Security & Privacy Practices
Version 1.0 · Effective 2026-08-09 · Last updated 2026-08-09
This page summarizes security and privacy practices currently reflected in the WriteBehavior product. It is informational and may change as the product evolves.
Security practices do not by themselves constitute HIPAA compliance.
Authentication
WriteBehavior uses authenticated sign-in with required email two-factor authentication. Access to application features requires a session that has completed both password sign-in and a one-time code emailed to the account address, unless the user opts into Remember this device for up to 14 days on that browser. Invitation-only registration is used so new accounts are created through controlled invites rather than open public signup.
Role-based access
Accounts have roles such as user and admin. Administrative tools are limited to active admin accounts. Regular users cannot access admin management features.
Private company document storage
Uploaded company documents are stored in private cloud storage associated with your account. Other users cannot browse or download your company documents through normal product access controls.
Row Level Security
Application tables that store user content are protected with Row Level Security so users can only access their own records (for example notes, guidelines, templates, documents, and policy acceptances), subject to authenticated access.
Server-side API secrets
Service credentials and AI API keys are configured as server-side environment variables and are not exposed in the browser bundle for normal product use.
Privacy checks before AI processing
Before note generation, WriteBehavior can scan submitted text for certain categories of potentially identifying information and ask you to review or acknowledge before continuing. Automated detection is incomplete; you should still review content carefully.
Data deletion
Users can download an account data export and permanently delete their account from Account Settings. Administrators can also review and complete previously queued deletion requests. Completed deletion removes associated application data according to the product’s deletion process.
Security contact
To report a security concern related to WriteBehavior: support@writebehavior.com.