Bylines.
Checks Pricing FAQ

Legal

Privacy Policy

Last updated 22 August 2026 Effective 22 August 2026

Bylines is run by YSA LLC, a Florida limited liability company with its registered address at 400 NW 1st Street, Miami, FL 33128. This policy says what we collect, what happens to the words you write, who else touches them, how long anything is kept, and how to make all of it go away. It goes with our Terms of Service.

Contents

  1. What we collect
  2. What happens to your writing
  3. Shared sessions
  4. Analytics and advertising
  5. What is stored in your browser
  6. Why we are allowed to hold it
  7. Who else receives it
  8. Where it is held
  9. How long we keep it
  10. Your rights, and how to use them
  11. California
  12. Children
  13. Security
  14. Changes to this policy
  15. Contact

What we collect

Your account

If you start writing without signing up, we create a guest account that holds nothing but an account identifier — no email, no name, no password. When you claim that account we store your email address and, if you sign in with Google, the name and email address Google gives us. Passwords are handled by Google Firebase Authentication and we never see or store yours. We also record whether your email has been confirmed, because unconfirmed accounts are limited.

Your writing

Drafts, their titles, the notes Bylines leaves on them, and any notes or documents you upload to a session. Files you upload are read in your browser and it is their text, not the file, that reaches us.

Usage and entitlement

Word counts, how many read-alongs you have used, and whether Bylines Pro is active — which for a subscription means the plan, its expiry, and the Stripe or app-store identifier for it.

Payments

We never receive your card number. Card details go straight to Stripe, who process the payment and hold whatever billing details you give them. What reaches us is the subscription's identifier and status. Purchases made in the iPhone app are handled by Apple, and we receive only the receipt.

Feedback

If you send feedback we store the message, whether it was positive or negative, where in the product you sent it from, and whether the account was a guest or a Pro subscriber. Your email address is attached only if you tick the box asking for a reply.

Technical records

Our server keeps ordinary request logs, which include IP addresses, on Google Cloud's default retention. These exist for debugging, rate limiting and abuse investigation.

What happens to your writing

To produce a note, the paragraph you are working on is sent to Google Vertex AI, which runs the models that do the checking. Under Google Cloud's terms for Vertex AI, content sent to it is not used to train Google's models. Results are cached so that re-reading an unchanged paragraph costs nothing and sends nothing.

Beyond that:

  • We do not sell your drafts, and we do not publish them.
  • We do not use them to train models of our own, and we do not have any.
  • We do not use anything you write to target advertising.
  • No person at Bylines reads your drafts as a matter of course. We would only open one where it is necessary to investigate a problem you have reported to us, to deal with abuse or a security incident, or where the law requires it.

Shared sessions

A shared session exists to show your work to someone else: for as long as it runs, the other participant sees your draft, the notes on it, and whatever you have uploaded to the session. That is the feature, not a leak — but it means the privacy of a session is decided by who you hand the invite link to.

Analytics and advertising

Analytics. We use Vercel Web Analytics and Vercel Speed Insights, which are aggregate and do not use cookies. On top of the page view, we record a small set of product events — a workspace opened, a paywall shown, a plan chosen. These are written to carry nothing identifying: no email address, no name, no account identifier, no draft title and none of your prose. Word counts are bucketed rather than sent exactly, because an exact count is most of a fingerprint for a single writer.

Advertising. Our pages load Google's advertising tag (gtag.js) so that we can measure whether an ad led to a subscription. Google sets its own cookies through that tag and may use them to attribute conversions across sites. The site and the writing workspace are one page, so the tag is present while you write — nothing you write is sent to it. Exactly one thing is: when a Pro subscription is bought, we report the amount paid, the currency, and the reference our payment processor gave that subscription. No email address, no name and no account identifier goes to Google. Google's handling is governed by Google's privacy policy, and you can limit it through your Google Ad settings or your browser's cookie controls.

What is stored in your browser

Bylines itself sets no cookies. It uses your browser's local storage, which stays on your device, for the things the app cannot work without: your signed-in session, your drafts, your preferences, whether Pro is on, session codes you have joined, whether you have seen the welcome tour, and any feedback that failed to send so it can be retried. Clearing your browser storage signs you out and removes the local copy of your drafts; anything already synced is still on the server under your account.

Why we are allowed to hold it

If you are in the UK or the EEA, the legal bases we rely on are: performance of a contract for your account, your drafts and the checks themselves; legitimate interests for security, abuse prevention, debugging and aggregate analytics; consent where local law requires it for the advertising tag described above; and legal obligation for records we are required to keep, such as those relating to payments.

Who else receives it

  • Google — Firebase Authentication for accounts, Firestore for storing drafts and notes, Cloud Run for the API, Vertex AI for the models, and Google Ads for the advertising tag on the marketing pages.
  • Stripe — payments and subscription management for web purchases.
  • Apple — the iPhone app and any purchase made inside it.
  • Vercel — serving this website, and its analytics.
  • Anyone you invite into a shared session, for what that session contains.

We do not sell your personal information, and we do not hand it to anyone else except where the law compels us or where it is necessary to protect the Service or someone's safety. If Bylines is ever sold or merged, your data may transfer with it, and this policy — or one at least as protective — would continue to apply.

Where it is held

Accounts, drafts, notes and model processing all sit in Google Cloud in the United States (region us-central1). If you are writing to us from outside the US, using Bylines means your data is transferred there and handled under US law, with our providers' standard contractual clauses covering the transfer.

How long we keep it

  • Your account and everything in it — until you delete it. Deleting your account from Settings cancels any web subscription and then removes your drafts, your notes, your entitlement record, your usage counters and any feedback you sent. It is immediate and it cannot be undone.
  • Server logs — on Google Cloud's default retention, after which they expire on their own.
  • Payment records — Stripe and Apple keep their own records of transactions for as long as their legal obligations require, and deleting your Bylines account does not erase those.
  • Backups — copies may persist in ordinary backups until those expire on their normal cycle.

Your rights, and how to use them

Depending on where you live, you may have the right to access what we hold, correct it, delete it, get a portable copy, object to or restrict some processing, and withdraw consent. Most of it you can do without asking us:

  • See and export your drafts — they are in the app, on any device you sign in on.
  • Delete everything — Settings → delete account.
  • Cancel Pro — the billing portal in Settings, or your Apple Account for App Store purchases.

For anything else, write to adrians.inquiries@gmail.com and we will answer within 30 days. If you are in the UK or the EEA and you think we have got it wrong, you can also complain to your local data protection authority.

California

We do not sell personal information for money. The advertising tag described above may count as “sharing” for cross-context behavioural advertising under California law; if you would rather it did not apply to you, write to adrians.inquiries@gmail.com and say so, or block the cookies in your browser. We will not treat you any differently for exercising a privacy right.

Children

Bylines is not for children under 13, or under 16 in countries where 16 is the minimum age for consenting to online services. We do not knowingly collect anything from them. If you believe a child has an account, tell us and we will delete it.

Security

Traffic runs over TLS, authentication is handled by Google Firebase, and the API checks a token on every request rather than trusting the client. Passwords never reach us. No service can promise perfect security, and we do not; if a breach ever affects your data, we will tell you and any regulator we are required to tell.

Changes to this policy

We will update this page when what we do changes, and the date at the top will change with it. If a change is material we will give reasonable notice by email or in the app before it takes effect.

Contact

YSA LLC — adrians.inquiries@gmail.com. Questions about this policy, or a request about your data, both go here.

Bylines Web app Sessions Checks Pricing FAQ © 2026 Bylines · Privacy · Terms