Legal
Last updated: August 4, 2026
Short version: this website uses no advertising cookies and no third-party trackers. We collect only anonymous, self-hosted first-party usage statistics — and only if you explicitly opt in first. Without your consent nothing is collected, no analytics ID is set, and no beacon is sent. Technically necessary `localStorage` (theme, language) is used without consent — no consent is required for it under § 25(2) No. 2 TDDDG (see below).
§ 25(1) TDDDG (Germany's Telecommunications-Digital-Services-Data-Protection Act) generally requires consent for storing information on your device or accessing it. § 25(2) No. 2 TDDDG carves out an exception when the storage is strictly necessary for a service you explicitly requested to function.
Without consent, we only use `localStorage` for your theme (light/dark) and language preference — a purely functional setting you trigger yourself, which would otherwise be lost on every page load. That falls under the § 25(2) No. 2 TDDDG exception: no consent is required for it.
For the optional usage statistics, we store random IDs in `localStorage`/`sessionStorage` only after you opt in. The legal basis for this access to your device is your consent under § 25(1) TDDDG; the subsequent processing of the anonymous statistics is based on Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future.
We only collect anonymous statistics after you click "Agree" in the banner. If you click "Decline" or make no choice, nothing is collected and no analytics ID is stored.
What we then collect: pages viewed, the referring website (its domain only) and any UTM campaign parameters, a coarse device class (desktop/tablet/mobile), a coarse browser and operating-system type, window size as a coarse category only, random visitor and session IDs, and individual interaction events (e.g. opening and submitting the waitlist or support form). Optionally a two-letter country code, if our hosting provides one.
What we never store: your full IP address, your full user agent, email addresses, names, your precise location, or any cross-site identifier. IP address and user agent are only combined server-side into a daily-rotating one-way hash that lets us count returning visitors without setting a cookie — the source data is discarded immediately and never stored.
Where: the data lives exclusively on our own hosting (first-party, PHP/MySQL with our provider in Germany). Nothing is sent to Google Analytics, ad networks, or any other third party.
How long: individual event records are deleted automatically after at most 90 days; only aggregate figures derived from them that can no longer be linked to a person may be kept longer.
Withdrawal: you can withdraw your consent at any time via "Analytics settings" in the footer. On withdrawal we delete the random IDs stored in your browser and stop collecting. Withdrawal does not affect the lawfulness of processing carried out beforehand.
We don't use Google Analytics, a Facebook pixel, or any ad networks. There are no cross-site profiles and no sharing of your data with third parties for advertising. Fonts are served directly by us and never loaded from Google's servers at runtime.
localStorage – theme: own website, remembers your light/dark choice, until you clear your browser storage, technically necessary, § 25(2) No. 2 TDDDG — no consent needed.
localStorage – language: own website, remembers your language choice, until you clear your browser storage, technically necessary, § 25(2) No. 2 TDDDG — no consent needed.
localStorage – consent decision (`writely.consent.v1`): own website, stores your agree/decline choice so we don't ask again and honour it, until you clear your browser storage, technically necessary to implement your decision (§ 25(2) No. 2 TDDDG).
localStorage – analytics visitor ID (`writely.analytics.vid`): own website, random ID to count returning visitors, set only after consent, until withdrawal or you clear your browser storage, § 25(1) TDDDG / Art. 6(1)(a) GDPR.
sessionStorage – analytics session ID (`writely.analytics.sid`): own website, random ID for session counting, only after consent, until the browser session ends, § 25(1) TDDDG / Art. 6(1)(a) GDPR.
Statistics events (server database): own MySQL database, anonymous event data (see above), only after consent, deleted automatically after 90 days, Art. 6(1)(a) GDPR.
Rate-limit counter: briefly protects forms from automated abuse, server-side only and not stored permanently, Art. 6(1)(f) GDPR (no access to your device, so § 25 TDDDG doesn't apply).
The Writely app itself still uses no analytics or crash-reporting SDK. The statistics described here concern this website only. Your app settings are stored exclusively on your device.
Should we materially change the nature or scope of these statistics, or add analytics to the app in the future, we will update this page and — where required — obtain your consent again under § 25(1) TDDDG beforehand.