WriteLang / 쓰면영어 Privacy Policy
As of 2026-09-08: written feedback and final text-free ratings are transmitted. Device IDs and device hashes are not transmitted.
Updated: 2026-09-08 · Effective date: First public beta release (date not yet set) · 한국어
1. Operator and scope
WriteLang, known in Korea as 쓰면영어, is a free desktop app provided by an individual developer without a registered business. This policy covers the first Windows public beta distributed through Microsoft Store and zip. It will be checked and updated for any later macOS release. There are no accounts, payments, subscriptions, cloud sync, or operator-owned remote inference servers.
Operator: the individual developer providing WriteLang. Privacy and complaints contact: WriteLang Privacy and Inquiries. Contact and rights requests: hello@writelang.com. The developer handles requests directly, without a separate department.
2. Processing on your device
Translation and correction input and output, local history, and settings are processed on your device. The operator does not automatically receive or remotely inspect them. Operating-system access used to read selected text or replace it with a result is used for those features. You manage local history. Uninstalling may leave settings or history files; delete those local files separately if needed. The operator cannot remotely erase them.
The app does not collect advertising identifiers, general usage tracking, automatic error or crash reports, or your entire clipboard history. We do not collect translation/correction input, output, notes, or copy/replace activity for the operator’s quality improvement. User-selected final like/dislike ratings are transmitted separately as described in section 3. Device IDs and device hashes are not transmitted or stored. Translation content and diagnostic logs are not automatically attached to feedback. Downloads needed for local execution and external providers' processing are explained separately in section 5.
3. App processing outside your device
The app has no tracking cookies or advertising collection tools. The zip distribution requests https://writelang.com/latest.json once at startup to check for a newer version. The request contains no translation content, device ID, email or current app version, but the hosting/CDN provider may receive your IP address and ordinary HTTP request information. Turn off Check for updates in Settings to stop these requests from the next launch. The Microsoft Store distribution does not make this request; Store updates are separate under section 5. Failed checks are silently ignored and do not prevent app use. The static site's actual hosting provider, processing countries and access-log retention must be confirmed and reflected here before public release.
Starting the app requires no blanket privacy-consent popup. Inquiry handling and rating collection have distinct grounds. A policy link or button click does not replace separate consent where required by law.
| Activity | Purpose and data | Basis and choice | Retention |
|---|---|---|---|
| Written feedback | Handle inquiries, investigate issues and reply. Written content, optional reply email, app version, OS, random submission id, time, schema/type | PIPA Article 15(1)(4), contract performance or requested steps toward a contract, only to the extent necessary for app-related inquiries. Email is used only when a reply is requested. Nothing is submitted until Send is pressed | Section 3.1's 30-day/90-day limits. Actual deletion operations are not complete |
| Final text-free ratings | Compare model/prompt quality. up/down, model_tag, prompt_version, app version, OS, random submission id, time, schema/type | Sent when a request with a selected rating ends. No rating, or cancelling it before completion, sends nothing. The inquiry-handling contract basis does not cover this statistical collection. Separate processing and international-transfer grounds for ratings remain unresolved | Raw rating-event retention remains to be set separately; inquiry limits do not automatically apply |
Feedback and ratings are sent over HTTPS to Cloudflare Workers at ingest.writelang.com and stored in D1. There is no R2 storage or remote model training. Ratings omit translation input/output, notes, copy/replace activity, window titles and source-app names. The current feedback form adds only written content and optional email to its payload, without automatic translation or diagnostic attachments. Legacy diagnostic-queue compatibility code remains; queued items from earlier installations can differ from the current form.
Failed submissions retry from a local queue (100 items maximum, 256 KiB per item, removal of 30-day-old items at startup/retry). This is not server retention. Submission ids prevent duplicates and are not persistent person/device identifiers. Events processed with email or other identifying information are not assumed anonymous. Surveys and automatic error/crash uploads are not currently exposed or enabled.
Cloudflare can process IP and HTTP request information during connections. The Worker uses IP transiently for request limiting, does not record it in D1, and has persisted Workers observability disabled in its configuration. This does not imply that Cloudflare itself collects or retains no network/security data. Its own processing follows its policy.
Do not include other people's personal data, sensitive information or confidential material. Inclusion in an inquiry does not authorize every use. Feedback and email are not used for model training, public datasets, sale or advertising.
