Privacy Policy
Last updated: May 31, 2026. Review our operational parameters, encryption protocols, and model boundary configurations.
1. Core Data Protection Philosophy
At WriteFlow AI, we approach data privacy as a core system constraint rather than a regulatory checkbox. All data in transit is encrypted using transport-layer security (TLS 1.3), and database clusters reside behind secure virtual networks. Role-Based Access Control (RBAC) boundaries are validated at the Edge for every API resource request, preventing cross-tenant leaks.
2. Workspace Content & LLM Training Exemptions
Your intellectual property is yours alone. Content drafted, generated, cached, or saved within your WriteFlow AI workspace is strictly private. We enforce a global contract with downstream LLM provider APIs ensuring that zero workspace submissions are cached, stored, or utilized for foundation model pre-training, fine-tuning, or feedback loops.
3. Session Authentication & Security Credentials
We leverage NextAuth.js for decentralized secure session management. When you sign in, authorization is maintained via secure, HTTP-only, encrypted JSON Web Tokens (JWT). Your OAuth or credentials credentials are never exposed to the client application layer, and sensitive database columns containing encrypted session identifiers are automatically scrubbed.
4. Database Retention & Cascading Deletions
We use Neon's serverless Postgres instances to store document metadata, folder schemas, and user configurations. In compliance with data integrity protocols, if a user requests account deletion, a cascading database trigger executes instantly across all relational models (User, Session, Account, and Document workspaces) to perform a hard wipe of your records.
5. Compliance and Auditing Mandates
Our infrastructure is continually audited against industry standards. If you are an enterprise customer under SOC 2 Type II or HIPAA compliance mandates, we offer customizable Dedicated Host nodes and strict Data Processing Addendums (DPA).