Privacy Policy
Effective date: August 27, 2026
This Privacy Policy explains how WriteStack ("we", "us", or "our") collects, handles, stores, and shares user data when you use https://www.writestack.io, our web application, and the official Chrome extension WriteStack: Substack Notes Scheduler & Analytics (the "Extension").
If a product handles personal or sensitive user data, Chrome Web Store policy requires a privacy policy that covers collection, handling, storage, and sharing. This document is that policy. Omission of any of those sections is not allowed, so each is described below in its own section.
User Data Collection
We collect user data that is needed to operate WriteStack: scheduling and publishing Substack Notes, analytics, automations, account access, billing, and related product features. We collect data you give us directly, data the Extension reads from Substack while you are signed in, and limited technical data generated by use of the Service.
Account and identity data we collect includes:
- Name, email address, profile photo, and password (stored as a hash) when you create an account
- Google account identifiers and OAuth tokens if you sign in with Google
- Session tokens and authentication cookies for your WriteStack account
Content and Substack data we collect includes:
- Notes, drafts, scheduled posts, images, attachments, voice memos, writing-style settings, and other content you create in WriteStack
- Public and non-paywalled Substack Notes, posts, comments, restacks, and engagement statistics needed for analytics, inspiration, scheduling, and automation
- Subscriber and audience metadata used by features you enable, such as welcome DMs (name, handle, photo, subscription type, and related profile data) and email-list export job records
- Direct-message metadata used to help you connect with people who engage with your content, such as thread participants, handles, timestamps, and unread counts. We do not store the body of your private Substack direct messages
Authentication and extension data we collect includes:
- Substack session cookies (including substack.sid, substack.lli, and related browser cookies) so the Extension can schedule, publish, and sync on your behalf while you are logged into Substack
- A WriteStack extension key, the installed Extension version, and your linked Substack author or publication identifiers
- API keys and OAuth tokens for optional integrations you connect, such as Buffer, Kit, or the WriteStack MCP
Billing, usage, and device data we collect includes:
- Subscription status, Stripe customer and subscription identifiers, and limited payment metadata. Full card numbers are collected and stored by Stripe, not by WriteStack
- Product usage events, feature interactions, pages viewed, approximate location derived from IP address, browser type, and device information
- Support messages, feedback, and emails you send us
The Extension does not collect paywalled, subscriber-only, or similarly designated paid Substack content. That paid content stays on your device and is not transmitted to or stored by WriteStack.
User Data Handling
We handle user data only to provide, maintain, secure, and improve WriteStack's single purpose: helping creators write, schedule, publish, analyze, and grow Substack Notes and related content.
Specifically, we handle user data to:
- Create and authenticate your account, keep you signed in, and connect the Extension to the correct Substack publication
- Schedule, sync, and publish Notes and chat posts through the Extension using your Substack session
- Show analytics, inspiration, activity, welcome DMs, and other features you turn on
- Generate or improve drafts when you use AI-assisted writing tools
- Process payments, manage subscriptions, and send transactional or product emails
- Diagnose errors, prevent abuse, and measure whether the product is working
- Comply with law, enforce our Terms of Service, and respond to support requests
User data is transmitted over HTTPS. Access inside WriteStack is limited to systems and people who need it to operate the Service, investigate abuse, or provide support you request.
Limited Use disclosure: We comply with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data collected through the Extension is used only to provide or improve user-facing WriteStack features. We do not sell Extension user data. We do not use Extension user data for personalized, retargeted, or interest-based advertising. We do not allow humans to read Extension user data except with your consent for support, when required for security or legal compliance, or after the data has been aggregated and anonymized for internal operations.
User Data Storage
We store user data on our application servers and in cloud infrastructure used to run the Service. That includes a hosted database, object storage for images and uploads, and application hosting.
How storage works:
- Account, notes, schedules, analytics, extension keys, integration tokens, and settings are stored in our primary database
- Images and other file uploads are stored in cloud object storage
- Substack session cookies needed for publishing are stored so the Extension and server-side automations can act on your behalf until they expire or you disconnect
- Payment card details are stored by Stripe. We store only the billing identifiers and subscription records needed to manage your plan
- Some preferences and UI state may also be stored locally in your browser (for example localStorage) and are not used to identify you across unrelated sites
We retain user data while your account is active and for as long as needed to provide the Service, meet legal or accounting requirements, resolve disputes, and prevent abuse. When you delete content or close your account, we delete or de-identify associated personal data within a reasonable period, except where we must keep a limited record (for example a billing receipt or a record of a ban).
We use commercially reasonable safeguards to protect stored data against loss, theft, unauthorized access, disclosure, copying, use, or modification. No method of storage is completely secure, and we cannot guarantee absolute security.
Chrome Extension
The official browser extension is WriteStack: Substack Notes Scheduler & Analytics (Chrome Web Store item ID emdlbnkhjpfcooclfbodmhkhkohcjaoa). The Extension runs in your Chromium browser so WriteStack can schedule Notes, publish content, collect analytics, run automations, and stay signed into the Substack account you choose.
The Extension may read Substack pages you are viewing or logged into, including cookies, public Note and post content, engagement stats, subscriber metadata for features you enable, and related non-paywalled resources. It sends that data to WriteStack over HTTPS using your Extension key. It does not collect paywalled or subscriber-only content.
Your Choices and Rights
You can refuse to provide personal information, but we may then be unable to provide some or all of the Service. You may access, update, or delete much of your account data in the product. You may disconnect integrations, sign out, uninstall the Extension, or request account deletion.
To request access, correction, or deletion of your personal data, email orel@writestack.io or support@writestack.io. We will respond within a reasonable time. Depending on where you live, you may also have rights under laws such as the GDPR or CCPA, including the right to object to certain processing or to lodge a complaint with a supervisory authority.
Children's Privacy
WriteStack is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will delete it.
International Transfers
We may process and store user data in the United States and other countries where we or our service providers operate. If you use the Service from the European Economic Area, the United Kingdom, or another region with data-transfer rules, you understand that your data may be transferred to and stored in countries that may not provide the same legal protections.
Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the bottom of this page will change when we do. For material changes we will provide notice through the Service or by email. Continued use of the website, app, or Extension after an update means you accept the revised policy.
Contact
Questions about this Privacy Policy or about how we collect, handle, store, or share user data can be sent to orel@writestack.io or support@writestack.io. The Service is operated by WriteStack at https://www.writestack.io.