Strunk  ·  revise your Google Docs from your AI tool, comments intact

Privacy Policy

Last updated: September 6, 2026

Strunk helps people publish drafts from their AI tool to Google Docs, bring reviewer comments back into that AI tool, and apply approved revisions to the same Google Doc.

Who we are

First Crack Studio Ltd operates Strunk. It is a company registered in Scotland (company number SC900936), with its registered office at 5 South Charlotte Street, Edinburgh EH2 4AN, United Kingdom, and it is the data controller for the information described in this policy. You can reach us at support@strunk.io.

Information we process

Strunk processes the information needed to provide the review workflow:

  • Account and authentication information, including your Strunk account identifier.
  • Google connection status after you connect Google Docs. WorkOS custodies your Google refresh tokens.
  • Document mapping data needed to update the right Google Doc, including user id, hashed local document key, Google document id, and version.
  • Document content, titles, URLs, and comment text only while handling your publish, pull, reply, resolve, or revision request.
  • Product usage information covering the pages you visit and the actions you take in Strunk. Once you sign in, this carries your account identifier, your email address, and your name.
  • Subscription and payment information when you subscribe, handled by Stripe. Strunk never sees your card details.

What we do not store

Strunk does not store Google Doc bodies, document titles, document URLs, or reviewer comment text. Google Docs remains the source of truth for the published document and review comments.

How we use information

We use information only to provide and maintain Strunk, including to:

  • Create or update Google Docs you ask Strunk to publish.
  • Read reviewer comments from Google Docs you use with Strunk.
  • Apply revisions, replies, and resolves that you approve.
  • Authenticate requests and protect the service from abuse.
  • Debug, secure, and improve the service.

Lawful basis for processing

UK data protection law asks us to have a lawful basis for each use of your information. Ours are:

  • Performing our contract with you, covering everything Strunk does when you use it: signing you in, publishing and revising your documents, keeping the mapping that finds the right doc again, and taking payment when you subscribe.
  • Our legitimate interests, covering the usage information and error reports described below, keeping the service secure and stopping abuse, and emailing you about getting started. Our interest is in running and improving a working product. We weigh that against your privacy, keep what we collect narrow, and put an unsubscribe link in every email we send.
  • Complying with a legal obligation, covering the billing records tax law requires us to keep.

You need an email address to have a Strunk account, because we sign you in with it. Where we rely on legitimate interests you can object, and where we ask for your consent you can withdraw it. Your rights below say how.

Analytics and error reports

Strunk records how people use the product, so we can see which parts they reach and where they run into trouble. That covers the pages you visit, the actions you take in Strunk, browser errors, and performance timings. Once you sign in, we attach your account identifier, your email address, and your name to that activity.

Strunk keeps this narrow on purpose. We record no video of your screen, we log no keystrokes, we run no advertising or cross-site tracking, and we sell this data to nobody.

Cookies and local storage

We ask before setting anything Strunk does not need to run. Until you answer, the only cookies here are the ones sign-in cannot work without:

  • wos-session keeps you signed in, and wos-auth-verifier cookies protect the sign-in exchange itself. Sign-in stops working without them, so they are always on.
  • strunk-cookie-consent remembers your answer, so we stop asking. It holds that one word and nothing else.
  • ph_…_posthog comes from PostHog and marks your browser, so the usage information above joins into a session rather than a pile of unrelated hits. PostHog keeps a copy in local storage too. This is the one we ask about, and it waits for a yes.

Decline and we still record the usage described above, but nothing goes to your device, so one visit no longer joins to the last. Change your mind whenever you like: Cookie settings at the foot of any page reopens the choice and clears whatever the old answer left behind.

We set no advertising cookies and nothing that follows you to other sites.

Google user data

Strunk uses Google's limited drive.file permission so it can work with Google Docs it creates or files you explicitly open with Strunk. Strunk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing

We share information with the providers we need to run Strunk, and we name them here:

  • WorkOS for sign-in, and for custody of the Google refresh token that Strunk itself never holds.
  • Google for the Docs and Drive requests you ask Strunk to make.
  • PostHog for the usage events and error reports described above, on their EU cloud.
  • Stripe for subscription payments and invoices.
  • Supabase for the database holding your account and document mapping rows, in the eu-west-1 region.
  • Vercel for running the application and keeping its request logs.

We do not sell your data. Beyond the providers above, we share information with Google when you ask Strunk to work with Google Docs, when the law requires it, or with your consent.

Where your information goes

First Crack Studio Ltd is based in the United Kingdom. Your account and document mapping rows sit in the eu-west-1 region, and our analytics provider holds its data on its EU cloud. Several of the providers named above operate from the United States, so some of your information reaches them there.

For information that leaves the UK we rely on the safeguards UK law provides: the UK Addendum to the European Commission's standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework where a provider holds that certification. Email us if you want the detail for a particular provider.

Security

Strunk uses HTTPS in transit. WorkOS custodies your Google refresh tokens, so Strunk's database never holds them. We keep stored document metadata minimal by storing hashed local document keys rather than document bodies, titles, URLs, or comment text.

Data retention

We keep account and document-mapping data for as long as your Strunk account is active. Deleting your account removes every one of those rows, removes your sign-in identity at WorkOS, ends Strunk's access to your Google account, and cancels any live subscription. Strunk handles Google Doc bodies, titles, URLs, and reviewer comment text only in memory while it serves your request, and never writes them to our database, so there is nothing of that kind to retain.

Two things outlive a deletion, and we would rather tell you here than let you discover it. Stripe keeps your customer record and your invoices, because tax law requires us to retain accounting records. Our analytics provider keeps a record of your past activity. Write to support@strunk.io if you want us to go further than that.

Your choices

You can revoke Strunk's Google access from your Google account settings. To request deletion of Strunk account data, email us at support@strunk.io.

Your rights

UK data protection law gives you rights over the information First Crack Studio Ltd holds about you. You can ask us to:

  • Give you a copy of your personal data, and explain how we use it.
  • Correct anything wrong. Your name and email address come from the account you sign in with, so correcting them there updates them here at your next sign-in.
  • Delete your account and the data we hold about you. You can do this yourself from your account page. Data retention above sets out what a deletion removes and what outlives it.
  • Stop or limit how we use your data, including the usage events described above.
  • Send you your data in a portable form, or pass it to another provider where that is technically possible.

Email support@strunk.io to exercise any of these. We answer within one month and we charge nothing for it.

Two limits are worth stating plainly. Tax law requires us to keep invoices, so a deletion leaves your Stripe billing records in place. And Strunk makes no automated decisions about you that carry legal effects.

If you think we have handled your data badly, tell us first and we will try to put it right. You can also complain to the Information Commissioner's Office, the UK supervisory authority.

Changes

We may update this policy as Strunk changes. If we materially change how we use Google user data, we will update this policy and request any required consent before using that data in a new way.