What we collect, and what we don't.
Short version: if you fill in a form, we keep what you typed so we can reply. If you just read the site, we count the visit without knowing who you are. We don't sell anything to anyone, and there are no advertising trackers on this site.
Write It Great LLC.
A literary agency and ghostwriting firm, working from Oakland, California and Boston, Massachusetts, with European representation in Brussels. We're the ones deciding what happens to the information described here — the "data controller", if you want the formal term.
Because we have people in the EU, European data protection law applies to us as well as US law. We've written this page to the stricter of the two throughout, rather than keeping two sets of rules.
Questions, or want something deleted: [email protected]. A person reads that address.
We keep what you typed, to answer you.
Three forms on this site send us something: the planning interview, the service enquiry forms, and the feedback bubble in the corner. What you type is stored in our own database and emailed to the relevant person here. That's your name, email address, company if you gave one, and whatever you wrote about your book or your project.
We use it to reply to you and to prepare for a conversation. It is not added to a mailing list, it is not sold, and it is not shared outside our team — the confidentiality statement covers what happens to the work itself in more detail.
We also record how you arrived — the site that linked you to us, or the campaign tag on the link you clicked. That's so we know which of our efforts actually reach people. It's about the link, not about you, and it's never bought from anyone.
We count the visit. We don't know it's you.
We run our own analytics — our software, our servers, no Google Analytics and no advertising network. It records which pages were read, roughly how long for, how far down the page people got, which site linked them here, which country the visit came from, roughly what browser and device were used, and which links out to other sites got clicked — including when someone sends us a form or starts a proposal. That's the whole list. Never what you typed into a form, and never anything bought from a data broker.
Your IP address is never stored in our analytics. It's used for a moment, in memory, to work out a country and to produce a scrambled identifier, and then it's gone — there is no IP column in our database and no IP in the analytics we keep. The same goes for your browser's user-agent string: we keep "Safari on iOS, phone" and discard the rest.
One thing we should be straight about, because most privacy policies quietly aren't: like every website, our hosting provider writes a short-lived server log of incoming requests, and those lines contain IP addresses. We don't build anything from them, they roll off after about a week, and we've turned off the application's own access log so it isn't duplicated — but it would be untrue to tell you no log anywhere ever sees your IP address.
If you haven't accepted the optional cookie (section 4), the identifier that lets us tell one visit from another is a one-way hash whose recipe changes every day at midnight UTC. So we can see that someone read three pages this afternoon, and we genuinely cannot tell whether that same person came back on Thursday. That's not an oversight — it's the point, and it's why this baseline measurement doesn't need your permission. If you did accept the cookie, the identifier is stable instead, for as long as the cookie lasts — that's exactly what the cookie is for.
Not forever.
Individual page-view records are deleted after 90 days. Visit summaries are kept for 400 days, so we can compare a month against the same month last year. After that, only the daily totals survive — numbers with nothing individual left in them, which we keep indefinitely.
What you send through a form is kept while there's a live conversation and for as long as we're required to keep business records afterwards. If you ask us to delete it and we're not obliged to keep it, we will.
Our suppliers, and no one else.
The site runs on Heroku (Salesforce) and our internal dashboard runs there too. Email is sent through Google Workspace. Images are hosted by Cloudinary. Each of them processes data on our instructions to run the service, and none of them is given anything for their own purposes.
We don't sell or share personal information, and we never have — including under the specific meaning California law gives those words.
Ask, and we'll do it.
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us using it. If you're in the EU or the UK you can also complain to your national data protection authority; if you're in California you have the equivalent rights under the CCPA and we won't treat you any differently for using them.
Requests about anything you sent us through a form we can act on straight away. Analytics depends on which of the two you are:
- If you never accepted the optional cookie — the identifier is scrambled and changes daily, and we don't keep your IP address or your browser's user-agent string. So there is nothing in anything we hold that could point us at "your" page views: no name, no address, and no way to join one day's visit to the next. In practice that means there is nothing for us to hand over or delete. If you'd like us to confirm that for your own situation, write to us and we'll explain exactly what we checked.
- If you did accept it — we can, and we will. The
wig_vidcookie in your browser is the key. Send us its value and we'll retrieve or delete everything recorded against it. (Developer tools → Application → Cookies, or just email us and we'll walk you through it.) Choosing "No thanks" in the cookie settings deletes the cookie immediately and stops any further linking.
Email [email protected] and say what you want. No form to fill in.
Last updated 29 July 2026.
If we change how any of this works, we change this page at the same time. This is the first version.