Written

Privacy Policy

Effective 5 August 2026 · Last updated 5 August 2026

Written is an iPhone dating app. It builds your profile out of what you already listen to, watch, plan and do, so that you do not have to write one. That only works if you let it read some accounts, which means this document has to be specific rather than reassuring.

This policy covers the Written iPhone app, its share extension, and this website. It is written in the first person plural — "we" is the team that makes Written.

How Written reads: a snapshot, not a subscription

Written takes a snapshot. Each read happens once, in the foreground, in the seconds after you tap — and then it is over. Nothing polls, nothing runs in the background, nothing keeps watching your account afterwards. Between one snapshot and the next, Written is not reading anything at all. Everything below describes what a snapshot picks up and what happens to it afterwards.

Two things follow from that, and they are the two we would most like you to hold on to. What a snapshot took, you can strike out — any artist, channel, sport, show or event, in the app, at any time. And you can take all of it back by deleting your account, which is a button in the app rather than a request to us.

What we collect

What you tell us

  • Your account. You sign in one of three ways, and only the one you choose is used.
    • Apple — we receive the identifier Apple gives us and, if you allow it, your name and email address, which is often a private relay address.
    • Google — sign-in only. We ask for openid email profile, which reads no content from any Google service, and we receive your email address and name.
    • Phone — your phone number, verified by a code sent over SMS. It is stored against your account and is shown to nobody.
    We never see your Apple or Google password.
  • Your profile. First name, date of birth, gender, the district you live in, and optionally education and occupation.
  • Your photographs. Up to six, in the order you arranged them.
  • How you want to be approached. Two answers, given during sign-up, about flirtatiousness and how quickly you reply.
  • What you write. Messages you send — text, photos, videos and voice notes — people you like or decline, links you share into the app, and anything you report.
  • A notification token, if you allow notifications: an address Apple uses to reach that one device. It identifies the device, not you, and it goes with your account when you delete it.

What each source gives us

Nothing is read unless you tap and grant it, one source at a time. Every one of these is read-only: Written never asks any of them for permission to write anything back.

  • YouTube — your subscriptions, liked videos, playlists and the contents of those playlists. We do not request, and cannot obtain, your watch history.
  • Google Calendar — the names of your calendars, and the events in them: title, date, location, organiser and any booking link. Calendars of birthdays and public holidays are left out.
  • Apple Music — your library, playlists, recently added and recently played music, heavy rotation, recommendations, and the tracks you have marked liked or disliked.
  • Apple Podcasts — the episodes held on your device and the shows they belong to.
  • Apple Calendar — the same fields as Google Calendar, within the window the app reads. Birthday and public-holiday calendars are excluded.
  • Apple Health — workouts, exercise minutes, active energy, steps, walking and running distance, and your date of birth and biological sex.

Health data never leaves your phone. It is read on the device, reduced there to a small number of general readings — roughly when you are awake, which sports you do and at what level, and an average daily step count — and the underlying workouts and samples are then thrown away without ever being uploaded. Only those readings are stored on our servers. This is enforced in two separate places rather than intended in one.

Calendar events are the one thing here that can name somebody else. An event called "Dinner with Sam" carries a name that is not yours. We keep events whole because the titles are the signal — a booking a ticketing site wrote into your calendar is the strongest statement of interest this app can see — and we say so here rather than leaving it to be discovered.

What we work out

From the above we derive the readings that make a profile: the subjects you care about, and where your interests, preferences and temperament sit relative to other people's. Some of these derived subjects — an artist, a kind of music — appear on the card other people see.

Nothing read from YouTube appears there. Channel names, video titles, playlists and what you have subscribed to or liked are shown to you and to nobody else. That is a condition YouTube sets on every app that reads your account, and it is described in full under Google user data.

And YouTube is not categorised by us at all. For every other source, working out what something is about is the whole job. For YouTube we use only the classifications YouTube itself returns — the category on a video, the topics on a channel, the tags its creator wrote — and never work one out from a title, a description or a channel's name. It is a narrower reading than the other sources get, and the practical effect is that some of what you watch stays unplaced.

Google user data, scope by scope

Written asks Google for three things and no others. Each is set out here with what it is called for, what is kept, and why a narrower scope would not do.

Scope What it is used for What we store How long
youtube.readonly Reads your subscriptions, liked videos, playlists and playlist contents, so the profile can say what you follow and what you keep. There is no narrower read scope for this data. Channel names, video titles and playlist names, plus the classifications YouTube itself returns — a video's category, a channel's topics, and the tags its creator wrote. Written does not work out a category of its own from a title, a description or a channel's name. 30 calendar days at most, then deleted automatically.
calendar.calendarlist.readonly Reads the names of your calendars only — no events — so that calendars of birthdays and public holidays can be identified and skipped before anything inside them is opened. Calendar names, and whether each is your primary one. While your account exists.
calendar.events.readonly Reads the events in the calendars that were not skipped. Title, date, location, organiser and booking link are what separate a concert you paid for from a note to yourself. Those fields per event, one row per repeating series rather than per occurrence. While your account exists.
openid email profile Sign in with Google, if you choose it. Reads no content from any Google service. Your email address and name, as your account record. While your account exists.

Why two calendar scopes rather than one. calendar.readonly would cover both in a single grant and we deliberately do not ask for it. The two narrow scopes name exactly what is read, and the first exists precisely so that calendars we have no business reading can be recognised and skipped without being opened.

