Writesonic
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Provider Training on customer data Default retention Configuration we use OpenAI (direct API) Not used to train OpenAI models. See OpenAI API data controls . Up to 30 days for safety and abuse monitoring under the standard API. Where eligible and approved, we use OpenAI's Zero Data Retention (ZDR) on supported endpoints. Anthropic (direct API)…”
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This carve-out is a standard but meaningful override of the retention table. The 'defend legal claims' basis in particular has no stated time limit and could justify extended retention of any category of personal data, effectively nullifying the specific retention periods in disputes.
The cookie/tracker table discloses sharing with multiple third-party processors across advertising, analytics, and sales-intelligence functions. Sharing with Meta and Google Ads may constitute 'sharing' under CPRA for cross-context behavioral advertising. The Unify tool for B2B account identification is an unusual use that may process business-contact data for sales purposes without explicit per-use consent.
This heading introduces Section 7 on data retention, defining the scope of Writesonic's data retention commitments and obligations that follow.
How to read this page: Overall risk rates what Writesonic's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 141 verified, verbatim-cited findings below — read the citations.
Based on 135 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Privacy PolicyVerified - read in full - 81 citationsstaticLast captured 2026-08-28
- Terms of ServiceVerified - read in full - 0 citationsstaticLast captured 2026-08-03
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment discloses the specific training and retention practices of OpenAI and Anthropic as Model Providers, stating that OpenAI does not use data to train models and retains data up to 30 days, and that Anthropic may not train on customer content, while also referencing Zero Data Retention configurations and incorporating Anthropic's Commercial Terms and DPA by reference.
" Provider Training on customer data Default retention Configuration we use OpenAI (direct API) Not used to train OpenAI models. See OpenAI API data controls . Up to 30 days for safety and abuse monitoring under the standard API. Where eli..."
This segment restricts users from submitting Inputs without necessary rights, consents, and permissions, and from submitting Inputs that violate applicable law, the Privacy Policy, Terms of Service, or Model Provider policies, while also disclaiming the accuracy and reliability of AI-generated Outputs and requiring independent review before reliance.
" The no-training commitment in §4.3 applies equally to Inputs, Outputs, and Usage Data generated under any Trial or free tier. We do not sell that data and we do not use it to train or fine-tune any general-purpose, foundation, or large-lan..."
Enumerates specific categories of personal data collected (account, billing, profile/preferences), their sources, and stated purposes, defining the scope of Writesonic's data collection and use obligations for these categories.
" Account information Name, work email, password, company name, role, country You, when you sign up or are added by an admin Create and operate your account; authenticate; provide support Billing information Billing contact, billing addres..."
Defines legitimate interests as a legal basis for processing, specifying the activities covered including security, fraud prevention, and marketing, establishing the scope of this basis under GDPR/UK GDPR.
" Legitimate interests , to operate, secure, maintain, and improve the Services, prevent fraud and misuse, and conduct lawful business and marketing activities;"
This segment specifies that support tickets are retained for 3 years from resolution, establishing a defined retention period obligation for that category of personal information.
" Active account information For the duration of the account, plus the period required by law Customer Data after account deletion Up to 30 days, then permanent deletion (subject to the DPA) Billing and tax records 7 years, or as require..."
This segment establishes the procedure for sub-processor disclosure and updates, specifying that the current sub-processor list is in Schedule 3 of the DPA and that customers receive at least 30 days' notice of sub-processor changes pursuant to the DPA terms.
" Sub-processors Cloud hosting (Microsoft Azure, AWS), Model Providers (OpenAI, Anthropic, Azure, others), CRM, helpdesk, error monitoring, analytics, billing, email Provide and operate the Services Affiliates Writesonic group entities Int..."
Clarifies that Customer-submitted data is excluded from this policy's scope, designates Customers as controllers and Writesonic as processor for that data, and incorporates the Data Processing Agreement as the governing instrument for such processing — a foundational allocation of controller/processor responsibility.
