Is Ownhand safe to use, and what does it store?
Ownhand is a reasonable choice for everyday work writing if you are comfortable with a cloud service holding your samples and drafts: it cannot send or post anything on its own, it stores your account, your Hand and your request history, it never stores the thread you reply to or your card number, and it does not sell your data or train its own models on it. The one trade-off is that feedback and style-card updates go to a learning model whose provider may use them to improve its models, so if no text may leave your control, keep to your chat app's own instructions or a local model.
For a tool like this, safe means three different things. What can it do inside your agent? What does it keep, and who else sees it? How do you get your data out? This page answers each question from the Privacy Policy, the Terms, and the code. Then it compares the answers with the built-in options in ChatGPT and Claude.
What it can do inside your agent
Ownhand is a remote MCP server. Your agent can call six tools. Each one only reads or changes your own Ownhand account.
| Tool | What it does |
|---|---|
write | Returns a draft in your voice. Nothing is sent. |
send_feedback | Records what you did with a draft so your Hand learns. |
get_hand | Lists your Hands, or shows one's style card and rules. |
create_hand | Makes a new Hand from texts you wrote. |
update_hand | Adds samples, or pins, rejects or activates a rule. |
get_account | Shows your balance and account. |
None of these tools reach outside Ownhand. They can't read your inbox, post to Slack, open a pull request, or touch your files. Each tool tells your client it stays inside its own service. update_hand is marked as one that can change data, so a client can ask you before it runs.
Every MCP server has the same risk: text a tool returns goes into your agent's context. Anthropic's help center says to connect only to trusted servers. A malicious one can hide instructions that try to make Claude do things you didn't ask for. OpenAI warns about prompt injection in ChatGPT's developer mode too. OWASP puts it first in its top 10 risks for model apps. Ownhand returns only a rewrite of your own draft. Its code is public, so you can read exactly what each tool returns.
Model output can also be wrong. The Terms say a draft can drop or change a fact. Ownhand checks every rewrite for the names, numbers, dates, links and email addresses in your draft. It tells your agent about any it couldn't keep. Read each draft before you send it.
What it stores
| Data | What exactly |
|---|---|
| Account | Email address and name from sign-in, credit balance, auto-reload settings, Stripe customer ID |
| API keys | A hash of each key and its first few characters, never the full key |
| Your Hands | Your samples, the style card, learned rules and past versions |
| Requests | The draft, the text returned, any alternate versions, the occasion and the model used |
| Feedback | Your verdict, your reason if you gave one, and the text you sent if your agent reports it |
| Usage | Token counts and the charge for each model call, and a ledger of grants, reloads and charges |
| Connected apps | The sign-in grant and its tokens for each MCP client you connect |
Two things are never stored. Thread messages, which your agent passes so a reply matches the conversation, are used for that one request and then dropped. Card details go to Stripe. Stripe is certified to PCI Service Provider Level 1. Ownhand never sees your card number.
Who processes your text
Six companies process data for Ownhand. Each gets only what its job needs. Cloudflare runs the hosting, database, queues and system logs. Clerk handles sign-in. Stripe takes payments. Resend sends account emails. Hemmingway runs the writing model and gets your draft, your Hand and any thread context for each request. The learning model, Muse Spark, runs through OpenRouter.
That last one is the trade-off. Learning runs on the provider's contributor tier. Under those terms, the provider may use what it receives to improve its models. It gets your feedback, the original draft, the rewrite, the text you sent, and your reason. When your style card is rebuilt, it also gets your recent samples, recent approved drafts, the current card, your rules, and simple stats about your writing.
Drafts you only rewrite, with no feedback, go to the writing model and never to Muse Spark. If you don't want your text used that way, the Privacy Policy's advice is to skip feedback and not add samples to a Hand. You lose most of the learning described in how the learning loop works. You keep the rewrite. Each feedback report costs about half a cent, so skipping it also saves a little.
Ownhand doesn't sell your data, share it for advertising, or train its own models on it. Learning only changes your Hand. One person's writing never shapes another person's Hand.
