Legal
Security
Last updated: August 28, 2026
The English version of this document is authoritative.
This page describes how cpywrk handles the content and data you put into the platform. It is written to be checked. Where a claim here can be checked, we have said how; where something is not yet in place, it is listed at the bottom rather than left out.
1. Encryption
Customer content is encrypted at rest using AES-256 and in transit using TLS. This covers your brand profile, briefs, drafts, corrections and finished articles, as well as account data.
2. Your content and AI models
Your inputs and outputs are not used to train AI models. Content is processed by our AI provider (Anthropic) strictly to serve your requests, subject to Anthropic's usage policies, which similarly prohibit using customer data for model training without consent.
Your brand profile is scoped to your account. Corrections you make train your own brand profile and nobody else's.
3. Payment data
Card details are handled by Stripe and are never stored on cpywrk systems. We hold the billing metadata Stripe returns to us, such as the plan, the status and the last four digits, and nothing that could be used to take a payment.
4. Sub-processors
We engage the following sub-processors under written data-processing agreements. This list mirrors section 5 of the Privacy Policy and is the current list, not an example.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting and edge delivery | US/EU |
| Anthropic | AI content generation | US |
| Stripe | Payment processing | US/EU |
| Google (Google Analytics 4) | Usage analytics, consent-gated | US/EU |
| Usercentrics (Cookiebot) | Cookie consent management | EU |
We do not sell personal data and we do not share it with advertisers or data brokers.
5. International transfers
Some sub-processors operate outside the European Economic Area. Where data is transferred to a country without an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission as the transfer mechanism.
6. Retention and deletion
Account and content data is retained while your account is active. When you delete your account or your subscription ends, data is retained for 60 days so you can export it, after which it is permanently deleted from production systems. Anonymised usage aggregates may be kept for longer for statistical purposes.
Billing records are retained for 7 years, as applicable accounting regulations require. That obligation sits above a deletion request, so those records survive account deletion.
7. Your controls
You can export your content and request deletion of your data at any time. Access, rectification, portability, objection and the other rights the GDPR gives you are set out in section 9 of the Privacy Policy, and the route to exercise them is privacy@cpywrk.com.
8. Data processing agreement
A DPA is available on request for customers who need one, including the sub-processor list above as an annex. Write to legal@cpywrk.com.
9. Reporting a vulnerability
If you believe you have found a security issue, write to legal@cpywrk.com with enough detail to reproduce it. We will acknowledge the report and work with you on a fix. Please do not test against other customers' accounts or data, and please give us a reasonable window before disclosing publicly.
We do not currently run a paid bug bounty, so we cannot offer a reward. We can offer credit in a fix note if you would like it.
10. Incidents
cpywrk is the data controller for personal data processed under the Privacy Policy. Where a personal data breach occurs, the GDPR requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and notification to affected individuals where the risk to them is high. We will also tell affected customers what happened, what data was involved, and what we have done about it.
11. What we do not claim
cpywrk is an early-stage company and this section exists so you do not have to guess what is behind the section above. As of the date at the top of this page:
- We hold no ISO 27001 certification and no SOC 2 report.
- We have not commissioned a third-party penetration test.
- We do not operate a bug bounty programme.
- We do not publish an uptime commitment or a service credit scheme. Availability is addressed in section 11 of the Terms of Service.
If any of these is a requirement for you, say so before you buy rather than after. We would rather lose the sale than describe a maturity we do not have.
12. Contact
Security questions, DPA requests and vulnerability reports: legal@cpywrk.com. Privacy rights requests: privacy@cpywrk.com.