Privacy Policy
Effective 23-Sep-2026
Manuscript is made by Zilloris. This policy explains what the app does with information, in the same plain register the app uses.
The short version. Your writing stays on your phone. Manuscript has no account, no login, no server of its own, and no way to send your draft anywhere. What does leave your phone is a small amount of information about how the app is used and when it crashes. It cannot contain any part of your draft, for a reason set out below.
What the app keeps on your phone
Everything you make in Manuscript lives on the device and only on the device.
- The pages. Each page is a plain
.txtfile in the app’s private storage. Plain text, no markup, nothing added. - The record of the writing. A local database holds the draft’s title, the form you chose, page numbers, page dates, word counts, which days you wrote, your kept lines, your red-pen strikes and your chapter names. Kept lines and strikes are stored as positions in a page — the start and end of a range — not as copies of the words.
- Your settings. Page size, the hour you picked, the hour the ink dries, whether the notification is on, typewriter mode, whether the lock is on, and the initial you sign the contract with.
Two of these are free text you type yourself: the draft title and any chapter titles. Like everything else here, they stay on the phone.
Android does not copy any of this either. The app switches off Android’s automatic backup, and its backup rules exclude the files, the database and the settings from both Google Drive backup and phone-to-phone transfer. Your draft is not in your Google account.
We never receive any of it. There is no server to receive it with.
What is collected and sent
Manuscript uses five Google services. Google acts as our data processor: it handles this information on our instructions, to run these services for us.
1. Firebase Analytics — how the app is used
What the app itself reports. Two kinds of thing, and nothing else.
Which screen you are on. One of eighteen fixed names, sent when the screen changes: a1_splash, a2_what, a3_when, a4_bring, b1_page, b2_dry, b3_desk, b4_keep, b6_dried, c1_drawer, c3_import, c4_resurrect, c5_you, c7_outline, c9_pages, c10_copy, c12_guide, c13_legal.
That something happened. Seventeen events, each a fixed name: setup started, setup signed, drafts brought in, drafts skipped, page dried, night entered, desk opened, drawer opened, outline opened, import started, draft resurrected, update prompt shown, update prompt answered, update installed, privacy policy opened, terms of use opened, guide opened.
Five of them carry one extra detail, of three kinds, and nothing else does:
- How a draft arrived — the word
file, on “drafts brought in” and “import started”. Not the draft. Not its name. - How many words were on a page when it dried — a number, on “page dried”. A count, not the words counted.
- Whether an update prompt was the blocking kind, and whether you accepted it — 1 or 0.
That is the complete list. No event carries text you wrote, a title, a name, a date you entered, or anything you typed.
What Google’s analytics collects automatically. This is the larger part, and it is not something the app chooses. When the analytics SDK is running, it collects, on its own defaults:
- an app-instance identifier and a Firebase installation identifier — random per-install identifiers that let events from the same install be counted as one install
- session identifiers and standard events: first open, session start, app update, app removal, OS update
- your device model and brand, Android version, app version, screen size and language
- an approximate location — country and region, worked out by Google from the network address your device connects from, not from any location permission (the app has none)
- Play install-referrer information, which can attribute an install to a Play Store campaign
It does not collect the advertising identifier — see The advertising identifier below.
2. Firebase Crashlytics — when the app breaks
If Manuscript crashes, a crash report goes to Google. It contains the stack trace (the sequence of code locations, by class, method and line), your device model, the Android version, app state at the moment of the crash, and an installation identifier that links reports from the same install.
The app adds exactly one piece of its own information to a crash report: the name of the screen that was open, from the eighteen names listed above.
Crash reports contain no page text. To be precise rather than reassuring: a crash inside the file-handling code could include a file path, and those paths contain a draft’s internal identifier and a page number. Those identifiers are random strings, not titles, and the path names a file — it does not contain what is in it.
3. Firebase Remote Config — four settings
Once per cold start, at most once an hour, the app asks Google for four values: which update policy is in force, the minimum app version, the address of this privacy policy, and the address of the terms of use. The request carries the installation identifier, the app and SDK versions, your language, time zone, and the network address it comes from. The app puts nothing of its own into it.
Nothing that comes back can change your page size, the hour, the dry hour, or anything that happens to your words.
4. Google Play In-App Update — whether a newer version exists
The app asks the Play Store app already installed on your phone whether there is an update. This is a message between two apps on your device; the app sends nothing to us and nothing of yours to Google. Whatever the Play Store itself reports to Google about your device and account is governed by Google’s own policy, not by this one.
5. The web pages — the text of this policy, and of the terms
This policy and the terms of use are published at zilloris.com, on GitHub Pages, a GitHub service. When you open either one inside the app, the app downloads that page, so that what you read is what is in force today. It is an ordinary web request, sent only when you open one of those two pages and never in the background. It carries the page’s address, a note that it came from Manuscript and which version, and — like any web request — your network address. Nothing from your draft or your settings goes with it. The app keeps the last copy it downloaded, and shows that, or the copy it was installed with, when there is no connection.
