Privacy Policy
Effective August 24, 2026
WriteFlow is developed and operated by Juraj Gajdos, an independent developer based in the European Union ("I," "me," or "my"). This Privacy Policy explains how I collect, use, and protect your information when you use WriteFlow on iPhone, iPad, or Mac, including the keyboard extension on iOS / iPadOS and the standalone app on macOS (collectively, the "Service").
This policy applies to all users worldwide and covers both distribution channels: WriteFlow on the App Store (iOS / iPadOS) and WriteFlow for Mac as a direct download from this website.
1. Information I collect
1.1 Text input data
When you use an AI feature (Rewrite, Translate, Generate, or custom tiles), the text in your current text field is temporarily sent to a secure server for AI processing. This text is:
- Transmitted over HTTPS with TLS 1.2 or higher
- Processed in real time to generate AI suggestions
- Not stored, logged, or retained on any server after processing is complete
- Not used to train AI models
This applies identically on iOS, iPadOS, and macOS.
1.2 Voice input — dictation (macOS only)
WriteFlow for macOS can dictate: you press a keyboard shortcut, speak, and a cleaned-up transcript is inserted into whatever you were typing in. Dictation is not part of the iOS or iPadOS apps, and those apps never request or use a microphone.
When you start a dictation:
- Audio is captured only between the moment you start the dictation and the moment it ends — either when you press the shortcut again, or automatically a few seconds after you stop speaking
- The recording is written to a temporary file on your Mac and deleted as soon as it has been sent, and also deleted if you cancel or it times out
- It is transmitted over HTTPS to the same secure server that handles text, and forwarded to OpenAI for transcription and a short clean-up pass that removes filler words and restores punctuation
- Neither the audio nor the transcript is stored, logged, or retained on any server after processing completes
- Not used to train AI models
The microphone is never opened unless you start a dictation yourself. See 2.3 for the macOS microphone permission.
1.3 User preferences (device-local)
The following preferences are stored locally on your device:
- Theme selection (light, dark, system)
- Tile configuration and custom presets
- Your custom prompts
- Haptic feedback preference (iOS only)
- iCloud sync preference
- Privacy consent status
These never leave your device unless you enable iCloud Sync
(see 1.6). On iOS / iPadOS this data lives in the App Group
container shared between the host app and the keyboard extension.
On macOS it lives in standard UserDefaults.
1.4 Account information (when you sign in)
WriteFlow lets you sign in to use your Pro subscription on multiple devices. Sign-in is optional — the app works without an account, subject to the free-tier limit.
When you sign in, I collect and store:
- A Supabase user ID (an opaque UUID)
- The email address linked to your sign-in identity (whether you signed in with Apple, Google, or email)
- The timestamp of your sign-in
- The identity provider you used (Apple, Google, or email OTP)
This data is stored at Supabase (see Section 4). You can delete your WriteFlow account at any time by emailing starsync.dev@outlook.com.
1.5 Subscription information
If you purchase a WriteFlow Pro subscription, the following data is collected by the relevant payment processor and shared with RevenueCat (my entitlement-management provider):
- Subscription tier (Monthly, Six Months, or Yearly)
- Purchase status (active, expired, in grace period)
- Purchase and renewal timestamps
- Receipt or transaction identifier (no card details)
On iOS / iPadOS, payment is processed by Apple through the App Store. On macOS, payment is processed by Stripe (acting as merchant of record via Stripe Managed Payments) through RevenueCat Web Billing.
Card numbers, billing addresses, and other payment-method details are handled exclusively by Apple or Stripe. I do not receive, store, or have any access to them.
Purchase event history. Each notification RevenueCat sends about your subscription — a purchase, a renewal, a cancellation, an expiry — is recorded so that I have a record of billing history if a question arises. Each record holds the event type and time, the product purchased, which store it came from, the price and currency, the billing period type, the expiry date, and your account identifier. It contains no card details and nothing about your use of the app.
