1 Who we are and what this policy covers
CombDesk LLC operates WritingDesk Guardian™. For this Policy, “we” means CombDesk LLC. Contact us about privacy, security, account closure or your rights at contact@combdesk.com. Official website: https://writingdeskguardian.com.
This Policy covers personal information processed through Guardian’s registration, author dashboard, uploads, protected reader, permission requests, approved exports, billing and support. It applies to Authors, Readers, prospective customers and people whose information appears in Works. It does not describe unrelated CombDesk products or external AI-testing services.
CombDesk acts as controller for account administration, billing administration, security and its own operational purposes. Where we process personal information within customer Works solely on a customer’s documented instructions, we may act as processor or service provider and the customer may be controller. Roles depend on the actual processing, not account labels. A separate data processing agreement is required where applicable. Contact the Author for requests concerning their decisions; you may also contact us and we will direct or assist the request appropriately.
Contact contact@combdesk.com for privacy enquiries, including questions about applicable local representation. This Policy does not assert that a representative, data protection officer or local privacy officer has been appointed.
2 Information collected and its sources
Account information: name or chosen display name, email address, rights-holder details, account identifiers, authentication records and account status. Sources include you, your organisation or the authentication provider used to sign in.
Works and associated data: uploaded originals, extracted text, page images, file names, titles, work type, page and section structure, versions, file sizes and rights-holder statements. Works may contain information about their authors, research participants or other individuals. Upload only information you are authorised to provide; redact unnecessary sensitive details.
Sharing and permission information: Author and Reader identifiers, invited email addresses, reader reference codes, share-link records, expiry and revocation state, requested actions and sections, named AI-testing service, purpose, messages, decisions and approval periods. An Author may supply your email before you register.
Activity and technical data: views, requests, approvals, downloads, version changes, revocations, timestamps, account and permission events, upload reservations and storage usage. Servers or infrastructure may also process IP addresses, browser and device information, diagnostic logs and session identifiers.
Billing data: selected plan, subscription and transaction identifiers, payment status, invoice or receipt details, currency, taxes and billing contact information received from the payment provider. The provider collects payment credentials through its checkout.
Support and communications: messages, attachments, complaint records and details needed to investigate an issue. Do not send full card numbers, passwords or unnecessary identity documents. We may obtain limited information from providers, fraud reports or lawful notices. We do not claim to collect precise location, biometrics or other special categories as ordinary account fields unless expressly disclosed and implemented.
3 Why we process information
We use account and authentication information to register you, provide access, recover accounts, manage settings and deliver operational communications. We use Works and file data to store, import, extract text, render page previews, watermark and provide authorised views or approved exports.
We use sharing, request and activity data to route requests, show Authors the purpose and scope, enforce their decisions, prevent duplicate requests, record events and investigate abuse. We use storage and subscription data to enforce plan allowances, process provider-confirmed access changes and explain billing status.
We use necessary technical and security information to operate, debug, maintain and protect the Service; detect compromised accounts, unlawful access and upload failures; and prevent fraud. We use complaint and support records to resolve issues, defend legal claims and meet legal duties. We may use genuinely anonymised or aggregated information to understand reliability and usage; pseudonymous information that can still be linked to a person remains personal information.
Optional marketing and analytics are separate from delivery of the Service. We obtain required permission before sending marketing or placing nonessential technologies. An unsubscribe does not stop necessary security, billing or permission messages. We do not use acceptance of the Terms as blanket consent for unrelated purposes.
4 Legal bases where required
Where GDPR-type legal bases apply, we rely on contractual necessity for processing objectively needed to provide the Service requested by the individual; legitimate interests for proportionate security, service administration, fraud prevention and legal defence, after considering individual rights; legal obligations for records or disclosures required by law; and consent for optional uses where required.
Our legitimate interests include maintaining a reliable permission service and protecting users and Works. Contract is not automatically a valid basis for every person mentioned inside a Work or for a Reader invited before registration. For those operations, the appropriate basis and any indirect-collection notice must be assessed separately. Customers are responsible for their own lawful basis for personal data they instruct us to process.
