Data policy
The short version: we don’t store your drafts or your rewrites. To rewrite your text we send it to a language model provider, and that provider may keep it for a limited time under its own terms. We tell you which provider that is. Everything else we hold is listed below, with why and for how long.
1. Who is responsible
Ghostwritin' is a division of Factory Zero Pte. Ltd., Singapore (“we”), which is the controller of the personal data described here. Contact: privacy@ghostwrit.in. Because we offer the service to people in the European Union and the United Kingdom, we will appoint an EU and a UK representative under Article 27 of the GDPR before launch and name them on this page.
2. Your text: not stored
- Drafts, rewrites, diffs and scores pass through our servers in memory to produce the response and are discarded when it is sent.
- We don’t write the content to disk, don’t log it, don’t use it to train or improve models, and don’t look at it.
- Request logs hold only metadata: time, account, word count, voice, strength, and error codes. Never the text.
3. The model provider: may keep it
A rewrite needs a large language model, so your text is sent to a model provider that processes it on our behalf (a processor under Article 28 GDPR). Under its own terms, a provider may keep API requests for a limited time, typically up to 30 days and usually for abuse and safety monitoring, before deleting them. We only use providers that:
- do not train their models on API data;
- sign a data processing agreement with us; and
- offer Standard Contractual Clauses or an adequacy decision for transfers outside the EU or UK.
We will name the provider, its retention period and a link to its terms in this section before launch, and update it whenever the provider changes. If you need zero retention, self-host Ghostwritin' with a provider and account settings you choose.
4. Self-hosted installs
A self-hosted install sends text only to the model provider whose key you set. It never reaches us, and we are not a controller or processor for it.
5. What we do keep, and why
- Account: email address and plan. Basis: the contract with you (Art. 6(1)(b)). Kept while your account is open, deleted within 30 days of closing it.
- Usage for billing: word counts per day and month. Basis: contract. Invoices and payment records are kept as long as tax law requires (Art. 6(1)(c)).
- My voice: a style summary built from the samples you upload. The samples are processed like any draft and not stored. Basis: contract. Deleted when you delete the voice or close your account.
- Payments: handled by our payment provider; we never see or store card numbers.
- Security: IP addresses in short-lived rate-limit and abuse logs. Basis: our legitimate interest in keeping the service safe (Art. 6(1)(f)). Kept up to 14 days.
- Waitlist: not open yet. The form on this site sends nothing and stores nothing.
6. This website
No cookies, no analytics and no advertising trackers. The site is served by Cloudflare, which processes visitor IP addresses to deliver and protect it. Typefaces load from Google Fonts, so your browser’s request, including your IP address, reaches Google.
7. Your rights
Under the GDPR and UK GDPR you can ask us to access, correct, delete or export your personal data, to restrict or object to its processing, and you can withdraw any consent at any time. Write to privacy@ghostwrit.in; we answer within one month. Since we don’t store your text, there is none to return or delete. You can also complain to the data protection authority where you live or work.
8. Automated decisions
The human score is an estimate shown to you. It is not used to make decisions about you that have legal or similarly significant effects.
9. Security
Traffic is encrypted in transit and stored account data at rest. API keys are stored hashed. Access to production is limited to the people who run the service.
10. Changes
We will post changes here with a new effective date and email account holders about material ones.