Privacy Policy
How Writ collects, uses, and protects your data, and the rights you have over it.
Effective June 22, 2026 · Version 2.0
Writ ("Writ", "we", "us") is the API and MCP layer for sites that have no API. It is operated by Benjamin Garcia, carrying on business as “Logiciels Writ”, NEQ 2282397514, who is the controller of the personal information described below. This policy explains what data we collect, how we use it, and the rights you have over it. Writ runs on your own accounts, with your own credentials and data, on sites you are authorized to use, and that principle shapes how we handle your data: your data is yours, we don't sell it, and we don't train models on your runs.
Data we collect
Account information
When you create an account we collect your name, email address, and organization name. Passwords are hashed with Argon2 and never stored in plaintext.
Billing and wallet data
Writ bills from a monthly pool of credits included with your plan, topped up from a prepaid balance once the pool is spent. We record wallet top-ups, balance, and metering events (cloud running time, AI token usage, and marketplace run charges) so we can show your usage and produce receipts. Card details are handled by our payments partner (Stripe); we never store full card numbers. We retain the usage metadata needed for billing, not the content of your workflows or their results.
Workflow and recipe data
Workflow definitions, recorded browser sessions, Monitors, automations, and the results of your runs are stored in your tenant and belong to you. We access this data only to provide the Service or where required by law. Credentials, personas, and secrets are encrypted at rest and are never exposed in logs or to AI features.
Marketplace data
Workflows you publish to the marketplace are recipes only: your own credentials, personas, secrets, and inputs are stripped at publish and are never shared with anyone who installs them. Whoever installs a recipe attaches and runs it on their own data. We process the metadata needed to list, review, and meter a listing.
Technical data
We collect standard server logs including IP addresses, browser user agents, and request timestamps, used for security, abuse prevention, and debugging.
Website analytics (optional, consent-based)
On our marketing website, if you opt in through our consent banner, we collect privacy-first, cookieless usage and performance measurements: pages viewed, links and buttons clicked, basic device/locale, referrer, first-touch campaign parameters (UTM), and anonymous Core Web Vitals (page-load and latency metrics). This is processed by Umami (self-hosted by us) and, where enabled for a deployment, PostHog (product analytics) and Sentry (error monitoring), each configured cookieless with personal-data scrubbing. It is off until you opt in, we honor Do Not Track and Global Privacy Control as a decline, and we never use it to profile you across other sites or sell your data. See the Cookie Policy and Sub-processors list.
How we use your data
- To provide, operate, and maintain the Service.
- To meter usage and process billing through your prepaid balance (via Stripe).
- To run marketplace listings and supply programs you opt into.
- To send transactional email (verification, password resets, receipts, notifications).
- To detect, investigate, and prevent abuse and enforce our Acceptable Use Policy.
- To improve the Service based on aggregate, non-identifying usage patterns.
Data sharing
We share data only with the sub-processors needed to run the Service:
- Stripe: subscription and prepaid-wallet payment processing (email, billing address, and tax information where required).
- Infrastructure providers: hosting and compute, with data encrypted in transit and at rest.
- AI gateway provider: model inference for assistive and automation features. (When you use a BYO-AI key, prompts go to your own provider and not to ours.)
- Email provider: transactional and notification delivery.
- Law enforcement: only when required by valid legal process.
The current list of sub-processors is maintained in our Data Processing Addendum and on the Trust Center.
BYO agents and local runs
When you run on your own (BYO) agent, on your own machine or inside your own network, the browser automation executes on your hardware. Local runs carry no compute charge, can reach intranet, localhost, and VPN-only systems the cloud can't, and your BYO-AI keys stay on your machine and never reach Writ servers. We still receive the run metadata needed to meter your execution allowance and provide the Service.
Data security
- All data is encrypted in transit (TLS) and at rest.
- Passwords are hashed with Argon2.
- Credentials, personas, and secrets are encrypted at rest and referenced with
{{secret:key}}syntax, never exposed in logs or to AI. - API keys (
wt_), consumer keys (csk_), and OAuth tokens (wto_) are generated with cryptographically secure randomness. - Sessions use signed, expiring tokens with refresh rotation and logout revocation.
- Tenant isolation is the default, and sensitive data is encrypted at rest.
Data retention
We retain your data while your account is active, and purge operational data on a rolling schedule:
- Run records and results are retained for up to 90 days.
- Detected-change history (Monitors) is retained for up to 90 days.
- Server and audit logs are retained for up to 90 days for security purposes.
Upon account deletion:
- Your account and tenant data (workflows, Monitors, configurations, and results) are permanently deleted.
- Billing and wallet records are retained as required by law (typically up to 7 years).
Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Export your workflow and account data.
- Delete your account and associated data (erasure).
- Object to or restrict certain processing.
Self-serve access, export, and deletion tools are available in your account. If you process personal data through Writ on behalf of others, see the Data Processing Addendum.
Cookies
We use essential cookies for authentication (an httpOnly refresh-token cookie). We do not use advertising or cross-site tracking cookies. With your consent, we also use privacy-first, cookieless analytics (see "Website analytics" above). See the Cookie Policy for detail.
Children
Writ is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We will notify you of material changes by email. Minor changes are posted here with an updated effective date and version.
Person responsible for the protection of personal information
Under Québec's Act respecting the protection of personal information in the private sector (Law 25), we have designated a person responsible for the protection of personal information. That person oversees our compliance, handles access, correction, portability and de-indexing requests, and is the point of contact for any privacy concern.
Responsable de la protection des renseignements personnels
Benjamin Garcia
privacy@usewrit.app
If you are not satisfied with our response, you may file a complaint with the Commission d'accès à l'information du Québec, or with the privacy authority of your own jurisdiction.
Transfers outside Québec
Some of the providers listed above operate outside Québec, which means your personal information may be stored or processed elsewhere. Before entrusting personal information to a provider outside Québec we assess whether it receives adequate protection, taking into account the sensitivity of the information, the purposes of its use, the protections afforded to it, and the legal framework of the destination — and we bind each provider by a written agreement.
Contact
For privacy questions or data requests, contact privacy@usewrit.app. See all policies in the legal index.