Skip to content
Candlewords
Condolence messages enfrde

Privacy Policy

Last updated: 2026-10-04

This policy explains what personal data we process when you visit candlewords.com, use our writer, buy a text or contact us, and what rights you have. It covers the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR, and ends with a short section for US residents.

The short version

  • You don't need an account. We only ask for what we need to write your text and handle your order.
  • We use your answers to write your text. To generate it, we send them through Cloudflare to Anthropic, the company behind the AI model Claude. Anthropic does not use them to train its models, and we never publish your texts.
  • Payment is handled by Stripe. We never see your full card number.
  • We don't show you personalized ads and don't use remarketing. In the EU, the EEA, the UK and Switzerland, we only measure our ads with Google if you allow it.
  • We do not sell your personal information.
  • Unpaid drafts are deleted after 30 days. Paid orders are deleted 60 days after purchase, when your order link stops working, or straight away if you get a refund, except for the records that tax and commercial law require us to keep.

1. Who is responsible

The controller responsible for your data is:

[company.legalName], [company.street], [company.city], [company.country], email: [company.email]

For privacy questions and requests, write to hello@candlewords.com.

We have not appointed a data protection officer, as we are not legally required to do so.

2. When you visit our website

Our website runs on Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Cloudflare delivers our pages through its network (CDN), runs our application (Workers) and our database (D1), and protects the site against attacks.

To do this, Cloudflare processes your IP address, information about your browser and device, and request logs, such as which page was requested and when. Cloudflare keeps these logs only briefly, for a few days.

We do not store your IP address in our database. To prevent misuse, such as too many requests in one day, we store only a salted, shortened hash of it: a one-way code from which your IP address cannot simply be read back. We use it to count requests per day and delete it after 2 days. We also store your country, as determined by Cloudflare.

Legal basis: our legitimate interest in running a secure and stable website (Art. 6(1)(f) GDPR).

3. Bot protection (Cloudflare Turnstile)

Our writer form is protected by Cloudflare Turnstile, which helps us tell humans from bots. Turnstile checks signals from your browser and device, and your IP address.

Legal basis: our legitimate interest in protecting our service from automated misuse (Art. 6(1)(f) GDPR). Where rules on accessing information on your device apply, such as § 25 TDDDG in Germany, this is allowed without consent because it is strictly necessary to provide the service you request.

4. When you use our writer

What we process

  • Your answers to the questionnaire. These may include names (for example of the person who died, the person you are writing to or your own first name), relationships, memories and any other details you choose to share.
  • The options you select, such as tone or format.
  • The texts we generate for you, your edits and your rewrite instructions.

How it works

We store your answers with your draft in our database. To write your text, we send your answers to the AI model Claude by Anthropic, PBC (USA). The request goes through AI Gateway, a service of Cloudflare, Inc. (USA), which passes it on to Anthropic. Cloudflare processes the request for us as our processor and uses Anthropic as its subprocessor. We have switched off the storage of request contents in AI Gateway. Under its commercial terms, Anthropic does not use data it receives through its API to train its models. The same applies to every rewrite you ask for.

Your answers are about other people: the person who died, the person you are writing to and their family. Please only enter what you want to appear in your text.

Sensitive information

If you choose religious wording, or mention health details such as an illness, this may reveal special categories of personal data under Article 9 GDPR. We use this information only to write the text you ask for. The legal basis is your explicit consent, which you give by entering the information (Art. 9(2)(a) GDPR). These fields are optional. You can withdraw your consent at any time by asking us to delete this information. Withdrawal does not affect processing that took place before.

Legal basis

Taking steps at your request before entering into a contract, and performing the contract (Art. 6(1)(b) GDPR). Where your answers contain information about other people, we also rely on our and your legitimate interest in writing the text you asked for (Art. 6(1)(f) GDPR).

Some questions are required to write a text; without them we cannot create one. Everything else is optional.

How long we keep it

  • Unpaid drafts are deleted after 30 days.
  • Paid orders: we keep your answers, your texts and your email address for 60 days after purchase, so that you can return to your order page, use your rewrites and print your card. Then your link stops working and we delete them.
  • Refunded orders: when we refund an order, we delete its answers, texts and email address straight away, and the order page closes.

You can ask us to delete your answers and texts earlier.

5. When you buy a text (Stripe)

Payments are processed through Stripe Checkout, a payment page hosted by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and Stripe, Inc., USA).

Stripe collects your payment details, your email address and your billing country or postcode directly. We receive your email address, the amount, the currency, the payment status and Stripe's reference numbers. We never receive your full card number. Stripe also processes data to prevent fraud and to meet its own legal obligations, as an independent controller under its own privacy policy.

