Legal
Privacy Policy
What data we collect, why we need it, who processes it, and how to export or delete your history.
Last updated
1.What we collect
We collect the minimum needed to run the Service, and we would rather not hold anything we do not need.
- Account data: your email address, an optional display name, and your plan defaults (tone, market, channel).
- Content you create: product details you paste in, the copy generated from them, compliance scores and flags, brand profiles, and bulk CSV jobs.
- Billing data: plan, status, expiry date, gateway name, the gateway’s own payment id, and the amount. We never see or store your card number — that stays with the payment provider.
- Operational data: rate-limit counters keyed to a hashed identifier, error logs, and aggregate usage counts. Contact-form submissions store your name, email, message and a one-way hash of your IP address for abuse prevention — never the raw IP.
2.How we use it
To provide the Service: generating copy, running compliance scans, keeping your history, enforcing plan limits, processing payments and sending transactional email (receipts, renewal reminders, bulk-export links, password resets).
To keep the Service working and safe: rate limiting, abuse prevention, debugging and capacity planning.
To improve the rule set, using aggregated and de-identified statistics — for example, how often a given rule fires across all accounts. This never involves reading or publishing your copy.
We do not sell your data, we do not share it with advertisers, and we do not use the content of your generations to train third-party AI models.
3.Third-party processors
We use a small set of infrastructure providers to run CopyForge AI. Each receives only the data needed for its specific function:
- Supabase: database hosting, authentication, file storage, hosted in the EU / US regions. Customer data is protected by Row Level Security.
- Upstash: Redis-compatible caching and durable rate-limiting queue in US/EU regions.
- AI inference providers: third-party models used to generate copy from your input. Text is transmitted over TLS and processed under zero-data-retention and zero-training API agreements. Provider names are available on request for enterprise customers.
- Resend: transactional email delivery.
- Payment processors: checkout and subscription billing. Card details are handled by the processor and never touch our servers.
4.Retention and your rights
You can export your complete generation history and account data at any time from Dashboard > Settings > Export Data.
You can delete your account at any time from Dashboard > Settings. Deletion is immediate and irreversible: all generations, brand profiles, and profile records are deleted from our primary database.
Backups are retained for 30 days for disaster recovery purposes and then permanently purged.
5.Contacting us
For any privacy inquiries, data subject requests, or security disclosures, use the contact form on our About page and mark your message "Privacy request". We respond within 30 days.
Questions about this document? Contact us and we will answer in plain language.