Privacy policy

What happens to your writing

You are pasting in work that may be confidential, or a client's. You are owed a straight answer about where it goes. This page gives one.

Last updated 1 September 2026.

The short version. Your writing is stored on our own server in London and backed up in London. The analysis, the voice profiles and the built-in rewriting happen there — your text does not leave. Two optional features do send it out, to a named company, and we say so before you use them. We never use your writing to train anything, and we never sell it.

Who we are

Wordcheck, based at 117 St Pauls Avenue, Harrow, Middlesex, HA3 9PT, United Kingdom, is the data controller for the information described on this page. Contact us about anything on this page at support@wordcheck.co.uk.

What we collect

WhatWhy
Your name and email addressTo create your account, sign you in, and contact you about it
Your passwordStored only as a bcrypt hash. We cannot read it, and neither can anyone who steals the database
Your account and planTo apply the right limits and, once billing is live, to charge the right amount
The text you submitTo analyse it, rewrite it if you ask, and let you come back to it
Writing samples in a voice profileTo build the fingerprint that steers rewriting towards that voice
Usage recordsHow many checks and rewrites you have run, so limits and credits are counted honestly
Your IP address, brieflyRate limiting and abuse prevention in the web server's logs

There is no analytics tracking on this site, no advertising pixel, and no third-party script watching what you do.

Cookies

One cookie, called tt_session. It keeps you signed in, lasts 30 days, and is marked HttpOnly and SameSite so other sites cannot read it. That is the entire cookie policy — there is nothing to consent to because there is nothing else being set.

Where your writing is processed

This is the part worth reading closely.

By default, your text stays on our server

The scoring, the stylometry behind voice profiles, and the built-in rewriting pass all run on our own machine in London. No third party sees your text for any of that.

Optional features that send text to a third party

If a feature would send your text outside our server, you are told at the point you use it. If you would rather nothing left the server, use the analysis and the built-in rewriting only — they are the default, and they do not call out.

Who else is involved

CompanyWhat they handleWhere
DigitalOceanThe server your account and writing live on, and the backup copiesLondon, United Kingdom
NamecheapThe domain name
Let's EncryptThe certificate that encrypts your connection
Model and search providersOnly the optional features named above, and only when you use themVaries, some outside the UK
A payment processorOnce billing is live, card details go directly to them and never touch our server

Our lawful basis

How long we keep things

Security

Connections are encrypted with TLS. Passwords are bcrypt-hashed. The application runs as a restricted user that can write to two directories and nothing else on the machine, so a fault in the app cannot reach the rest of the server. Backups are verified by being opened and checked, not simply written and assumed good. Access to the server is by SSH key only — passwords are switched off.

No system is perfect. If there is ever a breach affecting your data we will tell you and the Information Commissioner's Office as the law requires, and we will tell you what actually happened rather than a sanitised version.

Client report links

A report you share with a client sits at an address containing a long random token, and carries instructions to search engines not to index it. It is not password-protected: anyone with the link can open it. Send links only to people who should see the contents.

Your rights

Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or hand it to another provider. You can also object to processing based on legitimate interests.

Two of these you can do yourself, immediately, from inside your account: download everything we hold on you as a single file, and delete your account and its contents outright. Neither needs to go through us.

For anything else — correction, restriction, portability to another provider, or an objection to processing — email support@wordcheck.co.uk and we will respond within one month. There is no charge.

If you think we have handled your data badly, please tell us first — but you have every right to complain directly to the Information Commissioner's Office at ico.org.uk.

If you are using Wordcheck on someone else's writing

Agencies put client work through Wordcheck, which is what it is built for. In that arrangement you are the controller of your client's content and we are your processor. Make sure your own agreement with your client allows you to put their material through a tool like this. If you need a data processing agreement, ask and we will provide one.

Children

Wordcheck is not intended for under-18s and we do not knowingly create accounts for them. If you believe a child has signed up, tell us and we will remove the account.

Changes

If we change anything material here — a new sub-processor, a new category of data — we will email account holders before it takes effect. The date at the top says when this page last changed.

← Back to Wordcheck  ·  Terms  ·  Acceptable use