Legal

Privacy Policy

Last updated August 2026

This Privacy Policy explains what data Idiolect AI (“we”, “us”) collects, how we use it, and your choices. We designed Idiolect AI to be privacy‑first: your writing is used to serve you, not to build a public profile of you.

1. What we collect

  • Writing you provide — the samples you give us or approve for use in building your Voice Profile, and the briefs/text you submit to generate or score. Where possible this stays in your browser; when sent to our servers it is used only to provide the Service.
  • Your Voice Profile — the structured, abstract description of how you write (tone, rhythm, recurring positions), derived from your samples.
  • Account & payment context — your email and internal account ID when you sign in, buy a prepaid credit pack, use a legacy subscription, join a waitlist, or contact us.
  • Usage & technical data — basic, privacy‑preserving analytics and rate‑limit signals (e.g., approximate request counts), to keep the Service running.
  • Connector diagnostics — for authenticated MCP calls, we retain content‑free technical metadata by default, such as tool name, outcome, byte counts, and latency. If an incident requires body‑level diagnostics, an explicit temporary debug setting may retain credential‑redacted request and response bodies for approximately 24 hours. Authentication headers and bearer credentials are not stored. This covers the connector transport itself, not the writing you send through it; that is covered by Quality evaluation below.
  • Quality evaluation — we keep a pseudonymized copy of your writing and the profiles derived from it — wherever you write from, including the web app, the API, and connected AI assistants — for up to 12 months, to measure how well our output matches your voice. Identifiers are removed and we don’t try to re‑identify you. Some of it is reviewed by our team. You can opt out in Settings.

2. How we use it

  • To build your Voice Profile and generate text in your voice.
  • To compute the Voice Match metric.
  • To provide, secure, and improve the Service, and to prevent abuse.
  • To process one-time credit purchases and legacy subscriptions, maintain an auditable balance and purchase history, and send transactional receipts or access emails.
  • To measure and improve output quality, separately from model training. You can turn this off.

We do not sell your personal data. We do not use your private writing to train public models. Our evaluation copy is pseudonymized, not anonymous.

3. Who we share it with

We use trusted third‑party processors strictly to operate the Service:

  • AI model providers (e.g., OpenAI) — to generate and analyze text.
  • Model hosting (e.g., Modal) — to run the voice‑fidelity scorer.
  • Database & hosting (e.g., Supabase, Vercel) — to run the app and store data.
  • Payments (Dodo Payments, acting as merchant of record) — to process prepaid packs and legacy subscriptions. We store provider transaction identifiers and payment amounts for reconciliation, but do not receive or store your full card details.
  • Email (e.g., Resend) — to send transactional email.
  • Analytics (Google Analytics) — to measure aggregate traffic, referral sources and search terms. It receives page and event data and a pseudonymous identifier, never your writing samples or Voice Profile.

4. International data transfers

To provide the Service, your writing samples and account data are processed by sub‑processors located in the United States: OpenAI (text generation), Modal (the voice‑fidelity scorer), Vercel (hosting), and Supabase (database/auth). Separately, the analytics data described above — page and event data with a pseudonymous identifier, and no writing samples or Voice Profile — is transferred to Google in the United States. The legal basis for these transfers is the performance of our contract with you and our legitimate interest in providing the Service.

5. Data retention & your rights

Raw writing samples and voice profiles are retained while your account is active and for a reasonable period after, and are purged on account deletion or on request. Payment and credit-ledger records may be retained as required for tax, fraud prevention, refunds, and financial reconciliation. MCP diagnostic metadata uses a short retention window. When temporary body‑level diagnostics are explicitly enabled for an incident, those bodies are scheduled to expire after approximately 24 hours and are also removed through the account content-deletion flow. The pseudonymized evaluation copy described in section 1 — which covers writing from every surface, including connected AI assistants — is held separately, for up to 12 months, and is then deleted. Turning off quality evaluation in Settings stops future copies and removes the entries we already hold. You can request access to, an export of (data portability), or deletion of your data at any time by emailing hello@idiolect.app. We maintain reasonable technical safeguards to protect your information, though no system is perfectly secure.

6. Cookies & analytics

We use minimal, privacy‑preserving analytics to understand aggregate usage. Our own analytics are first‑party and cookie‑free, identified by a random value stored in your browser. We also use Google Analytics, which sets its own cookie to count returning visits; we do not enable its advertising or cross‑device features. We avoid placing personal or sensitive data in URLs.

7. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their data.

8. Changes & contact

We may update this policy; the “last updated” date reflects changes. Questions or requests: hello@idiolect.app.

Questions about these terms? Email hello@idiolect.app.

Privacy Policy - Idiolect AI | Idiolect AI