Privacy Policy
Effective 3 September 2026.
BlinkWrite reads what is on your screen. That is an unusual thing to let a piece of software do, and this policy exists to tell you exactly what happens as a result — what leaves your Mac, what does not, what we keep, and for how long.
The short version
| What BlinkWrite reads | The text in the window you are actively working in, so it can suggest what to write. |
| What leaves your Mac | Text, after an on-device process has tried to strip out contact details, account and ID numbers, and credentials. It does not remove people's names — see Section 2.3. Screen images never leave your Mac. |
| Where it goes | To our own servers in the United States, running our own AI models. Not to OpenAI, Anthropic, Google, or any other AI provider. |
| How long we keep it | We don't. The text is held in memory for the second or two it takes to generate your suggestion, and is then gone. It is not written to disk and not written to a log. |
| Do we train on it | No. Not your text, not the suggestions we generate for you. |
| Do we sell it | No. We do not sell or share personal information, and we run no advertising. |
| Can you turn it off | Yes, at any time, without asking us — see Section 5. |
This summary is here to be useful, not to replace the rest. The detail below is what governs.
1. Who we are
BlinkWrite is provided by TalentHQ Labs, Inc., a Delaware corporation with its principal place of business at 2261 Market Street, STE 85253, San Francisco, CA 94114, United States ("BlinkWrite", "we", "us", "our").
For the purposes of the EU and UK General Data Protection Regulation, we are the controller of the personal data described in this policy.
Privacy contact: [email protected]
This policy covers the BlinkWrite application for macOS, our website at blinkwrite.ai, and our support correspondence. It forms part of our Terms of Service.
2. What BlinkWrite reads from your screen
This is the section that matters. Please read it.
2.1 The two permissions, and what each one allows
BlinkWrite needs two macOS permissions to work. You grant them yourself in macOS System Settings. We cannot enable them for you and macOS will not let us.
Accessibility. Lets BlinkWrite read the text content of the application window you are actively working in, through the same macOS interface that screen readers and other assistive software use. This is how BlinkWrite reads most chat threads and email, and how it inserts a suggestion when you accept one.
Screen Recording. Some applications do not make their text available through the accessibility interface. This permission lets BlinkWrite read the text in those applications by capturing the screen image and extracting the text from it on your Mac.
2.2 What we do with them, and what we do not
macOS grants these permissions at the system level. What BlinkWrite actually does is narrower than what they technically allow:
- BlinkWrite reads the window you are actively working in. It does not read background windows, other desktops, or other users' sessions.
- BlinkWrite does not record video, take continuous screenshots, or keep any recording of your screen. A screen capture is taken only at the moment a suggestion is being generated, is used only to extract text, and is discarded immediately.
- BlinkWrite does not log your keystrokes outside the text field you are working in.
- BlinkWrite does not type or send anything on its own. It proposes text; you accept it and you send it.
2.3 On-device masking — what it does and what it does not
Before anything is transmitted, BlinkWrite runs a process on your Mac that attempts to detect and mask certain kinds of personal information, so they are not sent to us. This is what it looks for, and it is the complete list:
- Contact details — email addresses, phone numbers, postal addresses
- Financial details — card numbers, bank account numbers, dollar amounts
- Government and identity numbers — social security numbers, passport numbers, driver licence numbers, tax identification numbers, dates of birth
- Credentials and technical identifiers — passwords, PINs, API keys, access tokens, secret keys, IP addresses
It does not detect or remove people's names. That is a real limitation and we would rather state it than let the list above imply otherwise. What happens to names is covered in the next two paragraphs and in Section 3.
Your own name is handled separately. Where your name appears in the text, it
is replaced with a neutral [USER] marker before the text is sent, so the model
can tell your messages from everyone else's. We do also send your display name
alongside the text, as a separate field, so that a suggestion can address you or
sign off in your name. So your name reaches us — just not buried in the middle of
the text.
Other people's names are not masked. In a chat thread or an email, the names of the other participants are sent to us along with what they wrote, because that is how the model tells one speaker from another. Anything else our list covers — their email address, their phone number, their address — is masked in the normal way.
This is automated and best-effort. It is not perfect, even for the categories it does cover. It uses a machine learning model that can miss things, particularly in unusual formats, in mixed-language text, or in contexts it was not designed for. We do not promise that all personal or sensitive information is detected or masked.
