In and out
Your manuscript travels securely — both ways.
We never accept or return manuscripts as email attachments. Email isn’t built for confidential files: copies linger in sent folders, on mail servers, and in backups outside anyone’s control. Instead, both directions use encrypted transfer.
- You upload through a private, encrypted file request — no account required, and you can’t see anyone else’s files.
- We return your edited manuscript through a password-protected link that expires, so it can’t be passed around or left open indefinitely.
The transfer is encrypted in transit, and the storage behind it is encrypted at rest.
Who sees it
One editor. No subcontractors. No machines.
Your manuscript is read only by your editor, working under a written confidentiality agreement. It is never passed to a pool of freelancers, never sent offshore, and never uploaded to any third-party tool.
It is never given to an AI system — not to edit, not to check, and never to train one. Your unpublished ideas, data, and findings stay yours. That is the entire point of working with a human editor, and we hold to it without exception.
Encryption
Everything we touch it with is encrypted.
Every device used to open, edit, or store your manuscript is protected with full-disk encryption, so the files are unreadable to anyone who doesn’t have authorised access — even if a laptop were lost or stolen. Accounts that hold client work are protected with strong, unique credentials and two-factor authentication. Because we don’t ask you to create an account, the security of our own systems is the whole perimeter, and we treat it that way.
How little we keep
We hold as little of your information as possible.
The strongest way to keep your data safe is not to collect much of it. We ask only for what we need to quote your job and stay in touch — your name, your email, and the details of your manuscript. That’s it.
There is no customer login, no password for you to set, and no account database. Nothing for an attacker to break into, because the account simply doesn’t exist. The limited contact information we do keep is stored in an encrypted, access-controlled place that only your editor can reach.
Retention & deletion
Fifteen days after delivery, it’s gone.
We keep your edited files briefly after delivery in case you have a quick question or need the file resent. Then we remove them — on a fixed schedule, not “eventually.”
- While we’re workingYour manuscript sits in encrypted storage, accessible only to your editor.
- After delivery — 15 calendar daysWe hold the files for a short window so anything urgent can be handled without re-uploading.
- Permanent deletionOn day 15 we delete every copy, including from our storage’s trash and version history, so no recoverable copy remains on our side.
If you’d like your files deleted sooner, just ask — we’ll do it and confirm.
Standards
The principles we work to.
Our handling follows established information-security principles: encrypt everything, give access to as few people as possible, collect the minimum data needed, and delete it on a defined schedule. These are the same principles behind recognised security frameworks, applied honestly at the scale of a boutique studio.
Our practices are aligned with the principles of the ISO/IEC 27001 information-security standard. We are not formally certified to it; we’d rather show you concrete, specific safeguards than point to a badge.
Your choices
Your work, your call.
You can ask us at any time to delete your files early, to confirm that deletion has happened, or to tell you exactly what information we hold about you. We’ll always answer plainly.
Questions about your IP?
Ask us anything before you send a single page. If our answer doesn’t leave you confident your work is safe, don’t send it — that’s the standard we hold ourselves to.
Small print
About this page.
This is a plain-language description of how we handle your work, written to be read rather than to hide things. It isn’t legal advice, and it doesn’t replace our formal terms of service. If you operate under specific institutional or funder data-handling requirements, tell us — we’re happy to confirm whether we can meet them.