Privacy Policy for WriCo
Last updated: July 18, 2026
WriCo handles data differently depending on the feature you choose. Private projects use local storage and optional iCloud sync. Collaborative projects use a shared backend. Optional cloud AI, document import and media features send the content needed to perform the action you request. This policy explains those distinctions.
1. Who is responsible
WriCo, also known as Writer Copilot, is developed by Otourou Da Costa / TooflexDev, who acts as the data controller for the processing described in this policy. Questions and privacy requests can be sent to info@writercopilot.app.
This policy covers the WriCo app and the writercopilot.app website. Apple, Google and Supabase also process data under their own terms when their services are used.
2. Data WriCo processes
Private projects
Private-project content is stored in a local SwiftData database on your device. If iCloud sync is enabled, a private-project snapshot is mirrored through Apple CloudKit across devices signed in to your Apple account. Project content can include titles, synopses, plots, scenes, characters, locations, notes, relationships, story objects, storyboards and attachments.
Account and identity
WriCo uses Firebase Authentication for an initial anonymous session and, when you choose it, Sign in with Apple. Depending on your sign-in choice, WriCo may process a Firebase user ID, email address and display name supplied by Apple. Authentication tokens are stored in the device Keychain. App Check also processes app or device integrity signals to protect backend services from abuse.
Collaborative projects
When a project uses collaboration, Supabase is the remote source of truth rather than CloudKit. WriCo sends the shared project snapshot and later changes to Supabase. This can include the project content listed above, collaboration profiles, invitation email addresses, member roles, permissions, presence status and synchronization events. Other project members can access content according to the role and permissions assigned to them.
When configured and used, collaborative media such as covers, images, drawings or audio may be uploaded to Google Cloud Storage through short-lived signed URLs. Supabase stores the associated file references.
Optional cloud AI and document import
When you deliberately invoke a cloud AI feature, WriCo sends the material needed for that request to Google Cloud services, including Genkit and Vertex AI. Depending on the feature, this may include prompts, scene descriptions, summaries, plot and character information, locations, coherence rules, image instructions or a character conversation. Generated text, reports, images and service metadata are returned to the app.
When you choose cloud document import, the selected document and extracted content are sent to WriCo's authenticated Google Cloud import service for processing. On-device AI features, when available and selected, do not require the same cloud content transfer.
Analytics, diagnostics and performance
WriCo uses Firebase Analytics, Crashlytics and Performance Monitoring. These services may process a user or device identifier, app version and platform, screen views, product interactions, entity identifiers, subscription or entitlement status, credit balance, performance measurements, crash or non-fatal error details and related diagnostic parameters. WriCo does not use this information for third-party advertising.
Purchases
Purchases are handled by Apple through StoreKit. WriCo receives transaction, subscription, entitlement and credit information needed to unlock features, validate access and prevent fraud. WriCo does not receive your full payment-card details.
Website
The current writercopilot.app landing page does not run client-side analytics or advertising scripts and does not set an analytics cookie. The language selector stores a functional language preference in your browser's local storage so the site can remember your choice. The hosting provider may process routine request information such as IP address, browser headers and timestamps to deliver and secure the site. If you email WriCo, the message and contact details you provide are used to answer you.
3. Why data is used
WriCo processes data to provide storage and synchronization, authenticate users, enable collaboration, perform the cloud action a user requests, import documents, deliver purchases and credits, prevent fraud or misuse, diagnose failures, monitor performance, improve the app and respond to support or legal requests.
Depending on your location and the processing involved, the legal basis may be performance of the service you requested, WriCo's legitimate interests in operating and securing the app, consent where it is specifically requested, or compliance with a legal obligation.
4. Service providers and disclosure
Data is disclosed only as needed to operate the selected feature, comply with law or protect users and the service. The principal providers are:
- Apple: iCloud and CloudKit, Sign in with Apple, StoreKit and App Store services.
- Google: Firebase Authentication, App Check, Analytics, Crashlytics, Performance Monitoring, Cloud Functions, Cloud Run, Cloud Storage, Genkit and Vertex AI.
- Supabase: collaborative project storage, profiles, invitations, permissions and realtime presence.
WriCo does not sell personal data or project content. Project content is not used by WriCo for third-party advertising.
5. Retention and deletion
Local data remains on your device until you delete the relevant project, remove app data or uninstall the app. iCloud copies are managed through your Apple account and Apple's CloudKit infrastructure. Collaborative data and cloud-service records are retained for as long as needed to provide the shared project, protect the service, meet legal obligations or resolve disputes. Analytics and diagnostic data follow the applicable provider settings and retention periods.
Deleting a WriCo account removes the Firebase identity and local app data handled by that flow. Because iCloud and collaborative projects use separate systems, do not assume that deleting the Firebase identity alone removes every CloudKit copy, shared project or copy already available to another collaborator. Contact info@writercopilot.app to request access, correction or deletion of remaining WriCo-controlled data.
6. Security
WriCo uses platform security controls including the device Keychain, authenticated backend requests, App Check, short-lived upload URLs and role-based access rules for collaboration. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
7. International processing
Apple, Google and Supabase may process data in countries other than the one where you live. Where required, WriCo relies on the safeguards offered by those providers and applicable data protection law for cross-border processing.
8. Your choices and rights
You can choose whether to enable iCloud, create a collaborative project, sign in with Apple, use a cloud AI feature, import a document or make a purchase. Depending on your jurisdiction, you may also have rights to request access, correction, deletion, restriction, objection or a copy of personal data, and to complain to your local data-protection authority.
To exercise a right or ask how a particular feature handles data, contact info@writercopilot.app. WriCo may need to verify your identity before completing a request.
9. Changes to this policy
This page will be updated when WriCo's material data practices change. The revision date at the top identifies the current published version.
10. Contact
Privacy questions and requests: info@writercopilot.app.