TidyWrite Privacy Policy

Last updated: July 2, 2026

Provider: TidyWrite, operated by its individual developer ("TidyWrite", "we", "us"), based in Brazil.

Contact: opedrovmc@gmail.com

TidyWrite is a real-time writing assistant for English. It checks spelling and grammar and offers AI-powered rewriting, tone adjustment, and paraphrasing, through a browser extension and a macOS app. This policy explains what we collect, how your writing is processed, and the choices you have.

TidyWrite is operated from Brazil and serves users internationally. We apply the Brazilian LGPD as our baseline and honor the additional rights granted by the GDPR (EU/UK) and the CCPA/CPRA (California) where they apply to you.


1. The short version

  • Your writing is not stored on our servers. Spelling/grammar checking runs locally on your device (the Harper engine). We never see that text.
  • For AI features (rewrite, tone, paraphrase, and the AI grammar check), the relevant text is sent to our backend and forwarded to our AI provider only to produce the result. We do not save the text, and we do not use it to train any model.
  • We keep the minimum needed to run accounts and billing: your email, a hashed password, usage metadata (which feature you used and the length of the text — never the text itself), and your subscription status.
  • Payments are handled by a third-party payment processor. We never receive or store your card number.

2. Information we collect

2.1 Account information

When you create an account we store your email address and a bcrypt hash of your password (we never store the password itself). We also store an account status and creation date.

2.2 The text you write

  • Local checking (no transmission). Basic spelling and grammar checking is performed on your device by the Harper engine. This text does not leave your device and is not sent to us.
  • AI features (transient transmission). When you invoke an AI feature — Rewrite, Adjust tone, Paraphrase, or the AI grammar check — the necessary text is sent over an encrypted connection to our backend and forwarded to our AI provider to generate the result. We do not persist this text in our database or logs; our servers record only metadata about the request (the feature name and the number of characters) for abuse prevention and billing integrity. We do not use your text to train models. This description was verified against the deployed backend code on July 2, 2026.

2.3 Usage metadata

For each AI request we store: the feature used, the input length (character count), whether it was served from cache, a timestamp, and the associated account. This lets us prevent abuse and keep billing honest without retaining your content.

2.4 Billing information

Subscriptions are processed by a third-party payment processor. The processor collects and stores your payment details directly; we never receive your full card number. We store a mirror of your subscription state (the processor's customer and subscription identifiers, plan, status, current period end, trial end) so the app knows whether your access is active.

2.5 Waitlist

If you join the waitlist on our website, we store your email address and the source of the signup, so we can notify you at launch.

2.6 Diagnostics (error monitoring)

We use a third-party error-monitoring service to capture application errors. Our configuration strips request bodies, cookies, and headers from every report and disables the collection of personally-identifying data, so the text you write is not included in error reports. This configuration was verified in the production build on July 2, 2026.

2.7 Personal dictionary (browser extension)

Words you add to your personal dictionary in the browser extension are stored locally in your browser (chrome.storage.local) and are not sent to us.


3. How we use information — and the legal basis for each use

UseData involvedLegal basis (LGPD / GDPR)
Provide the service: accounts, login, AI featuresEmail, password hash, text submitted to AI features (transient)Performance of a contract (LGPD art. 7(V); GDPR art. 6(1)(b))
Process payments, trial, and subscriptionEmail, subscription state (payment details handled by the processor)Performance of a contract, and legal obligation for tax/accounting records
Prevent abuse and keep billing honestUsage metadata (feature, character count, timestamps)Legitimate interest (LGPD art. 7(IX); GDPR art. 6(1)(f)) — protecting the service from cost abuse, with no content retained
Diagnose and fix errorsScrubbed error reports (no text, no request bodies)Legitimate interest — keeping the service working
Account, security, and legal noticesEmailPerformance of a contract
Product updates / launch notification (waitlist)EmailConsent (LGPD art. 7(I); GDPR art. 6(1)(a)) — you can withdraw at any time via the unsubscribe link or by emailing us

We do not perform automated decision-making with legal effects, and we do not use your data for profiling or advertising.


