Writesonic — privacy & data policy
Provider: Writesonic. PromptPrivacy score: 89/100. Last verified August 26, 2026.
What happens to your data?
Writesonic processes your account details and prompts to generate text, images, and other AI content through integrated third-party model providers. Your inputs and outputs are protected under strict no-training commitments and are retained according to defined operational schedules before deletion. Data is shared only with vetted sub-processors necessary to run and secure the platform.
Does it train on your data?
Writesonic explicitly does not use customer data, prompts, or generated outputs to train or fine-tune general-purpose, foundation, or large language models (whether its own or those of third-party model providers like OpenAI and Anthropic). This no-training policy applies to both paid and free/trial tiers, though de-identified and aggregated data may be used for service debugging, security, and operational improvements.
Can you opt out?
Yes. Users can exercise their privacy rights and opt out of data sharing via in-product privacy controls or by emailing Writesonic. The service also honors Global Privacy Control (GPC) signals for opting out of data sharing/sales and provides cookie consent management.
Data retention
Customer data is retained for up to 30 days after account deletion before permanent deletion. Active account data is maintained for the life of the account, server access logs and crash reports are kept for 90 days, security audit logs for 1 year, support tickets for 3 years, and billing records for 7 years. Model providers typically retain API data for safety monitoring for up to 30 days unless Zero Data Retention is active.
Encryption & security
Writesonic implements administrative, technical, and physical security safeguards and maintains SOC 2 Type 2 certification. Specific cryptographic configurations and detailed security practices are published via its dedicated trust center.
Is it safe for work?
Yes. Writesonic is safe for enterprise and workplace use. It provides a formal Data Processing Agreement (DPA), SOC 2 Type 2 compliance, tenant-isolated cloud environments on Azure and AWS, and a strict commitment that customer prompts and outputs are not used to train foundation models.
Source policy: https://writesonic.com/privacy-policy