Devices on a Pro subscription. A Pro subscription may be used on up to six devices. To enforce that, I record for each device the anonymous device UUID, your account identifier, whether it is a Mac or an iPhone/iPad, and when it was first and last seen. No other information about the device is collected. If you sign in on a seventh device, the one you have not used for the longest is signed out to make room; you can sign it back in, which will displace a different one.
1.6 iCloud data
iCloud Sync is off unless you turn it on in Settings. While it is off, nothing leaves your device through iCloud.
If you switch it on, what syncs across your devices is:
- iOS / iPadOS: your tiles and their arrangement, and your theme and haptic preference
- macOS: your tiles and their arrangement, your custom prompts, and your theme
That is the whole of it. Your text, your dictation, your usage counts, and your account details are never put into iCloud. Sync travels through Apple's iCloud Key-Value Storage under whichever Apple ID is signed in to the device — which is separate from your WriteFlow account — and while it is there the data is governed by Apple's iCloud terms and privacy policy. I cannot read it.
iCloud Sync uses your macOS or iOS Apple ID, which is independent from your WriteFlow sign-in. You can have one without the other.
1.7 Purchase-funnel events (iOS / iPadOS only)
To understand whether the subscription flow actually works — how many people reach the paywall, and where they drop out — the iOS and iPadOS apps report a small, fixed set of events. This is first-party: there is no third-party analytics SDK in any WriteFlow app. The macOS app reports none of this.
The complete list of events is:
- The paywall was shown
- A plan was tapped (which of the three: monthly, six-month, yearly)
- The outcome of a purchase attempt (success, pending, cancelled, unverified, failed)
- The free daily limit was reached (at most once per day per device)
- The sign-in sheet was shown, and whether you signed in or skipped
Each event carries only its name, one short detail from the list above, the platform, and an identifier — your account ID if you are signed in, otherwise the anonymous device UUID. The server accepts only the event names listed above and rejects anything else, so these records cannot be widened to carry other information.
They contain no text you wrote, no prompt or tool you used, no audio, and no record of how often you use the AI features.
These events are kept for 90 days and then deleted automatically by a scheduled nightly job — I do not hold them indefinitely. What remains after that is a daily count per platform with no identifier attached to it, which cannot be traced back to you or your device. If you would rather not wait, email me and I will delete the records associated with your account or device.
1.8 Information I do NOT collect
- I do not collect keystrokes or typing patterns
- I do not collect passwords, credit card numbers, or other sensitive field data
- I do not collect contacts, photos, location, or advertising identifiers. The one device identifier I do use is an anonymous UUID generated by the app itself, stored in your device's keychain and never synced — it is used to count your free daily allowance, to attribute the events in 1.7 when you are not signed in, and to recognise your devices against the Pro device limit in 1.5. It is not linked to your Apple ID, your hardware, or any advertising identifier
- I do not use any third-party analytics, crash reporting, advertising, or tracking SDK — the only events recorded are the purchase-funnel ones listed in 1.7
- I do not record which AI tools or prompts you use, or how many times you use them
- I do not collect any data when the keyboard or app is open without you triggering an AI feature
- I do not sell your personal information to anyone
2. Permissions
2.1 iOS / iPadOS — "Allow Full Access"
WriteFlow's keyboard extension requests "Allow Full Access" in iOS Settings. This permission is required solely to enable the keyboard to make network requests to the AI processing server. Without Full Access, AI features will not function and no data leaves your device.
With Full Access enabled:
- Text is only transmitted when you actively tap an AI tile
- The keyboard does not passively monitor or transmit what you type
- Network requests go only to my own backend, and only to these endpoints: the AI processing endpoint; a check of how much of your free daily allowance remains; the purchase-funnel events in 1.7; and, once when you first sign in, a one-off request that moves your existing daily usage count from your device to your new account. Nothing is sent to any other destination.
2.2 macOS — Accessibility permission
WriteFlow on macOS requests Accessibility access (System Settings → Privacy & Security → Accessibility). This permission is required solely to read your currently selected text and replace it with the AI-rewritten version, which is the core function of the app.
