Privacy Policy
Last updated: 8 September 2026
This policy describes how Schreibly processes personal data when you use our website and writing-assistance service. It applies to all Schreibly surfaces: the website and account dashboard, the browser extension, and the macOS and Windows applications.
1. Who we are β the controller
The controller responsible for the processing described here, within the meaning of the General Data Protection Regulation (GDPR), is:
| Provider | Codexo |
| Owner | Ahmad Al Alloush |
| Address | Dietmarstr. 4, 87463 Dietmannsried, Germany |
| support@schreibly.com | |
| Website | https://schreibly.com |
The service is referred to below as "Schreibly", "we", or "us". Our full statutory provider details are on the imprint page.
We have not appointed a data protection officer; the statutory thresholds for a mandatory appointment are not met. Data-protection requests reach us at the address above and are handled by the provider directly.
2. What this policy covers
This policy covers the Schreibly browser extension, the macOS and Windows applications, the website and account dashboard, the spelling, grammar, context and writing-improvement services, and user accounts and subscriptions.
3. How the checking service works
When Schreibly is switched on, the client detects text in supported editable fields β text inputs, text areas, and content-editable elements in the browser, and the accessibility representation of an editable field on the desktop.
Password fields and hidden fields are excluded before any value is read.
The text of the active editable field is sent over an encrypted connection to Schreibly's servers so that we can identify spelling, grammar, context, punctuation and style issues, generate suggestions, and return them to your device for display in the page or application you are writing in.
Some of the work happens without leaving your device at all. A first spelling pass and the automatic language detection run locally, from data files shipped inside the client. Words that first pass flags may then be sent for verification, and everything beyond spelling is checked on our servers.
Text you enter may contain personal data, including data about other people. Please do not enter sensitive, confidential, or third-party personal data unless you are permitted to process it. See section 12.
4. What data we process, and why
4.1 Account and sign-in
When you create an account or sign in, your account is managed by Keycloak, an identity server we operate ourselves β it is not a third-party identity service, and your sign-in data is not passed to one. We process an internal account identifier, your email address, display name, subscription status and plan, your language preferences, and the correction categories you have enabled.
Before your account can be used, you are asked once to accept our Terms of Service and to confirm you have read this policy. We record that you did so: the date, and which version of each document you were shown. That record is what lets us show, later, which text you were actually given β it is an accountability record, not a consent, and it does not make your acceptance the legal basis for anything described here.
To protect your account, Keycloak also processes metadata about active sessions: your IP address, browser or device, and the session's start and last-access times. You can review those sessions and end other active sessions from the Security page in your account.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) for the account itself; our legitimate interest in account security (Art. 6(1)(f) GDPR) for the session metadata, which you may object to at any time (Art. 21 GDPR).
4.2 Text you submit for checking
Text you submit is processed for one purpose only: to check your spelling and grammar and return the corrections to your device. It is used for nothing else.
We never store it. It is not written to our databases, to durable storage, to analytics systems, or to our application logs. It exists only in volatile working memory β never on disk. When the field or page is closed, or the connection to Schreibly ends, the text held for that session is discarded, and nothing survives a restart of our servers. We keep no copy: there is no archive of your writing for us to search, export, sell, or hand to anyone else, because none was ever created.
It is never used to train, fine-tune, evaluate or improve any model β ours or anyone else's. It is not added to a training dataset, not sampled, and not retained for that purpose. Our model work uses separately prepared training, validation and evaluation material. There is no consent, no setting and no plan that changes this.
It is never used to build a profile of you, and we do not sell it or share it for advertising or marketing purposes.
If you explicitly ask for a rewrite, an explanation or a translation, the text you selected for that request is processed on exactly the same terms, and is likewise never stored.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
4.3 Usage counters
We count the AI actions and word credits used by your account so we can enforce plan limits and show you your remaining balance. Usage counters do not contain the text you submit.
