Политика конфиденциальности
Последнее обновление: 06/08/2026
Last updated: May 2026
1. Data Controller
GiaNet Media di Giannetta Francesco, based in Otranto (LE), Italy. For data-related requests: support system.
2. Data Collected
WriteForge collects and processes the following data categories:
- Registration data: first name, last name, email, password (hashed)
- Project data: texts, manuscripts, notes, narrative structures, created entities
- AI interaction data: prompts sent, generated responses, style preferences
- Technical data: IP address, browser type, operating system, access logs
- Payment data: handled entirely by Stripe (we do not store card data)
3. Purposes and Legal Basis
| Purpose | Legal basis | Retention |
|---|---|---|
| AI writing service delivery | Contract performance (Art. 6.1.b GDPR) | Account duration + 12 months |
| Service improvement and aggregate analytics | Legitimate interest (Art. 6.1.f) | Anonymized data |
| Service communications | Contract performance (Art. 6.1.b) | Account duration |
| Tax and accounting obligations | Legal obligation (Art. 6.1.c) | 10 years |
4. Creative Content Processing
Texts, manuscripts and projects created by users are the exclusive property of the user. WriteForge does not use user content to train AI models, nor share it with third parties. Content is processed by AI providers (Anthropic, OpenAI) solely to deliver the requested service, under their respective API data non-training policies.
5. Data Transfers
Data may be transferred to:
- AI Providers (USA): Anthropic, OpenAI — with adequate safeguards (DPA + SCCs)
- Stripe (USA): for payment processing — PCI DSS Level 1 certified
- Hetzner (Germany): server hosting — data within EU
6. Data Subject Rights
Under GDPR Articles 15-22, users have the right to: access, rectification, erasure, portability, objection, and restriction of processing. To exercise these rights: support system.
7. Account Deletion
Account deletion results in the removal of all projects, manuscripts, and personal data within 30 days. Tax-related data is retained as required by law.
8. Security
We implement appropriate technical and organizational measures: TLS encryption in transit, strong authentication, encrypted backups, continuous monitoring.
9. Supervisory Authority
Users may lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali — www.garanteprivacy.it).
Affiliate programme
If you arrive at this site via an affiliate link — a link that a person or a business has shared to refer you to our services — and you consent to the "Marketing" category in the cookie banner, we record the visit so that we can credit a commission to whoever referred you.
In that case we process: the link code and the visit identifier, the referring site and programme, the page you arrive from and the one you land on, the time of the click and your IP address. We need the IP address to identify self-referrals and artificially generated clicks: without it, the programme could be manipulated to the detriment of honest affiliates.
The legal basis is your consent (Article 6(1)(a) of the GDPR and Article 122 of the Italian Privacy Code) for storing and reading the cookie, and our legitimate interest (Article 6(1)(f)) solely for anti-fraud checks on data already collected with consent. Without consent we record nothing, and the referral is not registered with us. We retain this data for 90 days; after that period, clicks that have not resulted in a purchase are automatically deleted.
If you register after arriving via an affiliate link, your sign-up is associated with that affiliate so that they can be remunerated. We do not show the affiliate any of your data: they see only counts. And you do not see them.
If you are the affiliate
If you take part in the programme, we process your personal and tax details (name, address, tax code or VAT number, country of residence), the data needed to pay you — the identifier of the connected Stripe account or the PayPal address you provide us — the statistics of your links and your commission history. The legal basis is performance of the contract and, for the tax and social-security aspects, a legal obligation. Accounting records are kept for ten years.
Before every payment we check your name against the European Union's restrictive-measures lists: this is an obligation that applies to anyone making funds available to a third party, not a discretionary choice of ours.
If you promote the programme of a third-party advertiser, the conversion data is processed by us and by the advertiser under joint controllership (Article 26 GDPR): the essential content of the arrangement is available to you, and you may exercise your rights against either party indifferently.
The details of the affiliate cookie, including its name and duration, are set out in this site's Cookie Policy.
Stripe and PayPal process data as independent controllers
We rely on Stripe and PayPal to collect payments and to pay out the amounts owed to affiliates. For the purposes they determine themselves — fraud prevention, anti-money-laundering obligations, payment system security — these providers do not act on our behalf: they are independent controllers and answer for their own choices. Their privacy notices are available at stripe.com/privacy and paypal.com.
We disclose to them only the data the operation requires: for a payment, the transaction and billing details; for a commission payout, the recipient's email address and the amount. Both may process data outside the European Economic Area, on the basis of the standard contractual clauses approved by the European Commission.