Security

Your writing is yours. Here is how we protect it, who handles it, and what you control.

The short version

Your writing is not used to train AI

We do not use your documents to train AI models, and we do not sell your documents or personal information.

Private by default

A document is only visible to you until you choose to share it.

Encrypted

Connections to Writing Studio use HTTPS, and the data we store is encrypted at rest with AES-256.

AI sees only what it needs

When you use an AI feature, only the text it needs is sent: the passage you highlight, or your paper for a chat or review.

You are in control

Share, unshare or delete a document whenever you like, and delete your whole account from Settings.

Who can see your work

Every document is private when you create it. Only you can open it until you invite someone by email or turn on link sharing.

When you share, you choose what people can do: view, comment or edit. You can change or remove their access at any time. With link sharing on, anyone with the link can read it, even without an account. Publishing puts it on the open web.

Where your data is stored

Your documents and account data are stored in a database run by Neon, with access limited to your account and the people you share with. The database encrypts stored data with AES-256 and encrypts connections with TLS.

Uploaded PDFs and images are stored with Vercel. They are encrypted at rest with AES-256 and can only be opened with a long, unguessable web address that is not listed anywhere. We delete a PDF when you delete its source for good, and all your uploaded files when you delete your data or your account.

Your browser also keeps a working copy of your drafts so they load fast and work offline. When you are signed in, it syncs to your account automatically.

Usage counts and caches are kept in Upstash: how much of your plan you have used, and recent citation searches and checks, kept for up to 40 days.

Free tools on writingstudio.com, such as the citation finder, keep what you paste for up to 8 days so your results can be opened again, then delete it automatically.

We and our providers may process data in other countries, including the United States, and we take reasonable steps to keep it protected.

Who handles your data

Provider

What it does

What it can see

Anthropic

What it does

Generates AI suggestions, edits, chat answers and reviews

What it can see

The text an AI feature needs, up to your whole paper

Clerk

What it does

Account sign-in

What it can see

Your email address, and basic Google profile details if you sign in with Google

Neon

What it does

Stores your documents and account data

What it can see

Your stored documents, encrypted at rest

Vercel

What it does

Hosts Writing Studio and stores uploaded files

What it can see

Traffic needed to serve the app, and your uploaded files

Stripe

What it does

Subscription payments

What it can see

Your payment details. We do not receive or store your full card number

Resend

What it does

Sends emails about invites, access requests and comments

What it can see

The recipient’s email address and the email itself, such as the paper title and the comment

Upstash

What it does

Keeps usage counts and short-lived caches

What it can see

Your account’s usage counts, and recent citation searches and checks

Research databases

What it does

Find papers when you cite or search: OpenAlex, Crossref, PubMed, Europe PMC, arXiv and Firecrawl

What it can see

The sentence you are citing or what you search for, sent from our servers without your name or account

Book and web lookups

What it does

Fill in a source’s details: Open Library, Google Books, the Internet Archive and the site you link to

What it can see

The ISBN, title or link you add

Your own AI provider

What it does

Runs AI features if you add your own key: OpenAI, Google, xAI or Anthropic

What it can see

The same text an AI feature would send to Anthropic

These providers only receive what they need to do their job. See our Privacy Policy for details.

Two things happen in your browser itself: some citation styles load from jsDelivr, a public file network, and dictation in the chat uses your browser’s speech recognition, which in Chrome sends your audio to Google.

What happens when you use an AI feature

Step 1

You highlight text or ask a question.

Step 2

Only the text it needs is sent to the AI provider.

Step 3

The answer comes back to your screen.

Step 4

Your writing is not used to train AI models.

If you prefer, you can use your own AI key in Settings. It is kept in your browser and sent with each AI request, through our server, to your AI provider. We never store or log it.

Account security

  • Sign in with Google, or with your email and a password.

  • Change your password any time in Settings, and sign out of every other device if you want to.

  • See the devices you are signed in on and sign out of any of them.

  • Sign-in is handled by Clerk, a specialist authentication provider.

Your controls

Delete your account

In Settings, choose Delete account. This deletes your documents, version history, library, chats, profile and uploaded files, ends every signed-in session on every device, and closes your account.

Delete your data and keep your account

Settings also lets you delete everything you have written without closing your account.

Cookie choices

Analytics cookies are only set if you accept them, and you can change your choice any time on the Cookie Policy page. We do not use cookies for advertising.

Your rights

We support rights under the New Zealand Privacy Act 2020 and, where they apply, the CCPA and the GDPR. Email support@writingstudio.com to access, correct or delete your data.

Found a security issue?

We welcome reports from security researchers and students alike. Email support@writingstudio.com with what you found and how to reproduce it. We will reply and look into it. Please give us time to fix an issue before sharing it publicly.

Frequently asked questions

Does Writing Studio use my essays to train AI?

No. We do not use your documents to train AI models.

Who can see my documents?

You, and anyone you choose to share them with. When you use an AI feature, the text it needs is also sent to the AI provider to produce the answer.

Where is my data stored?

Your documents and account data are stored in a Neon database, uploaded files are stored with Vercel, and a working copy of your drafts stays in your browser.

Do you sell my data?

No. We do not sell your personal information or your documents.

Do you store my card details?

No. Payments are handled by Stripe, and we do not receive or store your full card number.

How do I delete my account?

Open Settings and choose Delete account. You can also email support@writingstudio.com.

Can my school or university use Writing Studio?

Yes. If your institution has security questions, email support@writingstudio.com and we will answer them.

Questions about security?

Email support@writingstudio.com and a person will reply. For the legal detail, read our Privacy Policy.