Limited Use

Written's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from your Google account is used only to build and present your own profile inside the app. It is never sold, never used for advertising, never transferred to anyone except as needed to provide the app, and never read by a person except where you have asked us to look at something or where we are investigating a report of abuse.

YouTube, and the thirty days

Written uses YouTube API Services. By using them through Written you also agree to the YouTube Terms of Service, and Google's own handling of your data is described in the Google Privacy Policy.

Titles, channel names and playlist contents are held for no more than 30 calendar days. This is not a promise to act on a request: a job runs once a day and removes them on that schedule whether or not anybody asks, whether or not you are still signed in, and whether or not you ever open the app again. What remains afterwards is the derived reading, which names nothing.

In Written, on the Memories page, there are two separate controls. Delete what was read erases everything read from YouTube and leaves the connection in place. Disconnect YouTube does the same and also withdraws Written's access at Google. Either way the deletion happens immediately, and no later than 7 days. Neither changes anything in your YouTube account — your subscriptions, playlists and liked videos are untouched.

At Google, you can review or withdraw Written's access at any time at myaccount.google.com/permissions. Where access is withdrawn there, everything read from YouTube is deleted within 30 days — and in practice the daily sweep above has already removed it, because it deletes 30 days after the data arrived, which is never later than 30 days after a withdrawal.

The two deadlines are different because YouTube sets them that way: 7 days when you tell us, 30 when you tell Google. We are not relying on the longer one for the first case.

Why we collect it

  • To build and show your profile, which is the product.
  • To order what each person is shown about you by what the two of you have in common.
  • To let you like, match with and message other people.
  • To tell you when somebody likes you, matches with you or writes.
  • To keep the service working, and to investigate reports of abuse.

We do not sell your data. We do not use it for advertising. We do not share it with data brokers. There is no analytics, attribution or advertising software of any kind in the app or on this website.

What other people can see

Two things are visible to other signed-in users of Written, and nothing else is:

  • Your card — first name, age, district, your photographs, and derived subjects such as an artist or a kind of music. It deliberately contains nothing from which a snapshot could be reconstructed, and nothing at all that was read from YouTube.
  • Anything you choose to share — a link you publish with a sentence about it, shown with your first name.

Your conversations are visible only to you and the person you are talking to. Nothing in Written is public on the open internet.

Notifications

If you turn notifications on, your phone gives us a delivery token and we send it to Apple's Push Notification service when there is something to tell you. A notification carries the sender's first name, a short line, an unread count, and — for a message — a link to that person's photograph which expires after one hour. It is prepared on our servers and delivered by Apple; nobody else is involved, and turning notifications off in iOS stops all of it.

Where it is kept, and who else touches it

Your data is stored in a Postgres database and file storage operated by Supabase, on servers in the United States. These are everyone who handles any part of it:

Who What they receive
Supabase Everything stored: the account, the profile, the snapshots, photographs and conversations. United States.
Apple Sign in with Apple; delivery of notifications; distribution of the app itself.
Google Only if you use Google to sign in or to read a Google source. The grant happens on Google's own screen.
Twilio Only if you sign in by phone: your number, to send one verification code. Arranged through Supabase.
lrclib.net, and music.163.com if the first has no answer One song title, and to the first of them one artist name. No account identifier, nothing about you, nothing about the rest of your library — sent to fetch the words of a song, and cached so a song is asked about once.
Cloudflare Serves this website. Sees the ordinary details of a request for a page, and nothing from the app.

How it is protected

  • Access is enforced row by row, in the database itself. A signed-in account can read its own rows and nothing else, with the two deliberate exceptions described under What other people can see. This is not a check in our code that could be forgotten; it is a rule the database applies to every query.
  • Photographs live in private storage. They are never publicly addressable — each viewing uses a link that expires.
  • Your session and any access tokens are kept in the iOS Keychain, not in ordinary app storage.
  • Everything travels over HTTPS.
  • There is no third-party analytics, advertising or tracking software in the app or on this site, so there is nothing to opt out of.

How long we keep it

What How long
YouTube titles, channel names, playlist contents 30 calendar days, deleted by an automatic daily job.
Raw Health workouts and samples Never stored. Reduced on the phone and thrown away there.
Everything else For as long as your account exists.
After you delete your account Removed from our live systems within 7 days.
After you write and ask us to delete something Removed within 7 days.

Encrypted backups roll over on their own schedule, and are never used to bring back an account or a record that was deleted.

What you can do

  • Strike something out. Any artist, channel, sport, show or event can be struck off your profile in the app. It is never used, never shown and never counted again, and it stays struck off through every snapshot after it — so you never have to remove the same thing twice.
  • Correct your profile from the Memories tab. Every field there can be changed after it is first set, including your name.
  • Delete your account from the Memories tab. This removes your profile, your snapshots, your photographs and your conversations, within 7 days.
  • Ask us to delete something narrower, or for a copy of what we hold, by writing to the address below. We will do it within 7 days.
  • Withdraw Google's grant directly at myaccount.google.com/permissions.

Depending on where you live you may have further rights — to object to processing, to restrict it, or to complain to a supervisory authority. Write to us and we will honour them. Support sets out how to do each of these step by step.

Children

Written is for adults. It is not directed at anyone under 18, and we do not knowingly keep data about anyone under 18. If you believe a minor has an account, tell us and we will remove it.

Changes

If this policy changes we will update the date at the top, and where the change is significant we will say so in the app before it takes effect.

Contact

hello@written-stl.com

← Back to Written