what we hold about you, to get a copy of it, to have it corrected, to have it deleted, to restrict or object to how we use it, and to complain to your data protection authority.
- A copy of your work: every document can be downloaded as a Word file from the application.
- Deleting your work: delete documents from the workspace, or your account from Settings.
- Anything else: write to [email protected]. We answer within 30 days.
If you write in a workspace run by your employer or a client, some of these requests are theirs to decide rather than ours. We will tell you and, where we can, pass the request on.
Keeping it safe
- Everything between you and our servers travels encrypted over HTTPS.
- Passwords are handled by our sign-in provider and never reach our servers in readable form.
- On Windows, the desktop application keeps your saved sign-in in the Windows Credential Manager rather than in a file.
- Access to a document is decided by workspace membership on every request, not by whether somebody knows an address.
- Access to production systems is limited to those who need it to run the service.
No service can promise perfect security. If a breach affects your data we will tell you and, where required, the relevant authority.
Cookies and local storage
- The application stores your sign-in and a few preferences in your browser's local storage, or in the Windows Credential Manager on the desktop. These are needed for it to work and are not used for tracking.
- This website sets Google Analytics cookies to count visits. Blocking them costs you nothing here.
- There are no advertising or cross-site tracking cookies anywhere in Wrifo.
Children
Wrifo is made for work and is not intended for children under 16. We do not knowingly collect their data; if you believe a child has an account, write to us and we will remove it.
Changes to this policy
When this policy changes we update the date at the top, and for anything significant we will say so in the application or by email before it takes effect.