← TypoZap

Privacy Policy

Last updated: September 8, 2026 · AdReed, LLC, a Delaware limited liability company ("we", "us") - the data controller for TypoZap. This policy is written in English; the English version is the only binding version.
The short version: we do not store or log the content of your texts on our servers - the relay is built so text is processed transiently in memory and discarded - and we do not use your texts to train AI models. That applies to every relay mode (guest trial, Free and Pro): no chat logs, no text history. In bring-your-own-key (BYOK) mode your text does not touch our servers at all: it goes straight from your computer to the AI provider using your own key. The app contains no analytics, no behavioural tracking and no crash reporting: we do not collect which features you use, when or how often. It does report its own version number when it signs in, so we can tell which builds are still in use; everything we receive is listed in Section 1.

1. What we collect, and why

DataWhenWhy (legal basis)
Email addressAccount creation and sign-in; waitlist signupSign-in codes, account identity and important service emails - performance of contract. Occasional product news about TypoZap for account holders, which you can opt out of at any time via the unsubscribe link or by emailing us - consent. Waitlist addresses receive a single launch announcement and nothing else - consent
Random device identifier (generated by the app, not derived from your hardware)Guest trial, sign-in, device limitsGuest quota and limiting an account to a small number of active devices (currently 5) - performance of contract; abuse prevention - legitimate interest
App version of your TypoZap installationSign-in and when your app renews its sessionStored on the device record so we can tell which builds are still in use - knowing whether an update actually reached people, and supporting you against the build you are actually running - legitimate interest. No other device or hardware details are collected
IP addressEvery request to our services, as with any internet serviceShort-lived rate-limit counters, abuse and fraud prevention, and standard infrastructure logs of our hosting provider - legitimate interest
Usage counters: number of edits, processed-volume (token) totals, preset key, model, error ratesGuest, Free and Pro relay useQuotas and providing your plan - performance of contract; cost control and service health - legitimate interest. Counters only - never text content, and custom preset names or instructions are never sent to us.
Subscription status: plan, paid-until date, Stripe customer referencePurchasesProviding what you paid for - performance of contract. When you purchase, we pass your account email and an internal account reference to Stripe so the purchase can be linked to your account; card numbers and billing addresses are handled entirely by Stripe and we never see or store them. Billing and tax records are retained to comply with tax and accounting law - legal obligation
Waitlist signup details: language, signup page, referring page, browser user-agent string, country, timeWaitlist signup on our websiteSpam and bot filtering, understanding where signups come from - legitimate interest
Support emails you send usWhen you contact usTo answer you - legitimate interest

You are never legally required to give us personal data. An email address is needed to create an account; without one you can still use the guest trial and BYOK mode.

2. Your text content - exactly what happens

The permission the app asks for

On macOS, TypoZap asks for one system permission: Accessibility (System Settings → Privacy & Security → Accessibility). macOS grants no other way to do the two things the app exists for:

The app does not read your screen, does not watch what you type, and does not look at windows you did not act on. It reads a selection when you press the hotkey, and only then. On Windows no comparable permission exists or is requested - the app uses the standard accessibility interface that is available to any application.

Because the permission sounds broader than what we use it for, here is the flip side: we do not request Input Monitoring (keystroke logging), Screen Recording, Full Disk Access, camera or microphone. If macOS ever prompts you for one of those on our behalf, something is wrong - please tell us at [email protected].

3. AI providers

In relay modes we currently use Google (Gemini) as the primary AI provider, with Anthropic (Claude) as an automatic fallback. We use paid, business API tiers under terms that do not permit the provider to use your content for training their models. In BYOK mode you choose the provider (Google, OpenAI or Anthropic) and your own agreement with them applies.

Providers keep what we send them for a limited time in order to police their own policies: Google retains prompts, context and responses for 55 days to detect and prevent violations of its Prohibited Use Policy, and content flagged by its systems may be reviewed by authorised Google staff. This retention is for abuse prevention only, not for model training. We do not control it, and it applies to the text of the request itself - so, as anywhere else, do not send secrets you would not want a third party to see.