With your order, we also record whether and when you agreed to immediate delivery and acknowledged the loss of your right of withdrawal, so that we can confirm this to you and prove it if necessary.

Legal basis: performing the contract (Art. 6(1)(b) GDPR), our legal obligations (Art. 6(1)(c) GDPR) and our legitimate interest in preventing fraud and being able to prove the consents given (Art. 6(1)(f) GDPR).

Refunds

If you ask for a refund on your order page, we have Stripe refund your payment. We then delete the texts, the answers and the email address stored with your order, and keep only the accounting records described in section 7.

Our money-back guarantee is meant for one refund per customer. To check this, we store two codes with each refund: a salted hash of your email address and a salted hash of the identifier that Stripe gives your card or PayPal account (the card's "fingerprint", not your card number). A salted hash is a one-way code: the email address or card cannot be read back from it, but the same address or card always gives the same code. If a new refund request matches an earlier refund, it is not refused automatically: a person checks it and replies to you by email. We delete these codes after 12 months.

Legal basis: performing the contract (Art. 6(1)(b) GDPR) and our legitimate interest in preventing abuse of our voluntary money-back guarantee (Art. 6(1)(f) GDPR).

Withdrawals and refund requests

If you use our online withdrawal form, we store your name, your email address, your order reference, your message and the date and time of receipt, and we send you an acknowledgement of receipt by email. If a person needs to check a refund request, we store your email address and the order with the request so that we can reply to you. We keep withdrawals and refund requests for 3 years after they have been dealt with, as proof in case of a dispute.

Legal basis: our legal obligations (Art. 6(1)(c) GDPR), performing the contract (Art. 6(1)(b) GDPR) and our legitimate interest in being able to prove how we handled a request (Art. 6(1)(f) GDPR).

6. Order emails

After your purchase, we send you an order confirmation with the private link to your order, using Cloudflare's email service. Stripe may also send you a receipt. If you get a refund, we send you a refund confirmation; if a person first needs to check your refund request, we send you an acknowledgement.

Legal basis: performing the contract (Art. 6(1)(b) GDPR).

7. Accounting records

We keep the order number, date, product, amount, currency, the date and amount of any refund, and Stripe's payment and refund references for as long as tax and commercial law requires, which can be up to 10 years. Your email address is not part of these records: we delete it with your order. Stripe keeps its own payment records.

Legal basis: our legal obligations (Art. 6(1)(c) GDPR).

8. Our own statistics, without cookies

To understand how our website is used, we record simple events in our database: writer viewed, writer started, preview shown, checkout started, paid, checkout expired and refunded. Each event is stored with the product, the language, the country and a coarse traffic source (ad, search, direct or other).

Sometimes we test two variants of the writer, for example a longer free preview or a different price. Which variant you see is chosen at random when you start the writer and is stored with your draft and these events. It is not based on your personal data, and the price shown before you pay is always the price you pay.

We do not store IP addresses with these events, we do not use cookies for them and we do not track you across other websites. We keep these events for 14 months.

Legal basis: our legitimate interest in understanding and improving our service (Art. 6(1)(f) GDPR).

9. Measuring our ads (Google Ads)

We use Google Ads conversion measurement to learn which of our ads lead to purchases. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, together with Google LLC, USA.

We do not use remarketing, personalized advertising or audience lists. Ad personalization is always switched off.

Visitors in the EU, the EEA, the UK and Switzerland

A banner asks for your consent first. Only if you click "Allow":

  • Google's tag is loaded. It may store and read identifiers on your device, for example cookies.
  • The ad click ID (gclid) and the campaign parameters (UTM) from the ad link are stored in your browser's local storage for 30 days and saved with your draft and, if you buy, with your order.
  • After your purchase, your order page reports the conversion to Google (order value, currency and order number). We may also upload ad-click conversions from our database to Google (click ID, time and value).

If you click "Decline", none of this happens.

Legal basis: your consent (Art. 6(1)(a) GDPR; for storing and reading information on your device, § 25(1) TDDDG in Germany and the corresponding rules in other countries).

Visitors elsewhere, for example in the US

The measurement described above runs by default. We honor your browser's Global Privacy Control (GPC) signal as an opt-out, and you can switch the measurement off at any time with the "Cookie settings" link at the bottom of every page. Where the GDPR applies, the legal basis is our legitimate interest in measuring the success of our ads (Art. 6(1)(f) GDPR), and you can object at any time.

Your choice

We store your choice in your browser's local storage and ask again after 6 months. We also save it with your draft and order, so that we know whether we may report a purchase to Google. You can change your choice or withdraw your consent at any time with the "Cookie settings" link at the bottom of every page. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

Google may also process this data for its own purposes as an independent controller, for example to provide and secure its advertising services. Google's privacy policy has more information.

