← Back to Homepage

Legal

Privacy Notice for ThesisDraft for Word

Version 1.0 · Effective 23 September 2026

This Privacy Notice explains how personal data is processed when you use ThesisDraft for Word, the add-in for Microsoft Word published under the name "ThesisDraft", and the services connected to it (the "Service"). It fulfils the information obligations under Articles 13 and 14 of the General Data Protection Regulation ("GDPR"). The analysis tools and the Academic Rewrite offered on thesisdraft.com are covered by a separate privacy policy at thesisdraft.com/legal/privacy/. Data processed in the Service is never combined with data processed by those tools.

1. Controller

The controller within the meaning of Article 4(7) GDPR is:

Morphica Technologies
Sole proprietor: Dino Dervisevic
Rathenaustraße 132, 80937 Munich, Germany
Email: contact@morphica.de
Telephone: +49 157 58540174

The controller is not required to appoint a data protection officer (Article 37 GDPR, § 38 of the German Federal Data Protection Act, BDSG). Data protection enquiries may be sent to the address above.

2. Summary

DataPurposeLegal basisRetention
Account dataProviding the AccountArt. 6(1)(b) GDPRUntil the Account is deleted
Sign-in security dataSecuring the AccountArt. 6(1)(f) GDPRA few weeks
Subscription dataContract and billingArt. 6(1)(b) GDPRUntil the Account is deleted
Accounting recordsStatutory retentionArt. 6(1)(c) GDPRStatutory period (section 8.3)
Projects, conversations, citation mapProviding the ServiceArt. 6(1)(b) GDPRUntil deleted by you
Library (Sources)Providing the ServiceArt. 6(1)(b) GDPRUntil deleted by you
Document textProcessing your instructionArt. 6(1)(b) GDPRNot stored
Usage dataUsage Allowance, abuse preventionArt. 6(1)(b) and (f) GDPRUntil the Account is deleted
Support communicationsAnswering your enquiryArt. 6(1)(b) and (f) GDPRThree years
Technical logsOperation and securityArt. 6(1)(f) GDPR30 days

3. Principles

3.1 Data minimisation. We do not ask for your name, institution, supervisor, student identification number or date of birth. None is needed for any function of the Service.

3.2 No document storage. Your Word document remains on your own systems. It is never uploaded or stored by us as a file.

3.3 No secondary use. Your data is used only to provide the Service to you. It is not used for advertising or profiling, is not sold, is not shared with other users, and is not used by us or by any of our service providers to train artificial intelligence models.

3.4 Separation. Data in the Service is kept separate from data processed by the analysis tools on thesisdraft.com, and the two are never linked.

4. Account and Authentication

4.1 Data processed. To create and maintain your Account we process your email address, your chosen sign-in method, a hash of your password if you sign in with email and password, the language setting of the add-in, and the date the Account was created.

4.2 Sign-in with Microsoft or Google. If you choose to sign in with an existing Microsoft or Google account, that provider confirms your identity to us and transmits your email address. We do not request or store your name or profile picture. Microsoft and Google act as independent controllers for the sign-in process; their privacy statements apply. If you sign in with an account issued by your university, the email address may indicate your institution.

4.3 Security. When you sign in, our authentication provider processes your IP address and browser information in order to protect your Account against unauthorised access and abuse.

4.4 Account emails. We send you the emails required to operate your Account, in particular to confirm your email address and to reset your password.

4.5 Legal basis. Article 6(1)(b) GDPR for 4.1, 4.2 and 4.4; Article 6(1)(f) GDPR for 4.3, our legitimate interest being the security of the Service and of your Account.

5. Subscription and Payment

5.1 Data processed. We process your Plan, the status of your Subscription, the end of the current billing period, any cancellation, and the reference numbers that our payment service provider assigns to you as a customer and to your Subscription. If you use a creator's discount code, we record which code was used, in order to apply the discount and to pay the creator a commission. The creator receives no information that identifies you.

5.2 Payment. Payments are processed by Stripe (section 10). We do not receive or store your payment card or bank details.

