Legal
Privacy Policy
1. Who this covers
This policy covers onwrite (“onwrite”) and the onwrite service. It is about people who sign up and write with onwrite. If you are just reading a blog published on onwrite, that is up to the blog author's own practices for anything they collect.
2. What we collect
- Account details. Your email, plus anything you add to your profile (name, bio, photo).
- What you create. Your posts, drafts, tags, images, and site settings.
- Billing details. If you subscribe, Stripe handles the payment. We only see things like your plan, status, and the last digits and brand of your card — never the full number.
- Usage. Privacy-friendly, aggregate numbers about how the app and published sites are used, like page views.
- Technical data. Things your device sends automatically — IP address, browser, timestamps — used for security and debugging.
3. How we use it
We do not sell your personal information, and we do not use your private drafts for advertising.
- Run, maintain, and secure the Service and publish your blog.
- Handle subscriptions and prevent fraud.
- Answer support requests and send service messages.
- Watch performance, fix errors, and improve features.
- Enforce our terms and meet legal obligations.
4. Cookies and analytics
We use cookies that are needed to keep you signed in and the Service secure. For analytics we use a privacy-friendly provider that is built to avoid tracking individuals across sites. You can manage cookies in your browser, though some are required for onwrite to work.
5. Who we share it with
We share information with the providers that help us run onwrite, under agreements that limit how they use it. We may also share it to follow the law, enforce our terms, or protect people. If onwrite is ever part of a merger or sale, information may transfer with it. Anything you publish is public by design.
Providers we use
- Supabase — Database, sign-in, and file storage
- Vercel — Hosting and privacy-friendly analytics
- Stripe — Subscription billing and payments
- Sentry — Error monitoring
- Upstash — Rate limiting and caching
- Unsplash — In-editor image search, when you use it
6. How long we keep it
We keep your information while your account is active. When you delete content or close your account, we take it off the live Service and permanently delete it after about 30 days — except records we must keep, like billing records for tax or accounting.
7. Your rights and choices
To use any of these or ask a question, email support@onwrite.app.
- Access and export. Export your whole workspace — profile, settings, posts, tags — as a JSON file from settings, anytime.
- Correction. Edit your profile and content right in the app.
- Deletion. Delete individual content or close your account from settings. Depending on where you live, you may have extra rights to access, correct, delete, or limit how we use your information.
8. Security
We protect your information with measures like encryption in transit, row-level access controls, and restricted access. No system is perfectly secure, so we cannot promise absolute security — but we work to keep your data safe and to act fast when something is wrong.
9. International transfers
Our providers may process and store information in countries other than yours. Where it is required, we rely on appropriate safeguards for those transfers.
10. Children
onwrite is not meant for children under 13 (or the minimum age in your country), and we do not knowingly collect their information.
11. Changes to this policy
We may update this policy from time to time. We will update the “Last updated” date and, for material changes, give extra notice where it makes sense.
12. Contact
For privacy questions or requests, email support@onwrite.app. You can also read our Terms of Service.
support@onwrite.app
Questions about this policy? Email support@onwrite.app.