Manuscript

Privacy Policy

Effective 23-Sep-2026

Manuscript is made by Zilloris. This policy explains what the app does with information, in the same plain register the app uses.

The short version. Your writing stays on your phone. Manuscript has no account, no login, no server of its own, and no way to send your draft anywhere. What does leave your phone is a small amount of information about how the app is used and when it crashes. It cannot contain any part of your draft, for a reason set out below.

What the app keeps on your phone

Everything you make in Manuscript lives on the device and only on the device.

Two of these are free text you type yourself: the draft title and any chapter titles. Like everything else here, they stay on the phone.

Android does not copy any of this either. The app switches off Android’s automatic backup, and its backup rules exclude the files, the database and the settings from both Google Drive backup and phone-to-phone transfer. Your draft is not in your Google account.

We never receive any of it. There is no server to receive it with.

What is collected and sent

Manuscript uses five Google services. Google acts as our data processor: it handles this information on our instructions, to run these services for us.

1. Firebase Analytics — how the app is used

What the app itself reports. Two kinds of thing, and nothing else.

Which screen you are on. One of eighteen fixed names, sent when the screen changes: a1_splash, a2_what, a3_when, a4_bring, b1_page, b2_dry, b3_desk, b4_keep, b6_dried, c1_drawer, c3_import, c4_resurrect, c5_you, c7_outline, c9_pages, c10_copy, c12_guide, c13_legal.

That something happened. Seventeen events, each a fixed name: setup started, setup signed, drafts brought in, drafts skipped, page dried, night entered, desk opened, drawer opened, outline opened, import started, draft resurrected, update prompt shown, update prompt answered, update installed, privacy policy opened, terms of use opened, guide opened.

Five of them carry one extra detail, of three kinds, and nothing else does:

That is the complete list. No event carries text you wrote, a title, a name, a date you entered, or anything you typed.

What Google’s analytics collects automatically. This is the larger part, and it is not something the app chooses. When the analytics SDK is running, it collects, on its own defaults:

It does not collect the advertising identifier — see The advertising identifier below.

2. Firebase Crashlytics — when the app breaks

If Manuscript crashes, a crash report goes to Google. It contains the stack trace (the sequence of code locations, by class, method and line), your device model, the Android version, app state at the moment of the crash, and an installation identifier that links reports from the same install.

The app adds exactly one piece of its own information to a crash report: the name of the screen that was open, from the eighteen names listed above.

Crash reports contain no page text. To be precise rather than reassuring: a crash inside the file-handling code could include a file path, and those paths contain a draft’s internal identifier and a page number. Those identifiers are random strings, not titles, and the path names a file — it does not contain what is in it.

3. Firebase Remote Config — four settings

Once per cold start, at most once an hour, the app asks Google for four values: which update policy is in force, the minimum app version, the address of this privacy policy, and the address of the terms of use. The request carries the installation identifier, the app and SDK versions, your language, time zone, and the network address it comes from. The app puts nothing of its own into it.

Nothing that comes back can change your page size, the hour, the dry hour, or anything that happens to your words.

4. Google Play In-App Update — whether a newer version exists

The app asks the Play Store app already installed on your phone whether there is an update. This is a message between two apps on your device; the app sends nothing to us and nothing of yours to Google. Whatever the Play Store itself reports to Google about your device and account is governed by Google’s own policy, not by this one.

5. The web pages — the text of this policy, and of the terms

This policy and the terms of use are published at zilloris.com, on GitHub Pages, a GitHub service. When you open either one inside the app, the app downloads that page, so that what you read is what is in force today. It is an ordinary web request, sent only when you open one of those two pages and never in the background. It carries the page’s address, a note that it came from Manuscript and which version, and — like any web request — your network address. Nothing from your draft or your settings goes with it. The app keeps the last copy it downloaded, and shows that, or the copy it was installed with, when there is no connection.

Why your draft cannot be collected, even by mistake

This is the strongest thing the app has to say, so here is exactly how it works.

The only code in Manuscript that can send anything is a single small piece of code we call the analytics facade. It offers callers one method, and that method accepts three things:

There is no way to pass it a piece of text. No second version of the method accepts one. A programmer who wanted to send a sentence of your draft could not do it by getting something wrong — they would have to deliberately add a new method, and that change would be visible in the app’s source.

Your page text also never enters the database, so there is no table anywhere that a future feature could accidentally read from and report. Kept lines and strikes are stored as positions in a file. The pages themselves live only as files, behind a single piece of code that reads and writes them and does nothing else.

The app’s own code opens one kind of connection, and it cannot carry your writing either. When you open the privacy policy or the terms of use inside the app, it downloads the current text of that page — see 5. The web pages above. That code is handed the page’s address and nothing else, so there is nothing of yours for it to send. There is no web view: the text is set in the app’s own type. Everything else that reaches the network is Google’s Firebase code, and Google’s code is never handed your prose.

The advertising identifier

Manuscript does not collect it, and cannot.

This is worth explaining, because it very nearly did. The Firebase Analytics library brings three advertising permissions in behind it — the Android advertising ID and two Privacy Sandbox attribution permissions — and they arrive whether or not an app has any advertising in it. Most apps that use Firebase ship them without noticing.

Manuscript removes all three from its manifest, and separately tells the analytics SDK not to collect the advertising ID. Both halves are in the app’s AndroidManifest.xml, which is readable in the published package. So the app does not merely decline to use the identifier: it does not hold the permission to ask for it.

