Privacy Policy
Last updated: 2026-09-26
Who we are
WriteTheRest is a collaborative creative-writing site where people post prompts, write stories, vote and comment. It is run by Alex Lougheed (trading as WriteTheRest), a sole trader based in the United Kingdom, who is the “controller” of your personal data under UK data protection law (UK GDPR and the Data Protection Act 2018).
- Privacy contact: legal@write-the-rest.alexlougheed.dev
- Postal address: available on request by emailing legal@write-the-rest.alexlougheed.dev
What we collect
- Account data from Google or Discord: when you sign in we receive your name, email address, profile image and your account ID with that provider. We keep these to identify your account. We do not store the access, refresh or ID tokens the provider issues, because we never call Google or Discord on your behalf after sign-in.
- Content you create: prompts, stories, comments, votes, pen names, tags and the content ratings you choose.
- Feedback: messages you send through the feedback form, with your account details if you are signed in.
- Reports and moderation: when you report content, we store the content reported, the reason and any details you give, and, if you are signed in, your account ID. We do not tell the author who reported them. When we act on content or an account, we record the decision, who made it and why, and any account suspension.
- IP address, for abuse prevention: to rate-limit requests we record a keyed hash of your IP address (not the address itself) with a request count. These records are deleted automatically, normally within 48 hours.
- Hosting logs: our host, Vercel, records standard request logs (such as IP address, browser type, requested page and time) for security and troubleshooting, kept for a short period under Vercel's own retention settings.
- Analytics: we use Vercel Web Analytics, which counts page views without cookies and without identifying you across sites. See Vercel's analytics privacy information.
- Data stored only in your browser: unsaved drafts and your theme preference (see “Cookies and local storage” below). We never receive these.
We do not use your data for advertising, we do not sell it, and we do not make automated decisions about you that have legal or similarly significant effects.
Why we use it, and our legal basis
| Purpose | Data | Legal basis (UK GDPR Art. 6) |
|---|---|---|
| Create and run your account; show your content as you choose | Account data, content | Contract |
| Keep the service safe: rate limiting, spam and abuse prevention, handling reports, moderation decisions and suspensions | Hashed IP, hosting logs, account data, content, reports, moderation records | Legitimate interests (a safe, working service) and legal obligation (UK Online Safety Act) |
| Answer feedback, reports, complaints and data requests | Messages, account data | Legitimate interests; legal obligation for data-rights requests |
| Understand overall site usage to improve it | Cookieless, aggregate analytics | Legitimate interests |
Pen names
You can post stories, prompts and comments under a pen name. Work posted under a pen name is shown only with that pen name: we don't show your account name, profile picture or account ID next to it, and we don't link your pen names to each other or to your profile. Your pen names are still tied to your account in our database, and we may use that link to handle abuse reports or legal requests.
If you delete a pen name that you have already posted under, it is retired: it can't be used for new posts, but existing work stays under that pen name and is never moved to your real name. To remove that work, delete it, or delete your account.
Who we share it with
We use the following service providers. They process data for us under their own terms, or as independent controllers where noted.
| Provider | What for | Data involved |
|---|---|---|
| Vercel Inc. (US) | Website hosting, logs and analytics | All data passing through the site |
| Prisma Data, Inc. (Prisma Postgres) | Database hosting | Account data, content, hashed IPs |
| Resend (US) | Delivering feedback and report emails to us | Message content, your email if signed in |
| Google (independent controller) | Sign in with Google | Your Google sign-in |
| Discord (independent controller) | Sign in with Discord | Your Discord sign-in |
| Ko-fi (independent controller) | Optional donations | Whatever you give Ko-fi if you choose to donate; if we show Ko-fi's button, your browser may load it from Ko-fi |
Reports are sent to us by email through Resend. Only the operator, and any moderators we appoint, can see reports and use the moderation tools; moderator access is granted to specific accounts in our configuration (by account email address) and checked on every request.
