Written
Privacy Policy
Effective 5 August 2026 · Last updated 5 August 2026
Written is an iPhone dating app. It builds your profile out of what you already listen to, watch, plan and do, so that you do not have to write one. That only works if you let it read some accounts, which means this document has to be specific rather than reassuring.
This policy covers the Written iPhone app, its share extension, and this website. It is written in the first person plural — "we" is the team that makes Written.
How Written reads: a snapshot, not a subscription
Written takes a snapshot. Each read happens once, in the foreground, in the seconds after you tap — and then it is over. Nothing polls, nothing runs in the background, nothing keeps watching your account afterwards. Between one snapshot and the next, Written is not reading anything at all. Everything below describes what a snapshot picks up and what happens to it afterwards.
Two things follow from that, and they are the two we would most like you to hold on to. What a snapshot took, you can strike out — any artist, channel, sport, show or event, in the app, at any time. And you can take all of it back by deleting your account, which is a button in the app rather than a request to us.
What we collect
What you tell us
- Your account. You sign in one of three ways, and
only the one you choose is used.
- Apple — we receive the identifier Apple gives us and, if you allow it, your name and email address, which is often a private relay address.
- Google — sign-in only. We ask for
openid email profile, which reads no content from any Google service, and we receive your email address and name. - Phone — your phone number, verified by a code sent over SMS. It is stored against your account and is shown to nobody.
- Your profile. First name, date of birth, gender, the district you live in, and optionally education and occupation.
- Your photographs. Up to six, in the order you arranged them.
- How you want to be approached. Two answers, given during sign-up, about flirtatiousness and how quickly you reply.
- What you write. Messages you send — text, photos, videos and voice notes — people you like or decline, links you share into the app, and anything you report.
- A notification token, if you allow notifications: an address Apple uses to reach that one device. It identifies the device, not you, and it goes with your account when you delete it.
What each source gives us
Nothing is read unless you tap and grant it, one source at a time. Every one of these is read-only: Written never asks any of them for permission to write anything back.
Written also keeps a copy of what each service actually replied, not only the version it makes of it. That copy is private to you, it is part of the data you can download, and it is deleted when you disconnect or when you delete your account. It exists so that improving how Written reads your data never means asking you to connect everything again. Two sources are left out of it on purpose — Apple Health and your location — because for those we throw the detail away on your phone and keep only the summary, and a stored copy would undo that.
- YouTube — the channels you subscribe to, the videos you have liked, and the playlists you made, with the labels YouTube returns alongside them. Not your watch history: the API does not expose it. Titles and channel names are deleted after 30 days, and nothing from YouTube is ever shown to another user.
- Google Calendar — the names of your calendars, and the events in them: title, date, location, organiser and any booking link. Calendars of birthdays and public holidays are left out.
- Apple Music — your library, playlists, recently added and recently played music, heavy rotation, recommendations, and the tracks you have marked liked or disliked.
- Apple Podcasts — the episodes held on your device and the shows they belong to.
- Apple Calendar — the same fields as Google Calendar, within the window the app reads. Birthday and public-holiday calendars are excluded.
- Apple Health — workouts, exercise minutes, active energy, steps, walking and running distance, and your date of birth and biological sex.
Your biological sex never leaves your phone. Apple Health reports it, we keep it on the device, and it appears in the copy of your data you can download — but it is refused before it can be uploaded, and it is not on our servers. The gender shown on your profile is the one you chose yourself, which is a different question and the only one we store.
The rest of what Health gives us is uploaded: your workouts, and one summary per day and per hour of the day. Not the raw measurements Apple Health holds — those are added up on the phone into daily and hourly totals first — and not continuously: only when you ask the app to read Health again.
Calendar events are the one thing here that can name somebody else. An event called "Dinner with Sam" carries a name that is not yours. We keep events whole because the titles are the signal — a booking a ticketing site wrote into your calendar is the strongest statement of interest this app can see — and we say so here rather than leaving it to be discovered.
What we work out
From the above we derive the readings that make a profile: the subjects you care about, and where your interests, preferences and temperament sit relative to other people's. Some of these derived subjects — an artist, a kind of music — appear on the card other people see.
Nothing on the card another person sees comes from YouTube. If you connect a YouTube account, what is read from it informs what you are shown about yourself and is never shown to anybody else — not on your card, not in a shared line, not in a chat opener. It is also deleted automatically 30 days after it arrives, whether or not anybody asks.
