Legal

Privacy Policy

Last updated: 13 August 2026

What we collect, why we need it, and how your manuscript and account data are handled.

1. Who this applies to

This Privacy Policy explains how Blocwrite (“we”, “us”) collects and uses personal data when you visit blocwrite.com, create an account, use Studio, contact support, or interact with share links. It should be read with our Terms & Conditions and Refund Policy.

2. Controller and contact

For UK GDPR / data protection purposes, the controller of personal data processed through the Service is the operator of Blocwrite, contactable at customerservice@blocwrite.com. We operate from the United Kingdom. If you have a privacy request (access, erasure, etc.), use that address and include the email on your account.

3. Data we collect

Depending on how you use Blocwrite, we may process:

Account data — email address, name (if provided), password hash, profile image if you upload one, and similar account settings.

Manuscript and workspace data — novels, chapters, plan/codex entries, comments, checkpoints, covers, format settings, and related Studio content you create or import, stored so the product can function and sync.

Billing data — subscription status, plan, trial dates, customer and subscription identifiers from Stripe. Lite and Pro trials require a payment method collected by Stripe at Checkout; card numbers are handled by Stripe and we do not store full card PAN data on our servers.

Usage and technical data — login sessions (cookies), approximate timestamps of access, product events needed to operate features, IP address and browser/user-agent as typically seen by our hosting stack, and support correspondence.

Share / reader data — when you create a share link, recipients may leave highlights or comments tied to the chapters you shared; you control who receives the link.

Marketing — if you are eligible for product emails, we may process email preference and unsubscribe tokens. You can opt out of marketing mailshots where offered.

4. Why we use data (purposes and legal bases)

We process personal data to: create and secure accounts; provide Studio features under trial or paid plans; sync and back up workspaces; process subscriptions and prevent fraud/abuse; send transactional email (verification, security, billing); provide customer support; improve reliability and fix bugs; and comply with law. Legal bases under UK GDPR typically include contract (providing the Service you requested), legitimate interests (security, abuse prevention, product improvement — balanced against your rights), consent where required (for example certain cookies or marketing), and legal obligation where we must retain or disclose information.

5. AI features and your key

Optional Assist / Companion features send prompts and relevant context to the AI provider behind the API key you connect. That traffic is processed by that provider under their terms. We do not sell your manuscript as training data and do not train Blocwrite’s own models on your writing. Avoid pasting secrets into prompts. Turn Assist off if you do not want that processing.

6. Processors and sharing

We use service providers who process data on our instructions, such as: hosting/infrastructure; Stripe (payments); email delivery; and, if you enable Assist, AI API providers you choose. We may disclose data if required by law, to protect rights and safety, or in connection with a business transfer (with appropriate safeguards). We do not sell your personal data or your manuscripts.

7. International transfers

Some processors may store or process data outside the UK. Where that happens we rely on appropriate safeguards recognised under UK data protection law (for example standard contractual clauses or the provider’s approved transfer mechanism), unless an exception applies.

8. Retention

Account and workspace data are kept while your account is active. After access ends or you delete your account, we may retain manuscripts for a short retention window (typically about 30 days) for restore or abuse investigation, then delete server copies, unless a longer period is required for legal claims, security, or accounting (for example Stripe billing records). Backups may persist for a limited time before rolling off. You should export work you want to keep.

9. Cookies and similar technology

We use essential cookies and similar storage for authentication (session), security, and core product preferences (for example theme). These are necessary to operate the logged-in Service. We do not use advertising trackers as a core part of Studio. Your browser controls can block cookies, but login and Studio may not work without essential cookies.

10. Your rights

Under UK GDPR you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability, and to withdraw consent where processing is consent-based. You may complain to the UK Information Commissioner’s Office (ICO). To exercise rights, email customerservice@blocwrite.com. We may need to verify your identity. Some rights are limited where we must keep data for legal or security reasons, or where erasure would prevent us providing the Service you still use.

11. Children

Blocwrite is aimed at adults. The Service is not directed at children under 16. If you believe we have collected personal data from a child without appropriate authority, contact us and we will take steps to delete it.

12. Security

We use reasonable technical and organisational measures to protect accounts and workspaces (including hashed passwords and access controls). No method of transmission or storage is perfectly secure; you are responsible for password strength and for securing devices you use to access Studio.

13. Changes

We may update this Privacy Policy from time to time. The “Last updated” date will change. Material changes may be notified by email or in-product notice where practical. Continued use after the effective date means you acknowledge the updated Policy.

14. Contact

Privacy requests: customerservice@blocwrite.com · Contact page.