" This Policy does not govern personal information that our business customers ("Customers") submit to the Services as Inputs or content they manage through the Services. For that personal information, the Customer is the controller and Writ..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"We and our service providers use cookies, pixels, SDKs, and similar tracking technologies. The categories we use: Category Purpose Example tools Strictly necessary Authentication, security, load balancing, fraud prevention Session cookies, CSRF tokens Functional Remember preferences and settings Locale, in-product UI state Analytics Understand how the Services are used; product improvement Google Analytics, Plausible, Microsoft Clarity Marketing and advertising (with consent where required) Measure marketing campaigns; serve and measure cross-site advertising Google Ads, Meta (Facebook), LinkedIn Ads Referral and attribution Track referrals and partner attribution FirstPromoter Sales and intelligence Identify accounts visiting our site for B2B outreach Unify Developer infrastructure Code hosting and developer-facing pages GitHub"
The cookie/tracker table discloses sharing with multiple third-party processors across advertising, analytics, and sales-intelligence functions. Sharing with Meta and Google Ads may constitute 'sharing' under CPRA for cross-context behavioral advertising. The Unify tool for B2B account identification is an unusual use that may process business-contact data for sales purposes without explicit per-use consent.
AI-generated interpretation, not legal advice.
"We may retain information longer where required to comply with legal obligations, defend legal claims, or address security or fraud incidents."
This carve-out is a standard but meaningful override of the retention table. The 'defend legal claims' basis in particular has no stated time limit and could justify extended retention of any category of personal data, effectively nullifying the specific retention periods in disputes.
AI-generated interpretation, not legal advice.
" Consent , where required by law, including for certain marketing communications, advertising cookies, and the processing of special-category personal data; and"
Defines consent as a legal basis for specific processing activities including marketing communications, advertising cookies, and special-category data, establishing when consent is required and its scope.
AI-generated interpretation, not legal advice.
" Account information Name, work email, password, company name, role, country You, when you sign up or are added by an admin Create and operate your account; authenticate; provide support Billing information Billing contact, billing address, last 4 of card, invoice history; full card data is held by our payment processor and not by us You, your finance team, our payment processor Charge fees; remit taxes; meet accounting obligations Profile and preferences Preferences, settings, in-product configurations, brand and competitor inputs You and your Authorized Users Provide and personalize the Services Inputs and Outputs Prompts, queries, brand configurations, agent instructions, tracked URLs, generated text, images, audio, video You and your Authorized Users Provide the AI Features (see §4) Usage and device data IP address, device identifiers, browser type and version, OS, page-view and click events, referrers, session duration, error logs Automatic, via our Services and analytics tools Operate, debug, and secure the Services; analytics; product improvement Cookies and similar tech Session cookies, preference cookies, security cookies, analytics cookies, and (with consent) advertising cookies Automatic, see §11 Authentication, preferences, security, analytics, and (with consent) advertising Communication content Support tickets, sales correspondence, recordings of meetings (where you consent), survey responses You Respond to inquiries; provide support; train our support team Marketing information Form submissions, content downloads, event registrations, newsletter subscriptions, contact data from data providers You and from licensed B2B data providers Send communications you've signed up for; account-based marketing Recruiting information CV, work"
Enumerates specific categories of personal data collected (account, billing, profile/preferences), their sources, and stated purposes, defining the scope of Writesonic's data collection and use obligations for these categories.
AI-generated interpretation, not legal advice.
" Legitimate interests , to operate, secure, maintain, and improve the Services, prevent fraud and misuse, and conduct lawful business and marketing activities;"
Defines legitimate interests as a legal basis for processing, specifying the activities covered including security, fraud prevention, and marketing, establishing the scope of this basis under GDPR/UK GDPR.
AI-generated interpretation, not legal advice.
" Strictly necessary Authentication, security, load balancing, fraud prevention Session cookies, CSRF tokens Functional Remember preferences and settings Locale, in-product UI state Analytics Understand how the Services are used; product improvement Google Analytics, Plausible, Microsoft Clarity Marketing and advertising (with consent where required) Measure marketing campaigns; serve and measure cross-site advertising Google Ads, Meta (Facebook), LinkedIn Ads Referral and attribution Track referrals and partner attribution FirstPromoter Sales and intelligence Identify accounts visiting our site for B2B outreach Unify "
Lists specific categories of cookies and tracking technologies (strictly necessary, functional, analytics, marketing, referral, sales intelligence), their purposes, and named third-party tools (Google Analytics, Meta, LinkedIn, etc.), disclosing the identity of subprocessors and the nature of data sharing with each.
