Privacy
Privacy Policy
The short version. Your writing stays on your device. All AI runs locally through Chrome's built-in AI, so the text you work on is never sent off your device to be processed — we never receive it, and there is no cloud model reading it. To run WritePair as a product we operate a small, separate operational layer that handles non-content data only: an anonymous identifier (no name, no email, no account), the feedback you choose to send, and anonymous diagnostics — on by default, and off with one switch in Settings. It never carries the words you write. You stay in control of both.
This policy applies to the WritePair browser extension ("WritePair", "the extension", "we", "us"). The sections below explain exactly what stays on your device (everything you write), what minimal non-content data the operational layer handles, and how the boundary between the two is guaranteed by the way WritePair is built.
1. Who we are
WritePair is a Manifest V3 Chrome extension that embeds an AI writing assistant into any text field — Gmail, LinkedIn, X, Notion, Slack, web forms, comment boxes and more — for one-click Rewrite, Proofread, Expand, Shorten, Tone, Translate, a free-form Ask AI instruction, and Compose (drafting into an empty field), plus one-click email replies on webmail. The same actions can be started from the in-page toolbar, the right-click menu, a keyboard shortcut, or the extension's popup. On text you are only reading, WritePair also offers Translate and its insight outputs (Summary, Key Points, List, Table).
- Website: https://writepair.app
- Support: https://writepair.app/support
- Privacy contact: privacy@writepair.app
If you have a question about this policy or about your privacy, you can always reach us at the address above. In practice, because we hold none of your data, there is nothing for us to look up, export, or delete on your behalf — the controls described in this policy let you do all of that yourself, instantly.
2. Our core privacy commitment: your content stays on your device
WritePair is built in two clearly separated tiers.
The content tier — everything you write — never leaves your device
WritePair's AI features are powered by Chrome's built-in, on-device AI models (Gemini Nano). When you ask WritePair to rewrite, proofread, translate, retone, summarize, or draft an email reply, the request is processed by an AI model that runs inside your own browser, on your own computer. As a direct, verifiable consequence:
- No network calls for your content. The part of WritePair that runs
on the pages where you type (the in-page toolbar and email assistant) makes no
fetch,XMLHttpRequest,WebSocketorsendBeaconrequest — there is no network path out for the text you write or the pages you browse. This is auditable in our source code. - No cloud AI. We send nothing you write to any AI service; generation happens on your device.
The privacy advantage many other AI writing tools cannot offer is structural here: they send what you type to their cloud to generate suggestions. WritePair does not — your words never leave your device to be processed.
The operational tier — non-content only — is small, separate, and partly optional
So that WritePair can run as a real product (and offer premium features in future), a separate part of the extension that runs only in the extension's own pages (the popup and settings), never on the pages where you write, handles a minimal amount of non-content data:
- An anonymous identifier. On first run WritePair creates a random, anonymous account (via Google Firebase) with no name and no email, created automatically. It exists only to tell installs apart; a small profile record (the creation time, and whether this device can run the on-device AI) is stored alongside it. Your plan is not here — it is stored against the email you sign in with, below.
- Payment, if you buy Pro — handled entirely by Paddle, not by us. WritePair Pro is sold through Paddle, which is the merchant of record: Paddle is the seller, and your name, email address and payment details are given to Paddle, never to us. We never see or store them. What reaches us is only the resulting plan — which plan it is, its status, and when it renews — recorded against the email you paid with. There is no password and no account to create, but to use Pro you do sign in with that email (a one-time link): that is what unlocks it on every computer you use.
- Feedback you choose to send. When you click Feedback or Roadmap, WritePair opens our hosted feedback portal (Featurebase) in a new tab, passing your anonymous identifier, the app version, and your operating system/architecture so a report is actionable. This happens only when you choose to open it.
- Crash reports and product analytics. Anonymous usage counts and crash reports that record which feature ran and error signatures — never the text you wrote — sent to our diagnostics providers (Sentry and Microsoft Clarity) to help us fix problems and improve the product. Alongside them we send your non-content settings, so those counts can be read in context: which toolbar layout you chose, your interface language, which optional features you have on or off, whether this device supports on-device AI, and how many sites you muted or custom actions you pinned — a count only, never the site names and never the instructions you wrote. We also send rough engagement and performance measures: how often the toolbar appeared and how often you used or accepted it, and — only if you turned the experimental autocomplete on — how fast its suggestions arrived and how often you took them. These are rounded into broad bands (e.g. "26–50%"), and the records behind them stay on your device. They run only on the extension's own pages, with all on-screen text masked, and you can turn them off any time with "Help improve WritePair" in Settings. (EU/UK users: see the consent note in §7.)