If you withdraw consent, we stop the relevant consent-based processing, subject to lawful retention; withdrawal does not invalidate earlier lawful processing. You may object to processing based on legitimate interests and to direct marketing. Sensitive personal data requires an additional lawful condition where applicable, not merely a general contractual basis. Where another jurisdiction requires a different basis, we apply its requirements.
5 What Authors and Readers can see
An Author can see the identity associated with their invited Reader and the requests, purposes, requested sections, decisions and relevant activity connected to that Work. Reader activity is visible to the Author as part of the permission workflow; it is not anonymous merely because a reference code is used.
Readers see the Works they are authorised to view, identifying information and notices supplied for that sharing, and their own requests or approvals. Approved copies may display the Reader’s email address, reference code, watermark and permission notice. These details can remain in a copy after the account or link is closed. Before requesting a copy, understand that anyone receiving that copy may see those identifiers.
The original uploaded file is private to the Author under Guardian’s original-file access controls. Authorised processors and personnel may access data only as necessary for their functions; “private” does not mean the Author is the only party involved in processing. The Service is not designed to publicly index private Works.
Reference codes identify a sharing context, not incontrovertible evidence that the associated person caused a leak. We do not authorise public exposure or harassment of a Reader using activity or watermark information. Handle suspected misuse through lawful complaint procedures.
6 Providers disclosures and business changes
We disclose information to contracted providers for hosting, storage, authentication, email, payment handling, file processing, security and support to the extent needed. Providers processing on our behalf are subject to appropriate contractual instructions, confidentiality and security obligations. Payment providers may also act independently for their own compliance and transaction purposes.
The Service uses Lovable Cloud for application hosting, account authentication and private storage, and Paddle for its test billing flow. Google Fonts supplies web fonts; loading them can send your IP address and browser request information to Google. Live charging is disabled. Contact contact@combdesk.com for questions about providers, their roles and processing locations.
We may disclose information when lawfully required by a court or competent authority, to investigate serious abuse, protect rights or establish and defend claims. We assess requests, minimise disclosure and notify affected users where lawful and appropriate. We do not promise notification where a legal restriction prohibits it.
In a genuine merger, financing, reorganisation or sale, relevant information may be disclosed under safeguards and transferred with the business, subject to applicable law and notice obligations. The successor must respect existing lawful commitments or obtain a lawful basis for changes. We do not grant an unrestricted right to sell user Works or personal information as a standalone asset.
Questions or requests concerning sale, sharing, cross-context behavioural advertising or targeted advertising may be sent to contact@combdesk.com. Ordinary service-provider disclosures must be distinguished from statutory sale or sharing definitions; this Policy does not make an unverified blanket no-sale claim.
7 AI testing model training and automated decisions
A request naming an AI-testing service is a permission record. It does not itself transmit the Work to that service. If a Reader obtains approved text and submits it elsewhere, that external service’s privacy, retention and training practices apply. Guardian cannot observe the destination of a later paste or recall content retained externally.
Guardian’s current import process extracts text and renders page previews in the Author’s browser. Naming an AI-testing service in a permission request does not activate model training or transmit the Work to that service. This Policy does not make a blanket assurance about every provider’s model-training practices. Any future optional AI feature requires a clear notice explaining the data sent, provider, purpose, retention and available choices before use.
Automatic checks enforce account, version, expiry, storage and payment status. Authors make permission decisions; the Service does not determine copyright ownership or academic misconduct from a detector score. Where applicable law provides rights relating to significant automated decisions, you may request the explanation, contest or human review that law requires.
8 Cookies device storage and communications
Necessary browser storage supports account authentication and sessions. Session data may persist between visits until sign-out or session expiry and may be renewed while the account remains signed in. Blocking or clearing this storage may prevent essential features or sign you out. These technologies are used by the Service and its authentication provider.
Nonessential analytics, advertising or similar technologies, if introduced, require the applicable notice and choice before activation. Where consent is required, we offer a genuine reject option and a way to change preferences. We do not treat merely opening a page as consent. Marketing consent or opt-out requirements apply separately to email and similar communications.