AI-generated interpretation, not legal advice.
" We do not sell personal information for money. Some advertising-cookie activity may qualify as "sale" or "sharing" under specific U.S. state laws; you can opt out under §10. We do not knowingly transfer personal information of children under 18."
This heading introduces Section 6 on international data transfers, defining the scope of the discussion about cross-border personal information flows and the legal mechanisms Writesonic relies upon for such transfers.
AI-generated interpretation, not legal advice.
" aggregate and de-identify information for analytics, benchmarking, and product development; and"
Permits Writesonic to aggregate and de-identify personal information for analytics, benchmarking, and product development purposes, establishing a permissible secondary use of data.
AI-generated interpretation, not legal advice.
" We and our service providers use cookies, pixels, SDKs, and similar tracking technologies. The categories we use:"
Discloses that the platform and its service providers use cookies, pixels, SDKs, and similar tracking technologies, identifying categories of tools used and implicitly acknowledging third-party data sharing with subprocessors.
AI-generated interpretation, not legal advice.
" We do not sell personal information for monetary consideration. Some online advertising practices qualify as "sharing" under the CPRA; you can opt out via §10."
Clarifies that the platform does not sell personal information for monetary consideration, while acknowledging that certain online advertising practices may qualify as 'sharing' under CPRA and directing users to §10 to opt out, limiting potential liability exposure.
AI-generated interpretation, not legal advice.
" history, references, interview notes You and from recruiters or third-party tools Evaluate applications Third-party integration data OAuth tokens and metadata from integrations you enable (for example, Google services, CMSs, ad platforms, AI platforms) The third-party service, with your authorization Provide the integration "
Describes collection of job applicant data and third-party OAuth integration data, identifying sources and purposes, defining the scope of data collection for these categories.
AI-generated interpretation, not legal advice.
" We may update this Policy. The "Last Updated" date at the top of this page reflects the most recent version. For material changes, we will provide additional notice (for example, in the Services or by email to the account owner) before the change takes effect. Continued use of the Services after the effective date of changes constitutes acceptance of the updated Policy."
Establishes the procedure for policy updates—notice via 'Last Updated' date, additional notice for material changes before they take effect, and a provision that continued use constitutes acceptance—creating an obligation on the platform to notify users and a binding acceptance mechanism for users.
AI-generated interpretation, not legal advice.
" We retain personal information only as long as necessary for the purposes for which it was collected, and as required by applicable law."
This segment specifies binding retention periods for active account information (duration of account plus legally required period) and Customer Data after account deletion (up to 30 days then permanent deletion subject to the DPA), establishing concrete data retention and deletion obligations.
AI-generated interpretation, not legal advice.
" enforce our Terms of Service and protect our rights, property, or safety, or that of others;"
Permits Writesonic to use personal information to enforce its Terms of Service and protect its rights, property, or safety, establishing an enforcement-based processing permission.
AI-generated interpretation, not legal advice.
" Compliance with legal obligations , to comply with applicable laws, regulations, legal processes, and governmental requests."
Defines legal obligation compliance as a legal basis for processing under GDPR/UK GDPR, specifying the types of legal requirements that trigger this basis.
AI-generated interpretation, not legal advice.
" comply with legal obligations and respond to lawful requests by public authorities;"
Obligates Writesonic to use personal information to comply with legal obligations and respond to lawful governmental requests, establishing a compliance-based processing basis.
AI-generated interpretation, not legal advice.
