Legal
Privacy Policy
Effective date: May 7, 2026
Draftly (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at draftly.io.
1. Information We Collect
Information you provide directly
- Account data: name and email address when you register. If you choose password authentication we also store a hashed password; if you choose magic-link or Google OAuth, no password is stored on our side.
- Workspace data: workspace name, slug, brand details (company name, tagline, logo) you optionally add for branded sharing or portals, and your role within the workspace.
- Project & document content: projects, documents, AI-generated drafts, version snapshots, comments, and any text or fields you supply — including descriptions of custom document types you ask the AI to draft.
- Integration tokens: if you connect a third-party service (GitHub, Linear, Jira, Notion, Confluence, Figma, OpenAPI), we store an encrypted access token solely to read or write the data you've explicitly authorised.
- Payment data: billing information processed through Stripe. We do not store raw card numbers — Stripe handles all payment data under their own privacy policy.
Information collected automatically
- Usage data: pages visited, features used, document types generated, and session duration — collected via PostHog analytics.
- Device data: browser type, operating system, and IP address.
- Cookies: session tokens required for authentication, an analytics cookie, and a short-lived signup-attribution cookie that records which public share, portal, or template page led you to sign up (so the publishing workspace can see how their shared docs convert).
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Draftly service.
- Process payments and manage your subscription.
- Send transactional emails (account confirmation, password reset, invoices).
- Analyse product usage to improve features and fix bugs.
- Comply with legal obligations.
We do not sell your personal data to third parties. We do not use your document content to train AI models.
3. Data Sharing
We share your information only with the following categories of trusted third parties (our “sub-processors”):
- Supabase — database and authentication infrastructure (EU/US data centres).
- Stripe — payment processing.
- Anthropic — AI document generation. The project context, dialog inputs, and any document content you submit for editing are sent to Anthropic’s API. Per Anthropic’s commercial terms, customer API data is not used to train their models.
- Voyage AI (planned) — text embeddings for in-product retrieval features. Document excerpts are sent only when this feature is enabled.
- Resend — transactional email (account confirmation, magic links, comment notifications).
- PostHog — product analytics (anonymised usage events).
- Vercel — hosting and edge network.
All sub-processors are bound by data processing agreements and handle data according to applicable privacy law.
User-initiated integrations (separate from sub-processors)
Draftly lets you connect third-party services you choose — GitHub, GitLab, Linear, Jira, Notion, Confluence, Figma, and OpenAPI providers. When you authorise an integration, your data is exchanged directly with that provider under their terms and privacy policy, not ours. You can disconnect any integration at any time from your workspace settings; we delete the associated access token immediately.
4. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or tax purposes.
Document content you create is stored until you explicitly delete it or close your account.
5. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (“right to be forgotten”).
- Object to or restrict processing of your data.
- Request a copy of your data in a portable format.
To exercise any of these rights, email us at info@draftly.io. We will respond within 30 days.
6. Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted storage, row-level security policies on our database, and access controls. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
7. Children
Draftly is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
8. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the application. The “Effective date” at the top of this page indicates when the policy was last updated.
9. Contact
Questions about this Privacy Policy? Contact us at info@draftly.io.
© 2026 Draftly. All rights reserved.
Terms of Service →