Nothing was lost by removing it. Analytics still counts screens and events against its own random per-install identifier. What goes is the identifier that could have followed you across other apps.

There is no ad network in the app, no Google Ads account linked to it, no remarketing audience, and no attribution beyond the Play install referrer described above.

What is never collected

None of the following is collected, in any build, by the app or by anything in it:

Turning it off

We will not pretend there is a switch we have not built. As Manuscript is currently released, there is no setting inside the app to turn analytics or crash reporting off. They start when the app starts.

What you can do today:

If we add an in-app switch, this section will say so.

Legal bases for processing (UK and EU)

If you are in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR apply. Our legal basis depends on the purpose.

Where we rely on legitimate interests, we have weighed them against your interests and rights. You can object to that processing at any time — see Your rights.

How long it is kept

On your phone: for as long as you keep it. Nothing expires, nothing is cleaned up behind you, and nothing is deleted without you asking. It goes when you use “delete everything”, or when you uninstall the app.

At Google: analytics event data is kept for a limited period set on our Firebase console, currently 2 months, after which Google deletes the event-level records; aggregated counts may remain. Crash reports age out on Google’s own schedule. Installation identifiers persist until the app is uninstalled or its data is cleared, or until we delete them on request.

Where it goes

Google processes this information on servers in the United States and in other countries outside the United Kingdom and the European Economic Area. Where information is transferred out of the UK or the EEA, the transfer is made under Google’s data processing terms, which incorporate the European Commission’s Standard Contractual Clauses and the UK Addendum to them.

Your writing is not transferred anywhere, because it is not transferred at all.

Your rights, and which button each one is

In this app, most of these are something you already hold rather than something you have to ask us for.

To see your information (access). It is on your phone. Your pages are in “the pages”, reached from the stack on the desk. Your writing record is the desk, the keep and the outline. We hold no copy to show you.

To take it with you (portability). Open you → a copy of everything. Two exports, both to a file you choose in your phone’s own file picker:

To delete it (erasure).

To object, or to restrict processing. Write to us. There is no in-app switch today, so this is a request we act on rather than a control you flip. Uninstalling stops it immediately.

To correct information (rectification). Everything you can correct, you correct in the app. We hold nothing about you to correct.

To complain. You can complain to your data protection authority. In the UK that is the Information Commissioner’s Office.

Requests: support@zilloris.com. We will answer within one month.

Children

Manuscript is not directed at children under 13, and we do not knowingly collect information from them. It is a tool for writing a book-length draft: there is no child-directed content in it, no games, no rewards, no ads, no purchases, and no way to talk to anyone else through it.

California

We do not sell personal information, and we never have. No money or other valuable consideration changes hands for any information described in this policy. There is no advertising network, no data broker and no analytics reseller involved.

We do not share personal information for cross-context behavioural advertising. Manuscript runs no ads, is linked to no advertising account, and builds no advertising audiences. As explained above, the app does not collect the advertising identifier at all — the permissions the analytics library would have brought with it are removed from the manifest.

California residents have the right to know what personal information is collected, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. The section above tells you how to exercise each one; the answer is usually a button in the app.

Security

What protects your writing. Your draft sits in the app’s private storage, which Android keeps separate from other apps on the device: on an ordinary, unmodified phone, no other app can read it. Modern Android devices encrypt their storage, so the file is protected by your screen lock in the same way the rest of your phone is. Automatic backup is switched off, so no copy is made to Google Drive or handed to a new phone during a transfer. Information sent to Google travels over an encrypted connection.

What does not protect it, stated plainly. The app adds no encryption of its own. Your pages are ordinary text files and the database is an ordinary database. That is a deliberate choice — your words in a plain format you can always read — but it means the protection is your device’s, not ours. On a phone that has been rooted or otherwise opened up, the draft is readable.

The optional lock. In you → lock with screen lock you can ask the app to open only after your phone’s own screen lock: a fingerprint, your face, or the phone’s PIN, pattern or password. Android checks it, not the app. Manuscript is told only whether you unlocked, and never receives or stores a fingerprint, a face or a code. While the lock is on, the app also hides its pages from the recent-apps screen and from screenshots. It is a lock on the screen, not encryption: it keeps the pages from someone holding your unlocked phone. It is off unless you turn it on, and it is not copied into a .manuscript file.

A copy you export is yours to look after. A .manuscript file contains every word you have written, unencrypted, with no password on it. Whoever holds that file holds the book. If you save one into a cloud folder, it is in that cloud, under that provider’s terms, and we have no way to know or to help. The same is true of a .txt export.

And because there is no copy anywhere but your phone, we cannot help you recover one. A lost, wiped or broken phone means a lost draft unless you exported a copy yourself. That is the cost of the promise, and we would rather say it than let you find out.

Changes to this policy

If this policy changes in a way that affects what is collected or why, we will update it here, change the effective date at the top, and note what changed. A change that materially widens what we collect will be announced in the app’s release notes on Google Play before it takes effect, and the app will point at this page from you → privacy policy.

What changed on 16-Sep-2026: the optional lock, described under Security. Nothing new is collected or sent.

We will not add a way to collect your writing. If that ever changed, it would be an opt-in that asked you first and explained itself, not a quiet edit here.

Who we are, and how to reach us

Manuscript is published by Zilloris, the data controller for the information described in this policy.

support@zilloris.com

Manuscript · one page a day until it’s done.

Zilloris