With Accessibility access:
- Text is only read when you actively trigger an AI feature (e.g., the global keyboard shortcut)
- The app does not passively monitor or log what you type
- It does not record screen contents or interact with other applications beyond the read/replace gesture you initiate
You can revoke Accessibility access at any time in System Settings. The app will continue to launch but AI features will stop working.
2.3 macOS — Microphone permission
WriteFlow on macOS asks for microphone access (System Settings → Privacy & Security → Microphone) the first time you use dictation. It is required solely to record the speech you are dictating.
- The microphone is opened only when you start a dictation, and closed as soon as it ends
- The app does not listen in the background, and cannot record while no dictation is running
- Nothing is captured before you press the shortcut or after the dictation finishes
Dictation is entirely optional. If you never use it you can leave the permission unasked or switch it off, and every other feature continues to work. You can revoke it at any time in System Settings; only dictation stops working.
The iOS and iPadOS apps do not request microphone access at all.
3. How I use your information
Text submitted through AI features is used exclusively to:
- Generate rewritten, translated, or AI-composed text
- Return suggestions to your device in real time
Dictation audio (1.2) is used exclusively to:
- Produce a transcript of what you said
- Clean that transcript up — remove filler words, restore punctuation — before it is inserted
Account information (1.4) is used to:
- Authenticate you on the device
- Sync your Pro subscription entitlement across your devices
Subscription information (1.5) is used to:
- Verify whether you have an active Pro subscription
- Enable Pro features when entitled
Purchase-funnel events (1.7) are used exclusively to:
- Count how many people reach the paywall and complete or abandon a purchase
- Decide whether the subscription and sign-in flows need changing
I do not use any of this data for advertising, profiling, or cross-site tracking, and I do not analyse your writing or your use of the AI features.
4. Data sharing — sub-processors
I do not sell, rent, trade, or otherwise share your personal data with third parties for marketing, advertising, or profiling purposes.
To operate the Service I rely on a small number of sub-processors:
4.1 OpenAI — AI processing
- Provider: OpenAI, L.L.C. (San Francisco, CA, USA)
- Role: Generates the AI suggestion from your text, and on macOS transcribes dictation audio and cleans up the resulting transcript
- Data sent: The text content you choose to process; on macOS, dictation audio (1.2). Each request also carries a one-way hashed identifier derived from your account ID or anonymous device UUID — OpenAI requires a stable per-user identifier so that misuse can be attributed to an individual rather than to the whole account. It cannot be reversed to identify you, and it is not sent with any of your text.
- Storage: Processed in real time, with requests marked so that OpenAI does not retain them. With API usage, OpenAI does not use your data to train their models (per OpenAI's API data usage policy).
- Documentation: OpenAI Privacy Policy, API Data Usage Policy
4.2 Supabase — Backend infrastructure
- Provider: Supabase, Inc. (San Francisco, CA, USA)
- Role: Hosts the WriteFlow edge function that proxies AI requests to OpenAI, the user authentication system (Supabase Auth), and the database mirroring your subscription entitlement
- Data passing through: Your AI request text, and dictation audio on macOS (both held only transiently in memory while the request is forwarded to OpenAI — not logged or retained); your account information (1.4); your subscription entitlement state mirrored from RevenueCat; the purchase-funnel events in 1.7
- Operational logs: For each AI request the backend writes one diagnostic line into Supabase's log system, so that I can tell whether subscription checks are working. It records the outcome of the entitlement check, the platform, the app version, and a one-way hash of your subscription identifier. It contains no text, audio, or transcript, and the hash cannot be reversed to identify you.
- Documentation: Supabase Privacy Policy
4.3 RevenueCat — Subscription management
- Provider: RevenueCat, Inc. (San Francisco, CA, USA)
- Role: Aggregates subscription state from Apple (App Store) and Stripe (RevenueCat Web Billing for macOS), surfaces a unified entitlement to the app, and notifies the backend on purchase events
- Data sent: Your device or user identifier, transaction receipts, subscription tier, purchase/renewal timestamps. No card details.
