Privacy Policy
Last updated July 2, 2026
This Privacy Policy explains what HumanPhrase (“we”, “us”) collects, how we use it, and the choices you have. It applies to humanphrase.ai and the services offered there.
1. Information we collect
Account & billing
- Your email address, used for authentication and receipts.
- Payment metadata from Stripe (such as the last four digits and status of a charge). We never receive or store your full card number.
Content you submit
- The text you submit for rewriting (“Input”) and the text we generate for you (“Output”). We store these to operate, debug, secure, and improve the Service, including to train, fine-tune, and evaluate our models.
Technical & security metadata
- Per-request metadata: timestamp, input length, latency, and status.
- A coarse device/network fingerprint, a hashed IP, and basic interaction signals. We use these to enforce limits and to detect and prevent abuse such as automated scraping or model distillation.
2. How we use your information
- To provide the Service — process rewrites and return Output to you.
- To bill you accurately and prevent fraudulent or abusive use.
- To operate, secure, debug, and improve the Service, including training, fine-tuning, and evaluating our models on Input and Output.
- To communicate with you about your account, receipts, security, and support.
- To comply with legal obligations.
3. How we share information
We do not sell your personal information. We share it only with service providers that help us operate the Service, and only as needed:
- Supabase — database, authentication, and storage.
- Stripe — payment processing.
- Vercel & Upstash — application hosting and rate-limiting infrastructure.
- Resend — transactional email (e.g. receipts, low-balance notices).
- Modal and Anthropic — AI infrastructure used to generate and refine rewrites.
- Providers used to evaluate output quality for internal quality assurance.
We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of our users and the Service. If we are involved in a merger or acquisition, information may be transferred as part of that transaction.
4. Retention
Account information is retained while your account is active. Security and billing metadata is retained for up to 12 months for accounting and abuse investigation. Input and Output may be retained to operate and improve the Service. We delete or de-identify data when it is no longer needed for these purposes.
5. Your rights & choices
- You may request access to, correction of, or deletion of your personal data and account content through our feedback page. We will remove it from active systems, subject to limited retention required for legal, accounting, or security reasons.
- Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing. We honor applicable rights.
6. Cookies
We use strictly necessary cookies to keep you signed in and to secure the Service. We do not use third-party advertising cookies.
7. Security
We use access controls, encryption in transit, and provider-level safeguards to protect your data. No system is perfectly secure, but we work to protect information against unauthorized access, loss, or misuse.
8. International transfers
We and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The Service is not directed to children under 18, and we do not knowingly collect their data.
10. Changes
We may update this Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, communicated to you.
11. Contact
Questions or requests? Reach us through our feedback page.