10. When you email us

If you write to us, we use your email address and your message to answer you.

Legal basis: performing a contract or taking steps before entering into one, if your message is about an order (Art. 6(1)(b) GDPR); otherwise our legitimate interest in answering your inquiry (Art. 6(1)(f) GDPR). We keep messages as long as we need them to deal with your request. Messages about an order are kept with that order.

11. Who receives your data

Recipient Purpose Location
Cloudflare, Inc. Hosting, content delivery, database, security, bot protection, sending emails, passing requests to the AI model (AI Gateway) USA
Anthropic, PBC (subprocessor of Cloudflare) Writing and rewriting your texts USA
Stripe Payments Europe, Limited and Stripe, Inc. Payment processing, fraud prevention Ireland and USA
Google Ireland Limited and Google LLC Ad conversion measurement, as described in section 9 Ireland and USA

Cloudflare processes data on our behalf and on our instructions (Art. 28 GDPR); to write your texts, it uses Anthropic as a subprocessor. Stripe and Google partly act as independent controllers, as described above. We only disclose data to authorities where we are legally required to do so.

12. Transfers outside the EU and the EEA

Cloudflare, Anthropic, Stripe and Google may process data in the USA and in other countries outside the EU and the EEA. Where a recipient is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the European Commission's adequacy decision for that framework (Art. 45 GDPR). Otherwise, we rely on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR). For data from the UK and Switzerland, the corresponding UK and Swiss safeguards apply. You can ask us for a copy of the safeguards we use.

13. How long we keep your data

Data Kept for
Cloudflare request logs a few days
Hashed IP address for daily limits 2 days
Unpaid drafts 30 days
Answers, texts and email address of paid orders 60 days after purchase
Answers, texts and email address of refunded orders deleted when the refund is made
Hashes of email address and card, for refunds 12 months
Withdrawals and refund requests 3 years after they have been dealt with
Accounting records as long as tax and commercial law requires, up to 10 years
Statistics events 14 months
Ad click ID and campaign parameters in your browser 30 days
Your cookie choice in your browser 6 months, then we ask again
Emails to us as long as needed for your request

14. Your rights

You have the right to:

  • access your data (Art. 15 GDPR);
  • have incorrect data corrected (Art. 16 GDPR);
  • have your data erased (Art. 17 GDPR);
  • restrict processing (Art. 18 GDPR);
  • receive your data in a portable format (Art. 20 GDPR);
  • withdraw your consent at any time, with effect for the future (Art. 7(3) GDPR);
  • lodge a complaint with a supervisory authority (Art. 77 GDPR).

Right to object (Art. 21 GDPR): where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then stop processing it, unless we can show compelling legitimate grounds or need the data to establish, exercise or defend legal claims.

To exercise your rights, email hello@candlewords.com. As there are no accounts, please give us the email address you used at checkout or your order link, so that we can find your data. We may ask for more information to make sure the request comes from you.

You can lodge a complaint with a supervisory authority, in particular in the EU or EEA country where you live or work or where you think the infringement took place. In the UK, this is the Information Commissioner's Office. In Switzerland, it is the Federal Data Protection and Information Commissioner (FDPIC).

15. No automated decisions

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). Our AI writes texts for you; it does not make decisions about you. Refunds on the order page are granted automatically, but a refund is never refused automatically: if a request matches an earlier refund, a person decides.

16. Children

Our service is not intended for children under 16, and we do not knowingly process their data. You must be 18 or older to buy.

17. Security

Connections to our website are encrypted (HTTPS). Your order page can only be reached through a long, random private link. Anyone who has this link can open your order, so please keep it private.

18. Changes to this policy

We may update this policy when our service or the law changes. We publish every change on this page.

19. Information for US residents

  • We do not sell your personal information, and we do not use it for targeted advertising based on your activity across other websites (cross-context behavioral advertising).
  • Global Privacy Control: if your browser sends a GPC signal, we treat it as an opt-out of the ad measurement described in section 9.
  • Sensitive information that you enter, such as religious or health details, is used only to write your text.
  • Your rights: depending on the state where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to delete it and to opt out of certain uses. To make a request, email hello@candlewords.com with the email address you used at checkout or your order link. We will verify your request and respond within the time required by law. An authorized agent can make a request for you if they show us your permission. If we decline your request, you can appeal by replying to our answer. We will not treat you differently for exercising your rights.
Condolence messages Contact
Terms Privacy Refunds Withdraw from contract here Imprint

Texts are written with AI (Claude by Anthropic) from your answers.

© 2026 Candlewords

We use cookies to measure which ads bring visitors who order. Allow them? Privacy