Draft — not yet reviewed by a lawyer.
Privacy
What Weekwrite holds about you, why, for how long, and who else sees it. No IP addresses in our records, no tracking cookies, no data sold.
Last updated [TO DECIDE: date]Who is responsible
Weekwrite is run by [COMPANY NAME, Y-TUNNUS, ADDRESS]. We are the controller for your account, billing, sign-in and the funnel tracking described below.
For the content of the websites you add, we act as your processor under our data processing agreement, which we give every customer on request. [TO DECIDE: publish it at a fixed address.]
Your account
Your email address. If you sign in with Google, also your name and your Google account id; we ask Google for nothing more than that.
Sign-in links are stored only as a hash, work for 15 minutes, and are deleted after they expire.
Your answers in the setup screens, and the settings of each site you add: its address, brand name, audience, tone, facts and contact details you type in.
Cookies
We set three cookies, all strictly necessary, so there is no cookie banner. The sid cookie keeps you signed in for 30 days. The oauth_state cookie lasts 10 minutes and protects the Sign in with Google step. The ww_vid cookie is set only when you vote on the feedback page without signing in; it holds a random id, nothing else, so your vote counts once, and lasts 1 year. We set no analytics or advertising cookies.
Billing and the free trial
Stripe collects and holds your card, billing address and VAT number. We keep only the Stripe customer id, the subscription id and status, the number of sites paid for, when the trial ends, and the fingerprint Stripe gives for your card. The card fingerprint is a code that identifies a card without revealing its number. We use it only to make sure each customer gets one free trial.
Your sites and articles
The public pages of the sites you add, as we crawled them. This can include names and facts about people that you published there.
The topics, drafts and articles we write, and their status.
Publishing access you connect, such as a WordPress, Ghost, Webflow or Shopify credential or a webhook secret. The secret is encrypted with AES-256-GCM before it is stored.
If you connect Google Search Console: daily clicks and impressions for the site, and search terms per week, which we keep for 13 weeks. Google leaves out rare queries before we receive them.
AI-visibility checks: the questions we ask AI assistants about your market and their answers. Full answers are kept 2 weeks, weekly summaries 52 weeks.
The AI crawler log on blogs we host: which known AI crawler fetched which article, on which day. No IP address and no other header is kept, and days older than 30 are deleted.
Deleting a site deletes all of this for that site at once. Articles already on your site stay there.
The waitlist
If you joined the waitlist, we hold your email address and which form you used. We use it for one email about Weekwrite, and nothing else. [TO DECIDE: when the waitlist is deleted.]
Feature requests
If you request a feature, we store its title and details, your account or the email you gave if you gave one, and the date, and we email it to ourselves when it arrives. The title and details are shown on the public feedback page, after we have read them if you were not signed in; your email is not. Your votes are stored with your account. If you vote without signing in, your vote is stored with the random id in the ww_vid cookie. We keep a request and your votes until you ask us to delete them.
How we measure our own marketing
We record the steps a visit takes on our own site and in the app, first-party and on our own server: which page a visit landed on, the campaign fields in the link (utm_source, utm_medium, utm_campaign, utm_content, utm_term), an ad click id if the link carried one (for example gclid or fbclid), the name of the referring website (not the full address), and later steps such as signing up, each setup screen reached, starting a trial, the first article written, viewed, approved and published, paying, renewing and cancelling.
We store no IP address with these records, do no fingerprinting of your browser or device, set no cookie for this, and use no third-party analytics.
To connect a visit to a later sign-up, the links on our pages carry a signed parameter (t=...) for up to 30 days. It identifies the visit, not you. It is not shared with any ad platform or third party for their own use; it passes through our hosting and email providers as part of a link, for example in a sign-in email.
When you sign up, the first and the last campaign and ad click id that brought you are stored on your account, so a payment later can be credited to the campaign that brought you. The campaign is kept for as long as the account exists.
Tracking records are deleted after 13 months. Ad click ids are kept 90 days, on these records and on your account, and then cleared.
If your browser sends the Global Privacy Control signal, we record the visit without the click id and carry nothing to sign-up.
You can object at any time by writing to us. We will delete these records and clear the campaign stored on your account, so later steps carry no campaign.
Today we send none of this to any ad platform. Before we ever upload conversions to one, we will update this page first.
Business contacts we email
We sometimes email people at agencies and small businesses whose job fits what Weekwrite does, such as the person who runs client websites or a company's own site. We found your name, work email and role on a public page of your company's website, and we keep that page's address and the date with it. We did not buy or scrape a list.
We use this only to write to you about Weekwrite: one email and at most one follow-up. The basis is our legitimate interest in offering our service to businesses it fits (Art. 6(1)(f)).
If you do not become a customer, we delete your row. [TO DECIDE: how long after the last email; suggested 12 months.]
You can object at any time, free of charge: reply "no" to any of our emails, or write to us. We then stop at once. Under Art. 21(3) we may no longer use your data for marketing, so we keep only your work email and the date on a do-not-contact list, for as long as we email anyone, so we never write to you again.
Security and abuse limits
To stop abuse, we count sign-in link, waitlist and feature requests per IP address, in memory only, for about an hour. The IP is not written to our database.
Who else sees data
AI providers write and check articles and answer the visibility questions: Google Gemini by default, and OpenAI as a fallback. They receive page text, site details and topics, not your account data.
Stripe handles payment and VAT. Google handles Sign in with Google and, if you connect it, Search Console.
An email provider sends sign-in links and reports. [TO DECIDE: name it; assumed Postmark.]
Render hosts the app and the database in Frankfurt, Germany. Render keeps its own request logs, which may include IP addresses. [TO DECIDE: how long Render keeps them.]
Our marketing pages load fonts from Google Fonts, so Google receives the IP address of the visitor's browser when it fetches them.
We do not sell personal data, rent it, or pass it to anyone for their own use.
Transfers outside the EU
Some of these providers may process data outside the EU, in particular in the United States. Where they do, the transfer rests on the EU-US Data Privacy Framework or on Standard Contractual Clauses. [TO DECIDE: which one for each provider.]
Why we may use it
To provide the service you signed up for: your account, sites, articles, billing and sign-in (contract, GDPR Art. 6(1)(b)).
Our legitimate interest in measuring which marketing brings customers, keeping the service secure, and preventing repeat free trials (Art. 6(1)(f)). You can object to this.
To meet our legal duties, such as keeping bookkeeping records under the Finnish Accounting Act (kirjanpitolaki) for 6 or 10 years; invoices are held by Stripe (Art. 6(1)(c)).
How long we keep it
The periods above apply where named. Everything else is kept while your account or the site exists. [TO DECIDE: how long an account is kept after it is closed, and how long backups keep deleted data.]
Your rights
You can ask to see your data, correct it, delete it, restrict it, object to its use, or get a copy to take elsewhere. Write to us and we will answer within one month. You can also complain to the Finnish Data Protection Ombudsman at tietosuoja.fi.
Contact
[COMPANY NAME, Y-TUNNUS, ADDRESS]. Write to us there about anything on this page.