Legal
Version 1.0 · Effective 23 September 2026
This Privacy Notice explains how personal data is processed when you use ThesisDraft for Word, the add-in for Microsoft Word published under the name "ThesisDraft", and the services connected to it (the "Service"). It fulfils the information obligations under Articles 13 and 14 of the General Data Protection Regulation ("GDPR"). The analysis tools and the Academic Rewrite offered on thesisdraft.com are covered by a separate privacy policy at thesisdraft.com/legal/privacy/. Data processed in the Service is never combined with data processed by those tools.
The controller within the meaning of Article 4(7) GDPR is:
The controller is not required to appoint a data protection officer (Article 37 GDPR, § 38 of the German Federal Data Protection Act, BDSG). Data protection enquiries may be sent to the address above.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data | Providing the Account | Art. 6(1)(b) GDPR | Until the Account is deleted |
| Sign-in security data | Securing the Account | Art. 6(1)(f) GDPR | A few weeks |
| Subscription data | Contract and billing | Art. 6(1)(b) GDPR | Until the Account is deleted |
| Accounting records | Statutory retention | Art. 6(1)(c) GDPR | Statutory period (section 8.3) |
| Projects, conversations, citation map | Providing the Service | Art. 6(1)(b) GDPR | Until deleted by you |
| Library (Sources) | Providing the Service | Art. 6(1)(b) GDPR | Until deleted by you |
| Document text | Processing your instruction | Art. 6(1)(b) GDPR | Not stored |
| Usage data | Usage Allowance, abuse prevention | Art. 6(1)(b) and (f) GDPR | Until the Account is deleted |
| Support communications | Answering your enquiry | Art. 6(1)(b) and (f) GDPR | Three years |
| Technical logs | Operation and security | Art. 6(1)(f) GDPR | 30 days |
3.1 Data minimisation. We do not ask for your name, institution, supervisor, student identification number or date of birth. None is needed for any function of the Service.
3.2 No document storage. Your Word document remains on your own systems. It is never uploaded or stored by us as a file.
3.3 No secondary use. Your data is used only to provide the Service to you. It is not used for advertising or profiling, is not sold, is not shared with other users, and is not used by us or by any of our service providers to train artificial intelligence models.
3.4 Separation. Data in the Service is kept separate from data processed by the analysis tools on thesisdraft.com, and the two are never linked.
4.1 Data processed. To create and maintain your Account we process your email address, your chosen sign-in method, a hash of your password if you sign in with email and password, the language setting of the add-in, and the date the Account was created.
4.2 Sign-in with Microsoft or Google. If you choose to sign in with an existing Microsoft or Google account, that provider confirms your identity to us and transmits your email address. We do not request or store your name or profile picture. Microsoft and Google act as independent controllers for the sign-in process; their privacy statements apply. If you sign in with an account issued by your university, the email address may indicate your institution.
4.3 Security. When you sign in, our authentication provider processes your IP address and browser information in order to protect your Account against unauthorised access and abuse.
4.4 Account emails. We send you the emails required to operate your Account, in particular to confirm your email address and to reset your password.
4.5 Legal basis. Article 6(1)(b) GDPR for 4.1, 4.2 and 4.4; Article 6(1)(f) GDPR for 4.3, our legitimate interest being the security of the Service and of your Account.
5.1 Data processed. We process your Plan, the status of your Subscription, the end of the current billing period, any cancellation, and the reference numbers that our payment service provider assigns to you as a customer and to your Subscription. If you use a creator's discount code, we record which code was used, in order to apply the discount and to pay the creator a commission. The creator receives no information that identifies you.
5.2 Payment. Payments are processed by Stripe (section 10). We do not receive or store your payment card or bank details.
5.3 Legal basis. Article 6(1)(b) GDPR; for accounting records, Article 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB).
6.1 Projects. For each project we store the title, the type of work, its language, target length and citation style, the chapter plan, and the text of any writing guidelines you provide. Guideline files themselves are not retained after their text has been extracted.
6.2 Conversations. We store the messages exchanged in the task pane for each project, so that you can continue your work across sessions and devices. The most recent 120 messages per project are retained; older messages are deleted automatically.
6.3 Citation map. We store which sentence of your document is based on which passage of which Source. This allows the task pane to show you the relevant Source when you select a sentence. The citation map is stored on our systems only. No link or reference to the Service is inserted into the text of your document.
6.4 Library. We store the Sources you upload or add, the text extracted from them divided into passages, and a numerical representation of each passage (embedding) that enables searching by meaning. The original file name is not stored. Your Library is accessible only through your Account.
6.5 Document text. When you give an instruction in the task pane, the add-in reads the text of your open document and transmits to us up to approximately 24,000 characters of it, together with its headings and the beginning of each paragraph, so that the instruction can be carried out in the right place and in context. This text is processed only to carry out your instruction and is not stored, save for the resulting content recorded in the conversation (6.2) and the citation map (6.3).
6.6 Project identifier in the document file. In order to reopen the correct project whenever you open your document, the add-in stores a randomly generated project identifier in the settings area of your .docx file. Microsoft Word also records in this area that the add-in has been used with the file. The identifier does not contain any personal data and cannot be used by anyone other than you, signed in to your Account, to access your data. It is not visible in the text of the document. It can be removed by exporting the document as PDF, or with Word's "Inspect Document" function (File → Info → Check for Issues → Inspect Document → Task Pane Add-ins).
