Data privacy & your IP

Your unpublished work, kept safe.

Your manuscript is your intellectual property and often your most sensitive asset before publication. Here’s exactly how we protect it — in plain language, with no fine print designed to wriggle out of.

Secure transfer only

Files move through encrypted upload and download — never as email attachments.

Encrypted devices

Every computer we work on is fully encrypted, with two-factor access.

Deleted in 15 days

All copies are permanently deleted 15 calendar days after delivery.

No AI, no accounts

Never fed to a model. No login to create — and none to be breached.

In and out

Your manuscript travels securely — both ways.

We never accept or return manuscripts as email attachments. Email isn’t built for confidential files: copies linger in sent folders, on mail servers, and in backups outside anyone’s control. Instead, both directions use encrypted transfer.

  • You upload through a private, encrypted file request — no account required, and you can’t see anyone else’s files.
  • We return your edited manuscript through a password-protected link that expires, so it can’t be passed around or left open indefinitely.

The transfer is encrypted in transit, and the storage behind it is encrypted at rest.

Who sees it

One editor. No subcontractors. No machines.

Your manuscript is read only by your editor, working under a written confidentiality agreement. It is never passed to a pool of freelancers, never sent offshore, and never uploaded to any third-party tool.

It is never given to an AI system — not to edit, not to check, and never to train one. Your unpublished ideas, data, and findings stay yours. That is the entire point of working with a human editor, and we hold to it without exception.

Encryption

Everything we touch it with is encrypted.

Every device used to open, edit, or store your manuscript is protected with full-disk encryption, so the files are unreadable to anyone who doesn’t have authorised access — even if a laptop were lost or stolen. Accounts that hold client work are protected with strong, unique credentials and two-factor authentication. Because we don’t ask you to create an account, the security of our own systems is the whole perimeter, and we treat it that way.

How little we keep

We hold as little of your information as possible.

The strongest way to keep your data safe is not to collect much of it. We ask only for what we need to quote your job and stay in touch — your name, your email, and the details of your manuscript. That’s it.

There is no customer login, no password for you to set, and no account database. Nothing for an attacker to break into, because the account simply doesn’t exist. The limited contact information we do keep is stored in an encrypted, access-controlled place that only your editor can reach.

Retention & deletion

Fifteen days after delivery, it’s gone.

We keep your edited files briefly after delivery in case you have a quick question or need the file resent. Then we remove them — on a fixed schedule, not “eventually.”

  1. While we’re workingYour manuscript sits in encrypted storage, accessible only to your editor.
  2. After delivery — 15 calendar daysWe hold the files for a short window so anything urgent can be handled without re-uploading.
  3. Permanent deletionOn day 15 we delete every copy, including from our storage’s trash and version history, so no recoverable copy remains on our side.

If you’d like your files deleted sooner, just ask — we’ll do it and confirm.

One honest caveat, because we won’t promise what no service can deliver: cloud and backup providers may briefly retain encrypted residual copies inside their own systems before those cycle out automatically. We keep nothing ourselves beyond the 15-day window, and nothing we hold is recoverable after deletion.

Standards

The principles we work to.

Our handling follows established information-security principles: encrypt everything, give access to as few people as possible, collect the minimum data needed, and delete it on a defined schedule. These are the same principles behind recognised security frameworks, applied honestly at the scale of a boutique studio.

Our practices are aligned with the principles of the ISO/IEC 27001 information-security standard. We are not formally certified to it; we’d rather show you concrete, specific safeguards than point to a badge.

Your choices

Your work, your call.

You can ask us at any time to delete your files early, to confirm that deletion has happened, or to tell you exactly what information we hold about you. We’ll always answer plainly.

Questions about your IP?

Ask us anything before you send a single page. If our answer doesn’t leave you confident your work is safe, don’t send it — that’s the standard we hold ourselves to.

Small print

About this page.

This is a plain-language description of how we handle your work, written to be read rather than to hide things. It isn’t legal advice, and it doesn’t replace our formal terms of service. If you operate under specific institutional or funder data-handling requirements, tell us — we’re happy to confirm whether we can meet them.

Editor’s note (remove before launch): have this page and your terms reviewed by a lawyer, particularly for EU/UK (GDPR) clients.