Privacy Policy

Effective August 24, 2026

WriteFlow is developed and operated by Juraj Gajdos, an independent developer based in the European Union ("I," "me," or "my"). This Privacy Policy explains how I collect, use, and protect your information when you use WriteFlow on iPhone, iPad, or Mac, including the keyboard extension on iOS / iPadOS and the standalone app on macOS (collectively, the "Service").

This policy applies to all users worldwide and covers both distribution channels: WriteFlow on the App Store (iOS / iPadOS) and WriteFlow for Mac as a direct download from this website.

1. Information I collect

1.1 Text input data

When you use an AI feature (Rewrite, Translate, Generate, or custom tiles), the text in your current text field is temporarily sent to a secure server for AI processing. This text is:

This applies identically on iOS, iPadOS, and macOS.

1.2 Voice input — dictation (macOS only)

WriteFlow for macOS can dictate: you press a keyboard shortcut, speak, and a cleaned-up transcript is inserted into whatever you were typing in. Dictation is not part of the iOS or iPadOS apps, and those apps never request or use a microphone.

When you start a dictation:

The microphone is never opened unless you start a dictation yourself. See 2.3 for the macOS microphone permission.

1.3 User preferences (device-local)

The following preferences are stored locally on your device:

These never leave your device unless you enable iCloud Sync (see 1.6). On iOS / iPadOS this data lives in the App Group container shared between the host app and the keyboard extension. On macOS it lives in standard UserDefaults.

1.4 Account information (when you sign in)

WriteFlow lets you sign in to use your Pro subscription on multiple devices. Sign-in is optional — the app works without an account, subject to the free-tier limit.

When you sign in, I collect and store:

This data is stored at Supabase (see Section 4). You can delete your WriteFlow account at any time by emailing starsync.dev@outlook.com.

1.5 Subscription information

If you purchase a WriteFlow Pro subscription, the following data is collected by the relevant payment processor and shared with RevenueCat (my entitlement-management provider):

On iOS / iPadOS, payment is processed by Apple through the App Store. On macOS, payment is processed by Stripe (acting as merchant of record via Stripe Managed Payments) through RevenueCat Web Billing.

Card numbers, billing addresses, and other payment-method details are handled exclusively by Apple or Stripe. I do not receive, store, or have any access to them.

Purchase event history. Each notification RevenueCat sends about your subscription — a purchase, a renewal, a cancellation, an expiry — is recorded so that I have a record of billing history if a question arises. Each record holds the event type and time, the product purchased, which store it came from, the price and currency, the billing period type, the expiry date, and your account identifier. It contains no card details and nothing about your use of the app.

Devices on a Pro subscription. A Pro subscription may be used on up to six devices. To enforce that, I record for each device the anonymous device UUID, your account identifier, whether it is a Mac or an iPhone/iPad, and when it was first and last seen. No other information about the device is collected. If you sign in on a seventh device, the one you have not used for the longest is signed out to make room; you can sign it back in, which will displace a different one.

1.6 iCloud data

iCloud Sync is off unless you turn it on in Settings. While it is off, nothing leaves your device through iCloud.

If you switch it on, what syncs across your devices is:

That is the whole of it. Your text, your dictation, your usage counts, and your account details are never put into iCloud. Sync travels through Apple's iCloud Key-Value Storage under whichever Apple ID is signed in to the device — which is separate from your WriteFlow account — and while it is there the data is governed by Apple's iCloud terms and privacy policy. I cannot read it.

iCloud Sync uses your macOS or iOS Apple ID, which is independent from your WriteFlow sign-in. You can have one without the other.

1.7 Purchase-funnel events (iOS / iPadOS only)

To understand whether the subscription flow actually works — how many people reach the paywall, and where they drop out — the iOS and iPadOS apps report a small, fixed set of events. This is first-party: there is no third-party analytics SDK in any WriteFlow app. The macOS app reports none of this.

