Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Writer keeps your personal data for as long as it needs to run the service and meet legal requirements, after which it deletes or anonymizes the data.
This analysis describes what Writer's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy does not specify exact retention periods for each data category, meaning users cannot easily determine how long their content and account data will be held.
Interpretive note: Specific retention periods for each data category are not disclosed in the policy, creating uncertainty about how long particular types of data are held in practice.
The updated policy removes detailed disclosures that previously explained five cookie categories (strictly necessary, functional, performance, targeting), their purposes, and user controls. The revised policy retains only a brief statement that Writer uses cookies to enhance navigation, analyze usage, personalize experience, and assist in advertising, but no longer provides the granular categories, opt-out procedures, or explanation of what data each type collects. Users can no longer reference specific cookie management options, targeting cookie opt-out procedures, or detailed functional descriptions within the policy itself.
View change record →Removal of specific data retention and deletion/anonymization commitments eliminates clarity on data lifecycle management.
View full change record →Writer does not disclose specific retention timelines in the policy text, so users cannot determine precisely how long their User Content, account information, or usage data will be retained after account closure.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
Monitoring
Writer has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We retain personal information for as long as necessary to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. When we no longer need personal information, we will delete or anonymize it.Excerpt from Writer's Privacy Policy
REGULATORY LANDSCAPE: GDPR Article 5(1)(e) requires that personal data be kept no longer than necessary for the purposes for which it was processed (storage limitation principle). The policy's formulation ('as long as necessary') is consistent with standard policy language but requires that specific retention schedules exist internally to operationalize this commitment. CCPA does not impose specific retention periods but requires accurate disclosure of how long personal information will be retained. GOVERNANCE EXPOSURE: Medium. The absence of specific retention periods in the policy is common in SaaS privacy policies but creates a GDPR compliance gap if internal retention schedules do not exist or are not enforced. Enterprise customers should request confirmation of retention periods for Customer Data in the DPA, particularly post-contract termination deletion timelines. JURISDICTION FLAGS: EU and UK data protection authorities have cited indefinite or unclear retention as a compliance concern. Organizations in regulated industries with specific record-keeping requirements (e.g., financial services, healthcare) must ensure Writer's retention practices do not conflict with those obligations. CONTRACT AND VENDOR IMPLICATIONS: The DPA should specify the period within which Writer will delete Customer Data following contract termination, and should address whether data is retained in backup systems and for how long. Standard GDPR processor agreements typically require deletion or return of data within 30 to 90 days of contract end. COMPLIANCE CONSIDERATIONS: Compliance teams should request Writer's data retention schedule as part of vendor due diligence, confirm that deletion of Customer Data upon contract termination is specified in the DPA, and verify that post-termination deletion is actually implemented in Writer's systems.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The policy does not specify exact retention periods for each data category, meaning users cannot easily determine how long their content and account data will be held.
Writer does not disclose specific retention timelines in the policy text, so users cannot determine precisely how long their User Content, account information, or usage data will be retained after account closure.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Writer.