Google user data, scope by scope
Written asks Google for four things and no others, and only for the ones you connect. Each is set out here with what it is called for, what is kept, and why a narrower scope would not do.
| Scope | What it is used for | What we store | How long |
|---|---|---|---|
calendar.calendarlist.readonly |
Reads the names of your calendars only — no events — so that calendars of birthdays and public holidays can be identified and skipped before anything inside them is opened. | Calendar names, and whether each is your primary one. | While your account exists. |
calendar.events.readonly |
Reads the events in the calendars that were not skipped. Title, date, location, organiser and booking link are what separate a concert you paid for from a note to yourself. | Those fields per event, one row per repeating series rather than per occurrence. | While your account exists. |
youtube.readonly |
Reads the channels you subscribe to, the videos you have liked, and the playlists you made. Watch history is not included — the API does not expose it. | Video and channel titles, and the labels YouTube returns with them: its own topic categories, the category a video is filed under, the uploader's tags, and a channel's subscriber count. | 30 days for titles, channel names and playlist contents. Counts and worked-out subjects outlive them. |
openid email profile |
Sign in with Google, if you choose it. Reads no content from any Google service. | Your email address and name, as your account record. | While your account exists. |
Why two calendar scopes rather than one.
calendar.readonly would cover both in a single grant and we
deliberately do not ask for it. The two narrow scopes name exactly what
is read, and the first exists precisely so that calendars we have no
business reading can be recognised and skipped without being opened.
Limited Use
Written's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from your Google account is used only to build and present your own profile inside the app. It is never sold, never used for advertising, never transferred to anyone except as needed to provide the app, and never read by a person except where you have asked us to look at something or where we are investigating a report of abuse.
YouTube
Connecting YouTube is optional and reads only what is listed above. Subscriptions, liked videos and your own playlists — never your watch history, which the API does not expose and Written does not attempt to reconstruct.
What Written does with it is deliberately narrow. The subject of a video is taken from the labels YouTube itself returns — its own topic categories, the category a video is filed under, and the tags the uploader wrote. Written does not read a title or a channel name and decide for itself what a video is about. That is a rule YouTube sets for every developer, and it is why a channel YouTube has not labelled stays unlabelled here rather than being guessed at.
Written also uses YouTube API Services in one place unconnected to your account: videos other people share into Written play here through YouTube's own embedded player. By using Written you also agree to the YouTube Terms of Service, and Google's own handling of your data is described in the Google Privacy Policy.
Titles, channel names and playlist contents are held for no more than 30 calendar days. That is not a promise to act on a request: a job runs once a day and removes them on that schedule whether or not anybody asks, whether or not you are still signed in, and whether or not you ever open the app again. It covers every place Written keeps them, including the encrypted copy.
What outlives those 30 days is what YouTube's rules allow to: counts, and the subjects Written worked out while the data was there. A subject derived from YouTube is still never shown to another user.
Settings → Disconnect all ends every connection, deletes the records read through them and withdraws Written's access at Google. Everything Written had worked out about you from those records is struck off in the same moment — never used, never shown and never counted again, on your profile or anybody else's. It acts immediately, and no later than 7 days.
Everything read from YouTube is deleted outright, including the encrypted copy, because YouTube's rules allow 7 days for a disconnection made in the app rather than the 30 the daily job works to. For the other apps, the encrypted copy of what Written read is held until you delete your account. Nothing is taken from it while you are disconnected; reconnecting is what brings your profile back, and it means you are not asked to hand the same thing over twice.
You can equally withdraw access at myaccount.google.com/permissions, where the deadline is 30 days — already met by the daily sweep, which deletes 30 days after the data arrived. Neither changes anything in your YouTube account: your subscriptions, playlists and liked videos are untouched.
Why we collect it
- To build and show your profile, which is the product.
- To order what each person is shown about you by what the two of you have in common.
- To let you like, match with and message other people.
- To tell you when somebody likes you, matches with you or writes.
- To keep the service working, and to investigate reports of abuse.
We do not sell your data. We do not use it for advertising. We do not share it with data brokers. There is no analytics, attribution or advertising software of any kind in the app or on this website.