4. Who we share it with (sub-processors)

We do not sell your personal data. We share the minimum necessary with service providers that process data on our behalf:

CategoryPurposeData shared
AI providerGenerate AI results for the text you submit to an AI featureThe submitted text (transiently), no account identity beyond what's needed to make the request
Payment processorPayments, trial, subscription managementEmail, payment details (collected by the processor directly)
Error-monitoring serviceApplication error diagnosticsError/diagnostic data (scrubbed of request bodies)
Hosting providerHosting the backend and databaseAll backend-stored data at rest

4.1 About the AI provider

Text you submit to an AI feature is processed by our AI provider, a company headquartered in the People's Republic of China; according to its public privacy documentation, the data it collects is stored on servers located in the People's Republic of China. Under the provider's current public terms (as of July 2026), data submitted through its paid API is not used to train models by default and is retained only for a limited period.

What we do to minimize what the provider can see:

  • We send only the text needed to produce the result you asked for — never your name, email, or account identity. Requests are made under TidyWrite's own API account, so the provider cannot link the text to you.
  • Identical AI grammar checks are served from our own cache, so repeated text is not re-sent to the provider.
  • If you do not want any text processed by the AI provider, simply don't invoke the AI features — local spelling/grammar checking never leaves your device.

5. Data retention

  • Text submitted to AI features: not retained by us (processed transiently). Any retention on the AI provider's side is governed by that provider (see §4.1).
  • Account data: kept while your account exists; deleted (or anonymized) within 30 days of account closure, subject to the legal retention requirements below.
  • Usage metadata: kept for 12 months, then deleted or anonymized. We keep it this long for abuse prevention and billing-dispute resolution.
  • Billing records: kept for 5 years, as required by Brazilian tax and accounting law.
  • Waitlist emails: kept until launch notification is sent and you have had the chance to create an account, or until you ask us to remove you — whichever comes first.

6. Your rights

Wherever you live, we honor the following rights over your personal data:

  • Access — receive a copy of the data we hold about you.
  • Correction — fix inaccurate or incomplete data.
  • Deletion — have your account and associated data deleted (subject to the legal retention requirements in §5).
  • Portability — receive your data in a structured, machine-readable format.
  • Objection / restriction — object to or restrict processing based on legitimate interest.
  • Withdraw consent — for anything based on consent (e.g. the waitlist), at any time, without affecting prior processing.
  • Information about sharing — know which categories of processors handle your data (see §4).

California residents additionally have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information — noting that we do not sell or share personal information as defined by the CCPA/CPRA — and the right not to be discriminated against for exercising these rights.

How to exercise them: email opedrovmc@gmail.com from the address associated with your account (that is how we verify it's you; if you no longer control that address, we will ask for reasonable additional verification). We respond within 15 days where the LGPD applies, one month where the GDPR applies, and 45 days where the CCPA applies. If we refuse a request, we will explain why, and you may appeal by replying to our decision; you may also complain to your local data protection authority (in Brazil, the ANPD).


7. Security

We protect data in transit with TLS and at rest on our hosting provider. Passwords are stored only as bcrypt hashes. Access to production systems is restricted. No method of transmission or storage is 100% secure.

8. International transfers

We operate from Brazil. Our sub-processors store data in other countries — notably the United States (payment processing, error monitoring, hosting) and the People's Republic of China (the AI provider, for text transiently submitted to AI features — see §4.1). Where we transfer personal data internationally, we rely on the sub-processor's data-processing terms, including standard contractual clauses where the sub-processor offers them, together with the technical safeguards described in this policy (encryption in transit, no persistence of your text on our side, and no account identity attached to text sent to the AI provider). Under the LGPD, these transfers rely on art. 33 (contractual guarantees and the necessity of the transfer to perform the contract you requested).

9. Children

TidyWrite is not directed to children under 16. We do not knowingly collect data from them; if you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We may update this policy. Material changes will be announced in-app or by email, and the "Last updated" date will change.

11. Contact

Questions or requests: opedrovmc@gmail.com.