Legal
Privacy Policy
Last updated July 2026
What we collect
When you create an account, we collect your email address. When you write and Proof documents, we store your writing, revision checkpoints, word counts, and writing time. When you subscribe to Proofwriter Pro, Stripe processes your payment information — we never see or store your card details. We also collect basic usage data (page views, feature interactions) through Vercel Analytics to improve the product.
Schools, parents, and student data (FERPA/COPPA)
When a school or institution sets up a Proofwriter enterprise account, we act as a "school official" with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)) — we process student data solely on behalf of, and at the direction of, the school for the educational purpose of assigning and evaluating writing. Within an institutional account, we collect: student email and display name, assignment submissions and writing content, word count and writing-time metadata, paste-flag data, and completion status. We do not use student data for behavioral advertising, do not build advertising profiles from it, and do not sell it to any third party, under any circumstances. Instructors and school administrators can request export or deletion of their students' data at any time by contacting help@proofwriter.app; we also delete institutional data upon request at the end of a contract term. Proofwriter is not directed at children under 13. Outside of a school-supervised account created and administered by a child's school — where the school's own consent to Proofwriter's data practices stands in for direct parental consent, as permitted by COPPA's school-official exception — Proofwriter is meant to be signed up for by someone 13 or older, or by a parent or guardian creating and managing the account on their child's behalf; a parent doing so is treated as giving consent under COPPA for that account. Parents or guardians who want to review, correct, or request deletion of their child's data should contact their child's school directly for a school-supervised account, or email us at help@proofwriter.app for an account they created themselves.
How we use it
Your email is used to send your magic link sign-in and, if you opt in, a welcome message. Your writing is stored securely in our database and used solely to power your dashboard and Proof pages. A cryptographic fingerprint (SHA-256 hash) of each Proofed document is submitted to the OpenTimestamps network and permanently anchored to the Bitcoin blockchain — this hash cannot be used to reconstruct your writing. Payment and subscription data is managed through Stripe.
Who can see your writing
Unproofed drafts are private and visible only to you. When you Proof a document, the resulting proof page (proofwriter.app/proof/...) becomes publicly accessible to anyone with the link — this is intentional and central to how the product works. You control when you Proof.
Google API Services
Proofwriter offers an optional feature that lets Pro subscribers export their documents directly to Google Docs. If you choose to use this feature, you will be asked to authorize Proofwriter to access your Google account using the limited "drive.file" scope. This scope grants Proofwriter permission only to create and manage files that Proofwriter itself creates in your Google Drive — it cannot read, modify, or delete any other files in your Drive. We store your Google OAuth access and refresh tokens securely in our database solely to perform this export on your behalf. We do not share these tokens or use them for any other purpose. You can revoke Proofwriter's access to your Google account at any time by visiting your Google Account permissions page (myaccount.google.com/permissions) or from your Proofwriter account settings. Proofwriter's use of Google API Services data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Third-party services
Proofwriter uses Supabase for database and authentication, Stripe for payments, OpenTimestamps and the Bitcoin network for blockchain anchoring, Vercel for hosting and analytics, Google Drive API (optional, for document export), and advertising pixels (currently the Meta Pixel) for marketing analytics on our public marketing pages. Each of these services has its own privacy policy governing how they handle data.
Cookies and ad tracking
Any advertising pixel we use (currently the Meta Pixel) only loads on our public marketing pages, and only after you accept it in the cookie banner shown on your first visit — it does not load by default, and it never loads on the dashboard, the editor, or any page tied to a school account. If your browser sends a Global Privacy Control signal, we treat that as a decline automatically and never show the banner. You can change your choice at any time using the "Do Not Sell or Share My Info" link in the footer.
Data retention
Your documents and account data are retained for as long as your account is active. You can delete individual documents from your dashboard. You can delete your account at any time from the account panel in your dashboard. To request deletion by email, contact help@proofwriter.app. Note that blockchain-anchored hashes cannot be removed from the Bitcoin blockchain — they contain no personal information or writing content.
Contact
Questions about this policy? Email help@proofwriter.app.