Type legal

Privacy Policy

This Privacy Policy explains how Tonic Studios LLC handles information in Type. Tonic Studios is the company's brand and registered fictitious name.

1. Current local-first behavior

The current build stores documents, folders, full settings, themes, uploaded fonts, sounds and images, a local Type profile cache, and any Type-specific profile picture in the browser or app database. Optional sign-in uses the separate Tonic ID service. For a signed-in user, Type's Cloudflare-hosted account service stores an opaque Type app-profile identifier, Type-specific display name, current Type legal acceptance, whether Type uses the shared or app-specific picture, bounded portable editor and sound preferences, profile creation/deletion events, premium-entitlement and purchase status, and an opaque hash identifying the active Type installation. The installation record also includes a generic device label, platform, status, and activity/expiration times. Type does not use or store a username. It does not store manuscript content, the Type-specific picture file, custom fonts, custom sounds, custom background/page images, export paths, cloud credentials, or user-controlled backup files. Native apps may store a signed, time-limited premium lease locally; the browser does not receive an offline lease. When you select the shared picture, Type displays the current profile-picture URL supplied by Tonic ID. When you select a Type-specific picture, Type stores that image locally and displays it instead without changing the shared Tonic ID picture. Type does not operate advertising or cloud manuscript synchronization. Its optional reporting is described below. If you connect a supported cloud provider, Type can also synchronize a more complete Writing Feel file to that provider's Type-owned app area. You can disable that provider sync in Cloud storage. The CarpeDiction selection lookup is temporarily disabled in normal Type builds. While it is disabled, selecting text or typing performs no CarpeDiction lookup or availability request. In a focused build where the lookup is explicitly enabled, choosing Look up in CarpeDiction from the text-selection menu sends only the selected word or phrase, limited to eight words, and the dictionary source to CarpeDiction. Every other lexical source remains collapsed and is sent only if you open that source card. Selecting text or typing does not send it. An enabled build may send CarpeDiction a content-free availability request when the editor opens, or returns after at least ten minutes of inactivity, to reduce free-host startup delay; it does not send periodic keep-alive requests. The availability request does not include selected text, document content, or Type identity, although ordinary connection metadata such as IP address and user-agent information may reach CarpeDiction's hosting provider. Pronunciation audio plays inside Type through a validated CarpeDiction proxy URL. Type does not open raw lexical-provider audio URLs; CarpeDiction contains provider retrieval and redirects, while the result identifies whether Merriam-Webster or Free Dictionary API supplied the audio.

On macOS, a Premium user may explicitly enable Background keyboard sounds and grant Type the system's Input Monitoring permission. While Type is not active, the native app then observes only that a key went down and whether it was a Return key, solely to play the locally configured sound. Type does not read the character or text, identify the other app, store or log the event, or send it anywhere. This opt-in is device-local, is excluded from account settings, backups, and exports, and stops when the user disables it or quits Type. Closing Type's window hides it only while this feature is active so the user can reopen it from the Dock.

After a material policy release, Type keeps any locally cached profile details readable and keeps profile deletion available even without a cached Type profile, but rejects profile edits, new device activation, server-backed settings writes, and new Premium checkout until the current Type Terms and Privacy Policy are accepted. Billing management and purchase restoration remain available for existing obligations without renewed acceptance.

2. Information you provide

Type may process your Tonic ID pairwise subject, stable opaque Type app-profile identifier, issuer, verified email, shared and Type-specific display names, shared profile-picture URL, bounded administrator status, Type profile and legal acceptance, profile-lifecycle events, premium entitlement, purchase and purchase-claim references, opaque installation hash, generic device-session information, portable preferences, optional Type-specific profile picture, writing, document metadata, custom themes, custom fonts, custom sounds, custom background/page images, imported files, backup files, and text you explicitly submit for a CarpeDiction lookup. Tonic ID handles passwords, Google/Apple provider credentials, owner hierarchy, security verification, and administration data; Type receives only whether the signed-in identity can open the central Admin dashboard. Cloud-file tokens are processed only after those separate integrations are explicitly enabled.

