Privacy Policy
Last updated 30 July 2026
What BranchBook collects when you use BranchBook, why, and what you can do about it. We are the data controller.
The short version.
We store your manuscripts so you can write them. When you submit a passage for checking, its text goes to Anthropic's API and comes back as a verdict; Anthropic doesn't train on it. Neither do we. We don't sell anything to anybody, and there's no advertising or analytics on this site. You can export everything, and delete everything, whenever you want.
What we collect
From Google, when you sign in
Your Google account identifier (a stable, non-reassignable id), your email address, and your display name. We never see your Google password, and we don't ask for access to Gmail, Drive, contacts or anything else.
What you write
The text of your manuscripts, their titles, structure, word counts, and validation verdicts. This is the bulk of what we hold, and it is the part we treat as confidential.
Billing
Paddle.com processes payments as Merchant of Record. We never see or store your card details. We receive a customer and subscription identifier and your subscription status.
Technical
Server logs containing IP address, timestamps, and requested paths, kept briefly for security and debugging. No advertising identifiers, no fingerprinting, no third-party analytics.
Automated validation, and what leaves our server
When you press Submit, we send the text of that passage, the text of the passage above it, and the criteria being checked to Anthropic's API. Anthropic returns a short structured verdict. Under Anthropic's commercial terms, inputs and outputs sent through the API are not used to train its models.
This is the only routine circumstance in which your prose leaves our infrastructure. Writing, autosaving, reading, and exporting do not transmit your text anywhere. If you never submit a passage, your writing never leaves our server.
Why we may process it
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Running the Service: storing and showing you your work | Performance of a contract |
| Validating submissions | Performance of a contract |
| Taking payment and preventing fraud | Contract; legitimate interests |
| Security, backups, debugging | Legitimate interests |
| Service emails (trial ending, billing problems) | Contract |
Who else processes your data
| Processor | What for | What they get |
|---|---|---|
| Anthropic | Validating submissions | The submitted passage and its parent |
| Sign-in | Confirms who you are; receives no manuscript data | |
| Paddle.com | Payments, as Merchant of Record | Billing details; receives no manuscript data |
| Hetzner (Germany) | Running the servers and database | Hosts the infrastructure your manuscripts sit on |
| Backblaze (Netherlands) | Encrypted offsite backups | A nightly encrypted copy of the database |
We don't sell personal information, and we don't share it for advertising.
Cookies
One cookie, holding a signed session token so you stay logged in, plus a short-lived one during sign-in itself. Both are strictly necessary to run the Service, which is why you aren't being asked to consent to them. There are no analytics, advertising or third-party cookies here.
Where your data is held
Your manuscripts are stored in Germany, on servers in Nuremberg, and backed up to encrypted storage in the Netherlands. If you're in the UK or EEA, your writing doesn't leave Europe to be stored, so no cross-border transfer safeguards are needed for it.
Two things do cross to the United States, and only these. When you submit a passage for checking it goes to Anthropic's API, as described above. Payments are handled by Paddle. Both are covered by Standard Contractual Clauses or equivalent safeguards. If you never submit a passage and never subscribe, nothing you write leaves Europe at all.
How long we keep it
- Manuscripts: until you delete them, or 60 days after you delete your account.
- Account records: for as long as the account exists.
- Billing records: as long as tax law requires, usually seven years.
- Server logs: 30 days.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. You can export your manuscripts yourself from inside the app any time, without asking. Deleting a project deletes it; deleting your account deletes all of them.
If you are in the UK or EEA you also have rights to restrict or object to processing, to data portability, and to complain to your supervisory authority. If you are a California resident you have rights to know, delete, correct, and to opt out of sale or sharing. We do neither, and we won't treat you differently for asking.
Write to support@branchbook.ai and we will respond within 30 days.
Security
Traffic is encrypted in transit. Access to a manuscript is checked against the account that owns it on every single request, in two independent places. We take backups so your work survives a failure on our side. No system is perfectly secure and we won't pretend otherwise. If we ever have a breach affecting your data we'll tell you quickly, and tell you what to do about it.
Children
The Service is not intended for children under 16, and we don't knowingly collect their data. If you think a child has made an account, write to us and we'll delete it.
Changes
If we change this policy in any way that matters, we'll give notice by email or in the app before it takes effect.
Contact
BranchBook1328 Spring St
Grinnell, IA 50112
United States
support@branchbook.ai