4. What we don't do

5. Service providers

ProviderPurposeLocation
Cloudflare, Inc.Hosting, relay infrastructure, bot protection (Turnstile), cookie-less website analyticsGlobal edge network; US company
Stripe, Inc.Payments, subscriptions, tax calculation, billing portalUS, with global affiliates
Resend (Plus Five Five, Inc.)Transactional email - sign-in codes, service noticesUS
Google LLC (Gemini API)AI text processing in relay modes (paid tier, no training on your content)US/global
Anthropic, PBC (Claude API)AI text processing - automatic fallback in relay modes (no training on your content)US

Stripe acts as an independent controller for payment processing and fraud prevention under its own privacy policy; the other providers act as our processors under data-processing agreements and only for the purposes above. In BYOK mode, the AI provider you use with your own key acts as your direct provider, not as our processor.

We may also disclose personal data where required by law or valid legal process, to protect our rights or users' safety, and to a successor in a merger, acquisition or sale of assets (with notice as described in Section 13).

6. Our websites

7. How long we keep data

DataRetention
Text contentNot stored - processed transiently only
Sign-in codesValid for 10 minutes and unusable afterwards; deleted on use or replaced by the next code
Rate-limit counters (email-, IP- or account-keyed)Minutes to ~26 hours, expire automatically
Quota and fair-use counters (account-keyed)Up to ~40 days, expire automatically
Guest-trial edit counter (random device identifier + count)Retained indefinitely to prevent repeated free trials on the same device
Hosting-provider infrastructure logsRetained by Cloudflare for short periods under its data-processing terms; we do not extend them
Aggregate service statistics (no identifiers)Hours to days
Account data (email, devices, plan)While your account exists; removed within 30 days of a deletion request
Billing recordsAs long as tax and accounting law requires (kept by Stripe and in our accounting)
Waitlist entriesUntil launch communication is done or you ask to be removed, whichever is earlier
Support correspondenceAs long as needed to handle the matter and reasonable follow-ups

8. Where data is processed; international transfers

We are a US company and our service providers process data primarily in the United States, on infrastructure with a global edge network (Cloudflare). If you use the Service from the EEA, UK or Switzerland, your personal data is transferred to the US. We rely on safeguards recognized under GDPR: our providers participate in the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF) and/or enter into the EU Standard Contractual Clauses (with the UK Addendum where applicable). You can obtain a copy or summary of these safeguards by emailing [email protected].

We are in the process of appointing an EU representative under Art. 27 GDPR and a UK representative; this policy will be updated with their contact details before we begin selling in the EU/UK.

9. Security

All connections use TLS encryption. Sign-in uses short-lived one-time codes instead of passwords; session tokens are short-lived, and long-lived credentials are stored only as cryptographic hashes on our side and in your operating system's secure vault on your device. Access to production systems is restricted. No method of transmission or storage is 100% secure, but we design the Service so that the most sensitive thing - your text - is simply not retained at all.

10. Your rights (EEA, UK and similar laws)

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, to withdraw consent, and to lodge a complaint with your data-protection authority (for example, the ICO in the UK). To exercise any of these - or to delete your account - email [email protected] from your account address. We respond within one month; if a request is complex we may extend by up to two further months and will tell you why.

Deleting your account removes your account records (email, devices, plan) within 30 days of your request; residual technical counters (quotas, rate limits) expire automatically within about 40 days, and records we must keep for legal or tax reasons (e.g. invoices held by Stripe) are retained as the law requires.

11. California and other US state privacy rights

12. Children

TypoZap is not directed at anyone under 18, and we do not knowingly collect their data. The Service relies on third-party AI providers whose terms require users to be 18 or older, so our Terms set the same minimum. If you believe someone under 18 has provided us personal data, contact us and we will delete it.

13. Changes

If we materially change this policy, we will notify you by email or in-app before the change takes effect. The current version always lives at this address.

14. Contact

AdReed, LLC · 131 Continental Dr, Suite 305, Newark, DE 19713, USA · [email protected]