You may send applicable opt-out requests, including questions about Global Privacy Control, to contact@combdesk.com. A browser signal alone is not confirmation that a request has been processed. This Policy does not assert an implemented automated signal-handling control. Browser settings and a generic “Do Not Track” signal are not necessarily equivalent to statutory opt-out mechanisms.
9 International processing and safeguards
The Service may involve storage, support or processing outside your country. Global availability does not mean data is stored locally in every market. Contact contact@combdesk.com for information about processing and backup locations.
Restricted international transfers require a legally recognised mechanism applicable to the transfer, such as an adequacy decision, approved contractual safeguards with supplementary measures, or another permitted route. EEA transfers may require EU standard contractual clauses; UK transfers may require the UK IDTA or UK Addendum; other countries require their own mechanisms. Contact contact@combdesk.com for information about applicable safeguards. This Policy does not certify that a particular agreement has been executed.
We do not rely on accepting these Terms as blanket consent for routine international transfers. Special consent, assessment, registration or localisation requirements must be addressed before processing for an affected market. If we cannot meet a mandatory requirement, we may restrict the relevant Service availability instead of claiming universal compliance.
10 Retention deletion and account closure
We retain information only for the purposes described and for the periods justified by those purposes, including applicable tax, accounting, security and dispute requirements. Cancelling billing is not account deletion and does not automatically delete Works. Authors should retain independent copies.
Account data, Works, originals, extracted text and previews remain associated with the account or Work until deletion is processed, subject to lawful retention. Permission, activity, security, support and billing records may be retained for operational needs, applicable accounting obligations and legal claims. This Policy does not promise a fixed deletion window or backup-expiry period. Contact contact@combdesk.com for the retention information applicable to a particular record and to request deletion.
Temporary upload reservations expire after 15 minutes in the current implementation. Leftover partial files are cleaned up on a subsequent upload rather than necessarily by an immediate background job. A new import that cannot fit its previews is rolled back.
Request account closure or deletion through contact@combdesk.com. There is no self-service account-deletion control. Requests are handled through this contact channel, subject to proportionate identity checks and lawful retention exceptions. Active-system deletion and backup expiry can occur at different times; no fixed backup-expiry period is specified here. Legal holds may extend retention for relevant records; they do not justify indefinite retention of unrelated information.
A deletion request cannot erase a Reader’s already downloaded copy or an external AI service’s records. Authors and external recipients may independently retain information under their own obligations. We may preserve limited approval evidence where needed for legitimate claims and permitted by law, with restricted access.
11 Security incidents and data minimisation
We use measures appropriate to the processing risks, including the Service’s account-based access checks, server-enforced permissions and storage controls. No method is completely secure; this is not a waiver of our statutory security duties.
We investigate suspected personal-data breaches and notify affected individuals, customers or authorities where required by applicable law. Notification timing and contents follow the relevant legal requirements. A general security event is not automatically a reportable breach, and a controller may have duties different from those of a processor.
Use appropriate account security, verify your Readers and avoid unnecessary sensitive information in Works. Report concerns to contact@combdesk.com. Do not publish other users’ data as evidence of a vulnerability.
12 Your requests choices and complaints
Depending on applicable law, you may request access to personal information and processing details; correction; deletion; restriction; portability; objection; withdrawal of consent; or opt-out of covered sale, sharing, targeted advertising and certain profiling. Additional rights may apply to sensitive information, automated decisions or complaints. These rights have lawful conditions and exceptions; they are not forfeited by using a free Reader account.
Contact contact@combdesk.com. State the request and an account identifier. We verify identity proportionately and may ask an authorised agent for evidence of authority. We do not require unnecessary identity documents or an account for a request where law forbids that requirement. We protect other people’s information when responding.
We respond within applicable statutory deadlines, explain lawful extensions or refusals, and provide an appeal or review route where required. EEA and UK requests are generally handled within one month, subject to lawful extensions; California requests generally have a 45-day response framework, with permitted extensions. Other countries may have different periods. We do not charge unless applicable law permits and we explain the basis beforehand.
