BranchBook

Privacy Policy

Last updated 30 July 2026

What BranchBook collects when you use BranchBook, why, and what you can do about it. We are the data controller.

The short version.

We store your manuscripts so you can write them. When you submit a passage for checking, its text goes to Anthropic's API and comes back as a verdict; Anthropic doesn't train on it. Neither do we. We don't sell anything to anybody, and there's no advertising or analytics on this site. You can export everything, and delete everything, whenever you want.

What we collect

From Google, when you sign in

Your Google account identifier (a stable, non-reassignable id), your email address, and your display name. We never see your Google password, and we don't ask for access to Gmail, Drive, contacts or anything else.

What you write

The text of your manuscripts, their titles, structure, word counts, and validation verdicts. This is the bulk of what we hold, and it is the part we treat as confidential.

Billing

Paddle.com processes payments as Merchant of Record. We never see or store your card details. We receive a customer and subscription identifier and your subscription status.

Technical

Server logs containing IP address, timestamps, and requested paths, kept briefly for security and debugging. No advertising identifiers, no fingerprinting, no third-party analytics.

Automated validation, and what leaves our server

When you press Submit, we send the text of that passage, the text of the passage above it, and the criteria being checked to Anthropic's API. Anthropic returns a short structured verdict. Under Anthropic's commercial terms, inputs and outputs sent through the API are not used to train its models.

This is the only routine circumstance in which your prose leaves our infrastructure. Writing, autosaving, reading, and exporting do not transmit your text anywhere. If you never submit a passage, your writing never leaves our server.

Why we may process it

PurposeBasis (UK/EU GDPR)
Running the Service: storing and showing you your workPerformance of a contract
Validating submissionsPerformance of a contract
Taking payment and preventing fraudContract; legitimate interests
Security, backups, debuggingLegitimate interests
Service emails (trial ending, billing problems)Contract

Who else processes your data

ProcessorWhat forWhat they get
AnthropicValidating submissionsThe submitted passage and its parent
GoogleSign-inConfirms who you are; receives no manuscript data
Paddle.comPayments, as Merchant of RecordBilling details; receives no manuscript data
Hetzner (Germany)Running the servers and databaseHosts the infrastructure your manuscripts sit on
Backblaze (Netherlands)Encrypted offsite backupsA nightly encrypted copy of the database

We don't sell personal information, and we don't share it for advertising.

Cookies

One cookie, holding a signed session token so you stay logged in, plus a short-lived one during sign-in itself. Both are strictly necessary to run the Service, which is why you aren't being asked to consent to them. There are no analytics, advertising or third-party cookies here.

Where your data is held

Your manuscripts are stored in Germany, on servers in Nuremberg, and backed up to encrypted storage in the Netherlands. If you're in the UK or EEA, your writing doesn't leave Europe to be stored, so no cross-border transfer safeguards are needed for it.

Two things do cross to the United States, and only these. When you submit a passage for checking it goes to Anthropic's API, as described above. Payments are handled by Paddle. Both are covered by Standard Contractual Clauses or equivalent safeguards. If you never submit a passage and never subscribe, nothing you write leaves Europe at all.

How long we keep it

Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. You can export your manuscripts yourself from inside the app any time, without asking. Deleting a project deletes it; deleting your account deletes all of them.

If you are in the UK or EEA you also have rights to restrict or object to processing, to data portability, and to complain to your supervisory authority. If you are a California resident you have rights to know, delete, correct, and to opt out of sale or sharing. We do neither, and we won't treat you differently for asking.

Write to support@branchbook.ai and we will respond within 30 days.

Security

Traffic is encrypted in transit. Access to a manuscript is checked against the account that owns it on every single request, in two independent places. We take backups so your work survives a failure on our side. No system is perfectly secure and we won't pretend otherwise. If we ever have a breach affecting your data we'll tell you quickly, and tell you what to do about it.

Children

The Service is not intended for children under 16, and we don't knowingly collect their data. If you think a child has made an account, write to us and we'll delete it.

Changes

If we change this policy in any way that matters, we'll give notice by email or in the app before it takes effect.

Contact

BranchBook
1328 Spring St
Grinnell, IA 50112
United States
support@branchbook.ai