Why your draft cannot be collected, even by mistake
This is the strongest thing the app has to say, so here is exactly how it works.
The only code in Manuscript that can send anything is a single small piece of code we call the analytics facade. It offers callers one method, and that method accepts three things:
- an event, which must be one of the fixed names listed above — they are constants written into the app when it is built;
- an optional label, which must come from one of a handful of small fixed lists inside the app — short enumerations like
file, whose every possible value is written into the app when it is built; - an optional number.
There is no way to pass it a piece of text. No second version of the method accepts one. A programmer who wanted to send a sentence of your draft could not do it by getting something wrong — they would have to deliberately add a new method, and that change would be visible in the app’s source.
Your page text also never enters the database, so there is no table anywhere that a future feature could accidentally read from and report. Kept lines and strikes are stored as positions in a file. The pages themselves live only as files, behind a single piece of code that reads and writes them and does nothing else.
The app’s own code opens one kind of connection, and it cannot carry your writing either. When you open the privacy policy or the terms of use inside the app, it downloads the current text of that page — see 5. The web pages above. That code is handed the page’s address and nothing else, so there is nothing of yours for it to send. There is no web view: the text is set in the app’s own type. Everything else that reaches the network is Google’s Firebase code, and Google’s code is never handed your prose.
The advertising identifier
Manuscript does not collect it, and cannot.
This is worth explaining, because it very nearly did. The Firebase Analytics library brings three advertising permissions in behind it — the Android advertising ID and two Privacy Sandbox attribution permissions — and they arrive whether or not an app has any advertising in it. Most apps that use Firebase ship them without noticing.
Manuscript removes all three from its manifest, and separately tells the analytics SDK not to collect the advertising ID. Both halves are in the app’s AndroidManifest.xml, which is readable in the published package. So the app does not merely decline to use the identifier: it does not hold the permission to ask for it.
Nothing was lost by removing it. Analytics still counts screens and events against its own random per-install identifier. What goes is the identifier that could have followed you across other apps.
There is no ad network in the app, no Google Ads account linked to it, no remarketing audience, and no attribution beyond the Play install referrer described above.
What is never collected
None of the following is collected, in any build, by the app or by anything in it:
- Your writing. No page, no sentence, no fragment, in any event, any crash report or any request.
- Draft titles, chapter titles, kept lines or strikes.
- Your initial — the short signature you type during setup. It is stored on the phone and written into a copy you export yourself. It is never sent anywhere.
- An account of any kind. There is no sign-up, no login, no password field and no account system in the app.
- Your name, email address, phone number or postal address. There is nowhere in Manuscript to type any of them.
- Precise location. The app holds no location permission and calls no location service.
- Contacts, calendar, messages, photos, camera or microphone. No permission, no code.
- Files on your phone. The app holds no storage permission and cannot list or read any directory. Importing and exporting work only through Android’s own file picker, on the one file you choose.
- Payment information. There is no billing code in the app.
- Push notifications. There is no push messaging service. The single reminder is created by your phone, at the hour you picked, and never leaves it.
Turning it off
We will not pretend there is a switch we have not built. As Manuscript is currently released, there is no setting inside the app to turn analytics or crash reporting off. They start when the app starts.
What you can do today:
- Write to us at the address at the foot of this policy and ask us to stop processing information about your use of the app, and to delete what we hold. See Your rights.
- Uninstall the app, which stops all of it.
If we add an in-app switch, this section will say so.
Legal bases for processing (UK and EU)
If you are in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR apply. Our legal basis depends on the purpose.
- Storing your draft, settings and writing record on your device. No basis is needed from us: we never receive this information and do not process it. Your device processes it for you.
- Analytics. Legitimate interests, Art. 6(1)(f): understanding whether a small app works well enough to keep improving it. The information is limited to fixed event names, counts and device context, and cannot include your writing.
- Crash reporting. Legitimate interests, Art. 6(1)(f): keeping the app from losing a writer’s day to a bug.
- Remote Config. Legitimate interests, Art. 6(1)(f): being able to point the app at a current policy and require a security update.
- Play In-App Update. Legitimate interests, Art. 6(1)(f): keeping installed copies current and secure.
- The daily reminder notification. Consent, Art. 6(1)(a): you choose the hour and grant the notification permission, and you can turn the notification off in “you”, or withdraw the permission in Android’s settings.
Where we rely on legitimate interests, we have weighed them against your interests and rights. You can object to that processing at any time — see Your rights.
How long it is kept
On your phone: for as long as you keep it. Nothing expires, nothing is cleaned up behind you, and nothing is deleted without you asking. It goes when you use “delete everything”, or when you uninstall the app.
At Google: analytics event data is kept for a limited period set on our Firebase console, currently 2 months, after which Google deletes the event-level records; aggregated counts may remain. Crash reports age out on Google’s own schedule. Installation identifiers persist until the app is uninstalled or its data is cleared, or until we delete them on request.