You may complain to the competent privacy authority or seek a judicial remedy without first exhausting our informal support process. We do not retaliate for exercising legal rights. Some essential features may be unavailable if data necessary to deliver them is withheld; we explain this rather than conditioning unrelated processing on access to the Service.
13 Regional privacy supplement
Europe including the EEA, UK and Switzerland: applicable GDPR, UK data-protection and Swiss requirements govern roles, lawful bases, rights, notices and transfers. You may object to legitimate-interest processing and direct marketing and complain to your competent authority. This Policy does not assert the appointment of a representative or data protection officer.
United States: where relevant state privacy laws apply to CombDesk, covered residents may exercise applicable access, deletion, correction, portability, opt-out, sensitive-data and appeal rights. California residents may request applicable collection, disclosure, sale/sharing and retention information at contact@combdesk.com. Applicability depends on the law and the actual processing; this Policy does not assert universal coverage or automated Global Privacy Control handling.
Canada and Mexico: applicable federal and provincial or national requirements govern accountability, notice, consent, access, correction, retention and complaints. Canadian requirements may include meaningful consent and specific Quebec notices or assessments. Additional local notices may be required for affected operations; this supplement is not a substitute for them.
South America: Brazil’s LGPD may provide confirmation, access, correction, anonymisation, blocking or deletion, portability where regulated, disclosure information, consent-related rights and review of covered automated decisions. Brazil transfers require an applicable authorised mechanism. Other countries, including Argentina, Colombia, Peru, Chile and Uruguay, have their own regimes and timing, and may require additional notices and request channels.
Asia: laws differ by country, including Singapore, Japan, South Korea, India, China, Indonesia, Malaysia, Thailand and the Philippines. Access, correction, consent, deletion, grievances, officer contacts and international-transfer restrictions depend on applicable law and provisions in force. Enacted provisions are not necessarily all effective at the same time. Some markets may require additional transfer procedures, separate consent or local storage and may need restricted availability.
Africa: applicable national rules may include South Africa’s POPIA, Kenya’s data-protection framework, Nigeria’s data-protection law and other national regimes. Rights, information-officer or registration duties, sensitive-data conditions, direct marketing and international transfers must be assessed for the actual operation. South African data subjects may use the Information Regulator’s complaint procedures where applicable.
Middle East: UAE federal law, UAE free-zone regimes such as DIFC or ADGM, Saudi Arabia and other national laws have different scope, rights and transfer requirements. A UAE hub does not automatically bring every operation under a free-zone regime. Applicable controller disclosures, request, notification and transfer requirements depend on the actual entity and processing.
Australia and New Zealand, if served: applicable national privacy requirements, access and correction routes, cross-border accountability and breach duties are also preserved. A regional list is illustrative rather than a promise that every country’s obligations are satisfied. Applicable mandatory rules prevail over conflicting policy wording.
14 Children and sensitive data
The Service is intended for adults and is not marketed as a children’s service. If we learn that a child has provided account information contrary to the eligibility rules, we investigate and take lawful steps to restrict or delete it, while preserving necessary evidence. Contact privacy support if this occurs. We do not rely on an 18-plus label as the only protective measure.
Works can incidentally include information about minors, research participants, health, beliefs or other sensitive matters. Authors must have lawful authority and appropriate notices or permissions. We may refuse processing for which suitable safeguards or legal conditions are not available. A general account acceptance does not authorise all sensitive-data processing or satisfy every country’s parental-consent requirement.
15 Policy changes and contacts
We date and version this Policy and communicate material changes through appropriate channels. New incompatible processing requires a lawful basis and, where required, fresh consent before it starts. Continued use alone is not deemed consent to an unrelated new purpose. We keep prior versions where necessary to explain historical practices.
Privacy enquiries, rights requests, account closure, security concerns and appeals: contact@combdesk.com. Company: CombDesk LLC. Website: https://writingdeskguardian.com. You may also contact the relevant regulator directly.