6.7 Literature search. When you ask the Service to propose publications, we derive search terms from your project's topic and send them to OpenAlex, a public index of scholarly literature operated by OurResearch (United States). No part of your document and no information identifying you is transmitted. Open-access publications are then retrieved by our servers directly from the publishers or repositories concerned.
6.8 Legal basis. Article 6(1)(b) GDPR. The processing described in this section is necessary to provide the Service you have contracted.
7.1 Generation. Your instructions, the parts of your document required for the instruction, relevant passages from your Library and your chapter plan are processed by the Gemini models of Google Vertex AI to generate AI Output. This processing takes place within the European Union.
7.2 Web research for chapter plans. When you request a chapter plan, the title and type of your project, your instruction, the current plan and the list of your Sources are used to carry out web searches through Google's "Grounding with Google Search" service. This service is operated globally; its processing cannot be restricted to the European Union. Google retains the related logs for a maximum of three days.
7.3 Search in your Library. Passages of your Sources and your search queries are processed by Mistral AI in the European Union to compute the embeddings described in section 6.4.
7.4 No training. Under the contractual terms applicable to our use, none of these providers may use your data to train or improve its models.
7.5 No automated decision-making. The Service does not make any decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR). AI Output is a proposal; you decide whether to use it.
7.6 Legal basis. Article 6(1)(b) GDPR.
8.1 Your own deletion. You can delete individual Sources from your Library at any time; the file, its text, its passages and its embeddings are deleted immediately. You can delete your entire Account at any time in the account settings or by email to contact@morphica.de. Deletion of the Account immediately and permanently deletes your Account, all projects, conversations, citation maps, Sources, usage records, subscription records and discount-code records, and your customer record at Stripe.
8.2 Inactive Accounts. If an Account has had no active Subscription and no sign-in for twenty-four (24) months, we notify you by email and delete the Account and all associated data sixty (60) days after that notification, unless you sign in beforehand.
8.3 Statutory retention. Invoices and other accounting records are retained for the periods required by commercial and tax law (currently up to eight years for accounting vouchers and up to ten years for books and records, § 147 AO, § 257 HGB), and are deleted thereafter. During this period they are restricted to the purpose of statutory retention.
8.4 Backups and logs. Data deleted from our live systems is removed from our authentication provider's backups within 180 days. Technical logs contain no document text or Source content and are deleted after 30 days.
The add-in stores the sign-in session in the storage of the browser component embedded in Microsoft Word. This storage is strictly necessary to provide the Service you have requested (§ 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). The add-in does not use analytics, advertising or tracking technologies.
10.1 We use the following service providers. Where they act as processors (Article 28 GDPR), they process your data only on our instructions and on the basis of a data processing agreement.
| Recipient | Function | Role | Location of processing |
|---|---|---|---|
| Google Cloud EMEA Limited, Dublin, Ireland | Hosting, database and file storage (Cloud Run, Cloud Functions, Firestore, Cloud Storage) | Processor | European Union (Belgium) |
| Google Cloud EMEA Limited, Dublin, Ireland | AI generation (Vertex AI, Gemini) | Processor | European Union |
| Google Cloud EMEA Limited, Dublin, Ireland | Web research for chapter plans (Grounding with Google Search) | Processor | Worldwide, including the United States |
| Google Cloud EMEA Limited, Dublin, Ireland | Authentication (Firebase Authentication) | Processor | United States |
| Mistral AI SAS, Paris, France | Embeddings for Library search | Processor | European Union |
| Stripe Payments Europe, Ltd., Dublin, Ireland | Payment processing and subscription billing | Processor; independent controller for fraud prevention and regulatory obligations | European Union and United States |
| Resend, Inc., San Francisco, USA | Sending account emails | Processor | European Union (Ireland); access from the United States possible |
| Microsoft Ireland Operations Limited, Dublin, Ireland | Sign-in with Microsoft | Independent controller | According to Microsoft's privacy statement |
| Google Ireland Limited, Dublin, Ireland | Sign-in with Google | Independent controller | According to Google's privacy policy |
10.2 Microsoft provides Microsoft Word and Microsoft AppSource under its own privacy statement. We receive no data about you from Microsoft, other than what the add-in reads from your open document when you use it.
10.3 We disclose personal data to public authorities only where we are legally obliged to do so.
Where personal data is processed in the United States (section 10), the transfer is based on the adequacy decision of the European Commission for the EU-U.S. Data Privacy Framework (Article 45 GDPR), under which the recipients concerned are certified, and in addition on the Standard Contractual Clauses of the European Commission (Article 46(2)(c) GDPR). You can obtain a copy of these safeguards from us on request.
We protect your data with appropriate technical and organisational measures (Article 32 GDPR), including encryption in transit (TLS) and at rest, access restricted per user Account, separate service identities with minimal permissions for each system component, multi-factor authentication for administrative access, and hosting in the European Union wherever the service concerned permits.
The Service is intended for persons aged 16 and over. We do not knowingly process personal data of persons under 16. Persons under 18 require the consent of their legal guardian to conclude a Subscription.
14.1 You have the right:
14.2 To exercise these rights, contact us at contact@morphica.de, preferably from the email address of your Account. We respond within one month (Article 12(3) GDPR). Many of these rights can be exercised directly in the add-in: you can view, edit and delete your projects and Sources, and delete your Account.
14.3 You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work (Article 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.
Your right to object, Article 21 GDPR
Where we process your personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation (Article 21(1) GDPR). We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You can send your objection to contact@morphica.de.
We update this Privacy Notice when the Service or the legal requirements change. The current version is always available at thesisdraft.com/legal/word-privacy/. We inform you by email in advance of any material change.