By construction the operational tier cannot carry the content tier's data: it has no access to the text you write, your selections, the pages you browse, your history, or your style profile.
3. What data WritePair handles, and where it lives
WritePair handles three kinds of data: the content it uses momentarily
to produce a suggestion (and then discards), the data it saves locally so
features work across sessions, and a small amount of operational data
that — unlike everything you write — does leave the device. The first two kinds stay
entirely on your device, in your browser's local extension storage
(chrome.storage.local) or in transient memory, and are never transmitted. The
operational data (§3.3) is non-content only.
3.1 Data processed momentarily and not stored
| Data | Why it is used | Stored? | Your control |
|---|---|---|---|
| The text you select or type in the active field | Sent to the on-device AI to produce a suggestion | No — held only in memory during the request | Only acts on the field you invoke it in |
| Text you select while only reading a page | Read locally so you can translate or summarize what you selected; the result is offered as a copy, never written back to the page | No — never persisted, and never saved to history | Fully suspended by Privacy Mode; mute WritePair on the site |
| Surrounding page content (context awareness) | Read locally so a suggestion fits what you are responding to | No — never persisted | Toggle Context awareness off; fully suspended by Privacy Mode |
| Email thread content (email assistant) | Read locally on supported webmail so a one-click reply understands the thread | No — never persisted | Toggle Email assistant off; fully suspended by Privacy Mode |
| The address of the tab you are on | Read when you open the WritePair popup, so it can show whether WritePair is on for that site and let you turn it off there | No — shown to you only; never persisted, never transmitted | Nothing to turn off: it stays inside your browser |
This content is processed on your device and is gone as soon as the suggestion is produced. It is never uploaded.
3.2 Data saved locally on your device
WritePair saves a small amount of data in your own browser so its features work. This data never leaves your device, and you can view, edit, or erase all of it from the WritePair settings page.
| Data | What it contains | Default | Your control |
|---|---|---|---|
| Settings | Your preferences: feature toggles, default tone, preferred language, keyboard shortcuts, Privacy Mode, the list of sites you muted WritePair on, and any custom Ask AI quick actions you pinned | Always on (local only) | Change any time in Settings |
| History & favorites | Suggestions you accepted — the source text and the generated result, length-capped and limited to a small number of recent entries (favorites are pinned) | On | Toggle History off; remove single entries or Clear history in Settings |
| Ask AI instructions | The most recent free-form instructions you typed into Ask AI (for example "make this a bullet list"), kept as a short, length-capped list of quick picks | On | Shares the History toggle; Clear recent instructions in Settings |
| Writing-style profile | A bounded, length-capped set of samples of your own writing, plus aggregate style signals (e.g. average sentence length), used to gently match your voice | On | Toggle Style learning off; Clear the profile in Settings |
| Usage analytics | Anonymous counts of which feature ran (never what you wrote), plus aggregated error names/messages (no stack traces, no page content) | On (opt-out) | Turn "Help improve WritePair" off in Settings; review and clear all of it there too |
| Autocomplete measurements (only if you turn the experimental inline autocomplete on) | How fast each suggestion arrived, how long it was, and whether you accepted it — timings and a yes/no, never the suggested or typed text | Off (the feature is off by default) | Toggle the experimental autocomplete off |
Notes:
- History, your recent Ask AI instructions, and the style profile can contain text you wrote. That text stays on your device only; it is never transmitted. You can clear it at any time, and uninstalling the extension removes it entirely.
- Analytics is anonymous and on by default — and you can turn it off. It records only a counter for a fixed list of feature events and aggregated error signatures — never the content of what you wrote. These counters are kept on your device for you to review and wipe, and the same non-content signatures are sent to our diagnostics providers (§3.3) to help us improve WritePair. Turn off "Help improve WritePair" in Settings to stop both.