This data is kept for the life of your account, with one exception. When you delete your account, the current month's action count is kept: it is that month's allowance rather than a record about you, and erasing it would turn account deletion into a way of resetting a monthly limit. Everything else in the usage record β token totals and the per-feature split β is erased with the account.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
4.4 Technical and connection data
Operating the service produces limited technical data:
- the application or extension version, and the selected language;
- request times, connection status, and processing duration;
- text length and the number of sentences or words;
- the number of issues detected and suggestions produced;
- error codes, and technical request or field identifiers;
- the IP address and connection data generated automatically when your client talks to our servers.
Our operational logs contain no user text, no prompts, no suggestions, and no model output. They record counts, timings, outcomes and identifiers.
Legal basis: our legitimate interest in a secure, reliable, debuggable service (Art. 6(1)(f) GDPR).
4.5 Storage on your device, cookies, and local storage
The clients store, on your device:
- the access and refresh tokens for your sign-in session, and the account information contained in the identity token (such as your name and email address);
- your selected language and preferences, whether Schreibly is switched on, the enabled correction categories, your ignored applications and sites, and your personal dictionary;
- on the website, the cookies required to keep you signed in and to remember your language.
Signing out deletes the Schreibly session data locally wherever the platform supports it. You can also remove this data by uninstalling the client or clearing its stored data through your browser or system settings.
We use no advertising cookies and no behavioural-tracking cookies.
4.6 Contact form
When you submit the contact form on our About page, we process your name, email address, subject and message, and forward them to SendGrid (a Twilio Inc. service, United States) solely to deliver the message to us and to reply. We do not use this data for marketing.
Legal basis: our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
4.7 Payments
When you buy a paid plan the payment is processed by Stripe. Card details are entered on Stripe's own hosted pages and never reach our systems. What we receive and store is the state of your subscription: the plan, its billing status, the period end, and Stripe's customer and subscription identifiers. Your internal account identifier is attached to the subscription so the purchase can be linked to your account; your email address is not used for that link.
Stripe processes payment data under its own privacy notice (stripe.com/privacy).
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and, for keeping billing records, our legal obligations (Art. 6(1)(c) GDPR).
4.8 Administration
Schreibly has an internal administration surface used for support β to look up an account's plan and usage, to grant an account additional AI actions, and to grant an account a paid plan for a limited period without a payment (for example a test account). Four properties of it are worth stating, because they are design decisions rather than current accidents:
- it never displays text you have written;
- it never displays your IP address;
- it cannot change your subscription β only Stripe's payment notification writes a subscription record. A plan an administrator grants is stored separately from that record, never touches it, and never affects what you are charged;
- it never sends anything to an AI model.
What a grant stores about you. A grant β of extra AI actions, or of a plan β is kept under the same pseudonymous account identifier as your settings, and holds what was granted, the monthly limit that applies, the date it ends, which administrator granted it, when, and a short note that administrator wrote explaining why. That note is free text about a specific person; it is limited to 280 characters, it is never shown to you, never sent to any app, and never written to our logs. It is erased when you delete your account.
Every grant is also recorded in an administration audit trail: which account was granted what, by whom, and when. That record describes the administrator's action, not you, and it holds no text you wrote.
Legal basis: performance of the contract and our legitimate interest in supporting and accounting for our own service (Art. 6(1)(b) and (f) GDPR).
5. The AI models
Schreibly's checking and writing features run open-source large language models that we fine-tune for the task. We do not publish which models we use or which company operates the computing infrastructure they run on: that is operational security information about our own systems. It also tells you nothing about what happens to your text β that is what the rest of this section is for.
What is sent to run a check is the text, sentence, or section that has to be checked, the selected language, and the technical instructions needed to perform the check.
Your name, email address, and internal account identifier are not sent with it. The client's user-identification field is switched off in production, so the request carries no account reference at all.
The company that operates that computing infrastructure acts as our processor and is bound by a data-processing agreement with us. Under it, the text exists in memory only while the request is being processed, is not written to disk during standard inference, is deleted from memory once processing finishes, and is not used to train any model. The provider is not permitted to use Schreibly users' text for its own purposes beyond providing the contracted service.
