Privacy Policy
1. What we collect, and why
| Data | When | Why (legal basis) |
|---|---|---|
| Email address | Account creation and sign-in; waitlist signup | Sign-in codes, account identity and important service emails - performance of contract. Occasional product news about TypoZap for account holders, which you can opt out of at any time via the unsubscribe link or by emailing us - consent. Waitlist addresses receive a single launch announcement and nothing else - consent |
| Random device identifier (generated by the app, not derived from your hardware) | Guest trial, sign-in, device limits | Guest quota and limiting an account to a small number of active devices (currently 5) - performance of contract; abuse prevention - legitimate interest |
| App version of your TypoZap installation | Sign-in and when your app renews its session | Stored on the device record so we can tell which builds are still in use - knowing whether an update actually reached people, and supporting you against the build you are actually running - legitimate interest. No other device or hardware details are collected |
| IP address | Every request to our services, as with any internet service | Short-lived rate-limit counters, abuse and fraud prevention, and standard infrastructure logs of our hosting provider - legitimate interest |
| Usage counters: number of edits, processed-volume (token) totals, preset key, model, error rates | Guest, Free and Pro relay use | Quotas and providing your plan - performance of contract; cost control and service health - legitimate interest. Counters only - never text content, and custom preset names or instructions are never sent to us. |
| Subscription status: plan, paid-until date, Stripe customer reference | Purchases | Providing what you paid for - performance of contract. When you purchase, we pass your account email and an internal account reference to Stripe so the purchase can be linked to your account; card numbers and billing addresses are handled entirely by Stripe and we never see or store them. Billing and tax records are retained to comply with tax and accounting law - legal obligation |
| Waitlist signup details: language, signup page, referring page, browser user-agent string, country, time | Waitlist signup on our website | Spam and bot filtering, understanding where signups come from - legitimate interest |
| Support emails you send us | When you contact us | To answer you - legitimate interest |
You are never legally required to give us personal data. An email address is needed to create an account; without one you can still use the guest trial and BYOK mode.
2. Your text content - exactly what happens
- Relay modes (guest trial, Free, Pro): the selected text travels over an encrypted connection to our relay, is forwarded to the AI provider, and the result is returned to you. The text is processed transiently in memory and is not stored, not logged, and not used to train anything. Only counters (edit counts, token totals) are recorded. No account identifiers, email or IP address are attached to the text we forward to AI providers.
- You control what text you select. We do not ask for and do not want sensitive data; whatever you choose to process is handled transiently as described above and never stored.
- BYOK mode: the app sends your text directly to the AI provider you configured, using your key. It never passes through our servers. The provider's own privacy terms apply - note that some free API tiers (for example Google's free AI Studio tier) allow the provider to use submitted content for training; paid API tiers generally do not.
- "Write like me" style profile (optional, off by default): your writing samples are analyzed to build a short style card. The samples and the card are stored locally on your device (you can delete them in the app at any time). When the feature is on, the style card - not your samples - is attached to relay requests transiently, like the text itself.
- Conversation context (optional, on by default): to keep consecutive edits consistent, the app can remember the corrections you already made in the same window and any excerpt you explicitly marked as context. This context lives only in the app's memory, for up to 30 minutes, and is never written to disk. When the feature is on and you are signed in, it is attached to relay requests transiently, exactly like the text itself: processed in memory, not stored and not logged. Guest requests never carry context. You can switch this memory off, or clear it instantly, in Settings → Privacy.
- The in-app journal of recent edits holds the last 10 edits in memory only, disappears when the app closes, and is never sent anywhere.
- BYOK API keys are stored in your operating system's secure vault (macOS Keychain / Windows credential storage) and are never sent to us.
The permission the app asks for
On macOS, TypoZap asks for one system permission: Accessibility (System Settings → Privacy & Security → Accessibility). macOS grants no other way to do the two things the app exists for:
- read the text you selected - the app asks the system for the element you are focused on and reads only its selected-text value, at the moment you press the hotkey;
- paste the corrected text back - this is a synthetic copy/paste keystroke, which macOS only allows from apps holding this permission.