The complete list of events is:

Each event carries only its name, one short detail from the list above, the platform, and an identifier — your account ID if you are signed in, otherwise the anonymous device UUID. The server accepts only the event names listed above and rejects anything else, so these records cannot be widened to carry other information.

They contain no text you wrote, no prompt or tool you used, no audio, and no record of how often you use the AI features.

These events are kept for 90 days and then deleted automatically by a scheduled nightly job — I do not hold them indefinitely. What remains after that is a daily count per platform with no identifier attached to it, which cannot be traced back to you or your device. If you would rather not wait, email me and I will delete the records associated with your account or device.

1.8 Information I do NOT collect

2. Permissions

2.1 iOS / iPadOS — "Allow Full Access"

WriteFlow's keyboard extension requests "Allow Full Access" in iOS Settings. This permission is required solely to enable the keyboard to make network requests to the AI processing server. Without Full Access, AI features will not function and no data leaves your device.

With Full Access enabled:

2.2 macOS — Accessibility permission

WriteFlow on macOS requests Accessibility access (System Settings → Privacy & Security → Accessibility). This permission is required solely to read your currently selected text and replace it with the AI-rewritten version, which is the core function of the app.

With Accessibility access:

You can revoke Accessibility access at any time in System Settings. The app will continue to launch but AI features will stop working.

2.3 macOS — Microphone permission

WriteFlow on macOS asks for microphone access (System Settings → Privacy & Security → Microphone) the first time you use dictation. It is required solely to record the speech you are dictating.

Dictation is entirely optional. If you never use it you can leave the permission unasked or switch it off, and every other feature continues to work. You can revoke it at any time in System Settings; only dictation stops working.

The iOS and iPadOS apps do not request microphone access at all.

3. How I use your information

Text submitted through AI features is used exclusively to:

Dictation audio (1.2) is used exclusively to:

Account information (1.4) is used to:

Subscription information (1.5) is used to:

Purchase-funnel events (1.7) are used exclusively to:

I do not use any of this data for advertising, profiling, or cross-site tracking, and I do not analyse your writing or your use of the AI features.

4. Data sharing — sub-processors

I do not sell, rent, trade, or otherwise share your personal data with third parties for marketing, advertising, or profiling purposes.

To operate the Service I rely on a small number of sub-processors:

4.1 OpenAI — AI processing

4.2 Supabase — Backend infrastructure

4.3 RevenueCat — Subscription management

4.4 Apple — App Store payments (iOS / iPadOS only)

4.5 Stripe — Web payments (macOS only)

4.6 Resend — Transactional email

4.7 Apple iCloud — Optional cross-device sync

4.8 Cloudflare — Website hosting and macOS auto-updates

4.9 Google — Sign-in, and web fonts

No data is shared with any other third party.

5. Auto-updates (macOS only)

The macOS app uses the Sparkle update framework to check for new versions and offer to install them. Periodically (typically once per day on first launch), the app fetches appcast.xml from https://writeflowapp.org/dl/appcast.xml. This request reveals to Cloudflare your IP address, User-Agent, and the fact that you are running WriteFlow.

If a new version is available, Sparkle prompts you before downloading or installing anything. You can disable update checks in Settings.

The iOS / iPadOS app updates exclusively through Apple's App Store and does not include Sparkle.

6. Data retention

DataWhereRetention
Text submitted to AI featuresOpenAI + Supabase Edge FunctionNot retained. Discarded immediately after processing.
Dictation audio and transcripts (macOS)Your Mac, then OpenAI + Supabase Edge FunctionNot retained. The temporary file on your Mac is deleted as soon as it is sent; nothing is stored server-side.
Free-tier daily usage counterSupabaseDeleted automatically after 7 days. A count only — no record of what you did.
Purchase-funnel events (1.7, iOS only)Supabase90 days, then deleted automatically by a scheduled nightly job. You can also ask me to remove your records sooner.
Account information (Supabase Auth)SupabaseUntil you delete your account. Email me to request deletion.
Subscription stateRevenueCat + SupabaseUntil you delete your account, or per RevenueCat / Apple / Stripe statutory retention requirements (typically up to 7 years for tax/audit).
Purchase event history (1.5)SupabaseKept as billing history. Deleted with your account on request.
Pro device records (1.5)SupabaseUntil you sign the device out, it is displaced by the six-device limit, or you delete your account.
Operational request logs (4.2)Supabase logsPer Supabase's log retention for the project. Contains no text, audio, or transcript.
Email delivery logsResendPer Resend's retention policy (typically 30 days).
Device-local preferencesYour deviceDeleted when you uninstall, reset to defaults, or sign out.
iCloud-synced preferencesApple iCloudPer Apple's iCloud retention. Disable iCloud Sync to stop.
Web traffic / update check logsCloudflarePer Cloudflare's standard log retention.