" Sub-processors Cloud hosting (Microsoft Azure, AWS), Model Providers (OpenAI, Anthropic, Azure, others), CRM, helpdesk, error monitoring, analytics, billing, email Provide and operate the Services Affiliates Writesonic group entities Internal operations, support, sales, billing Integrations you enable Google services, CMSs, ad platforms, social platforms, third-party AI platforms Provide the integration you authorized Professional advisers Lawyers, auditors, accountants Run the business; comply with law Authorities and others Regulators, law enforcement, courts Comply with valid legal process; protect rights, safety, security Buyers and successors In a merger, financing, acquisition, restructuring, or sale of all or part of the business Continuation of the business "
This segment establishes the procedure for sub-processor disclosure and updates, specifying that the current sub-processor list is in Schedule 3 of the DPA and that customers receive at least 30 days' notice of sub-processor changes pursuant to the DPA terms.
AI-generated interpretation, not legal advice.
" When you use AI Features, we send Inputs to the relevant Model Provider, receive Outputs, and return them to you in the Services. We may also send a limited amount of operational metadata (for example, a request identifier or model parameters)."
This clause describes the operational procedure by which Writesonic transmits Inputs to Model Providers, receives Outputs, and returns them to users, and discloses that limited operational metadata may also be sent, establishing what data flows occur with third-party subprocessors.
AI-generated interpretation, not legal advice.
Common questions about Writesonic's policies
- Does Writesonic train its AI models on your data?
- No training on your content by default — based on 4 verified findings from Writesonic's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Writesonic's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
30 verified clausesClauses in Writesonic's policies that work in your favour — commitments the platform made to you.
- Model trainingdoes-not-train
“Provider Training on customer data Default retention Configuration we use OpenAI (direct API) Not used to train OpenAI models. See OpenAI API data controls . Up to 30 days for safety and abuse monitoring under the standard API. Where eligible and approved, w…”
This segment discloses the specific training and retention practices of OpenAI and Anthropic as Model Providers, stating that OpenAI does not use data to train models and retains data up to 30 days, and that Anthropic ma…
📍 § 4.2 (What Model Providers do with that data)Jump to exact text → - Model trainingdoes-not-train
“We rely on Anthropic's Commercial Terms and DPA for these deployments. Custom models on Microsoft Azure or AWS We control these deployments; customer data is not used to train any model. Per our internal retention schedule. Tenant-isolated deployments under…”
This segment discloses Writesonic's configuration choices for Anthropic, custom Azure/AWS models, and other providers (Stability AI, OpenRouter, Google Cloud), confirming that customer data is not used for training in th…
📍 § 4.2 (What Model Providers do with that data)Jump to exact text → - Audit rights, DPA & residency
“This Policy does not govern personal information that our business customers ("Customers") submit to the Services as Inputs or content they manage through the Services. For that personal information, the Customer is the controller and Writesonic acts as a proc…”
Clarifies that Customer-submitted data is excluded from this policy's scope, designates Customers as controllers and Writesonic as processor for that data, and incorporates the Data Processing Agreement as the governing…
📍 § 1 (Overview)Jump to exact text → - Privacy & data use
“If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, New Hampshire, Delaware, New Jersey, Minnesota, Maryland, or another state with a comprehensive privacy law, you have rights similar to those abov…”
Grants residents of enumerated U.S. states rights of access, correction, deletion, portability, and opt-out from targeted advertising and profiling, and provides an appeal procedure for denied requests, establishing mult…
📍 § 9.3 (Other U.S. states)Jump to exact text → - Model trainingdoes-not-train
“We do not use Customer Data to train or fine-tune any general-purpose, foundation, or large-language model offered by Writesonic or by any Model Provider. However, we may use de-identified Inputs, Outputs, and Usage Data, that does not identify any Customer or…”
This clause restricts Writesonic from using Customer Data to train or fine-tune any general-purpose, foundation, or large-language model, while creating a limited exception permitting use of de-identified data for operat…
📍 § 4.3 (Use of Customer Data to train Writesonic models)Jump to exact text → - Audit rights, DPA & residency
“For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed adequate by the relevant authority, we rely on Standard Contractual Clauses approved by the European Commission, the…”
This segment establishes Writesonic's general obligation to retain personal information only as long as necessary for collection purposes and as required by applicable law, setting the foundational principle governing th…
📍 § 6 (International Transfers)Jump to exact text →
+ 24 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat Writesonic requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Writesonic's published policies yet.
