Privacy
Your account is not your manuscript.
Kaizen separates online identity and provider access from the writing held in your browser. Weaver keeps Books, sources, decisions, provider results you retain, the Record, and the complete Archive locally. The account service stores only the identity, session, entitlement, billing, and connection records needed to operate online service.
Local custody
What the account can never become.
- Weaver's Books, source material, decisions, retained provider results, Record, Archive, restore material, and portable handoff stay in the browser unless you deliberately export a file or request a provider Read.
- No online Kaizen service stores enough writer material to reconstruct a complete Weaver Archive.
- Signing out, losing a session, cancelling a subscription, or deleting an account stops new online service. It does not remove local writing, prior results, Archive, restore, source download, or portable handoff.
- Weaver account deletion and Weaver's local reset are separate actions. The account service does not send a command that deletes browser-local Weaver data.
Account records
What Kaizen stores for online service.
- The account service may store your email address, a stable Google identity identifier when you choose Google, internal account and app identifiers, entitlement state, billing references, session records, connected Drive grant metadata, and an account deletion record.
- Passwordless email uses a single-use challenge that expires after 15 minutes. Kaizen stores the records needed to deliver, validate, consume, rate limit, and audit that challenge. Kaizen does not create an account password.
- The account browser receives a secure, host-only session cookie. The database stores a keyed digest rather than the raw session secret. Sessions expire after 30 days without activity or 90 days in total. A short-lived Weaver service credential lasts about 10 minutes and is not an Archive record.
- Bounded service logs may include route, provider mode, status, latency, model, contract version, an anonymous account identifier, allowance decision, reservation metadata, and byte counts. They must not include manuscript text, complete prompts or responses, email addresses, account secrets, provider keys, or Archive contents.
Google connections
Sign in, Gemini, and Drive are separate.
- Continue with Google uses a dedicated Google Identity Services client for sign-in. Kaizen links that identity by Google's stable account identifier, not by matching an email address alone. The sign-in request does not ask for Google Drive scope.
- A Google Drive connection is a separate, optional authorization shown only where an app currently provides a visible Drive control. R/W and Rewriter retain their published Drive controls. Weaver does not currently claim a shipped Drive control.
- Where Drive is connected, Kaizen asks only for the identity and file access the visible feature needs. Files remain in the writer's Drive. Disconnecting or deleting the Kaizen account revokes Kaizen's grant, but it does not delete writer-owned Drive files.
Google's current API Services User Data Policy and privacy and terms govern Google's side of those distinct services.
Provider request path
What travels when you ask for AI.
Your browser
The app shows the material, purpose, destination, provider path, and credential mode before a Weaver provider Read. Nothing leaves because of a background decision. Declining sends nothing.
Kaizen's proxy
The requested passage and context pass through the relevant Kaizen route to the provider and the response returns to your browser. Kaizen does not keep the manuscript body or complete response. Hosted Weaver requests use a short-lived account credential and reserve one paid Read until the result is kept locally.
The model provider
The provider processes the disclosed text under the provider account and terms for that credential. Provider policies can include safety logging, retention, regional processing, and legally required disclosures. Read the current provider terms before sending sensitive work.
Credential modes
Hosted Gemini and BYOK have different owners.
- Weaver Free includes zero Kaizen-hosted Reads. After account activation, you may use your own Gemini API key.
- Weaver Pro and Suite Pro may use Kaizen's server-side paid Gemini API key. That key never reaches the browser. Google states that paid Gemini API prompts and responses are not used to improve its products, while limited safety and security logging can still apply.
- Bring your own key keeps provider billing on your provider account and does not consume Kaizen-hosted allowance. The key lives in your browser, passes through Kaizen's proxy only for your request, and is not stored by Kaizen. Your provider plan controls its data terms. Google's unpaid Gemini services can use submitted content and responses to improve products, while its paid services use different data terms.
- R/W and Rewriter retain their currently published hosted Google and Anthropic paths. Anthropic's commercial terms state that it does not train models on commercial customer content. Provider terms remain the source of truth.
Read the current Gemini API terms, Gemini data retention guidance, and Anthropic commercial terms.
Deletion
What account deletion does.
Account deletion is managed at account.kaizenrw.com. Kaizen cancels active Kaizen subscriptions, revokes connected Drive grants, clears paid Weaver rollover, revokes account sessions and identities, and keeps only the bounded tombstone and usage evidence needed to prevent a deleted account from being silently restored. Stripe, Google, Anthropic, and your BYOK provider may retain records under their own legal duties and policies.
This site also uses cookieless Cloudflare Web Analytics. Cloudflare receives ordinary request information such as the visited URL, referrer, browser type, and delivery IP address to count visits and screen bot traffic. Kaizen does not use that analytics path to build a cross-site writer profile.