writezone | wordtracker
Sign inDownload free →

Privacy Policy – WriteZone

Last updated: September 2026

This privacy policy applies to our website writezone.app, including the blog at writezone.app/blog, and to the optional community area of WriteZone / WordTracker (hereinafter the “Service”), provided via our server backend at api.writezone.app (account, friends, activity feed, motivations, competitions/“challenges”, push notifications).

Simply reading the website and the blog requires no account; section 2.10 sets out what data arises when you do. Beyond that, use of the community area is voluntary and disabled by default. Without signing up, none of the server-side data described in 2.1 to 2.8 is processed. The privacy policy of the app applies to local use of the app (writing statistics, projects, iCloud/cloud sync, purchases).

1. Controller

Mathias Todisco
Schleswiger Ufer 5
10555 Berlin
Germany

Email: hello@writezone.app
Phone: +49 179 8174113
Legal notice: Legal Notice

2. What data we process

2.1 Account & sign-up

To use the community area you create an account. In doing so we process:

Alternatively, you can sign up via Sign in with Apple; in that case we receive an identifier provided by Apple and – depending on your choice – your email address (possibly an anonymized relay address from Apple).

Registration, sign-in, verification, password reset: For these processes we log the IP address, timestamp, and technical details of the browser/client (user agent) to prevent abuse. From the IP address we derive an approximate location (country and city) and the network operator (autonomous system, ASN and provider name) using locally operated geo databases (MaxMind GeoLite2); your IP address is not transmitted to third parties in the process. When you change your email address, the previous address is retained in a history record.

2.2 Profile & uploads

2.3 Social features (user-generated content)

2.4 Push notifications

If you enable push notifications, we store your device token and deliver notifications via the Apple Push Notification service (APNs).

2.5 Security & abuse prevention

2.6 Transactional emails

For verification, password reset, and email changes we send emails via an email delivery provider (processor).

2.7 Analytics (Matomo)

On our website (writezone.app), on the blog (writezone.app/blog) and in the web app (app.writezone.app) we use the self-hosted analytics software Matomo to statistically evaluate and improve the use of our offering. Matomo runs on our own server (i.writezone.app); no data is transferred to third parties. The measurement is deliberately privacy-friendly:

We record anonymized information such as the pages visited, approximate origin (country/region based on the anonymized IP), the referring page, and technical details about your browser and device. In the web app we additionally count moves between views – that is, which areas are opened, not what they contain. This is not combined with your community account, nor is it used to identify you.

The legal basis is our legitimate interest in data-minimizing, cookieless analytics (Art. 6(1)(f) GDPR). As no cookies are used and processing is anonymized, no consent is required; you can object to the measurement at any time via your browser’s “Do Not Track” function.

2.8 Error diagnostics in the web app (GlitchTip)

So that we can detect and fix faults in the web app (app.writezone.app), we collect technical error reports using the self-hosted software GlitchTip. It runs on our own server (tip.todisco.de); no data is passed to third parties.

A report is only created when an error occurs. It contains the technical error message, the place in the program, the page you were on and details about your browser and operating system. Your name, email address and account identifier are not transmitted, nor is any content from your projects or texts.

Error diagnostics can be switched off in the settings of our phone and Mac apps. In the web app they remain active throughout, because faults in the browser would otherwise go unnoticed; as no personal identifiers are transmitted, the interference is minor.

Legal basis is our legitimate interest in a functioning, secure service (Art. 6(1)(f) GDPR). You have the right to object to this processing under Art. 21 GDPR – please contact us at the address given in section 1. We delete error reports as soon as they are no longer needed to fix the fault.

2.9 Contact form

When you write to us via the contact form on writezone.app, we process the details you enter – name, email address and your message – in order to answer your enquiry. The email we receive also carries technical details of the submission: IP address, the approximate location (country and city) and network operator derived from it, browser or client details (user agent), language setting, referring page, time of receipt and how long the form took to complete. Location and network operator are derived using locally operated geo databases (MaxMind GeoLite2) as described in section 2.1; your IP address is not transmitted to third parties in the process. These details help us assess your enquiry and protect the form against automated or abusive submissions. The enquiry reaches us as an email; it is not additionally stored in a database. Your IP address is additionally evaluated for one hour in order to limit the number of enquiries per sender (protection against automated bulk submissions).