For that reason, we treat everything we receive as personal data and apply this policy to it. We do not claim the text reaching our servers is anonymous, because we cannot prove it is.
And for the same reason: do not use BlinkWrite in text fields containing information you cannot afford to have transmitted to us — health records, payment card data, government identification numbers, legally privileged material, classified information, or trade secrets. You can pause BlinkWrite for one application or one website, pause it everywhere, or withdraw the permissions entirely, at any time — see Section 5.
2.4 What we transmit, and to where
Masked text is sent over an encrypted connection to our servers in the United States, where our own AI models generate a suggestion and return it to your Mac.
We run these models on infrastructure we control. Your text is not sent to OpenAI, Anthropic, Google, or any other third-party AI provider, and never has been.
Screen images are not transmitted. Where BlinkWrite uses Screen Recording, the text is extracted from the image on your Mac and only the masked text is sent. The image itself never leaves your device.
2.5 What happens to it afterwards — nothing
Text you send for a suggestion, and the suggestion we generate, are not stored.
They are held in server memory only for as long as it takes to produce your suggestion — normally under a second. They are not written to disk. They are not written to a log file. They are not put in any database. There is no record of what you were writing, and no way for us to retrieve what you wrote yesterday, because it was never kept.
Our inference servers keep a short-lived working cache in memory so that repeated requests are faster. It holds no readable text, it is overwritten as new requests arrive, and it never reaches disk.
This has a consequence worth stating plainly: if you ask us for a copy of the message text we hold about you, the answer is that we hold none. We can give you your account data, your subscription record, your usage counts, and the record of which terms you accepted. There is nothing else to give.
2.6 We do not train on your content
We do not use your text, or the suggestions we generate for you, to train, fine-tune, evaluate, or otherwise improve our AI models. Not with your name attached, not with it removed, not in aggregate.
We do keep counts of how the product is used — how many suggestions were requested and how many were accepted. Those are numbers, not text, and they are covered in Section 8.
3. Other people's information
BlinkWrite reads conversations, and conversations have other people in them. When you use BlinkWrite in a Slack thread or an email chain, the text on your screen includes messages written by people who have not agreed to anything and do not know BlinkWrite is running.
Here is what happens to that content:
- It goes through the same on-device masking as everything else, so their email addresses, phone numbers, postal addresses and account numbers are masked exactly as yours are.
- Their names are not, and are sent to us. In a thread, the name against each message is what tells the model who said what, so it travels with the message. We would rather say this plainly than let the paragraph above imply otherwise. It is not retained, for the same reason nothing else is.
- What survives masking is transmitted, used to generate your suggestion, and not retained, on the same terms as your own text.
- It is not used for training, not sold, and not disclosed to anyone.
We are the controller for that content while we process it, and we process it on the instruction of the BlinkWrite user whose screen it is on. Under our Terms of Service §6.1, that user is responsible for having the rights and permissions needed to run BlinkWrite over content involving other people — including any duty of confidentiality they owe, and any consent rule that applies to recording or monitoring communications where they live.
If your information reached us because someone else used BlinkWrite, and you want to exercise a right over it, contact [email protected]. We will help — but be aware that because nothing is retained (Section 2.5), there is in practice nothing for us to locate, correct, or delete. That is the strongest protection we can offer you, and it is structural rather than a promise about our conduct.
4. The personal data we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Your email address, your first and last name, your sign-in method, and whether you have ever started a free trial. For Apple or Google sign-in, this includes the provider account identifier. For email sign-in, this includes a salted one-way password hash. We never store your plaintext password. | You, when you create an account or sign in — see Section 4.1 |
| Message text | Masked text from the window you are working in, sent to generate a suggestion, plus the suggestion returned | Your Mac, at the moment you ask for a suggestion. Not retained — see Section 2.5. |
| Subscription data | Your plan, price, billing period, renewal date, trial and cancellation status, and a Stripe customer reference | Stripe, as your subscription changes. We never see or hold your card number — see Section 4.2 |
| Usage counts | Per day, per suggestion type: how many suggestions were requested, how many you accepted, and how many tokens were used. These are numbers. They contain none of your text. | Our servers, when the app asks for a suggestion — see Section 8 |
| Session records | For each active session: a token record, the IP address and app or browser user agent it was created from, and when it was last used. This is how sign-out, session expiry, and account security work. | Automatically, when you sign in |
| Technical and security data | Timestamps, request volumes, response codes, error codes. Aggregate server metrics that are not tied to an account. No message content. | Automatically, when the app talks to our servers |
| Consent records | Which version of the Terms, of this policy, and of our Consumer Health Data Privacy Policy you accepted, when, and where you accepted it, with a fingerprint of the exact text | You, on the consent screen shown the first time you sign in, and at any later re-acceptance |
| Support data | Your email address and whatever you tell us | You, when you contact us |
Your BlinkWrite settings — your paused apps and sites, and your preferences — are held on your Mac. They are not sent to us and we cannot see them.