How the built-in options compare
Putting a style prompt in ChatGPT or Claude means your text is stored by a company you already use. Their default training settings differ, so check yours.
| Where your text goes | Used to train models? | How to turn it off | |
|---|---|---|---|
| ChatGPT Free, Plus, Pro | OpenAI | On by default | Settings, Data Controls, Improve the model for everyone |
| ChatGPT Business, Enterprise, Edu | OpenAI | Off by default | Nothing to do |
| Claude Free, Pro, Max | Anthropic | Your choice. Kept 5 years if you allow it, 30 days if not | Privacy Settings |
| Claude for Work and the API | Anthropic | Not covered by the consumer training choice | Nothing to do |
| Ownhand | Ownhand, its writing model, and its learning model for feedback | Ownhand does not train. The learning model's provider may use feedback inputs | Do not send feedback |
Using Ownhand inside ChatGPT or Claude doesn't take you out of their policy. Your draft and the rewrite pass through that chat, so its own setting still applies. If you only need a few lines about tone, custom instructions may be enough, and they add no new company to the list.
Sign-in, keys and money
- You connect by signing in through your browser. There is no key to paste into a config file.
- If you use an API key for scripts, only its hash is stored. Revoke any key in the dashboard and anything using it stops at once.
- All traffic uses HTTPS, and access to production data is limited to the people who run the service.
- Credit is prepaid, with no subscription. When it runs out, new calls stop. A call already running can dip your balance slightly below zero, and the next reload covers it.
- Auto-reload is off unless you turn it on.
- Each account can make 60 requests a minute and hold 20 Hands and 20 API keys.
Getting your data out
Delete a Hand in the dashboard and it's gone right away, with its past versions. Requests and feedback made with it stay in your history until you delete your account. Email hi@thalientlabs.ai to get a copy of your data, correct it, or delete your account. Account data is deleted within 30 days. Backups and provider logs can hold copies for up to 30 days more, and Stripe keeps payment records as tax law requires.
Before you connect any writing server
- Read its privacy policy for three things: what it stores, which models see your text, and whether any of them train on it.
- Look at its tools. A writing tool should return text and nothing else.
- Keep approval on for any tool that changes data, and do not choose Allow always for it.
- Leave secrets out of drafts.
- Check that you can delete your account and get a copy of your data.
If you build or review servers yourself, the MCP specification has a security guide. It covers session hijacking, token passthrough and other attacks to ask about. The Terms set one more rule: use Ownhand to write as yourself. Building a Hand from someone else's writing without their permission, sending spam, or handing in generated work where it is forbidden all break them. The service isn't for anyone under 16. To see how it fits next to other ways of connecting a voice tool, read MCP servers for writing in your voice.
Follow-up questions
Can Ownhand send an email or post to Slack by itself?
No. Its tools only return text to your agent. It has no access to your inbox, your chat apps, or your code host. Whatever gets sent, your agent or you send it. The agent instructions say to wait for your OK first.
Does Ownhand train AI on my writing?
It doesn't train its own models on your data. It doesn't sell or share it for advertising. The learning step runs on Muse Spark through OpenRouter, on the provider's contributor tier. That provider may use what it receives to improve its models. Drafts you only rewrite, without feedback, don't go to it.
Is the conversation I am replying to stored?
No. Your agent can pass recent messages from the thread so the reply matches it. They're used for that one request and not saved. The draft and the text returned are stored as part of your request history.
How do I delete everything?
Delete a Hand in the dashboard and it's gone right away, past versions included. To delete your whole account, email the address on the privacy page. Your data is deleted within 30 days. Backups and provider logs can hold copies for up to 30 days more.
Can I use it for confidential work text?
Check your employer's rules on outside AI services first. Your drafts are stored with your request history and processed by the providers listed on the privacy page. Don't put passwords, keys, or personal data in drafts. Treat it like any hosted model.
Sources
Checked on 2 October 2026. If something here is out of date, email hi@thalientlabs.ai and we will fix it.
- Ownhand Privacy Policy: what is stored, what is not, providers, retention and deletion
- Ownhand Terms of Service: acceptable use, billing, no warranty
- Ownhand source code: the MCP tools and what each one can do
- Claude Help Center: custom connectors using remote MCP: only connect to trusted servers; review tool calls; avoid Allow always for sensitive connectors
- OpenAI: ChatGPT developer mode: prompt injection and write-action risks with MCP
- OpenAI Help: Data controls FAQ: Improve the model for everyone is on by default for Free, Plus and Pro
- Anthropic: Updates to consumer terms and privacy policy: training choice for Free, Pro and Max; 5 years or 30 days retention
- OpenRouter Docs: provider logging: each provider has its own data policy
- OWASP: LLM01 Prompt injection: direct and indirect prompt injection
- Model Context Protocol: security best practices: attacks on MCP servers and clients, and their defenses
- Stripe Docs: Security at Stripe: PCI Service Provider Level 1