Legal basis is our legitimate interest in responding to enquiries and in preventing abuse (Art. 6(1)(f) GDPR); where your enquiry concerns a contract, additionally Art. 6(1)(b) GDPR. We delete your enquiry once it has been dealt with conclusively and no statutory retention periods apply.

Spam protection with Cloudflare Turnstile: To protect the form against automated submissions we use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile checks in the background whether the submission comes from a human. In doing so, technical details about your browser and device as well as your IP address are transmitted to Cloudflare and evaluated there; according to Cloudflare it does not set cookies for advertising purposes and does not create a user profile. Processing is based on our legitimate interest in a functioning contact form that is protected against abuse (Art. 6(1)(f) GDPR).

Transfer to the USA (Cloudflare): This involves transferring data to Cloudflare in the USA. The basis for this is the EU standard contractual clauses agreed between us and Cloudflare (Art. 46(2)(c) GDPR) together with Cloudflare’s certification under the EU-US Data Privacy Framework. Despite these safeguards, access by US authorities cannot be entirely ruled out. For details see Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/

2.10 Website and blog

The website and the blog are there to be read. There is no account, no sign-in, no comment function and no newsletter. Opening a page requires nothing from you, and we create no record of that visit that would be attributable to a person.

No cookies. The blog sets no cookies and reads none. The only thing stored on your device is your choice between the light and the dark appearance, held in your browser’s local storage. That value never leaves your device and serves only the appearance you asked for yourself. It therefore requires no consent under section 25 TDDDG; you remove it by clearing the site data in your browser.

No embedded third-party content. We embed no fonts, maps, videos or other content from outside servers. The images in the articles are on our own server as well. Opening a page therefore opens no connection from your browser to a third party. Where we link to other sites, that connection is made only once you follow the link.

Server logs. As with any web server, retrieving a page produces a technical log entry: IP address, time, the address requested, the HTTP status, the amount of data transferred, the referring page and the browser identifier. These logs serve operation, fault-finding and the defence against attacks. The blog is delivered over two stages (writezone.app and an origin server reachable only internally), each of which writes such a log. Both servers are located in Germany. The logs are deleted automatically after 14 days at the latest and are not combined with any other source of data.

Legal basis for the server logs is our legitimate interest in secure and uninterrupted operation (Art. 6(1)(f) GDPR).

For analytics on the blog, section 2.7 applies: Matomo runs on our own server, without cookies, with your IP address truncated before storage and respecting your browser’s “Do Not Track” setting.

4. Recipients / processors

We only share data insofar as necessary for operation:

Data processing agreements pursuant to Art. 28 GDPR are in place with processors.

Transfer to the USA (Apple): When using push notifications (APNs) and Sign in with Apple, personal data is transferred to Apple Inc., USA. Apple is not certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Despite these safeguards, access by US authorities cannot be entirely ruled out. You can obtain a copy of the safeguards on request at hello@writezone.app.

5. Retention & deletion

We process personal data only for as long as necessary for the respective purpose:

You can remove individual posts, competitions, and relationships in the Service at any time and request the deletion of your account and all associated server data.

Account deletion: You can delete your community account directly in the app or request deletion by email to hello@writezone.app. Competition contributions already transmitted to other participants are not retroactively withdrawn for consistency reasons.

6. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21 – in particular to processing based on legitimate interests).

Where we process data based on your consent, you can withdraw it at any time with effect for the future; the lawfulness of processing carried out up to the withdrawal remains unaffected.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), https://www.datenschutz-berlin.de.

7. Data security

Transmission is encrypted (TLS/HTTPS); passwords are stored exclusively as hashes. We take appropriate technical and organizational measures to protect your data.

8. No profiling / minors

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. The community area is not directed at children. Use requires a minimum age of 16 years (Art. 8 GDPR); younger persons may only use the community area with the consent of their legal guardians.

9. Changes

We reserve the right to adapt this privacy policy to changes in the law or in features. We will communicate material changes within the Service.

10. Contact

For questions about data protection: hello@writezone.app, Mathias Todisco