3. How information is used

Information is used to provide editing, personalization, account, export, backup, restore, user-requested synchronization, and user-requested lexical lookup features; maintain security; diagnose errors; and comply with law.

Optional performance and reliability reports help us understand slow page loads, rendering and interactions, and recurring technical failures. They contain coarse performance ranges, fixed error categories and counts, and limited release, initial page-category and platform information. They do not contain writing, document names or paths, account or visitor identifiers, page URLs, credentials, raw error messages or stack traces. We do not use them for advertising, identify individual visitors, reconstruct browsing histories, or join them to account or billing records. This is a bounded sample of an app run, not a complete record of activity or an upload of local console logs.

4. Storage and sharing

Writing, a Type-specific profile picture, custom media, and other local information remains on your device or browser unless you export it or enable a clearly identified external service. Type's app-profile, portable-preference, lifecycle, and entitlement records are stored in a separate Cloudflare D1 database and are available to authorized Tonic Studios administrators through Tonic ID. At your request, Tonic ID can create one protected account-data export containing Type's allowlisted server-backed profile, portable settings, lifecycle, entitlement, license/purchase/claim, and bounded device metadata. Type's contribution excludes manuscripts, documents, local custom media, credentials, full payment details, service logs, and private administrator notes. Identity sign-in exchanges the minimum OIDC claims described above with Tonic ID, including the shared profile-picture URL when one exists. When the CarpeDiction integration is explicitly enabled and you invoke it, the lookup shares only the selected word or phrase with CarpeDiction and its active lexical providers; the surrounding document and Type identity are not included. CarpeDiction may cache the query and provider results for up to 30 days without a Type account identifier. Type does not sell personal information. When CarpeDiction is explicitly enabled, its content-free availability request is the only CarpeDiction sharing that can occur without an explicit lookup action. Other information is shared only at your direction, with providers needed for enabled features, to protect rights and security, or when legally required.

These summaries are sent to Type's first-party reporting endpoint and processed by Cloudflare Analytics Engine in a separate dataset, not the account database or cloud backups. Ordinary connection metadata reaches Cloudflare when a request is delivered and is separate from the fields in this dataset. We use the dataset for aggregate statistical analysis; no persistent visitor, account or installation identifier is added.

5. Third-party services

Cloudflare hosts and protects Type's website and account endpoints. Delivering requests involves ordinary connection and request metadata, such as IP address, browser or user-agent information, requested URL, request time, and response or error status. Cloudflare and Tonic Studios may process this metadata to deliver the service, maintain security, prevent abuse, and diagnose availability problems. Local manuscript text is not included in this operational reporting. Type does not enable stock Cloudflare Web Analytics or advertising trackers; its separate first-party summaries are described below. Cloudflare may process browser Network Error Logging reports containing URL/referrer and network/error information. Cloudflare states that IP addresses are held transiently and personal information is purged during processing: https://developers.cloudflare.com/network-error-logging/#privacy. This describes Cloudflare's documented handling, not a promise of zero request metadata or proof of a particular redaction method. Cloudflare's Self-Serve Agreement incorporates its data-processing addendum for covered processing: https://www.cloudflare.com/terms/ and https://www.cloudflare.com/cloudflare-customer-dpa/.

For a web purchase, Paddle processes the payment details you provide directly to its checkout under its own buyer terms and privacy notice. Type and Tonic ID do not store your full card details, payment method, or billing address. Tonic ID stores the minimum provider references, selected plan, price and currency, billing status, paid-through dates, verified event summaries, and entitlement needed to bind the purchase to the authenticated Tonic ID and reconcile changes. It does not send your manuscript, Type profile picture, or editor preferences to Paddle. The checkout-policy receipt contains only the public policy version and a server-assigned acceptance time linked to that operation. It is separate from optional marketing or payment-method-saving consent, neither of which is implied by using Type.

