Legal

Privacy Policy

Last updated: 2026-05-10

Data we collect

  • Account data: email, full name, plan, usage counters.
  • Content you author or upload: document text, photos of notes you submit for AI processing, handwriting scans for your custom font, rendered PDFs.
  • Billing metadata from Polar / Apple: customer id, subscription id, transaction id (no card numbers).
  • Operational logs: action audit log entries (e.g., plan changes, admin actions, login events).

Why we process it

To operate the Service for you (Article 6(1)(b) GDPR — performance of a contract). We do not sell personal data and we do not use your content to train any third-party AI model.

AI processing

Some HandwriterAI features send your content to third-party AI providers in order to function:

  • Image processing. When you submit a photo of a page of notes, the image is sent to Anthropic (Claude Sonnet 4.6 vision, via the Vercel AI Gateway) to read the text. The image and the extracted text are stored against your account so you can re-render or revise the result.
  • Title and clean-up. The text of a new document may be sent to Groq (Llama 3.1 8B) to generate a short title and to normalise messy formatting. These calls are text-only.
  • Glyph quality check (optional). When you train a custom handwriting font, individual cropped letter images may be sent to Anthropic (Claude Haiku 4.5) to flag illegible cells.

The handwriting render itself (placing your characters on the page and producing the PDF) is fully deterministic and runs on our servers — no AI model touches that step.

Where data is stored

Database, file storage, and authentication: Supabase (Frankfurt, eu-west-3, Germany). Hosting and durable background jobs: Vercel. AI inference is performed by Anthropic and Groq under their respective data processing terms.

Sub-processors

  • Supabase Inc. — database, auth, storage
  • Vercel Inc. — hosting, durable background jobs, AI Gateway routing
  • Anthropic PBC — vision OCR + solve, glyph QA
  • Groq Inc. — text title generation and cleanup
  • Polar — payment processing
  • Apple Inc. — App Store in-app purchases
  • Resend — transactional email
  • Sentry (optional) — error tracking, if enabled

Retention

Account data is retained until you delete your account. Photos you submit for an AI solve are processed in memory and are never written to durable storageon our side; once the AI has read the image and returned a text answer, the bytes are released and only the text answer (attached to your document) persists. Rendered PDFs and the custom-font scans you upload to train your own handwriting font persist until you delete the corresponding document, font, or your account. Audit log entries are retained for 24 months for security review. You can wipe all of your documents at any time from the in-app settings ("Delete history").

Your rights (EU/UK)

You have the right to access, correct, delete, export, restrict, and object to processing of your data. The easiest way to exercise these is from the Settings page in-product. For other requests email privacy@handwriter.app.

Cookies

We set strictly-necessary cookies (auth session, CSRF). We do not set advertising or third-party tracking cookies.

Contact

privacy@handwriter.app.