5.3 Legal basis. Article 6(1)(b) GDPR; for accounting records, Article 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB).

6. Use of the Service

6.1 Projects. For each project we store the title, the type of work, its language, target length and citation style, the chapter plan, and the text of any writing guidelines you provide. Guideline files themselves are not retained after their text has been extracted.

6.2 Conversations. We store the messages exchanged in the task pane for each project, so that you can continue your work across sessions and devices. The most recent 120 messages per project are retained; older messages are deleted automatically.

6.3 Citation map. We store which sentence of your document is based on which passage of which Source. This allows the task pane to show you the relevant Source when you select a sentence. The citation map is stored on our systems only. No link or reference to the Service is inserted into the text of your document.

6.4 Library. We store the Sources you upload or add, the text extracted from them divided into passages, and a numerical representation of each passage (embedding) that enables searching by meaning. The original file name is not stored. Your Library is accessible only through your Account.

6.5 Document text. When you give an instruction in the task pane, the add-in reads the text of your open document and transmits to us up to approximately 24,000 characters of it, together with its headings and the beginning of each paragraph, so that the instruction can be carried out in the right place and in context. This text is processed only to carry out your instruction and is not stored, save for the resulting content recorded in the conversation (6.2) and the citation map (6.3).

6.6 Project identifier in the document file. In order to reopen the correct project whenever you open your document, the add-in stores a randomly generated project identifier in the settings area of your .docx file. Microsoft Word also records in this area that the add-in has been used with the file. The identifier does not contain any personal data and cannot be used by anyone other than you, signed in to your Account, to access your data. It is not visible in the text of the document. It can be removed by exporting the document as PDF, or with Word's "Inspect Document" function (File → Info → Check for Issues → Inspect Document → Task Pane Add-ins).

6.7 Literature search. When you ask the Service to propose publications, we derive search terms from your project's topic and send them to OpenAlex, a public index of scholarly literature operated by OurResearch (United States). No part of your document and no information identifying you is transmitted. Open-access publications are then retrieved by our servers directly from the publishers or repositories concerned.

6.8 Legal basis. Article 6(1)(b) GDPR. The processing described in this section is necessary to provide the Service you have contracted.

7. Artificial Intelligence

7.1 Generation. Your instructions, the parts of your document required for the instruction, relevant passages from your Library and your chapter plan are processed by the Gemini models of Google Vertex AI to generate AI Output. This processing takes place within the European Union.

7.2 Web research for chapter plans. When you request a chapter plan, the title and type of your project, your instruction, the current plan and the list of your Sources are used to carry out web searches through Google's "Grounding with Google Search" service. This service is operated globally; its processing cannot be restricted to the European Union. Google retains the related logs for a maximum of three days.

7.3 Search in your Library. Passages of your Sources and your search queries are processed by Mistral AI in the European Union to compute the embeddings described in section 6.4.

7.4 No training. Under the contractual terms applicable to our use, none of these providers may use your data to train or improve its models.

7.5 No automated decision-making. The Service does not make any decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR). AI Output is a proposal; you decide whether to use it.

7.6 Legal basis. Article 6(1)(b) GDPR.

8. Retention and Deletion

8.1 Your own deletion. You can delete individual Sources from your Library at any time; the file, its text, its passages and its embeddings are deleted immediately. You can delete your entire Account at any time in the account settings or by email to contact@morphica.de. Deletion of the Account immediately and permanently deletes your Account, all projects, conversations, citation maps, Sources, usage records, subscription records and discount-code records, and your customer record at Stripe.

8.2 Inactive Accounts. If an Account has had no active Subscription and no sign-in for twenty-four (24) months, we notify you by email and delete the Account and all associated data sixty (60) days after that notification, unless you sign in beforehand.

8.3 Statutory retention. Invoices and other accounting records are retained for the periods required by commercial and tax law (currently up to eight years for accounting vouchers and up to ten years for books and records, § 147 AO, § 257 HGB), and are deleted thereafter. During this period they are restricted to the purpose of statutory retention.