What the policies actually cover
11 topics- Product telemetry & usage tracking8 clauses
- Advertising & tracking5 protective13 clauses
- Sale or sharing of personal data3 protective5 clauses
- Sensitive data (biometric, location, health)1 protective1 clause
- Children's data1 clause
- Government & law-enforcement disclosure3 clauses
- Data shared with other AI providers3 clauses
- Does not train on your content4 protective4 clauses
- Terms can change at any time1 protective1 clause
- Deletion rights & post-termination survival3 protective4 clauses
- Breach-notification promises1 protective1 clause
37 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Cookies See cookie table in §11” addresses how long content is retained, and the Privacy Policy, § 4.2 (What Model Providers do with that data) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Verified retention clauses point in different directions: the Privacy Policy, § 7 (Data Retention) describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Type Retention” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain personal information only as long as necessary for the purposes for which it was collected, and as required by applicable law.”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Type Retention Active account information For the duration of the account, plus the period required by law Customer Data after account deletion Up to 30 days, then permanent deletion (subject to the DPA) Billing and tax records 7 years, or as required by tax law in the relevant jurisdiction Support tickets 3 years from resolution Marketing-list data Until you unsubscribe or 24 months of inactivity, whichever is so...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Active account information For the duration of the account, plus the period required by law Customer Data after account deletion Up to 30 days, then permanent deletion (subject to the DPA) Billing and tax records 7 years, or as required by tax law in the relevant jurisdiction”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain personal information only as long as necessary for the purposes for which it was collected, and as required by applicable law.”Open source citation
The clause provides a deletion or time-bounded retention path.
“Type Retention Active account information For the duration of the account, plus the period required by law Customer Data after account deletion Up to 30 days, then permanent deletion (subject to the DPA) Billing and tax records 7 years, or as required by tax law in the relevant jurisdiction Support tickets 3 years from resolution Marketing-list data Until you unsubscribe or 24 months of inactivity, whichever is so...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | audit rights dpa residency | worsens | HIGH | 1 |
| All applicable tiers | commercial use | worsens | HIGH | 9 |
| All applicable tiers | data retention | conditional | MEDIUM | 2 |
| All applicable tiers | indemnity liability | conditional | MEDIUM | 6 |
| All applicable tiers | privacy data use | worsens | HIGH | 5 |
| Free | moderation enforcement | worsens | HIGH | 1 |
| Free | output ownership | conditional | MEDIUM | 3 |
| Free | privacy data use | conditional | MEDIUM | 6 |
| Free | prompt ownership | conditional | MEDIUM | 3 |
| Free | training use | worsens | HIGH | 4 |
| Pro / Paid | data retention | conditional | MEDIUM | 4 |
| Team / Business | privacy data use | worsens | HIGH | 3 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“Customer grants Writesonic a worldwide, non-exclusive, royalty-free license to host, store, process, transmit, display, and otherwise use Customer Data only as necessary to provide the Service and meet its obligations under the Agreement, including the rights described in §6 and the DPA. Such license includes the right for Writesonic to engage Affiliates, subprocessors, hosting providers, and other service providers in connection with the provision of the Service, subject to the terms of the Agreement and the Data Processing Agreement, where applicable.”Before citation
“We do not sell personal information for money. Some advertising-cookie activity may qualify as "sale" or "sharing" under specific U.S. state laws; you can opt out under §10. We do not knowingly transfer personal information of children under 18.”After citation
model training improved from high/training permitted to low/no training claim.