- Also sent when you sign in: your email address, and your full name if your identity provider supplied one. These are attached to your RevenueCat subscriber record so that a subscription can be recognised as belonging to a person rather than a bare UUID — which is what makes it possible for me to help when you write in about billing. They play no part in deciding whether you have Pro.
- Documentation: RevenueCat Privacy Policy
4.4 Apple — App Store payments (iOS / iPadOS only)
- Provider: Apple, Inc. (Cupertino, CA, USA)
- Role: Processes subscription payments and acts as merchant of record for in-app purchases on iOS / iPadOS
- Data shared: Whatever the App Store transaction normally entails (App Store account ID, payment method, country). I do not receive any of this directly.
- Documentation: Apple Privacy Policy
4.5 Stripe — Web payments (macOS only)
- Provider: Stripe Payments Europe, Ltd. (Dublin, Ireland) / Stripe, Inc. (San Francisco, CA, USA)
- Role: Processes subscription payments for the macOS direct-download app via RevenueCat Web Billing. Stripe acts as merchant of record under Stripe Managed Payments, meaning Stripe is responsible for VAT / sales-tax collection and remittance.
- Data shared: Card details, billing email, country, and any other information you enter on the Stripe Checkout page. I never see your card number. Stripe shares only a transaction identifier and status with RevenueCat and my backend.
- Documentation: Stripe Privacy Policy
4.6 Resend — Transactional email
- Provider: Resend (Wilmington, DE, USA)
- Role: Delivers sign-in OTP emails (and any other transactional email Supabase sends on my behalf)
- Data sent: Your email address and the email body (containing the one-time code or magic link)
- Documentation: Resend Privacy Policy
4.7 Apple iCloud — Optional cross-device sync
- Provider: Apple, Inc.
- Role: When you switch iCloud Sync on, syncs your tiles and theme between your Apple devices — plus your custom prompts on macOS, and your haptic preference on iOS. Nothing else. See 1.6
- Data shared: Tile configuration, custom prompts, theme preference
- Documentation: Apple iCloud Terms
4.8 Cloudflare — Website hosting and macOS auto-updates
- Provider: Cloudflare, Inc. (San Francisco, CA, USA)
- Role: Hosts writeflowapp.org and serves the macOS auto-update manifest (
appcast.xml) and DMG/ZIP artifacts to the Sparkle update framework inside the macOS app - Data exposed: Standard HTTP request metadata (IP address, User-Agent, timestamp) when your Mac checks for updates. Cloudflare may retain this in standard server logs.
- Documentation: Cloudflare Privacy Policy
4.9 Google — Sign-in, and web fonts
- Provider: Google LLC (Mountain View, CA, USA)
- Role — sign-in: If, and only if, you choose "Sign in with Google", Google authenticates you and returns an identity token which is exchanged for a WriteFlow session. Choose Apple or an email code instead and Google receives nothing.
- Data exposed by sign-in: Whatever Google's own sign-in flow involves, plus the fact that you signed in to WriteFlow. I receive your email address and, if you have one set, your name — see 1.4.
- Role — web fonts: The pages of this website load a typeface from Google Fonts. Your browser therefore contacts Google when you visit, which exposes your IP address and User-Agent to Google. This affects the website only — the iOS, iPadOS, and macOS apps do not load anything from Google.
- Documentation: Google Privacy Policy
No data is shared with any other third party.
5. Auto-updates (macOS only)
The macOS app uses the Sparkle update framework
to check for new versions and offer to install them. Periodically
(typically once per day on first launch), the app fetches
appcast.xml from
https://writeflowapp.org/dl/appcast.xml. This request
reveals to Cloudflare your IP address, User-Agent, and the fact
that you are running WriteFlow.
If a new version is available, Sparkle prompts you before downloading or installing anything. You can disable update checks in Settings.