8.4 Backups and logs. Data deleted from our live systems is removed from our authentication provider's backups within 180 days. Technical logs contain no document text or Source content and are deleted after 30 days.

9. Storage on Your Device

The add-in stores the sign-in session in the storage of the browser component embedded in Microsoft Word. This storage is strictly necessary to provide the Service you have requested (§ 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). The add-in does not use analytics, advertising or tracking technologies.

10. Recipients

10.1 We use the following service providers. Where they act as processors (Article 28 GDPR), they process your data only on our instructions and on the basis of a data processing agreement.

RecipientFunctionRoleLocation of processing
Google Cloud EMEA Limited, Dublin, IrelandHosting, database and file storage (Cloud Run, Cloud Functions, Firestore, Cloud Storage)ProcessorEuropean Union (Belgium)
Google Cloud EMEA Limited, Dublin, IrelandAI generation (Vertex AI, Gemini)ProcessorEuropean Union
Google Cloud EMEA Limited, Dublin, IrelandWeb research for chapter plans (Grounding with Google Search)ProcessorWorldwide, including the United States
Google Cloud EMEA Limited, Dublin, IrelandAuthentication (Firebase Authentication)ProcessorUnited States
Mistral AI SAS, Paris, FranceEmbeddings for Library searchProcessorEuropean Union
Stripe Payments Europe, Ltd., Dublin, IrelandPayment processing and subscription billingProcessor; independent controller for fraud prevention and regulatory obligationsEuropean Union and United States
Resend, Inc., San Francisco, USASending account emailsProcessorEuropean Union (Ireland); access from the United States possible
Microsoft Ireland Operations Limited, Dublin, IrelandSign-in with MicrosoftIndependent controllerAccording to Microsoft's privacy statement
Google Ireland Limited, Dublin, IrelandSign-in with GoogleIndependent controllerAccording to Google's privacy policy

10.2 Microsoft provides Microsoft Word and Microsoft AppSource under its own privacy statement. We receive no data about you from Microsoft, other than what the add-in reads from your open document when you use it.

10.3 We disclose personal data to public authorities only where we are legally obliged to do so.

11. Transfers to Third Countries

Where personal data is processed in the United States (section 10), the transfer is based on the adequacy decision of the European Commission for the EU-U.S. Data Privacy Framework (Article 45 GDPR), under which the recipients concerned are certified, and in addition on the Standard Contractual Clauses of the European Commission (Article 46(2)(c) GDPR). You can obtain a copy of these safeguards from us on request.

12. Security

We protect your data with appropriate technical and organisational measures (Article 32 GDPR), including encryption in transit (TLS) and at rest, access restricted per user Account, separate service identities with minimal permissions for each system component, multi-factor authentication for administrative access, and hosting in the European Union wherever the service concerned permits.

13. Age

The Service is intended for persons aged 16 and over. We do not knowingly process personal data of persons under 16. Persons under 18 require the consent of their legal guardian to conclude a Subscription.

14. Your Rights

14.1 You have the right:

  • to obtain access to your personal data (Article 15 GDPR);
  • to have inaccurate data rectified (Article 16 GDPR);
  • to have your data erased (Article 17 GDPR);
  • to have processing restricted (Article 18 GDPR);
  • to receive your data in a structured, commonly used and machine-readable format and to transmit it to another controller (Article 20 GDPR);
  • to object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR, see section 15).

14.2 To exercise these rights, contact us at contact@morphica.de, preferably from the email address of your Account. We respond within one month (Article 12(3) GDPR). Many of these rights can be exercised directly in the add-in: you can view, edit and delete your projects and Sources, and delete your Account.

14.3 You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work (Article 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

15. Right to Object

Your right to object, Article 21 GDPR

Where we process your personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation (Article 21(1) GDPR). We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You can send your objection to contact@morphica.de.

16. Changes

We update this Privacy Notice when the Service or the legal requirements change. The current version is always available at thesisdraft.com/legal/word-privacy/. We inform you by email in advance of any material change.