The app does not read your screen, does not watch what you type, and does not look at windows you did not act on. It reads a selection when you press the hotkey, and only then. On Windows no comparable permission exists or is requested - the app uses the standard accessibility interface that is available to any application.
Because the permission sounds broader than what we use it for, here is the flip side: we do not request Input Monitoring (keystroke logging), Screen Recording, Full Disk Access, camera or microphone. If macOS ever prompts you for one of those on our behalf, something is wrong - please tell us at [email protected].
3. AI providers
In relay modes we currently use Google (Gemini) as the primary AI provider, with Anthropic (Claude) as an automatic fallback. We use paid, business API tiers under terms that do not permit the provider to use your content for training their models. In BYOK mode you choose the provider (Google, OpenAI or Anthropic) and your own agreement with them applies.
Providers keep what we send them for a limited time in order to police their own policies: Google retains prompts, context and responses for 55 days to detect and prevent violations of its Prohibited Use Policy, and content flagged by its systems may be reviewed by authorised Google staff. This retention is for abuse prevention only, not for model training. We do not control it, and it applies to the text of the request itself - so, as anywhere else, do not send secrets you would not want a third party to see.
4. What we don't do
- No advertising, no ad trackers, no sale or sharing of personal data for advertising.
- No analytics, behavioural tracking or crash reporting inside the desktop app: nothing about how you use it is collected. The app reports its version number, listed in Section 1.
- No profiling and no automated decisions with legal or similarly significant effects.
- No keystroke logging, no screen reading, no watching of apps you are not editing in - the permissions that would allow it are not requested (see Section 2). We do not train AI models on your content, and in relay modes we use paid API tiers whose terms prohibit our AI providers from training on it.
5. Service providers
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, relay infrastructure, bot protection (Turnstile), cookie-less website analytics | Global edge network; US company |
| Stripe, Inc. | Payments, subscriptions, tax calculation, billing portal | US, with global affiliates |
| Resend (Plus Five Five, Inc.) | Transactional email - sign-in codes, service notices | US |
| Google LLC (Gemini API) | AI text processing in relay modes (paid tier, no training on your content) | US/global |
| Anthropic, PBC (Claude API) | AI text processing - automatic fallback in relay modes (no training on your content) | US |
Stripe acts as an independent controller for payment processing and fraud prevention under its own privacy policy; the other providers act as our processors under data-processing agreements and only for the purposes above. In BYOK mode, the AI provider you use with your own key acts as your direct provider, not as our processor.
We may also disclose personal data where required by law or valid legal process, to protect our rights or users' safety, and to a successor in a merger, acquisition or sale of assets (with notice as described in Section 13).
6. Our websites
- The waitlist form is protected by Cloudflare Turnstile (a CAPTCHA alternative), which checks your browser and IP to filter bots. We also verify that the email domain exists (only the domain, never the full address, is looked up via an encrypted DNS query).
- Website statistics use Cloudflare Web Analytics, which is cookie-less: it stores nothing on your device and sets no identifiers; we see only aggregate statistics (page views, referrers, countries, browser types).
- Our pages currently load fonts from Google Fonts; when your browser fetches them, Google receives your IP address and browser details, as with any web resource.
- Short-lived rate-limit counters keyed by IP address protect the waitlist and our services from abuse; they expire automatically within about an hour.
- See the Cookie Notice for the full picture - our own pages set no cookies.