The iOS / iPadOS app updates exclusively through Apple's App Store and does not include Sparkle.
6. Data retention
| Data | Where | Retention |
|---|---|---|
| Text submitted to AI features | OpenAI + Supabase Edge Function | Not retained. Discarded immediately after processing. |
| Dictation audio and transcripts (macOS) | Your Mac, then OpenAI + Supabase Edge Function | Not retained. The temporary file on your Mac is deleted as soon as it is sent; nothing is stored server-side. |
| Free-tier daily usage counter | Supabase | Deleted automatically after 7 days. A count only — no record of what you did. |
| Purchase-funnel events (1.7, iOS only) | Supabase | 90 days, then deleted automatically by a scheduled nightly job. You can also ask me to remove your records sooner. |
| Account information (Supabase Auth) | Supabase | Until you delete your account. Email me to request deletion. |
| Subscription state | RevenueCat + Supabase | Until you delete your account, or per RevenueCat / Apple / Stripe statutory retention requirements (typically up to 7 years for tax/audit). |
| Purchase event history (1.5) | Supabase | Kept as billing history. Deleted with your account on request. |
| Pro device records (1.5) | Supabase | Until you sign the device out, it is displaced by the six-device limit, or you delete your account. |
| Operational request logs (4.2) | Supabase logs | Per Supabase's log retention for the project. Contains no text, audio, or transcript. |
| Email delivery logs | Resend | Per Resend's retention policy (typically 30 days). |
| Device-local preferences | Your device | Deleted when you uninstall, reset to defaults, or sign out. |
| iCloud-synced preferences | Apple iCloud | Per Apple's iCloud retention. Disable iCloud Sync to stop. |
| Web traffic / update check logs | Cloudflare | Per Cloudflare's standard log retention. |
7. Data security
I implement appropriate technical measures to protect your data:
- All network communication uses HTTPS with TLS 1.2 or higher
- No persistent server-side storage of your AI text. It exists in transient memory only during the request.
- App-level data on iOS is sandboxed within Apple's security model; on macOS it lives inside the app sandbox and is signed and notarized by Apple
- iCloud-synced data is encrypted by Apple in transit and at rest
- Supabase Auth credentials and API keys are managed via environment configuration; the iOS and macOS apps use a public anon key only
What this does and does not cover. Transit encryption protects your text from being intercepted on the network. It is not end-to-end encryption: the WriteFlow edge function and OpenAI's API briefly process your text as plaintext in memory to generate AI suggestions. No party other than you, my infrastructure, and OpenAI has access to the content, and none of it is persisted.
8. International data transfers
When you use an AI feature, your text is sent to servers operated by Supabase and OpenAI, both located in the United States. Account data sits at Supabase (US). Stripe payments are processed via Stripe's EU/US infrastructure; Apple App Store payments stay within Apple's infrastructure.
If you are located outside the United States (including within the European Economic Area), this constitutes an international data transfer. Such transfers are protected by:
- Encryption in transit (HTTPS with TLS 1.2 or higher)
- The contractual obligations of OpenAI, Supabase, RevenueCat, Stripe, Resend, and Cloudflare to protect your data under their terms of service
- Standard contractual clauses (where applicable) and other safeguards in accordance with GDPR Articles 44–49
9. Legal basis for processing (EEA / UK users)
Under the General Data Protection Regulation (GDPR), I process your data on the following legal bases:
- Consent (Art. 6(1)(a)) — for AI text processing. You provide explicit consent through the in-app privacy consent screen before any data processing occurs. You may withdraw consent at any time by disabling Full Access (iOS) or Accessibility access (macOS).
- Contract performance (Art. 6(1)(b)) — for processing your text through AI features and for delivering your subscription.
- Legitimate interest (Art. 6(1)(f)) — for free-tier rate limiting and enforcing the Pro device limit (using an anonymous device UUID to prevent abuse); for the operational request logs in 4.2, which keep subscription checks working; for the purchase-funnel counts in 1.7, so that I can tell whether the upgrade screens function; and for delivering security-related transactional emails.
