Privacy policy
A book is made of other people's photographs and words, so this matters more here than on most sites. Written plainly, and short enough to actually read.
We collect the names, messages, photographs and email addresses needed to make and post one book. We do not sell anything to anybody, we run no advertising trackers, and photographs have their location data stripped in your browser before they are ever uploaded. A finished book’s contents are deleted after 24 months.
Who is responsible
Adam Grieve, trading as Wewrote, is the data controller for the information described here. Our business address is not finalised and will be stated here before we take any payment. For anything on this page, write to privacy@wewrote.co.uk.
What we collect, and why
That is the entire list. There is no analytics, no advertising, no profiling and no third-party tracking script anywhere on this site.
Photographs, and the location data cameras add
Phones record where a photograph was taken. Every photograph added to a book is re-encoded in the browser it came from before it is uploaded, which removes that data along with the rest of the camera’s metadata. It was done to make uploads fast; the effect is that we never receive anybody’s home address in a picture, and neither does anybody else.
Photographs are stored at long, random web addresses. They are not listed or searchable, but anyone holding the exact address of a photograph can open it without signing in — that is how the pages load instantly. Treat those links as private, and do not paste them anywhere public.
Cookies
We use three, all strictly necessary, and none of them for advertising:
- A contributor marker — a random code so someone can find and change their own pages, and so a book’s per-person page limit means something.
- A sign-in session — set only if you choose to sign in, so you stay signed in.
- A short-lived key for sending photographs from a phone to a page you are writing on a laptop.
Because all three are necessary for the thing you asked us to do, there is no cookie banner. We would rather run no trackers than ask permission to run them.
Who else sees any of it
- Vercel — hosting and photograph storage, in London.
- Neon — the database, in London.
- Stripe — payments. They handle your card; we do not.
- Resend — sending our emails.
- Our printer — receives the finished print files and the delivery address, and nothing else.
Each is a processor acting on our instructions. Some are outside the UK; where they are, transfers are covered by the standard safeguards those companies publish. We do not sell or share personal data for anybody else’s purposes.
How long we keep things
- An open book — while you are filling it, and until you delete it.
- A printed book’s pages and photographs — 24 months after printing, so we can reprint it if it is lost or damaged in the post. Then deleted.
- Order and payment records — six years, which is what tax law requires.
- Sign-in tokens — twenty minutes. Sessions — sixty days, or until you sign out.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, or object to us doing it. Write to privacy@wewrote.co.uk and we will answer within 30 days.
If you wrote a page in somebody else’s book and want it removed, you can do it yourself from that book’s page while it is still open, or ask us. If the book has already been printed we can delete our copy, but we cannot recall a printed book that has been given away — and it is worth knowing that before you write in one.
If you think we have got this wrong, please tell us first. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
Children
Wewrote is for adults organising a gift. We do not knowingly collect data from children, and a child’s drawing or message added by their parent is treated exactly like any other page in the book. If you believe a child has given us information directly, tell us and we will delete it.
Security
Everything travels over HTTPS. A book is reached by a long, unguessable link rather than a password, and every organiser action re-checks that link on the server. Sessions can be revoked. Payment card details never touch our servers.
We are honest about the trade in that design: a private link is only as private as the place you put it. If one gets out, replace the invite link from your book’s page and email us about the organiser link.
See also our terms and conditions and delivery and returns.
Last updated 4 September 2026.