7. How long we keep data
| Data | Retention |
|---|---|
| Text content | Not stored - processed transiently only |
| Sign-in codes | Valid for 10 minutes and unusable afterwards; deleted on use or replaced by the next code |
| Rate-limit counters (email-, IP- or account-keyed) | Minutes to ~26 hours, expire automatically |
| Quota and fair-use counters (account-keyed) | Up to ~40 days, expire automatically |
| Guest-trial edit counter (random device identifier + count) | Retained indefinitely to prevent repeated free trials on the same device |
| Hosting-provider infrastructure logs | Retained by Cloudflare for short periods under its data-processing terms; we do not extend them |
| Aggregate service statistics (no identifiers) | Hours to days |
| Account data (email, devices, plan) | While your account exists; removed within 30 days of a deletion request |
| Billing records | As long as tax and accounting law requires (kept by Stripe and in our accounting) |
| Waitlist entries | Until launch communication is done or you ask to be removed, whichever is earlier |
| Support correspondence | As long as needed to handle the matter and reasonable follow-ups |
8. Where data is processed; international transfers
We are a US company and our service providers process data primarily in the United States, on infrastructure with a global edge network (Cloudflare). If you use the Service from the EEA, UK or Switzerland, your personal data is transferred to the US. We rely on safeguards recognized under GDPR: our providers participate in the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF) and/or enter into the EU Standard Contractual Clauses (with the UK Addendum where applicable). You can obtain a copy or summary of these safeguards by emailing [email protected].
We are in the process of appointing an EU representative under Art. 27 GDPR and a UK representative; this policy will be updated with their contact details before we begin selling in the EU/UK.
9. Security
All connections use TLS encryption. Sign-in uses short-lived one-time codes instead of passwords; session tokens are short-lived, and long-lived credentials are stored only as cryptographic hashes on our side and in your operating system's secure vault on your device. Access to production systems is restricted. No method of transmission or storage is 100% secure, but we design the Service so that the most sensitive thing - your text - is simply not retained at all.
10. Your rights (EEA, UK and similar laws)
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, to withdraw consent, and to lodge a complaint with your data-protection authority (for example, the ICO in the UK). To exercise any of these - or to delete your account - email [email protected] from your account address. We respond within one month; if a request is complex we may extend by up to two further months and will tell you why.
Deleting your account removes your account records (email, devices, plan) within 30 days of your request; residual technical counters (quotas, rate limits) expire automatically within about 40 days, and records we must keep for legal or tax reasons (e.g. invoices held by Stripe) are retained as the law requires.
11. California and other US state privacy rights
- In the last 12 months we have collected the categories described in Section 1: identifiers (email, random device identifier, IP address), commercial information (subscription status), internet or other electronic network activity (usage counters, app version, waitlist signup details), and coarse geolocation (country only, derived from IP for spam filtering). We disclosed these categories only to the service providers listed in Section 5, for the business purposes described there; we disclosed nothing to third parties for sale or cross-context advertising.
- The data we retain contains no sensitive personal information, biometric data or precise geolocation. Transient one-time sign-in codes are used only to authenticate you. Text you choose to process may contain anything, but it is processed transiently and not retained.
- We do not sell and do not share personal information for cross-context behavioral advertising, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age (we sell or share no personal information at all). Because there is nothing to opt out of, Global Privacy Control signals require no action, and we honor them by default.
- You have the right to know and access (including in a portable format), correct and delete your personal information, and the right not to be discriminated against for exercising these rights. Use [email protected]; an authorized agent may act for you with proof of authorization. We do not require account verification beyond confirming control of the account email.
- Residents of other US states with privacy laws (Virginia, Colorado, Connecticut, Utah and others) have equivalent rights, exercised the same way. If we decline a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General.
12. Children
TypoZap is not directed at anyone under 18, and we do not knowingly collect their data. The Service relies on third-party AI providers whose terms require users to be 18 or older, so our Terms set the same minimum. If you believe someone under 18 has provided us personal data, contact us and we will delete it.
13. Changes
If we materially change this policy, we will notify you by email or in-app before the change takes effect. The current version always lives at this address.
14. Contact
AdReed, LLC · 131 Continental Dr, Suite 305, Newark, DE 19713, USA · [email protected]