Tonic ID and optional Apple, Google, Dropbox, Microsoft, iCloud, OneDrive, or other enabled integrations have their own privacy terms. CarpeDiction and the lexical providers it exposes for a source you request, which may include Merriam-Webster, Words API, Datamuse, Free Dictionary API, or Twinword, have their own privacy terms. Type does not request Urban Dictionary or Translation sources. Lexical results may be incomplete, inaccurate, or offensive. Store privacy disclosures must match every production provider and data flow before release.

6. Retention and deletion

Local information, including a Type-specific profile picture, remains until you delete or replace it, switch back to the Tonic ID picture, clear app/browser data, uninstall the app, or restore a device. You control exported copies and backups separately. Deleting a Type profile removes its current server profile, synced portable preferences, and active Type installation session and records a deletion event; it does not cancel or refund a purchase and does not delete Tonic ID, other app profiles, local writing, exports, or user-controlled backups. Deleting Tonic ID automatically triggers that same server-profile and portable-settings deletion before the central identity is removed. Minimal lifecycle, purchase, purchase-claim, entitlement, device-session, security, or legal records may remain where needed to preserve or recover a purchase, prevent abuse, resolve disputes, or comply with law. Deleting or changing a Tonic ID picture does not delete a Type-specific picture. Tonic ID cannot remotely erase local writing, app-specific pictures, exports, or user-controlled backups; remove those separately.

Current paid entitlement information is retained for the account lifetime. Minimal billing audit records are retained for seven full years after the calendar year of the final related event, adjustment, or relationship end, then deleted or irreversibly anonymized. A checkout-policy receipt associated with a retained billing transaction follows that record's retention. Unlinked terminal checkout and portal operations are retained for 90 days. Tonic ID does not retain raw webhook bodies, full card details, payment-method data, or billing addresses in this billing ledger. Account deletion removes direct identity links where appropriate; minimal retained billing records do not promise license restoration or transfer. The protected Tonic ID account export includes bounded paid-billing summaries and associated policy version/time.

Timestamped reporting contributions are retained in Cloudflare Analytics Engine for three months. Sampling and delivery failures can make statistical counts approximate. Turning reporting off drops unsent summaries and stops future collection in that page; it does not undo processing already completed. Reports carry no account or visitor identifier that Type can use to locate an individual's contributions. We do not retain exports to bypass this retention period.

7. Security

Type uses platform storage and input validation appropriate to the current local build, but no system can guarantee absolute security. Keep independent backups of important writing and protect access to your device.

8. Children

Type is not directed to children under 13 and does not knowingly collect their personal information through a production service. Contact us if you believe a child has provided personal information.

9. Your choices and rights

You can manage identity, linked providers, active sessions, and the shared profile picture through Tonic ID; request the protected unified account-data export; choose that shared picture or upload or replace a Type-specific profile picture in Type; switch the active Type installation; sign out; delete the Type profile and synced portable preferences; delete local documents; export backups; disable Background keyboard sounds; disable provider-based Writing Feel sync; disconnect cloud providers; or clear app data. Depending on location, you may have additional access, correction, deletion, portability, objection, or complaint rights.

Use Reporting at the bottom of Type to allow or turn off these optional summaries, independently of sign-in, purchases and Terms acceptance. Type shows a notice before collection. For this release, reporting defaults on with an off control only for the United States; all other or unknown regional dispositions require an affirmative choice first. A saved refusal or browser Global Privacy Control signal keeps reporting off. Only a coarse policy disposition is returned to the app; country and IP address are not added to summaries. Your preference is stored locally without an identifier and is not synchronized to your account. Withdrawal takes effect immediately for unsent and future reports; re-enabling applies on the next page load and does not trigger a retry. Writing, sign-in, existing Premium and billing management do not depend on this choice.

10. Changes

We may update this policy as Type changes. Material changes will be shown in the app and renewed acknowledgment will be requested where required.

11. Contact

Privacy requests and legal correspondence may be sent to legal@tonicstudios.org. Product help may be requested at help@tonicstudios.org. The current hosted policy is available at https://writewithtype.com/privacy.