Where it goes
Google processes this information on servers in the United States and in other countries outside the United Kingdom and the European Economic Area. Where information is transferred out of the UK or the EEA, the transfer is made under Google’s data processing terms, which incorporate the European Commission’s Standard Contractual Clauses and the UK Addendum to them.
Your writing is not transferred anywhere, because it is not transferred at all.
Your rights, and which button each one is
In this app, most of these are something you already hold rather than something you have to ask us for.
To see your information (access). It is on your phone. Your pages are in “the pages”, reached from the stack on the desk. Your writing record is the desk, the keep and the outline. We hold no copy to show you.
To take it with you (portability). Open you → a copy of everything. Two exports, both to a file you choose in your phone’s own file picker:
- the words — a plain
.txtof the draft on the desk, readable in any editor, no app needed. - everything, to put back — a
.manuscriptfile: every draft including the ones in the drawer, every page in full, every date, the days, the keep, the strikes, the chapters and your settings. It is plain readable JSON, and it is the file that restores onto a new phone.
To delete it (erasure).
- On the phone: you → delete everything. It cancels the app’s scheduled work, deletes every page file, empties every table, and clears every setting, and then puts you back at the first screen. There is no undo. The sheet offers “write a copy first” above it for that reason.
- Uninstalling removes everything the app stored, and nothing comes back if you reinstall — there is no backup of it anywhere.
- At Google: “delete everything” wipes your phone, not Google’s records. To have the analytics and crash information associated with your installation deleted, write to us at the address below. We will need you to tell us which installation, and we may not be able to identify it once the app has been uninstalled.
To object, or to restrict processing. Write to us. There is no in-app switch today, so this is a request we act on rather than a control you flip. Uninstalling stops it immediately.
To correct information (rectification). Everything you can correct, you correct in the app. We hold nothing about you to correct.
To complain. You can complain to your data protection authority. In the UK that is the Information Commissioner’s Office.
Requests: support@zilloris.com. We will answer within one month.
Children
Manuscript is not directed at children under 13, and we do not knowingly collect information from them. It is a tool for writing a book-length draft: there is no child-directed content in it, no games, no rewards, no ads, no purchases, and no way to talk to anyone else through it.
California
We do not sell personal information, and we never have. No money or other valuable consideration changes hands for any information described in this policy. There is no advertising network, no data broker and no analytics reseller involved.
We do not share personal information for cross-context behavioural advertising. Manuscript runs no ads, is linked to no advertising account, and builds no advertising audiences. As explained above, the app does not collect the advertising identifier at all — the permissions the analytics library would have brought with it are removed from the manifest.
California residents have the right to know what personal information is collected, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. The section above tells you how to exercise each one; the answer is usually a button in the app.
Security
What protects your writing. Your draft sits in the app’s private storage, which Android keeps separate from other apps on the device: on an ordinary, unmodified phone, no other app can read it. Modern Android devices encrypt their storage, so the file is protected by your screen lock in the same way the rest of your phone is. Automatic backup is switched off, so no copy is made to Google Drive or handed to a new phone during a transfer. Information sent to Google travels over an encrypted connection.
What does not protect it, stated plainly. The app adds no encryption of its own. Your pages are ordinary text files and the database is an ordinary database. That is a deliberate choice — your words in a plain format you can always read — but it means the protection is your device’s, not ours. On a phone that has been rooted or otherwise opened up, the draft is readable.
The optional lock. In you → lock with screen lock you can ask the app to open only after your phone’s own screen lock: a fingerprint, your face, or the phone’s PIN, pattern or password. Android checks it, not the app. Manuscript is told only whether you unlocked, and never receives or stores a fingerprint, a face or a code. While the lock is on, the app also hides its pages from the recent-apps screen and from screenshots. It is a lock on the screen, not encryption: it keeps the pages from someone holding your unlocked phone. It is off unless you turn it on, and it is not copied into a .manuscript file.
A copy you export is yours to look after. A .manuscript file contains every word you have written, unencrypted, with no password on it. Whoever holds that file holds the book. If you save one into a cloud folder, it is in that cloud, under that provider’s terms, and we have no way to know or to help. The same is true of a .txt export.
And because there is no copy anywhere but your phone, we cannot help you recover one. A lost, wiped or broken phone means a lost draft unless you exported a copy yourself. That is the cost of the promise, and we would rather say it than let you find out.
Changes to this policy
If this policy changes in a way that affects what is collected or why, we will update it here, change the effective date at the top, and note what changed. A change that materially widens what we collect will be announced in the app’s release notes on Google Play before it takes effect, and the app will point at this page from you → privacy policy.
What changed on 16-Sep-2026: the optional lock, described under Security. Nothing new is collected or sent.
We will not add a way to collect your writing. If that ever changed, it would be an opt-in that asked you first and explained itself, not a quiet edit here.
Who we are, and how to reach us
Manuscript is published by Zilloris, the data controller for the information described in this policy.
support@zilloris.com
Manuscript · one page a day until it’s done.
Zilloris