3.3 Operational data (the only data that leaves your device)
This is the complete list of data WritePair transmits. It is non-content — it never includes the text you write, your selections, the pages you browse, your history, or your style profile — and it is handled only by the extension's own pages, never by the part of WritePair that runs on the pages where you type.
| Data | What it is | When it is sent | Recipient |
|---|---|---|---|
| Anonymous identifier + profile | A random ID with no name/email, plus its creation time. Your plan is not stored here — it is keyed to your sign-in email (below) | On first run | Google Firebase (our infrastructure provider) |
| Payment details | Your name, email and card details — given to Paddle, never to us. Paddle is the merchant of record (the seller); we receive only the resulting plan (keyed to your email), never your card or your billing identity | Only if you buy Pro | Paddle (our payment provider and merchant of record) |
| Email address + plan | The email you sign in with to use Pro, and the plan stored under it (which plan, its status, its renewal date). Signing in with this email is how any device unlocks the Pro you paid for; never used to contact you, never linked to anything you write | When you buy Pro and sign in — required to use Pro; the free tier needs no email | Google Firebase (authentication) |
| Feedback metadata | Your anonymous ID, the app version, and your OS/architecture | Only when you click Feedback or Roadmap | Featurebase (our feedback portal) |
| Crash reports & usage analytics | Anonymous feature counts, error signatures, your non-content settings (toolbar layout, interface language, which toggles are on, on-device AI support, and bucketed counts of muted sites / custom actions), and banded engagement/performance measures — never your text, never the site names, never your instructions; on-screen text masked | On by default (turn off in Settings) | Sentry, Microsoft Clarity |
3.4 What WritePair never collects
- We do not collect your name, phone number, card details, or any password — the identifier in §3.3 is random and anonymous, not tied to your real identity. This stays true even if you buy Pro: your name and card go to Paddle, the merchant of record, never to us. The one thing we do hold is the email you sign in with to unlock Pro — used only to carry your plan to your devices, never to contact you and never joined to anything you write; the free tier needs none.
- We do not collect or transmit the text you write, your selections, your page content, your email threads, your history, or your learned writing style.
- We do not collect your browsing history, the list of sites you visit, or any advertising identifiers, and we do not use fingerprinting or cross-site tracking.
- We do not sell or rent your data to anyone.
4. Privacy Mode and per-feature controls
WritePair is private by default, and gives you stronger, explicit controls on top:
- Privacy Mode — turn it on for a sensitive page and WritePair will not read that page's content, will not save history from it, and will not learn writing style from it. Nothing about that page is read or persisted.
- Per-feature toggles — context awareness, the email assistant, style learning, history, and analytics can each be turned off independently at any time. Toggles take effect immediately.
- Sensitive fields are never touched. Password, one-time-code and payment fields are never adopted by WritePair — and that one is not a setting you can turn back on.
5. Permissions WritePair requests
WritePair asks only for what it needs to work as an in-field writing assistant, and no permission is used to collect or transmit your data:
- Storage — to save your settings and the on-device data described in §3.2 in your browser's local storage. This data never leaves your device.
- Access to the pages where you write (host access to the sites you use) — so the toolbar can appear in, read from, and write back to the text field you are actively working in. Because you write on many different sites, this access is broad by necessity, but WritePair only ever reads or edits the field you are using, and it does all of that work locally — it never uses this access to read your browsing or send anything anywhere. The same access lets the popup show you the site you are on and run an action on it; that address is shown to you and never stored or transmitted.
- Context menus — to add the "WritePair" entry to your right-click menu, so you can run the same on-device actions from there. The menu reads nothing on its own: a click simply tells WritePair which action you chose.
WritePair requests no permission that enables collection or network transmission of the content you write. The extension does connect to our operational services (the anonymous-identity provider and, when you open it, the feedback portal) for the non-content data described in §3.3; those connections never carry your writing.
6. Your rights and how to exercise them
Because your WritePair data lives only on your device and we never receive it, you exercise your privacy rights directly, instantly, and without asking us:
- Access / see your data — open the WritePair settings page to view your settings, history & favorites, learned style profile, and analytics.
- Rectify / edit — change your settings, remove individual history entries, or pin favorites.
- Erase / delete — clear your history, clear your recent Ask AI instructions, wipe your style profile, clear analytics, or uninstall the extension to remove all WritePair data from your device.
- Restrict / object to processing — turn off any feature (context awareness, email assistant, style learning, history, analytics) or enable Privacy Mode.
- Data portability — your data is plain text in your local browser storage and is yours.
If you are in the European Economic Area, the United Kingdom, or another region with data-protection laws (e.g. GDPR/UK GDPR), see §7. If you are a California resident (CCPA/CPRA): WritePair does not collect, sell, or share personal information, so there is nothing to opt out of — but the same local controls above apply.
7. GDPR / UK GDPR notice (EEA & UK users)
WritePair is built on data minimisation and privacy by design and by default (GDPR Articles 5(1)(c) and 25): the most private way to handle your data is to never collect it, and that is exactly how WritePair is engineered.
