Security and privacy

Your texts are yours. WriteFlow encrypts them on your device, and no server we or anyone else runs can read them. This page explains how – and where the limits are.

End-to-end encryption

Projects are stored encrypted with AES-256-GCM – in the browser and with the local companion, including backups and the AI audit trail. Synchronisation and groups only move encrypted, signed envelopes: the server never sees project names, texts, sources, notes, PDFs or cursor positions. Browser tests check exactly that.

Devices with their own keys

Every device has a signed identity. Devices are paired by comparing a code; removing a device gives the project a new key. A server cannot slip in a device of its own.

A recovery code instead of a back door

A 128-bit recovery code is shown once and can be printed; it unlocks your projects in any browser, also from a backup file. Without a device or this code nobody can restore your data – including us.

Sign-in without a password

A device key plus a link by e-mail; every request is signed, fresh and valid once.

A private area

Each person has an encrypted area for private notes on shared texts. Nothing from it ever ends up in a project, an export, a printout or an AI request.

AI only when you want it

WriteFlow has no AI of its own and no hidden AI features. AI runs with your own key and a provider of your choice, down to a local model, within the permissions you set; every interaction is logged. Your text goes to an AI provider only when you ask for it.

No telemetry, no tracking

The error log contains steps, never text, and stays on your device. There are no analytics – neither in the app nor on this website.

A hardened server

The server software has a documented threat model, limits on size and rate, no account enumeration, strict security headers and a security self-test that runs with every check of the code.

App or browser?

Both encrypt your projects end to end. They differ in where the program code comes from.

Mac app – the most secure

The program code is installed on your computer and only changes when you update it. A compromised server cannot hand you modified code.

Download

Browser – the most convenient

Nothing to install: open it and write. The code comes from the server each time you load the page, so you trust that server each time. Strict content security rules and no third-party scripts reduce the risk; signed builds and installation as an app are coming.

Start in the browser

For sensitive work we recommend the app.

Limits we name

  • Lost device and lost recovery code mean lost data. We cannot help – that is the point of end-to-end encryption.
  • There is no search and no AI on the server side over your contents, because the server cannot read them.
  • Signing out locks your private area, but does not protect your projects from the next person using the same browser.
  • Provenance cannot detect text that was typed in from a second device. WriteFlow describes how a text came about; it does not prove independence.