- Legal obligation (Art. 6(1)(c)) — for retention of subscription and payment records by Apple, Stripe, and RevenueCat where required by tax or commercial law.
10. Your privacy rights
10.1 All users
Regardless of where you are located, you can:
- Stop AI data processing at any time by disabling Full Access (iOS) or Accessibility access (macOS)
- Delete local data by uninstalling the app or using "Reset to Defaults" in Settings
- Disable iCloud Sync in the app's settings to stop cross-device syncing
- Delete your WriteFlow account by emailing starsync.dev@outlook.com. I will action the deletion within 30 days.
- Cancel your subscription at any time via your Apple ID Settings (iOS) or your RevenueCat billing portal (macOS)
- Contact me with any privacy-related questions or requests at starsync.dev@outlook.com
10.2 European Economic Area, UK, and Swiss users (GDPR / UK GDPR)
You additionally have the right to:
- Access: Request confirmation of whether your personal data is being processed and obtain a copy of it
- Rectification: Request correction of inaccurate personal data
- Erasure: Request deletion of your personal data
- Restrict processing: Request restriction of processing in certain circumstances
- Data portability: Request your data in a structured, machine-readable format
- Object: Object to processing of your personal data
- Withdraw consent: At any time, without affecting the lawfulness of prior processing
- Lodge a complaint: With a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement
10.3 California users (CCPA / CPRA)
California residents have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information collected
- Delete: Request deletion of your personal information
- Opt-out of sale: I do not sell personal information. No opt-out is necessary.
- Non-discrimination: You will not be discriminated against for exercising your privacy rights
Categories of personal information collected: Text input (only during active AI processing, not retained); audio recordings, on macOS only and only while you hold a dictation active (transmitted for transcription, not retained — see 1.2); account information (email, name where your provider supplies one, Supabase user ID); subscription metadata and purchase event history (no card details); commercial information (which devices carry your subscription); internet activity (the purchase-funnel counts in 1.7 and the operational request logs in 4.2); device-local preferences (not transmitted); anonymous device UUID (rate limiting, device limit, and attributing 1.7 events before sign-in).
Categories of personal information sold: None.
Categories shared for cross-context behavioral advertising: None.
10.4 Brazilian users (LGPD)
Under the Lei Geral de Proteção de Dados (LGPD), you have rights of confirmation, access, correction, anonymization, portability, deletion, information about data sharing, and revocation of consent. Contact me to exercise any of these rights.
10.5 Other jurisdictions
If you are located in another jurisdiction with specific data protection rights, I will honor those rights to the extent required by applicable law. Contact me to exercise your rights.
11. Children's privacy
WriteFlow is not directed at children. The minimum age to use WriteFlow is:
- 16 years in the European Economic Area (in accordance with GDPR Article 8)
- 13 years in the United States (in accordance with COPPA)
- The minimum age required by local law in all other jurisdictions
I do not knowingly collect personal information from children under the applicable age. If you believe a child has provided personal data through the Service, please contact me and I will delete it promptly.
12. Do Not Track
WriteFlow does not track users across third-party websites or services, does not build advertising or behavioural profiles, and contains no third-party tracking SDK. The only events recorded are the purchase-funnel ones described in 1.7, which are first-party and never leave my own infrastructure. I do not respond to Do Not Track (DNT) browser signals, as no cross-site tracking occurs for them to apply to.
13. Changes to this policy
I may update this Privacy Policy from time to time. Changes will be reflected by updating the effective date above. For significant changes, I will provide notice through the app. Continued use of WriteFlow after changes constitutes acceptance of the updated policy.
14. Data controller and contact
The data controller responsible for your personal data is:
Juraj Gajdos
Email: starsync.dev@outlook.com
Location: European Union
If you are in the EEA and wish to lodge a complaint, you may contact the data protection authority in your country of residence. A list of EEA data protection authorities is available at edpb.europa.eu.