4.1 Signing in
You can sign in with your email address and password, Sign in with Apple, or Google.
For email sign-in, we store a salted one-way password hash. We never store your plaintext password. We also store one-way hashes of email-verification and password-reset tokens. Verification links expire after 24 hours. Password-reset links expire after one hour and stop working after use.
For Apple or Google sign-in, the provider confirms who you are. It gives us an account identifier and your email address. We do not receive your contacts, your calendar, or your mail. Apple and Google control the records that they keep about the sign-in under their own privacy policies.
If you use Apple's Hide My Email, we receive a relay address rather than your real one. That works normally, and we will only ever have the relay address. Turning the relay off in your Apple ID settings stops our emails reaching you, including receipts and renewal notices.
4.2 What Stripe holds, and we do not
Payments run through Stripe, which acts as merchant of record — it is the seller for the purchase, and it calculates and collects any tax due. Your name, billing address, country, card details, and invoice history sit with Stripe, under its own privacy policy. We receive back only what is listed as subscription data above: the plan, the status, the dates, and a customer reference.
We never receive your card number, and we could not produce it if you asked.
5. Turning it off
You do not need our permission or our help to stop BlinkWrite reading anything.
| To do this | Do this |
|---|---|
| Stop it reading a specific app or website | Pause BlinkWrite for that app or site in settings — for an hour, for the day, or until you turn it back on |
| Stop it everywhere, for a while | Pause BlinkWrite globally, or quit it |
| Stop it reading apps that don't expose text | Withdraw Screen Recording in macOS System Settings. Everything else keeps working. |
| Stop it entirely | Withdraw Accessibility in macOS System Settings. BlinkWrite can then neither read through the accessibility interface nor insert suggestions, so the product stops working. |
| Close your account | Close it in settings on the web, or email [email protected] - see Section 11.1. To remove the app from your Mac at the same time, uninstall it and tick Also delete my BlinkWrite account. |
| Remove it from your Mac | Settings › General → Uninstall BlinkWrite. Removes the app, the on-device model, your settings, and your sign-in — see Section 11.2 |
6. Why we process your data, and on what legal basis
The right-hand column applies if you are in the EEA, the United Kingdom, or Switzerland. It is the basis we rely on under Article 6 of the GDPR.
| What we do | Why | Legal basis |
|---|---|---|
| Generate suggestions from the text on your screen | It is the product | Performance of a contract (Art. 6(1)(b)) |
| Run your account and your sign-in sessions | To provide what you signed up for | Performance of a contract |
| Take payment, run the trial, handle renewals and cancellations | To bill you | Performance of a contract; legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Count how many suggestions you request and accept | To enforce the limits of your plan, which is part of what you bought, and to know which features earn their place | Performance of a contract for the limits; legitimate interests (Art. 6(1)(f)) for the rest |
| Keep the service secure; detect and investigate abuse, fraud, and duplicate trials | To protect the service and other users | Legitimate interests — running a service that is not defrauded or abused |
| Keep a record of which terms you accepted | To be able to show what was agreed | Legal obligation and legitimate interests |
| Diagnose and fix faults | To keep the product working | Legitimate interests |
| Establish, exercise, or defend legal claims; comply with lawful requests | To handle disputes and legal obligations | Legitimate interests and legal obligation |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. Ask us at [email protected] and we will explain the assessment for any given purpose.
We do not process your data for advertising, for profiling for advertising, or for any form of behavioural targeting. We do not run ads and we do not sell data.
7. Cookies and the website
Our website is separate from the app. Nothing in this section touches what BlinkWrite reads from your screen.