We may also disclose data where the law requires it, for example to the police or a court, or to protect someone from serious harm.
International transfers
Some of these providers store or access data outside the UK, mainly in the United States. Where they do, we rely on the UK adequacy regulations (including the UK–US “data bridge” for certified companies) or on the UK International Data Transfer Addendum / EU Standard Contractual Clauses in the provider's terms. You can ask us for more detail.
How long we keep it
- Account and content: until you delete them or your account. Deleting your account removes them immediately from the live database.
- Hashed IP rate-limit records: normally deleted within 48 hours.
- Feedback emails: kept in our inbox for up to 12 months, or longer if needed for an open complaint or legal claim.
- Reports and moderation records (including suspensions, and content we removed for breaking the rules): may be retained for up to 12 months to handle appeals and meet our duties under the Online Safety Act 2023. We may delete them sooner; we keep them longer only where the law requires it or for an ongoing legal claim or law-enforcement request. Report notification emails follow the same rule. If you delete your account, your content is deleted as described above, including any content of yours that we had removed, so we do not keep it as a record after that. Reports and moderation decisions that mention you may still be retained for up to this period, but are no longer linked to your account.
- Hosting logs: kept by Vercel for its standard short retention period.
- Backups: if our database provider keeps backups, deleted data may remain in them until they expire under that provider's schedule. We do not restore deleted accounts from backups.
Your rights
You have the right to:
- Access and portability: download a copy of your data at any time from your account page (“Download my data”, as JSON).
- Erasure: delete your account and everything linked to it from your account page (“Delete my account”). You can also delete individual prompts, stories, comments and pen names at any time.
- Rectification: edit your content directly; your name, email and image come from your sign-in provider and update when you change them there.
- Restriction and objection: ask us to limit or stop processing based on legitimate interests.
- Complain to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to help first.
For anything you cannot do yourself in the app, email legal@write-the-rest.alexlougheed.dev. We will reply within one month (extendable by two further months for complex requests, in which case we will tell you why). We may need to confirm that the request comes from the account holder. These rights also apply if your account has been suspended.
Children
You must be at least 16 to use WriteTheRest; you confirm this when you sign in. We do not allow sexually explicit content, and the highest content rating is Mature. If we learn that an account belongs to someone under 16, we will delete it. Parents or guardians who believe their child has an account can contact us at legal@write-the-rest.alexlougheed.dev.
Cookies and local storage
We use only what is strictly necessary to sign you in and to remember choices you make on this device. We use no advertising or tracking cookies, and our analytics are cookieless, so we do not show a cookie banner.
| Name | Type | Purpose | Duration |
|---|---|---|---|
authjs.session-token | Cookie (first-party) | Keeps you signed in (sign-in session) | 30 days, or until you log out |
authjs.csrf-token, authjs.callback-url | Cookie (first-party) | Protects sign-in from forgery and returns you to the right page | Browser session |
authjs.pkce.code_verifier, authjs.state | Cookie (first-party) | Secures the Google / Discord sign-in handshake | Up to 15 minutes |
wtr-prompt-draft, wtr-story-draft-* | Local storage | Unsaved drafts, kept only in your browser | Until you publish, discard or clear browser storage |
theme | Local storage | Your light / dark theme choice | Until you clear browser storage |
Cookie names may carry a __Secure- or __Host- prefix on the live site. If we show Ko-fi's donation button, or you visit Ko-fi, Ko-fi may set its own cookies under its privacy policy.
Security
All traffic is encrypted with HTTPS. Sign-in is handled by Google or Discord, so we never see or store a password. Access to the database is restricted to the operator. No system is perfectly secure; if we suffer a breach that puts you at risk, we will tell you and the ICO as the law requires.
Changes to this policy
We will post any update on this page and change the “Last updated” date. If a change materially affects how we use your data, we will also tell signed-in users on the site before it takes effect.