3.1. Optional reply email and inquiry retention
Implementation status: These are the operating rules established in this draft. Server expiry, inquiry closure tracking, and deletion checks for mail and copies have not yet been implemented and verified. Publishing this text does not perform deletion; put the actual procedures in place before making the policy effective.
- Choice and purpose: Enter an email only if you want a reply. You can submit comments without an email, with no disadvantage in app functionality. Use the address only to answer that inquiry and related follow-up questions. Do not use it for advertising, newsletters, profiling, linking translation ratings to an identity, or automatically tracking the sender across different inquiries.
- Data and basis: The address you provide, your inquiry, and submission identifiers and receipt/reply times needed to handle it. PIPA Article 15(1)(4), contract performance or requested steps toward a contract, is the basis for necessary app-related inquiry handling. It does not extend to general quality statistics, advertising or unnecessary collection. Establish a lawful basis and any necessary separate consent before adding another purpose. Merely labelling the field optional or receiving a voluntarily entered address is not treated as consent.
- Retention limit: Keep inquiries/comments, their optional email and replies until 30 days after the final reply or 90 days after first receipt, whichever comes first. Unanswered or unresolved inquiries also have a maximum of 90 days from first receipt. Follow-up replies do not extend the 90-day limit, and retries of the same submission do not reset first receipt. Written comments without an email also have a maximum of 90 days from receipt. These are operational limits, not statutory minimum retention periods.
- Earlier deletion: Delete without delay, rather than waiting for the limit, if the reply/follow-up purpose ends earlier or a valid deletion request, suspension or consent withdrawal makes the data unnecessary. Apply the exception in section 6 only when a specific legal preservation obligation actually applies.
- Deletion scope: Delete the entire relevant D1 feedback row, including email and content within stored JSON, as well as received/sent mail, attachments, drafts, trash and downloaded JSON/CSV or working copies. Removing only an email field while retaining the same address in a raw record is insufficient. Do not delete other users' records when handling one inquiry.
- Backups and recovery: Under the documented Free plan, D1 has up to seven days of recovery history. Deleted operational data may remain in that history during its recovery window and must not be reused for inquiry handling or analysis. After restoration, exclude previously deleted data again before resuming operations. Reassess disclosures and procedures when changing the plan or backup settings. This is not a promise that email providers' internal backups are deleted within the same seven days; their terms remain to be verified under section 5.
- Requests and protection: Request deletion or suspension at hello@writelang.com. Where possible, write from the submitted address and provide an approximate submission date or identifier. Verify only what is needed to locate the data; do not routinely demand identity documents. The operating standard is to prevent automatic accumulation in an address book, restrict inquiry access to the responsible developer, and use multifactor authentication for administrative accounts, device locking and disk protection.
4. Disclosure, processors, and international transfers
We do not sell personal data or disclose it for advertising. Disclosures required by law are limited to the applicable basis and scope. There are currently no account, payment, or sync processors.
Receiving and processing services
| Provider and contact | Task and data | Location and timing | Retention |
|---|---|---|---|
| Cloudflare, Inc. — privacy contact, 101 Townsend St, San Francisco, CA 94107, USA | Workers receipt and D1 storage of section 3 submissions and event metadata; IP/request information for network security | On submission/retry. Initial D1 hint: eastern North America (ENAM), not a country restriction. Workers operate on a global network | Inquiries: section 3.1. Rating retention unresolved. Provider security-log periods require separate confirmation |
| Cloudflare, Inc. — contact above | Email Routing forwards inquiries sent to the public address | On email receipt, forwarded to Gmail through the US provider's global network | Mailbox storage is below; forwarding and security/delivery metadata are distinct |
| Google LLC — privacy contact, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | Personal Gmail storage/service for inquiry messages, replies, addresses and attachments | On receipt/reply. The US-resident developer accesses mail in the US; Google also processes data on servers abroad | Operator-controlled mail: section 3.1. Provider deletion/backups: Google retention policy |
Cloudflare publishes its Self-Serve terms and DPA, with an official subprocessor list. Not every listed entity necessarily receives this app's data. Personal Gmail is not represented as covered by a Google Workspace agreement or Workspace DPA.
