Privacy Policy

Last updated August 16, 2026. This policy explains how SneakWrite handles account information, submitted content, usage records, and payment data.

Information we collect

Account and authentication data. An account is required to use the SneakWrite workspace. We collect your email address, display name, account identifier, authentication method, and account status. Authentication is provided through Supabase. If a social sign-in option is enabled, the relevant identity provider also processes the information required to authenticate you. Passwords are submitted directly to the authentication service and are not stored by SneakWrite in readable form.

Submitted content. We process text you paste and the mode, refinement level, and other settings you select to fulfil your refinement or AI-detection request. File content is processed only if and when a file-processing feature is made available and you choose to use it.

Usage and subscription data. We record your account identifier, the number of words processed, selected mode, request timestamp, plan, subscription status, plan dates, allowance usage, and related account settings. These records enforce plan limits, display usage, prevent abuse, and administer subscriptions.

Payment data. For purchases, we process your email address, selected plan, payment provider, transaction reference, amount, currency, status, and relevant timestamps. Paystack or Flutterwave handles checkout and card processing. SneakWrite does not receive or store your complete card number or card security code.

Service events. We may record product events such as account creation, refinement start or completion, AI-detection activity, pricing views, upgrade clicks, and successful payments. These events are stored in our own database using a strict allowlist of event names and properties such as plan, mode, level, word count, duration, status, and billing period. Document text, passwords, access tokens, provider keys, and full payment references are not included. We also record sanitised application error messages, with credentials and identifying tokens redacted, so we can diagnose failures. Third-party analytics providers receive these events only if an analytics integration is enabled later.

How we use information

We use this information to authenticate users, provide writing refinement and AI detection, enforce allowances and security controls, administer subscriptions, process payments, send transactional messages, troubleshoot failures, prevent misuse, and improve SneakWrite. We do not sell submitted documents or use them to build advertising profiles.

Document processing and storage

Submitted text is processed through SneakWrite's server-side infrastructure for the feature you request. To run a request reliably, the text you submit and the text we generate are stored temporarily in our processing database. This allows a processing job to continue if you close the tab and allows the service to return the result when the job finishes.

Retention: document text in completed and failed processing records is automatically scrubbed after it has been retained for approximately 24 hours. A scheduled database-maintenance job runs hourly and removes the submitted and generated text while retaining only non-content metadata such as timestamps, status, selected mode and level, and word counts for usage limits, security, billing accuracy, and support.

Your authentication session may be persisted in browser storage so you can remain signed in between visits. SneakWrite does not currently claim to provide browser-saved writing history unless that feature is explicitly shown in the product. Clearing browser storage removes locally persisted session data from that browser.

Account profiles, subscription data, and usage records are retained while your account remains active or as needed to provide and secure the service. Transaction records may be retained after account deletion for financial, fraud-prevention, dispute, and legal recordkeeping requirements.

Subprocessors used to deliver processing may hold request data transiently under their own retention practices, described in "Other service providers" below.

Secure AI processing

SneakWrite is a global software-as-a-service platform. To deliver writing-refinement and AI-detection features, we operate server-side workflows that may use selected automation infrastructure and specialist writing or detection processors.

Only the submitted text, selected settings, and limited technical metadata needed to perform, secure, and troubleshoot a request are processed. SneakWrite does not send your account password or payment-card information through its writing-processing workflows.

These workflows are designed to isolate requests and limit processing to delivering the service you selected. Information handled by subprocessors remains subject to the safeguards, retention practices, and international-processing disclosures described in this policy.

Other service providers

We share only the information needed for each provider's function. Current categories include Supabase and Lovable for application infrastructure and authentication, Browser Use for browser-automation infrastructure used in processing, configured specialist writing or detection processors used to complete requested jobs, Paystack or Flutterwave for payments, Brevo for transactional email, an identity provider if social sign-in is enabled, and an analytics provider only if optional third-party analytics is enabled. These providers process information under their own terms and privacy policies.

International processing

SneakWrite and its providers may process information in the United States or other countries where they operate. Privacy and data-protection rules in those locations may differ from those in your country.

Account deletion and user choices

You can sign out at any time and can permanently delete your account from the account page after completing the required confirmation. Clearing your browser storage also removes locally persisted authentication/session information from that browser.

Account deletion removes the authentication account, profile, role records, usage history, preferences, and security records associated with the account. Financial transaction records may be retained and detached from the deleted account, with the transaction email preserved where required for bookkeeping and legal obligations.

To request access, correction, or deletion that is not available in the product, contact support@sneakwrite.net. We may need to verify your identity before completing a request.

Security

We use access controls, authenticated server endpoints, encrypted network connections, restricted server credentials, encrypted provider-credential storage, and database row-level security to protect information. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

Children

SneakWrite is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information so we can review and delete it where appropriate.

Policy updates and contact

We may update this policy when the product, providers, or legal requirements change. We will publish the revised policy with a new last-updated date. Questions or privacy requests can be sent to support@sneakwrite.net.