We use Google Analytics 4 on blinkwrite.ai, to count visits and see which pages people read. It is the only third-party tag on the site. We use it to decide what to write and what to fix, and for nothing else.
We run no advertising tag and set no advertising cookie. Google Signals and ad personalisation are switched off in our configuration, so what Google Analytics collects for us cannot be used to build advertising audiences — ours or anyone else's.
7.1 If you are in the EEA, the UK, or Switzerland
Nothing loads until you accept. The Google Analytics script is not requested, not downloaded, and stores nothing on your device until you have chosen. You are asked on your first visit, and until you answer, Google is not told you are here.
Refusing takes one click, exactly as accepting does, and the two are given the same prominence. If you refuse, the script is never loaded at all.
7.2 If you are somewhere else
Google Analytics runs unless you turn it off. You can turn it off at any time from the "Cookie settings" link at the foot of any page, and turning it off deletes the cookies below.
That link is there wherever you are, so a choice you have already made can always be changed.
7.3 What is stored on your device
| Name | What it is | How long |
|---|---|---|
_ga | Google Analytics — tells one browser apart from another | 400 days |
_ga_YW6ZRMG9BX | Google Analytics — keeps session state for our property | 400 days |
bw.cookie-consent.v1 | Your choice about the above. Held in browser storage rather than a cookie. Strictly necessary | Until you clear it |
bw.country | Which country you are in, so we know whether to ask you. Held for the tab only | Until you close the tab |
The first two are set only when Google Analytics is running for you. The last two are set whatever you choose, because without them we could not remember your answer or know whether to ask.
400 days is not our choice of number — it is the longest a browser will keep a cookie, and every browser shortens anything longer to that.
7.4 What Google Analytics collects, and who sees it
Which pages you visit on blinkwrite.ai and roughly when, an approximate location worked out from your IP address, and the kind of device and browser you use. Google states that Google Analytics 4 does not log or store IP addresses.
It sees nothing from the app. It does not run in the app, it cannot see what BlinkWrite reads from your screen, and it is not present on your account pages.
Google acts as our processor for this under Google's data processing terms. Google LLC is in the United States — see Section 10. What our property collects is deleted after 14 months.
7.5 The web app
The web app at your account pages uses only what is needed to keep you signed in and to remember your choices on that device. That is not optional, because without it you could not stay signed in. There is no analytics tag there.
7.6 If this changes
If we add another provider, or start using analytics for a new purpose, we will publish an updated version of this policy naming it before the tag goes live, and ask you again.
8. Usage counts
Our servers count what the app asks for: per day, and per kind of suggestion, how many suggestions were requested, how many you accepted, and how many tokens were used.
These counts contain no message content. They record that something happened, not what you wrote. They are kept against your account, because that is what makes them useful — they are what enforces the limits of your plan and what fills the usage view in your account.
They are held in our own database. There is no third-party analytics service in BlinkWrite, and no analytics SDK in the app. The app does not report your device model, your macOS version, or your app version to us.
Counts are kept for 14 months and then deleted. This is what produces the aggregate numbers our Terms of Service §6 refers to.
9. Who else sees your data
We use a small number of service providers. Each acts on our instructions under a written data processing agreement, and none of them may use your data for their own purposes.
| Who | What they do | Where | What they can see |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting, our database, and the GPU servers that run our models | United States | Account, subscription, and technical data. Message text passes through memory during a request and is not stored. |
| Stripe, Inc. and its affiliates (shown as Link at checkout) | Merchant of record — payments, tax, invoicing | United States and Ireland | Name, email, billing address, card details, transaction history. Stripe is a controller in its own right for the payment; its own privacy policy applies. |
| Cloudflare, Inc. | CDN and reverse proxy in front of our website, our web app, and the endpoint your Mac sends suggestion requests to | United States and globally | Web request logs, including IP address. Suggestion requests pass through Cloudflare in transit, so the masked text passes through it too. It does not store the contents of a request, and keeps no copy of your text. |
| Google LLC and Google Ireland Limited | Website analytics on blinkwrite.ai only — see Section 7 | United States and Ireland | Which pages are viewed on our website, an approximate location, and the browser and device used. No app data, no message content, and nothing from your account pages. |
Google appears above for website analytics and for nothing else. If you use Apple or Google sign-in, that company verifies your identity as a separate controller. Its privacy policy covers the records that it keeps about the sign-in. See Apple's privacy policy or Google's privacy policy, and see Section 4.1. Apple is not on the processor list.
