Privacy Policy
What Writers Hub collects, why, who else sees it, and how to get it back or deleted.
In effect from 10 August 2026
The short version
Writers Hub is a place to read and write stories. To do that we hold your account details, the work you write, and what you have read. We do not run advertising, we do not use third-party analytics or tracking tools, and we do not sell or share your information for marketing. The one thing that leaves our systems in the ordinary course is text you deliberately send to the writing assistant, and this policy says exactly where that goes.
This policy covers the Writers Hub app on iOS and Android and the website at wh.trustworthlabs.com. The service is operated by Trustworth Labs ("we", "us"). Questions go to privacy@trustworthlabs.com.
What we collect
When you create an account:
- Your name and email address, which are required.
- A password, which we store only as a salted hash — we never hold the password itself and cannot tell you what it is.
- A phone number and date of birth, only if you choose to give them. Both are optional and the app works without either.
If you sign in with Google, Apple or Facebook instead of a password:
- That provider tells us your name and email address, and we create an account from them. We never see your password for that provider, and we ask for nothing beyond your name and address — no contacts, no posts, no friends.
- With Apple you can choose to hide your address. We then receive a relay address that forwards to you, and we cannot see the real one behind it. Your account is identified by an anonymous id Apple gives us rather than by the address, so hiding it costs you nothing here.
- Signing in tells the provider you use Writers Hub. That is unavoidable in any "sign in with" flow — it is their sign-in screen — which is why the password option remains and is listed first.
On your profile, if you fill it in:
- A handle, a short biography, and a profile colour or picture.
As you use the service:
- What you write — stories, serials and their chapters, titles, synopses, tags, and drafts you have not published.
- What you post about other people's work — comments, reviews, ratings and likes.
- What you keep — bookmarks, the writers and serials you follow, and stories saved for offline reading.
- Where you have got to in a story, so you can pick it up again on another device.
- Your preferences: reading language, the highest content rating you want shown, whether notifications are on, and the reading and writing interests you give at sign-up.
If you continue as a guest:
- The app generates a random identifier the first time it runs and keeps it on your device, so the same guest session resumes next time. It is generated by the app — it is not your device's serial number, advertising identifier, or any other hardware or platform identifier, and it is not shared with anyone.
- A guest session has no name and no email address attached to it.
Automatically, when your app or browser talks to us:
- Your IP address and the basic details of the request. We use these to keep the service up, to spot abuse, and to enforce rate limits on sign-in and password reset — which cannot be done without them.
What we do not do
- No advertising, and no advertising identifiers.
- No analytics, attribution or crash-reporting product is built into the app, and nothing here follows you across other apps or websites.
- The sign-in kits for Google, Apple and Facebook are the only third-party code in the app. They do nothing at all unless you tap one of those buttons, and Facebook's automatic event logging and advertiser-id collection — which its kit turns on by default — are switched off in our builds.
- We do not sell your information, and we do not share it for anyone else's marketing.
- The app's typefaces are bundled inside it rather than fetched from a font service while you use it, so browsing does not hand your IP address to a third party you did not choose.
The writing assistant
When you ask the assistant to do something — continue a passage, fix grammar, suggest titles, check continuity — the text you selected, or the draft it needs for context, is sent to our servers and on to the company that runs the underlying language model, together with your instruction. For a continuity check that may include earlier chapters of the same serial.
The model provider is [[AI MODEL PROVIDER — name the company, link its data-processing terms, and state whether it trains on submitted text]]. We do not use your writing to train any model of our own.
Nothing is sent to the assistant unless you ask for it. Work you never run an assist on is never transmitted to the model provider. If a passage is confidential, do not run an assist on it.
Cookies and similar technologies
On the website we set one cookie that keeps you signed in. It is HTTP-only and Secure, which means page scripts cannot read it and it is only ever sent over an encrypted connection. It is strictly necessary for the service to work and it is not used to track you.
There are no advertising or analytics cookies, so there is no consent banner to click through.
What is stored on your device
Some things stay on your phone or computer rather than on our servers:
- Stories cached for offline reading, up to a few dozen at a time.
- Actions you took while offline — a like, a comment, a published story — held in a queue until the connection comes back and they can be sent.
- Drafts you are part-way through writing.
- Your app settings and, for guest sessions, the random identifier described above.
Signing out clears the cached stories and the queue. A draft you have not published yet is deliberately kept, so that signing in to publish it does not throw it away. Deleting the app removes all of it.
This data sits in the app's private storage, protected by your device's own operating-system protections. The app does not add a further layer of encryption on top, so treat an unlocked, shared or jailbroken device accordingly.
Who else sees it
We use a small number of companies to run the service. They may only act on our instructions:
- Our hosting provider, which runs the servers and the database.
- Our email provider, Resend, which delivers confirmation and password-reset messages. It receives your email address and the contents of those messages.
- The model provider behind the writing assistant, as described above.
- Google, Apple or Facebook — but only if you choose to sign in with one, and only as much as that sign-in requires. We send them nothing about what you read or write.
Anything you publish — a story, a comment, a rating, your public profile — is visible to others by design, according to the visibility you chose for it. Your email address, phone number and date of birth are never shown to other users.
We will disclose information if the law requires it, or where it is necessary to protect someone's safety or our rights. We are not in the business of volunteering it.
Data is stored and processed in [[HOSTING REGION — where the servers and database physically are, plus the transfer mechanism if users outside that region are covered]].
How long we keep it
- Your account and what you have written: until you delete them, or until you ask us to close the account.
- Stories, comments and ratings you delete: removed from the service straight away, and cleared from routine backups within [[BACKUP RETENTION — e.g. 30 days]].
- Server and security logs: [[LOG RETENTION — e.g. 30 days]].
- Guest sessions with no activity: [[GUEST SESSION RETENTION]].
Your rights
You can ask us to give you a copy of what we hold about you, correct it, delete it, or stop a particular use of it. Depending on where you live you may also have the right to complain to a data-protection regulator. Write to privacy@trustworthlabs.com and we will answer within 30 days.
Much of it you can do yourself: edit or delete your profile, your stories, your comments and your ratings from inside the app at any time.
Closing your account: email privacy@trustworthlabs.com from the address on the account and we will delete the account and everything on it. We are building this into the app itself; until that ships, the email route is the way, and we will confirm when it is done.
Children
Writers Hub is not for children under 13, and we do not knowingly collect anything from them. If you believe a child under 13 has an account, tell us at privacy@trustworthlabs.com and we will remove it.
Stories carry a content rating from G to NC-17 and an intended audience. Readers can cap the rating shown to them in Settings, and that setting applies everywhere stories are listed.
Security
Traffic between the app and our servers is encrypted in transit. Passwords are stored only as salted hashes. The session cookie is HTTP-only and Secure. Sign-in and password-reset attempts are rate limited.
No service can promise perfect security. If a breach affects you, we will tell you and the relevant regulator as the law requires.
Changes
If we change this policy we will update the date at the top. For changes that materially affect you we will give notice in the app or by email before they take effect.
Contact
Privacy questions and requests: privacy@trustworthlabs.com. Anything else: support@trustworthlabs.com.
Trustworth Labs, [[REGISTERED ADDRESS]]. [[DATA PROTECTION REPRESENTATIVE / DPO, if one is required]]