What other people can see
Two things are visible to other signed-in users of Written, and nothing else is:
- Your card — first name, age, district, your photographs, and derived subjects such as an artist or a kind of music. It deliberately contains nothing from which a snapshot could be reconstructed, and nothing at all that was read from YouTube.
- Anything you choose to share — a link you publish with a sentence about it, shown with your first name.
Your conversations are visible only to you and the person you are talking to. Nothing in Written is public on the open internet.
Notifications
If you turn notifications on, your phone gives us a delivery token and we send it to Apple's Push Notification service when there is something to tell you. A notification carries the sender's first name, a short line, an unread count, and — for a message — a link to that person's photograph which expires after one hour. It is prepared on our servers and delivered by Apple; nobody else is involved, and turning notifications off in iOS stops all of it.
Where it is kept, and who else touches it
Your data is stored in a Postgres database and file storage operated by Supabase, on servers in the United States. These are everyone who handles any part of it:
| Who | What they receive |
|---|---|
| Supabase | Everything stored: the account, the profile, the snapshots, photographs and conversations. United States. |
| Apple | Sign in with Apple; delivery of notifications; distribution of the app itself. |
| Only if you use Google to sign in or to read a Google source. The grant happens on Google's own screen. | |
| Twilio | Only if you sign in by phone: your number, to send one verification code. Arranged through Supabase. |
| lrclib.net, and music.163.com if the first has no answer | One song title, and to the first of them one artist name. No account identifier, nothing about you, nothing about the rest of your library — sent to fetch the words of a song, and cached so a song is asked about once. |
| Cloudflare | Serves this website. Sees the ordinary details of a request for a page, and nothing from the app. |
How it is protected
- Access is enforced row by row, in the database itself. A signed-in account can read its own rows and nothing else, with the two deliberate exceptions described under What other people can see. This is not a check in our code that could be forgotten; it is a rule the database applies to every query.
- Photographs live in private storage. They are never publicly addressable — each viewing uses a link that expires.
- Your session and any access tokens are kept in the iOS Keychain, not in ordinary app storage.
- Everything travels over HTTPS.
- There is no third-party analytics, advertising or tracking software in the app or on this site, so there is nothing to opt out of.
How long we keep it
| What | How long |
|---|---|
| YouTube titles, channel names and playlist contents | 30 calendar days, deleted by an automatic daily job — in every place we hold them, including the encrypted copy. Counts and the subjects worked out from them outlive that. |
| The copy of what each service replied | Kept until you disconnect that app or delete your account, whichever comes first. The YouTube part of it is deleted after 30 days along with everything else from YouTube. Nothing from Apple Health or your location is kept this way at all. |
| Your biological sex, as reported by Apple Health | Never uploaded. Kept on your phone only, and included in the copy of your data you can download. |
| After you disconnect an app, or all of them | The records read through it are deleted, and everything worked out from them is struck off — never used, never shown, never counted. Anything read from YouTube is deleted outright, the encrypted copy included. For the other apps that encrypted copy is kept until you delete your account, so reconnecting does not ask you for it again. |
| Everything else | For as long as your account exists. |
| After you delete your account | Removed from our live systems within 7 days. |
| After you write and ask us to delete something | Removed within 7 days. |
Encrypted backups roll over on their own schedule, and are never used to bring back an account or a record that was deleted.
What you can do
- Strike something out. Any artist, channel, sport, show or event can be struck off your profile in the app. It is never used, never shown and never counted again, and it stays struck off through every snapshot after it — so you never have to remove the same thing twice.
- Correct your profile from the Memories tab. Every field there can be changed after it is first set, including your name.
- Delete your account from the Memories tab. This removes your profile, your snapshots, your photographs and your conversations, within 7 days.
- Ask us to delete something narrower, or for a copy of what we hold, by writing to the address below. We will do it within 7 days.
- Withdraw Google's grant directly at myaccount.google.com/permissions.
Depending on where you live you may have further rights — to object to processing, to restrict it, or to complain to a supervisory authority. Write to us and we will honour them. Support sets out how to do each of these step by step.
Children
Written is for adults. It is not directed at anyone under 18, and we do not knowingly keep data about anyone under 18. If you believe a minor has an account, tell us and we will remove it.
Changes
If this policy changes we will update the date at the top, and where the change is significant we will say so in the app before it takes effect.