7. Data security

I implement appropriate technical measures to protect your data:

What this does and does not cover. Transit encryption protects your text from being intercepted on the network. It is not end-to-end encryption: the WriteFlow edge function and OpenAI's API briefly process your text as plaintext in memory to generate AI suggestions. No party other than you, my infrastructure, and OpenAI has access to the content, and none of it is persisted.

8. International data transfers

When you use an AI feature, your text is sent to servers operated by Supabase and OpenAI, both located in the United States. Account data sits at Supabase (US). Stripe payments are processed via Stripe's EU/US infrastructure; Apple App Store payments stay within Apple's infrastructure.

If you are located outside the United States (including within the European Economic Area), this constitutes an international data transfer. Such transfers are protected by:

9. Legal basis for processing (EEA / UK users)

Under the General Data Protection Regulation (GDPR), I process your data on the following legal bases:

10. Your privacy rights

10.1 All users

Regardless of where you are located, you can:

10.2 European Economic Area, UK, and Swiss users (GDPR / UK GDPR)

You additionally have the right to:

10.3 California users (CCPA / CPRA)

California residents have the right to:

Categories of personal information collected: Text input (only during active AI processing, not retained); audio recordings, on macOS only and only while you hold a dictation active (transmitted for transcription, not retained — see 1.2); account information (email, name where your provider supplies one, Supabase user ID); subscription metadata and purchase event history (no card details); commercial information (which devices carry your subscription); internet activity (the purchase-funnel counts in 1.7 and the operational request logs in 4.2); device-local preferences (not transmitted); anonymous device UUID (rate limiting, device limit, and attributing 1.7 events before sign-in).

Categories of personal information sold: None.

Categories shared for cross-context behavioral advertising: None.

10.4 Brazilian users (LGPD)

Under the Lei Geral de Proteção de Dados (LGPD), you have rights of confirmation, access, correction, anonymization, portability, deletion, information about data sharing, and revocation of consent. Contact me to exercise any of these rights.

10.5 Other jurisdictions

If you are located in another jurisdiction with specific data protection rights, I will honor those rights to the extent required by applicable law. Contact me to exercise your rights.

11. Children's privacy

WriteFlow is not directed at children. The minimum age to use WriteFlow is:

I do not knowingly collect personal information from children under the applicable age. If you believe a child has provided personal data through the Service, please contact me and I will delete it promptly.

12. Do Not Track

WriteFlow does not track users across third-party websites or services, does not build advertising or behavioural profiles, and contains no third-party tracking SDK. The only events recorded are the purchase-funnel ones described in 1.7, which are first-party and never leave my own infrastructure. I do not respond to Do Not Track (DNT) browser signals, as no cross-site tracking occurs for them to apply to.

13. Changes to this policy

I may update this Privacy Policy from time to time. Changes will be reflected by updating the effective date above. For significant changes, I will provide notice through the app. Continued use of WriteFlow after changes constitutes acceptance of the updated policy.

14. Data controller and contact

The data controller responsible for your personal data is:

Juraj Gajdos
Email: starsync.dev@outlook.com
Location: European Union

If you are in the EEA and wish to lodge a complaint, you may contact the data protection authority in your country of residence. A list of EEA data protection authorities is available at edpb.europa.eu.