Privacy Policy
Last updated: June 27, 2026
This policy describes how the Just Writeweb application ("we", "us", or "the service") handles personal information when you use the site (including sign-in, editing books, beta reading, and related features).
1. Who is responsible
The data controllerfor personal data processed through this deployment is the person or organization operating this website (for example, the author or publisher who runs the app). If you access the service through someone else's project, they may also act as a controller for content and invitations they manage.
For privacy questions about this deployment, contact the site operator using the support channel they provide (for example the email shown in your account or invitation).
2. What we collect
- Account information when you sign in (for example name, email address, and profile image) from your chosen provider (such as Google or Facebook), processed by our authentication provider (NextAuth) and stored in our database.
- Content and usage you create or upload in the app, including books, chapters, comments, notes, questionnaires, and beta-reader responses tied to your account.
- Technical data typical of web hosting, such as IP address, browser type, timestamps, and cookies/session identifiers needed to keep you signed in and secure the service.
- Billing and subscription informationwhen you purchase a paid plan, including your name, billing email address, billing address, the plan you purchased, and your subscription/payment status (active, cancelled, past due, etc.). See "Payment processing" below for details on how this is handled.
3. How we use your information
- To provide, maintain, and improve the service.
- To authenticate you and enforce access (for example, book owner vs beta reader).
- To send transactional emails when you use magic-link sign-in (if enabled).
- To process payments, manage subscriptions, and send billing-related notices (such as receipts, renewal reminders, or failed-payment alerts).
- To comply with law and protect rights, safety, and integrity of users and the service.
4. Payment processing
Paid plans are billed through Stripe, Inc., a third-party payment processor. When you subscribe, your payment card details are entered directly into Stripe's secure, PCI-compliant systems — we do not collect, see, or store your full card number, CVC, or other full payment card data on our servers.
We store limited billing-related identifiers needed to manage your subscription, such as your Stripe customer ID, subscription ID, selected plan, and subscription status. Stripe may also independently collect and process information (for example for fraud prevention) under its own privacy policy, available at stripe.com/privacy.
5. Legal bases (EEA/UK users)
Where the GDPR applies, we rely on:
- Contract — processing necessary to provide the service you asked for (account, books, collaboration).
- Legitimate interests — for example security, abuse prevention, and product improvement, balanced against your rights.
- Consent — where we ask for it (for example optional communications or non-essential cookies, if offered).
6. Sharing and subprocessors
We may share data with service providers needed to run the service, for example:
- Hosting and database providers where the application and data are stored.
- Authentication providers (for example Google, Meta/Facebook) according to their policies and your settings.
- Email delivery providers if magic-link sign-in is enabled.
- Stripe, our payment processor, to process subscription payments and manage billing (see "Payment processing" above).
We do not sell your personal information.
7. Cookies
We use a small number of cookies that are necessary for the service to work, such as session cookies that keep you signed in and security cookies (for example CSRF protection). Our payment processor, Stripe, may also set cookies during checkout and in the billing portal for fraud prevention. We do not use third-party advertising cookies. You can control cookies through your browser settings, though disabling necessary cookies may prevent you from signing in or completing a purchase.
8. Retention
We keep account and content data for as long as your account is active and as needed to provide the service. You may request deletion of personal data as described on our Data deletion page. Billing records may be retained longer where required for tax, accounting, or fraud-prevention purposes. Some records may be retained where required by law or for legitimate security/audit needs.
9. Security
We use industry-standard measures appropriate to the service (such as encrypted connections where configured, access controls, and secure handling of credentials). No method of transmission over the Internet is completely secure.
10. International transfers
If you are in the EEA/UK, your data may be processed in countries outside your region where our hosting or subprocessors operate. We use appropriate safeguards where required (for example contractual clauses).
11. Your rights
Depending on your location, you may have the right to:
- Access, correct, or update your personal information.
- Request erasure, restriction, or objection to certain processing.
- Data portability where applicable.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority.
To exercise these rights, contact the controller using the contact information above. We may need to verify your identity before responding.
12. Children
The service is not directed at children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children.
13. Changes
We may update this policy from time to time. The "Last updated" date will change when we do. Continued use of the service after changes constitutes acceptance of the updated policy where permitted by law.