No AI provider appears on this list, and that is deliberate. We run our own models on our own servers precisely so that your text is not somebody else's training data.
We will also disclose data where we are legally required to — in response to a valid court order, subpoena, or lawful request from a public authority. We will tell you if that happens, unless we are legally barred from doing so. Because we retain no message content, the most a legal request can produce is account, subscription, and session data.
If we are ever acquired or merged, your data may transfer to the acquirer. We will tell you beforehand, and this policy will continue to apply until you are given notice of a new one.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California and other US state privacy laws.
10. Where your data is processed
All of it, in the United States. Our servers, our models, and our account database all run in a United States region of Amazon Web Services. We do not currently operate infrastructure in Europe.
If you are in the EEA, the UK, or Switzerland, that means your data is processed in a country whose surveillance and privacy laws differ from your own, and which the European Commission has not found to provide an equivalent level of protection generally.
We take these steps as a result:
- The GDPR and UK GDPR apply to us and we comply with them, because we offer the service to people in Europe (Article 3(2) GDPR). Being in the United States does not exempt us.
- Where a transfer to one of our service providers requires a safeguard, we use the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for the UK, the International Data Transfer Addendum.
- Most of the risk that would normally attach to processing in the United States does not arise here, because there is no store of message content to disclose. Text is held in memory for the length of one request.
- Website analytics data goes to Google in the United States. That transfer runs on the Standard Contractual Clauses in Google's data processing terms, and in the EEA, the UK, and Switzerland it happens only if you have accepted it. It concerns our website alone, never the app.
11. How long we keep things
| Data | Kept for |
|---|---|
| Message text and generated suggestions | Not kept. Held in memory for the duration of the request, then discarded. |
| Screen images | Never transmitted; discarded on your Mac immediately after text is extracted |
| Account and subscription data | While your account exists. Erased when you close it — see Section 11.1. |
| Session records | Until the session expires or you sign out |
| Usage counts | 14 months, then deleted |
| Security and access logs (IP, timestamps, error codes) | 12 months — long enough to investigate an incident or abuse pattern found some months after it happened |
| Terms-acceptance records | Kept after the account is closed, as proof of what was agreed |
| Trial fingerprint | Kept after the account is closed, so the one-time trial stays one-time |
| Deletion record | Kept after the account is closed, so we can show the deletion was carried out |
| Invoices and tax records | Held by Stripe, for as long as tax law requires |
11.1 Closing your account
You can close your account from the web app, or by emailing [email protected].
It is a hard delete, not a hidden flag. Your profile, your sessions, your subscription record, and your usage counts are erased immediately, and your Stripe customer is deleted, which cancels any active subscription.
One qualification, because "immediately" should mean what it says: our database takes routine encrypted backups, which are kept for 14 days and then expire. Your data is gone from the live service the moment you close your account, and ages out of those backups within a fortnight. We do not restore a backup to recover a deleted account.
Three things survive, deliberately, and this is the complete list:
- an irreversible hash of your email address, so the one-time free trial cannot be taken again by deleting the account and signing up with the same address. It is a one-way fingerprint — it cannot be turned back into your address, and it is useless for identifying you. Lawful basis: Art. 6(1)(f), fraud prevention;
- a dated record that a deletion happened, with no personal data in it, because we have to be able to show we honoured the request (Art. 5(2) GDPR);
- the record of which terms you accepted and when, because we have to be able to show what was agreed even after the account is gone (Art. 7(1) GDPR). It carries no IP address and no user agent.
Stripe keeps past invoices, which it is required to do by tax law.
Closing your account is permanent. You cannot reactivate it or recover your settings, and a new account would not come with another free trial — that is what the fingerprint above is for.
Closing your account does not remove the app from your Mac. That is a separate step, below, and either one can be done without the other.
11.2 Removing BlinkWrite from your Mac
Everything BlinkWrite stores on your Mac can be removed from the app itself: Settings › General → Uninstall BlinkWrite. It removes the app, the on-device model it uses to mask personal information, your settings and per-app rules, the sign-in credential held in your Mac's Keychain, and the Accessibility and Screen Recording permissions it was granted. Nothing is left for you to find and delete by hand.
Dragging the app to the Trash removes only the app, and leaves the rest in place.
