Privacy policy for Squiggle - Privacy focused grammar corrector
Squiggle - Privacy focused grammar corrector by ywnz
What is processed
When you ask Squiggle to check, rewrite, translate or generate text, that text is sent through our proxy (squiggle.ywnz.dev) to our model provider (OpenRouter) to produce the result. This is the core of the service — a grammar checker that never sees your text cannot check it.
What we store
Usage counters only: how many requests a token made per day. We deliberately keep no logs of the text you check, and no request or response bodies.
Token identifiers: only the SHA-256 hash of your access token and its device label, so tokens can be validated and revoked without storing the token itself.
Account: your email plus password hash, and one access-token hash per device you sign in from. Delete the account and all of it goes.
On your device: your token, settings and a random device id live in your browser's extension storage. They never leave your device except the token, which authenticates requests to the proxy.
Feedback: what you write on the feedback page is stored with your optional email address, categorized automatically, and read only by the developer.
Payments (premium plans)
When premium plans are offered, payment happens on Stripe's hosted checkout page. Card numbers never reach our servers: we receive only your email, the plan you chose, and your subscription status, which we store to keep your tier active. That subscription status is the only payment-related data we hold.
What we never do
Accounts are minimal: your email and a salted password hash (PBKDF2, 100k rounds). We never see your password — and no name, address or phone is ever asked.
No analytics, no trackers, no advertising, no fingerprinting.
No selling or sharing of usage data with anyone.
Third parties
Cloudflare — hosts the proxy and this page (squiggle.ywnz.dev). Subject to Cloudflare's own privacy policy.
OpenRouter — model provider receiving the text you submit for checking, together with its upstream model providers. Every inference request carries OpenRouter's zdr routing flag, so only endpoints with a zero-data-retention policy ever see your text (list: openrouter.ai/api/v1/endpoints/zdr). OpenRouter privacy policy.
Retention
Usage counters expire automatically after roughly 30 days. Account records and token hashes are kept until you ask us to delete them. Text sent for checking is processed transiently to return your result and is not stored by us.
Your rights & contact
Under the GDPR you may request access to, correction or deletion of any data we hold about you. Delete means your account row, password hash and every token hash, gone — email me and I will. Contact: me@ywnz.dev.