Skip to content

Security and privacy

What actually happens to what you write

Written for the person who has to sign off on a new tool, and for the writer who simply wants to know whether their drafts are safe here. No certifications we have not earned, no wording chosen to be difficult to pin down.

Data handling

How your content is stored and reached

The practices behind the product, described in enough detail to be checked.

Encrypted in transit and at rest

Everything between your browser and Writibot travels over TLS, and your documents, presets and account records are encrypted where they are stored. That applies to backups as well as to the live database.

Access on a need-to-have basis

Internal access is role based, logged, and limited to the smallest group that can do the job. Nobody at Writibot opens your documents to browse them. Support reads a document only when you ask us to look at a specific problem.

Separated workspaces

Each workspace is logically separated, so your projects, presets and templates are only ever reachable by the accounts you have granted access to. Adding somebody to a workspace is an explicit action with a record against it.

Backups with a fixed window

We keep encrypted backups so an outage does not cost you a week of writing. When you delete something it goes from the live service immediately and works its way out of backups within thirty days rather than sitting there indefinitely.

Card details never reach us

Payments are handled by a dedicated payment processor. Writibot stores the plan you are on and enough billing metadata to raise an invoice. We never see or store your full card number.

A short list of sub-processors

Running the service needs a handful of outside providers: cloud hosting, model providers, payment processing, email delivery and product analytics. The categories and what each one receives are set out in the privacy policy.

The important one

Your writing is not training data.

We do not train models on customer content. Your drafts, your prompts, your voice presets and your samples are used to produce the output you asked for, and then they sit in your workspace until you do something with them.

Our model providers are contractually bound not to train on content sent through the service either. If any of that ever changed, it would arrive as a clearly labelled opt-in that starts switched off, announced before it takes effect, and never as a quiet edit to a policy page.

Your controls

Things you can do without asking us

Control that needs a support ticket is not really control. All of this sits in your own settings.

Export everything, any time

Every document leaves as Markdown, HTML, Docx or plain text, and a whole project can be exported in one go. No export queue, no support ticket, no waiting period.

Delete a draft or the lot

Delete a single document, a project, or your entire account from your own settings. Deletion is real deletion, not a hidden archive we keep in case you change your mind.

Decide how long history is kept

Version history is useful until it is a liability. Workspace owners can shorten how long earlier versions are retained, or switch history off for a project entirely.

Revoke review links

Every read-only share link has an expiry you choose, and any link can be revoked immediately. Once revoked it stops working for everyone who has it, including people who already opened it.

Remove access instantly

Workspace owners can change a role or remove somebody in a single action. Access ends with the next request, not at the end of their session.

Opt out of product analytics

Usage analytics help us find where the editor is confusing. If you would rather not be counted, switch it off in your settings and it stops for your account.

Transparency

What we tell you, and when

Commitments are only worth something with a number attached to them.

Security incident

If your data is affected by a breach we will tell you within 72 hours of confirming it, with what we know at that point, and follow up rather than waiting until the picture is complete.

New sub-processor

We give 30 days notice before a new sub-processor starts handling customer content, so that a team with a review process has time to use it.

Policy changes

Material changes to the privacy policy or the terms are emailed to account owners before they take effect, and every version carries the date it was last updated.

Data requests

Requests to access, correct, export or delete your personal data are answered within 30 days, and usually inside a week. Write to privacy@writibot.com.

What we do not claim

  • We do not claim a security certification we have not completed. If we hold one, this page will name it and give you the report. Today it names none.
  • We do not promise perfect availability. We promise honest status updates and a fixed window for telling you when something has gone wrong.
  • We do not describe our built-in checks as a guarantee of originality, here or anywhere else. They are an aid to your judgement.

The full detail sits in the privacy policy and the terms of service. For a security review, or anything a policy page does not answer, write to privacy@writibot.com and a person will answer.