“(h) use the Service to develop, train, or improve a competing product, service, or AI model, or to assist a third party in doing so;”Before citation
“Provider Training on customer data Default retention Configuration we use OpenAI (direct API) Not used to train OpenAI models. See OpenAI API data controls . Up to 30 days for safety and abuse monitoring under the standard API. Where eligible and approved, we use OpenAI's Zero Data Retention (ZDR) on supported endpoints. Anthropic (direct API) "Anthropic may not train models on Customer Content from Services." See Anthropic Commercial Terms and Anthropic DPA . Trust-and-safety logs may be retained for a limited period. We use Anthropic's commercial API under their Commercial Terms and DPA. Microsoft Azure OpenAI Service Not used to train OpenAI's or Microsoft's models. See Data, privacy, and security for Azure Direct Models in Microsoft Foundry . Up to 30 days of abuse-monitoring retention by default, with content logging. Where we are eligible, we use Microsoft's Modified Abuse Monitoring to disable content logging (verifiable as ContentLogging=FALSE ). Microsoft Azure for Anthropic models (Microsoft Foundry) "By default, Anthropic will not use your inputs or outputs from commercial products to train their models." See Data, privacy, and security for use of Anthropic Claude models in Microsoft Foundry . For these deployments, Anthropic (not Microsoft) is the processor. Per Anthropic's terms; Anthropic Claude on Microsoft Foundry is not covered by the Azure OpenAI Zero Data Retention program.”After citation
data sharing improved from high/sale or sell to medium/third party or vendor sharing.
“We do not sell personal information for monetary consideration. Some online advertising practices qualify as "sharing" under the CPRA; you can opt out via §10.”Before citation
“Customer grants Writesonic a worldwide, non-exclusive, royalty-free license to host, store, process, transmit, display, and otherwise use Customer Data only as necessary to provide the Service and meet its obligations under the Agreement, including the rights described in §6 and the DPA. Such license includes the right for Writesonic to engage Affiliates, subprocessors, hosting providers, and other service providers in connection with the provision of the Service, subject to the terms of the Agreement and the Data Processing Agreement, where applicable.”After citation
model training worsened from low/no training claim to high/training permitted.
“We rely on Anthropic's Commercial Terms and DPA for these deployments. Custom models on Microsoft Azure or AWS We control these deployments; customer data is not used to train any model. Per our internal retention schedule. Tenant-isolated deployments under Writesonic's cloud accounts. Stability AI, OpenRouter, Google Cloud, and other providers We select providers and configurations that prohibit training on customer data and that meet our security and privacy requirements. Per the relevant provider's policy. We review provider terms before onboarding; configurations vary by use case.”Before citation
“(h) use the Service to develop, train, or improve a competing product, service, or AI model, or to assist a third party in doing so;”After citation
Latest stance: third party or vendor sharing on privacy data use
“Sub-processors Cloud hosting (Microsoft Azure, AWS), Model Providers (OpenAI, Anthropic, Azure, others), CRM, helpdesk, error monitoring, analytics, billing, email Provide and operate the Services Affiliates Writesonic group entities Internal operations, support, sales, billing Integrations you enable Google services, CMSs, ad platforms, social platforms, third-party AI platforms Provide the integration you authorized Professional advisers Lawyers, auditors, accountants Run the business; comply with law Authorities and others Regulators, law enforcement, courts Comply with valid legal process; protect rights, safety, security Buyers and successors In a merger, financing, acquisition, restructuring, or sale of all or part of the business Continuation of the business”Open timeline citation
Latest stance: sale or sell on training use
“The no-training commitment in §4.3 applies equally to Inputs, Outputs, and Usage Data generated under any Trial or free tier. We do not sell that data and we do not use it to train or fine-tune any general-purpose, foundation, or large-language model. We may use de-identified Trial data for the Service-improvement purposes set out in §4.3.”Open timeline citation
Latest stance: no training claim on training use
“We rely on Anthropic's Commercial Terms and DPA for these deployments. Custom models on Microsoft Azure or AWS We control these deployments; customer data is not used to train any model. Per our internal retention schedule. Tenant-isolated deployments under Writesonic's cloud accounts. Stability AI, OpenRouter, Google Cloud, and other providers We select providers and configurations that prohibit training on customer data and that meet our security and privacy requirements. Per the relevant provider's policy. We review provider terms before onboarding; configurations vary by use case.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We do not sell personal information for money. Some advertising-cookie activity may qualify as "sale" or "sharing" under specific U.S. state laws; you can opt out under §10. We do not knowingly transfer personal information of children under 18.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-28· verified 2026-08-28
- Terms of Service:Last captured 2026-08-03· verified 2026-08-03
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 367 more findings this quarter vs last (486 vs 119). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Writesonic's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Writesonic's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.