The text itself may of course contain personal data, if you put it there.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
6. Business and enterprise use
Schreibly may be used at work, including where an employer buys individual seats for its employees. Nothing in this section is a different product: it sets out how the promises above apply when the person paying is not the person writing.
Nothing about the handling of text changes for a business account. Employee text is processed exactly as section 4.2 describes β checked in volatile memory, never stored, never logged, never used to train any model. There is no tier in which we retain your staff's writing, and there is no setting an administrator, a reseller or we ourselves can switch on that would make us retain it.
Individual accounts stay individual. Paying for a seat does not give an employer access to that employee's account, their personal dictionary, their settings, or anything they have written. We provide no administrative view of employee text, and we could not build one without changing this policy first: there is no stored text to show.
Who is responsible for what. An organisation that provides Schreibly to its staff decides that the service is used and for which purposes, and is accountable for that decision under its own data-protection obligations. We remain the controller for operating the service itself, as described in section 1.
What the employer has to do. An organisation deploying Schreibly is responsible for telling its staff that it is in use, for establishing the legal basis for that under its own employment and works-council arrangements, and for deciding which categories of information staff may enter (see section 12). Employees remain able to exercise the rights in section 13 against us directly.
Data processing agreement. If your organisation requires a data processing agreement under Art. 28 GDPR, or has security, hosting or procurement questions, write to us at the address in section 1 and we will provide one.
We do not sell user text, and we do not share it for advertising or profiling.
7. How long we keep things
| What | How long |
|---|---|
| Text submitted for checking | Volatile memory only. Never persisted; nothing survives a restart. |
| Account data, settings, personal dictionary | For the life of the account. |
| Usage counters | For the life of the account, except the current month's action count (section 4.3). |
| Sign-in history | For the life of the account. |
| Terms acceptance record (date + version) | For the life of the account. |
| Contact-form messages | As long as needed to handle the enquiry and the correspondence around it. |
| Billing records and invoices | For the statutory period β books and records under Β§ 147 AO. |
| Administration audit trail | Kept beyond the account it concerns, so the decision stays accountable. |
What survives deleting your account
Deleting your account erases your settings and personal dictionary, your sign-in history, your token totals, the subscription record we hold, and anything an administrator granted you β both extra AI actions and any plan, together with the note explaining why it was granted. Connected applications are signed out at once.
Two things are deliberately kept, and you are told both on the deletion screen, in plain words, before you confirm β not afterwards, and not only here: the administration audit trail (section 4.8) and the Stripe customer record and its invoices (section 4.7). Nothing you wrote is among them, because none of it was kept in the first place.
One further technical trace is kept briefly: a note that this account was deleted, and when β the account identifier and a timestamp, nothing else, and nothing you wrote. It stops a payment notification arriving after the deletion from recreating the subscription record we have just erased, and it is removed automatically after 30 days, or as soon as the same sign-in starts a new subscription.
Deleting an account cannot be undone.
8. Legal bases, in one table
| Purpose | Legal basis |
|---|---|
| Providing the service: sign-in, checking, suggestions, preferences | Art. 6(1)(b) GDPR β contract, or pre-contractual steps at your request |
| Security, abuse prevention, session validation, error diagnosis | Art. 6(1)(f) GDPR β legitimate interest in a secure, reliable service |
| Billing, accounting and tax records | Art. 6(1)(c) GDPR β legal obligation |
| Answering contact-form enquiries | Art. 6(1)(f) GDPR β legitimate interest |
9. Who receives data
| Recipient | Role | Where |
|---|---|---|
| AI inference infrastructure provider | Runs the models that perform checking and writing (processor) | Outside the EEA β see section 10 |
| Stripe | Payment processing | EU / United States |
| SendGrid (Twilio Inc.) | Contact-form email delivery | United States |
| Server hosting provider | Hosts the Schreibly backend and website (processor) | Germany |
| Keycloak | Identity server β operated by us, not a third party | Our own infrastructure |
We do not sell personal data, and we do not share user text for advertising or marketing-profiling purposes.
