Privacy Policy

Last updated 13 August 2026

This explains what Polyscribe collects, why, and who else sees it. Cookies are covered here too, in section 5, rather than in a separate document. We run no analytics, no advertising and no tracking of any kind, which makes this shorter than most.

1. Who we are

Polyscribe is a writing tool operated by Polyscribe. For anything in this document, including a request to see or delete your data, email hello@polyscribe.com.

2. What we collect

Only what the service needs to work:

  • Your Google profile. When you sign in we receive your name, email address, profile photo and Google account id, and we store them. We never receive your Google password.
  • What you write. The drafts you paste, the rewrites we produce, and the writing samples you upload when you build a style. These are saved to your account so your history is there when you come back.
  • Billing records. Your plan, your credit balance and a reference to your customer record at Stripe. We never see or store your card details.
  • Basic technical logs. Requests to our servers, which include an IP address, so we can keep the service running and spot abuse.
  • Free rewrites, before you have an account. Rewriting on the home page is limited to three per connection a month. To count them we store a one-way hash of your IP address, never the address itself, and it is deleted after 30 days. We also set a cookie so that if you then sign up, those rewrites move into your account rather than being lost.

A rewrite you run on the home page is not linked to any account unless you go on to create one, at which point it moves into your history so nothing you have already written is lost.

3. Why we hold it

To sign you in, to produce rewrites, to show you your history, to count credits and take payment, and to keep the service secure. That is the whole list. We do not sell your data, we do not share it for advertising, and we do not use what you write to train any model.

4. Who else sees it

A few companies process data on our behalf so the service can function:

  • Google, for sign-in.
  • EchoWriting, our rewriting provider. The text you ask us to rewrite is sent to them to produce the rewrite. This is the one place your writing leaves our systems, and it only happens when you press Rewrite.
  • Stripe, for payments. Your card goes to them directly, never through us.
  • Our hosting and database providers, who store the data on our behalf.

We may also disclose data if the law requires it. Otherwise, nobody else gets it.

5. Cookies

Polyscribe sets up to four cookies, all of them strictly necessary. There are no analytics, advertising or tracking cookies, which is why you are not being asked to accept anything.

  • ps_session keeps you signed in. It holds your account id with a signature so it cannot be tampered with, and lasts 30 days.
  • qs_oauth_state protects the Google sign-in handshake against forgery. It lasts ten minutes and is deleted the moment it is used.
  • qs_post_signin_next remembers the page you were heading for so you land there after signing in. It also lasts ten minutes.
  • ps_visitor is a random id, set only if you rewrite something on the home page without an account. It exists so those rewrites can follow you into an account if you make one. It identifies nothing about you and lasts a year.

All of them are httpOnly, meaning no script on the page can read them. Blocking them in your browser will stop sign-in from working.

6. How long we keep it

Your drafts and rewrites stay until you delete them. Deleting a document from your history removes it from our database. Ask us to close your account and we delete the account and everything attached to it, except records we have to keep for tax and accounting.

7. Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, and we will do it. Email hello@polyscribe.com. Depending on where you live you may have further rights under local data protection law, and those apply on top of this.

8. Security

Traffic is encrypted in transit. Your session cookie is signed and cannot be read by scripts. Every database query runs scoped to your account, so one account cannot reach another's writing even if our own code has a bug. No system is perfectly secure, but we treat what you write as private, because it is.

9. Children

Polyscribe is not for children under 13, and we do not knowingly collect their data. If you believe a child has given us data, email us and we will remove it.

10. Changes

If we change this policy we will update the date at the top, and say so on the site when the change is significant. The Terms & Conditions cover the rest of your relationship with us.

Questions about this document? Email hello@polyscribe.com.