Uninstalling is local and does not close your account. To do both at once, tick Also delete my BlinkWrite account in the uninstall confirmation.
12. Your rights
12.1 If you are in the EEA, the UK, or Switzerland
You have the right to:
- know what we hold about you and get a copy of it;
- have it corrected if it is wrong;
- have it deleted;
- restrict or object to our processing, including any processing based on legitimate interests;
- take your data elsewhere in a machine-readable format;
- withdraw consent at any time, for anything we do on the basis of consent — which does not affect what we did before you withdrew it.
How to use them: email [email protected]. We will respond within one month. If a request is complicated we may take up to two further months, and we will tell you within the first month if that happens. It costs nothing.
We may need to confirm who you are before we act, so that we do not hand your data to somebody else.
Complaints. You can complain to the data protection authority in the country where you live, work, or where you think something went wrong. We would rather you came to us first, but you do not have to. Because we have no establishment in the EU, there is no single lead authority for us — your own national authority is the right one.
12.2 If you are in California
We are a California company, so we will say this plainly: we do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling that produces legal or similarly significant effects. There is no "Do Not Sell or Share" mechanism on our site because there is nothing to opt out of.
You may request to know what we collect and disclose, delete it, correct it, and receive a portable copy. You may name an authorised agent to act for you. We will not discriminate against you for exercising any of these rights — your price, your plan, and your service stay the same.
Contact [email protected]. We verify identity before acting and respond within 45 days, extendable once by a further 45 with notice.
12.3 If you are in another US state
Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and a growing number of other states give residents comparable rights to know, delete, correct, and obtain a copy of their data, and to appeal a refusal. We extend those rights to everyone in the United States regardless of where you live, because operating one process is simpler than operating fifteen. Use the same address: [email protected].
We honour Global Privacy Control and similar browser opt-out signals on our website.
12.4 If you are in Canada
You may request access to your personal information and ask us to correct it. If you are not satisfied with how we handle a complaint, you may escalate to the Office of the Privacy Commissioner of Canada or to your provincial privacy commissioner.
13. Security
We protect data in transit with TLS and at rest with encryption. Access to production systems is limited to the people who need it, requires multi-factor authentication, and is logged. Payment card details are handled by Stripe and never reach our systems. For email sign-in, we use salted scrypt hashes and never store plaintext passwords.
The strongest thing we do for your security is not keeping your content. A store of message text would be the obvious thing to attack. There isn't one.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that puts your rights at risk, we will notify the relevant authority within 72 hours where the law requires it, and tell you directly where the risk to you is high.
14. Children
BlinkWrite is for adults. You must be 18 or over to use it, and we do not knowingly collect personal data from anyone under 18. If we learn that someone under 18 has an account, we will close it and delete the data. If you believe a child has given us data, tell us at [email protected].
15. Automated decisions and AI
BlinkWrite generates text with AI models. It does not make automated decisions about you that produce legal effects or similarly significant effects, and there is no profiling of that kind anywhere in the product. Nothing here decides whether you get a service, a price, or a credit line.
Every suggestion is exactly that — a suggestion. It appears, you accept it or you do not, and nothing happens without your keystroke.
AI output can be wrong. That is covered in our Terms of Service §7.
16. Contact us
Privacy questions, and any request under Section 12, go to [email protected]. So does everything else — it is one address and it is read.
17. Changes to this policy
We will update this policy as the product changes. Each version is published with a version identifier, an effective date, and a note of what changed. Every past version stays available at its own address, so you can always read exactly what applied when — see previous versions. We keep a record of which version you accepted and when.
If a change materially affects how we handle your data — a new category collected, a new purpose, a new recipient, or a longer retention period — we will email you at least 30 days before it takes effect, and ask you to accept it. The new version is published at its own address during that notice period, so you can read it before it applies. If the change requires your consent, we will ask for it rather than assume it.
Editorial changes — typos, formatting, clearer wording that changes nothing about what we do — are published as a new version without asking for a new acceptance.
We will not make a change that lets us train our AI models on your content, or sell your personal data, without your express opt-in consent. Those two commitments are the point of this document.
Previous versions
- 2026-09-13Effective 13 September 2026 · Explain regional analytics choices, ad attribution, limited product milestones, and subscription measurement.
- 2026-08-24Effective 24 August 2026 · Added email sign-in and password-security details before publication.