- We are not a controller or processor of your content. WritePair's publisher does not collect, receive, transmit, or have any access to the text you write or the pages you browse. That content is processed locally by software running on your own device and under your sole control; there is no transfer of your content to us or to any third party.
- We are the controller of a minimal set of non-content operational data (§3.3) — an anonymous identifier, the feedback you choose to send, and anonymous diagnostics (on by default, off with one switch). We process it to operate and improve WritePair, using infrastructure providers (e.g. Google Firebase, Featurebase) as our processors/sub-processors under their data-processing terms.
- International transfers. This operational data may be processed on our providers' servers outside your country, under the safeguards (such as Standard Contractual Clauses) those providers offer. Your content is never transferred, because it never leaves your device.
- Legal basis. To the extent any optional, user-enabled feature involves additional local processing (context awareness, email assistant, style learning, and diagnostics), it is subject to your own choice — your consent — which you can withdraw at any time by toggling the feature off, with no loss of the core writing features.
- Your data-subject rights (access, rectification, erasure, restriction, objection, portability) are satisfied by the on-device controls in §6, which you can use yourself at any time without contacting us.
- Retention. Locally saved data persists on your device until you clear it or uninstall the extension; history and the style profile are size-capped. We retain nothing, because we receive nothing.
- Automated decision-making. WritePair produces writing suggestions you can Replace, Regenerate, or Dismiss. It makes no decision that has a legal or similarly significant effect on you.
If you believe your data-protection rights have been infringed, you may contact us at privacy@writepair.app or lodge a complaint with your local supervisory authority.
8. Children's privacy
WritePair is a general-purpose writing tool and is not directed at children. It does not knowingly collect any personal data from anyone — including children — because it does not collect personal data at all.
9. Data security
The strongest protection for your data is that it never leaves your device, so there is no server, database, or transmission for an attacker to target. Locally saved data is held in your browser's standard extension storage and is protected by your operating system and browser profile security. We recommend keeping your browser and device up to date and using your OS account protections.
10. Changes to this policy
We may update this policy as WritePair evolves. Material changes will be reflected by an updated "Last updated" date above and, where appropriate, noted in the extension or on this page. Continued use after an update means you accept the revised policy.
11. This website (writepair.app)
Campaign tags. If you arrive from an ad or a link that carries
utm_* parameters, we keep them for the life of the browser tab
(sessionStorage, never a cookie) and pass them on to the Chrome Web Store
listing if you click "Add to Chrome". They describe the visit — which ad, which
link — not you: there is no identifier in them, and they are gone when you close the tab.
It is the only way we can tell which of our own pages and campaigns actually help people
find WritePair.
Everything above is about the extension. This website is a separate thing, and it is worth being just as clear about it.
- Google Analytics (GA4). We use it to see how many people visit and which pages they read. It sets cookies.
- It is opt-in where consent is required. In the EEA, the UK and Switzerland, Google Consent Mode v2 denies analytics storage by default, and the cookie banner asks before anything is set. Decline and no analytics cookies are stored. You can change your mind any time with the Cookies link in the footer.
- Cloudflare Web Analytics — cookieless, and that is the point. Cloudflare already serves this site, so it sees the request either way. Its analytics add a count of page views on top: no cookie, no browser storage, and no identifier that follows you between visits, which is why it is not part of the cookie banner and why declining the banner does not switch it off — there is nothing stored to decline. It is what lets us see a page's traffic honestly, including the visitors who said no to Google Analytics.
- Paddle on two pages: the checkout, and the home page. The checkout page loads Paddle's script because that is the payment form. The home page loads it for Paddle Retain, which exists for one thing: if you are a Pro subscriber whose card just failed, it offers you a one-click way to update it instead of losing your subscription. Paddle sees the visit (your IP address and that you loaded the page); it stores nothing in this site's own cookies or browser storage, and it never sees anything you write — the extension and this website share no data in either direction. No other page loads it. Our own pages take their font from a privacy-friendly mirror rather than Google; the one exception is that recovery dialog, which is Paddle's and fetches its font from Google Fonts. It is only ever drawn for a subscriber whose payment has already failed.
- The website's analytics and the extension are completely separate. Visiting this site tells us nothing about what you write in the extension, and the extension does not report your browsing to this site.
Fonts are served from Bunny Fonts, a privacy-friendly host that does not set cookies or log identifying data.
12. Contact
Questions about this policy or your privacy:
- Email: privacy@writepair.app
- Web: https://writepair.app/privacy
WritePair: your AI pair for every word you write — and every word stays yours.