Privacy
Word AI for Microsoft Word — Privacy Policy
What this app collects, why it collects it, and what you can ask us to delete.
Word AI is an independent writing app. This policy explains how information is used when you write locally, choose account and cloud features, request AI assistance, or use a subscription.
Your choices
An active subscription is required to create, open, edit or export documents. Subscribed users can use local documents without a Word AI account. Recent verified access supports bounded offline use; expiry does not delete saved documents. Account management, privacy export and deletion remain available without payment. Local documents stay in the app's storage on your device or browser unless you choose cloud sync, sharing, export, or an AI request that sends text. The device or browser also stores preferences and sign-in/session information used by the app.
Usage and diagnostics is enabled by default. You can turn it off in Settings → Usage and diagnostics → Share usage and diagnostics. Account sign-in, cloud sync, and AI consent are separate from this preference.
Accounts, documents and collaboration
Optional accounts use Firebase Authentication. Firebase processes your email address, password and account identifier to sign you in, verify your email and handle password resets. Authentication also processes technical information such as IP addresses and device/app information to operate the service and prevent abuse. Word AI uses your account identifier and display name, when present, to associate your cloud activity with you.
When you choose cloud sync, Word AI's backend stores the document title, document content and embedded images, editing updates and related document metadata. Collaboration also uses invitations, access roles, comments and presence information. People you give access to can receive the shared document and information needed to collaborate. Exporting or sharing a file sends it to the destination you choose.
AI assistance
An AI request requires a separate consent choice. The request identifies whether your selected text or document text, together with your instructions, will be sent. Drafting sends your instructions. Images, comments and file names are excluded from the AI request. You can decline and continue editing without sending that request.
Consented text goes through Word AI's backend to OpenRouter and the selected model provider. The current implementation requests OpenAI models, with a Google Gemini fallback for certain service failures. The backend requests routes that disallow provider data collection and require zero data retention. Those request settings are not a promise that no service processes operational metadata. OpenRouter's data handling information describes its controls and request metadata.
Word AI records the AI operation, request identifier, account/install association, timing, outcome and allowance usage to provide the feature and limit abuse. Its AI usage records do not store your submitted text or the returned proposal. If you insert a proposal into a document, it becomes part of that document and follows your local, cloud and sharing choices. AI can make mistakes; review its output before using it.
Purchases
Apple or Google processes purchases made through its store. Word AI receives purchase and subscription identifiers, proof of purchase, product and expiry information, and verification results to enable or restore Pro and prevent purchase reuse. Verified access can be associated with your Word AI account. Purchase references used for server verification are encrypted in the app's backend storage.
Deleting your Word AI account does not cancel an Apple or Google subscription. Manage or cancel it separately in the store account used for the purchase.
Usage and crash diagnostics
When Usage and diagnostics is enabled, the mobile app uses Google Analytics for Firebase and Firebase Crashlytics to understand feature use and investigate failures. The web app uses Analytics when its web measurement configuration is available; it does not use the mobile Crashlytics SDK.
Usage events describe fixed actions such as opening, saving or exporting a document, using review controls, opening an offer, or completing an account action. They do not contain document text, titles, file names, AI instructions or proposals, email addresses, purchase proofs, or arbitrary exception messages. Word AI does not set a Firebase Analytics account user ID or custom user properties.
The SDKs also process their automatic technical data, including app-instance or installation identifiers, app interactions, device/application information, approximate location inferred from network information, and crash stack traces and session information. Word AI's custom crash reporting removes the original exception message, but native crash diagnostics can still include device and application state. See Firebase's data disclosures and Firebase privacy information.
Word AI does not show advertisements. Its Analytics configuration denies advertising storage, advertising user data and ad personalization; the app does not request the advertising identifier. Turning diagnostics off stops the app's optional collection. It does not remove information previously received by service providers.
Security and service providers
Protected account requests use account authentication, app-integrity checks, installation identifiers and public keys, and signed request information to prevent impersonation and replay. Network security and usage-limit records may also be processed. These protections remain active when optional diagnostics are off.
Firebase provides authentication, integrity checks and diagnostics. Web integrity checks use reCAPTCHA Enterprise. Word AI's hosting infrastructure serves its app, public pages and backend; network requests expose technical connection information to the services handling them. Apple, Google and OpenRouter process data for the features described above. Their services may process information outside your country. Firebase describes its processing locations and retention practices in its privacy information.
Export and account deletion
You can request account deletion without reinstalling the mobile app: Delete your Word AI account online. Sign in to the account you want to delete and follow the password confirmation and deletion controls.
In the app, open Settings → Manage account. Export account data lets you download an account record and your owned cloud documents before deletion. Delete account asks you to confirm with your password.
Deletion removes your owned cloud documents and their updates/sharing records, your memberships, authored comments, presence, active entitlement records and AI usage records. It also requests deletion of your Firebase sign-in identity. If identity deletion is delayed by a service failure, the app shows that completion is pending and supports retry; it does not report success before confirmation.
Local document copies on your device remain available and are disconnected from the deleted cloud account. Copies that other people already downloaded remain with them. Contributions within documents owned by other people may remain in those documents. Deleting your account does not delete files exported to another app or storage location, cancel store billing, or automatically erase past Analytics or Crashlytics records.
Minimal retired account and installation records, public keys, and purchase-owner/security mappings remain to prevent replay and reuse of a purchase by another account. These retained mappings do not contain document content or email addresses. The app currently has no automatic expiry for these retained security mappings. Provider records follow the relevant provider's retention and deletion processes; there is no single deletion period covering all of these services.
Contact
For questions about Word AI or its data handling, use the developer contact on the app's store listing. The app's support page provides the current contact guidance.