10. Transfers outside the EEA
Some of our processors β the provider that operates our AI computing infrastructure, Twilio/SendGrid, and Stripe for parts of its processing β are established outside the European Economic Area, which can mean personal data is transferred outside it.
Such transfers take place only where an appropriate transfer mechanism exists: an adequacy decision, the provider's certification under an applicable data privacy framework, Standard Contractual Clauses adopted by the European Commission, or other appropriate safeguards. Write to us at the address in section 1 for details of the safeguards applied to a specific transfer.
11. Security
We apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for every connection between a Schreibly client and our services;
- verification of authentication tokens against our identity server's signing keys;
- separation of account data from checking requests β the inference request carries no account reference;
- exclusion of user text, prompts and model output from our operational logs;
- transient, in-memory-only processing of submitted text;
- limits on request size and on the number of simultaneously open fields;
- restricted administrative access, with every administrative grant written to an audit trail.
No electronic service can guarantee absolute security, and we do not claim otherwise.
12. Special categories of data, and confidential text
We check language, not content. Schreibly examines your text for spelling, grammar, punctuation and style. It does not assess what the text is about, and the subject you write about is not our concern: a crime novel, a news report about an offence, a legal brief, a history essay, or a blunt private message are all handled the same way β as sentences with language rules to check. There is no content filter in the service, no prohibited-words list, and no mechanism that flags, blocks or reports what you write. We will not withhold a correction or refuse a check because of your subject matter.
Nor is any of it recorded. Your text stays in volatile memory for as long as the check takes and is then discarded: it is not stored, not written to our logs, and never used to train a model (sections 4.2 and 5). Because no copy is kept, there is nothing in the content of your writing for us to read, review, or act on afterwards.
Section 4 of the Terms of Service asks you not to use Schreibly to produce unlawful content. That is an obligation on you; it is not enforced by screening your text, because we do not screen it.
Schreibly is still not intended for processing passwords, trade secrets, health data, biometric data, political or religious information, or other special categories of personal data under Art. 9 GDPR β not because we look for such data, but because the text does leave your device to be checked. Please do not enter them.
If you use Schreibly at work, it is your responsibility to make sure that doing so is permitted by your employer's or client's policies.
13. Your rights
Under the GDPR you have the right to information about and access to your personal data, to have inaccurate data corrected, to have your data erased, to have processing restricted, to object to processing based on our legitimate interests, to receive your data in a portable format, to withdraw consent where processing rests on consent, and to lodge a complaint with a supervisory authority.
Erasure is self-service. You can delete your account yourself from Security β Delete account. A free account is erased straight away, and you are then handed to our identity server to remove the sign-in itself. A paid account is not deleted mid-period: you can schedule the deletion for the day your paid period ends, and we will also ask Stripe not to renew the subscription. What is kept in either case is listed in section 7 and stated on the screen before you confirm.
To exercise any right β including an erasure you would rather we carried out for you β write to support@schreibly.com. We answer within the period required by data protection law.
You may lodge a complaint with the supervisory authority for your place of residence, your place of work, or the place of the alleged infringement. For our registered seat that is the Bavarian Data Protection Authority for the private sector (Bayerisches Landesamt fΓΌr Datenschutzaufsicht, Ansbach).
Using Schreibly, or accepting this policy, waives none of these rights.
14. Automated decision-making
Schreibly uses AI to generate language and writing suggestions only. It makes no decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
You are free to accept, reject or ignore any suggestion. Suggestions are not authoritative rulings on whether a text is correct, and they can be wrong β review them before you rely on them.
15. Children
Schreibly is not directed at children under 16. We do not knowingly collect the personal data of children under 16 without the consent of the holder of parental responsibility.
16. Changes to this policy
We may update this policy when the service, its infrastructure, or the legal requirements change. Where the law requires it, we will inform you appropriately about material changes before they take effect. The revision date is at the top of this page.
Contact
support@schreibly.com β for all data-protection requests, erasure requests, and questions about this policy.