International processing grounds and choice
The developer handles inquiries in the United States. For overseas processing/storage necessary to handle app-related inquiries, the intended route is policy disclosure under PIPA Article 28-8(1)(3)(a). This applies only where necessary contract performance and all required disclosures are satisfied; it does not extend to rating statistics or independent third-party disclosure. EU standard clauses or US certifications alone are not treated as automatically satisfying Korean transfer requirements.
Still unresolved: actual D1 storage country and applicable Workers/mail processing and subprocessor countries; contractual coverage for Korean users' data under the current accounts; and a separate transfer basis for ratings. ENAM or “worldwide” does not establish a complete statutory country disclosure. The table describes the verified service structure, not approval of these unresolved matters.
To avoid this processing, do not submit feedback/email or select a rating. Local translation/correction remains available, but no individual email reply is possible without an address. Contact hello@writelang.com to exercise rights over submitted data.
5. External services you access
At first launch you download a model from Hugging Face. The Windows zip distribution also downloads llama.cpp executable files from GitHub; the Store distribution includes them in its package. These requests contain no translation input or output, but the providers and their CDNs may receive your IP address and ordinary HTTP request information. This is independent processing by download providers, separate from app feedback collection. Microsoft Store may also process download and update information under its own policy. This does not mean the operator receives their logs.
If you email the contact address, email services process your reply address and the inquiry you choose to send. This is not automatic app collection. Avoid unnecessary information such as translation text or identity documents. The public contact address routes incoming mail through Cloudflare Email Routing to a personal Gmail account. The same purpose, retention and deletion rules in section 3.1 apply to inquiries sent directly by email, including inbox/sent messages, attachments, trash and downloaded copies controlled by the operator. Email Routing and the Gmail destination are configured, but receipt testing for each alias remains outstanding. A separate outbound relay for hello@ is not configured, so Resend is not listed as a current processor.
Provider policies: Hugging Face, GitHub, Microsoft, Cloudflare, Google.
6. Deletion and safeguards
Personal data no longer needed after retention expires, the purpose is fulfilled, a valid deletion request, or consent withdrawal is deleted without delay. Electronic files are deleted in a way that makes recovery difficult; any paper copies are shredded. If a legal preservation obligation actually arises, we identify the law, data and period and store it separately. We do not arbitrarily apply paid-transaction retention periods to this free, account-free beta.
Operational requirements for external processing are HTTPS, developer-only access, account protection, scheduled deletion and incident response. Verify feedback storage access controls and backup deletion before public distribution. You manage device security and backups; this policy does not promise that all local app files are encrypted.
7. Your rights
You or an authorized representative may request access, correction, deletion, suspension of processing, or withdrawal of consent at hello@writelang.com. We verify only the minimum information needed to locate the request and respond within applicable legal deadlines, including reasons for any restriction. There is no account-deletion process because there are no accounts. Use the contact address above to request suspension or deletion of feedback. Before sending, Cancel closes the form. There is currently no screen to cancel individual queued items. To stop pending transmissions, fully exit the app and request queue-cleanup guidance at the contact address. The submitted email and approximate date help locate records; identity documents are not routinely required. For local data we do not hold, we provide guidance for your own management.
We do not profile you or make automated personal-data-based decisions about your rights or obligations. Korean rights assistance and dispute resolution are available through the Privacy Portal and Personal Information Dispute Mediation Committee.
8. Children under 14
The first public beta is intended for people aged 14 and older, and we do not accept feedback submissions from children under 14. We do not routinely collect birth dates or identity documents. If we learn that we received personal data from a child under 14, we stop that processing and take appropriate measures, including deletion without delay. Any future consent-based processing for that age group requires a parent/legal-guardian consent and verification process first.
9. Changes
Changes and their effective date will be published with the policy and through accessible app notices. If a changed optional purpose or data category requires new consent, we obtain it separately before transmission. The Korean and English versions describe the same processing; please report discrepancies to the contact address.
Website feedback
When you press Send on the website, your message, a random submission reference, submission time, form version and a web-channel label are sent through Cloudflare Pages to the existing Worker and D1. The form has no email field and does not attach device identifiers, your actual OS, translation content or diagnostic logs. Messages are used for inquiry handling; section 3.1’s retention rules for comments without email and deletion-request process apply.
The form does not save messages in cookies or persistent browser storage. After a failed send, text remains only in the open page; no background retry occurs. Closing the page discards that text and its retry reference. Cloudflare may process IP and HTTP request information during HTTPS connections; this does not guarantee zero retention.