Legal
Privacy Policy
What the service processes, where it goes, and how to export or delete it — without unsupported infrastructure promises.
Last updated
1.Who controls this data
CopyForge AI is the service operator and controller for account, product-workflow and support records described here. Privacy requests can be submitted through /contact and marked “Privacy request.”
This policy covers CopyForge AI. It does not control how Amazon, Shopify, Meta, Google, Gumroad or another destination handles information after you publish or send content there.
2.What we collect
We collect the data needed to operate accounts, generate copy, apply limits, provide support and maintain the Service.
- Account data: email address, optional full name, authentication identifiers and saved defaults.
- Content data: product facts, verified-claim notes, generated copy, compliance matches and scores, brand profiles, uploaded logos and bulk-job records.
- Compliance-workflow records: structured product records (name, SKU, ASIN/GTIN, category and similar listing fields), claim-registry wording with version, approval history and the use limits you set (scope, channels, markets), and claim-evidence links that tie a claim to its supporting record.
- Evidence documents: files you upload to the private evidence vault (PDF, TXT, CSV, Markdown, PNG, JPEG, DOCX or XLSX), URL-reference records, their metadata (title, type, issuer, dates, checksum) and any extracted or manually entered excerpt. Files are stored privately and downloads use short-lived signed URLs.
- Catalog and monitoring data: imported catalog listings, listing scan results and scan history, and monitoring alerts generated from content, rule or evidence changes.
- Developer-access data: API key records (only a SHA-256 hash is stored, never the plaintext key), webhook endpoint configurations you register, and webhook delivery logs.
- Plan and payment records: plan, status, expiry, provider, provider transaction reference, amount and currency. Card numbers stay with the payment provider.
- Usage and reliability data: hashed rate-limit identifiers, quota counters, provider/model name, provider-reported token counts, latency, application errors and deployment diagnostics.
- Website analytics: Google Analytics 4 can receive page URL, referrer, browser/device information, approximate location and interaction events such as page views, scrolls and outbound clicks. CopyForge does not intentionally send product facts, generated copy or evidence-vault contents as analytics parameters.
- Communications: contact or security reports, newsletter requests and Pro/Agency launch-waitlist entries, including the email and message you submit.
3.Why we process it and the legal basis
Contract or steps requested before a contract: create and secure your account, generate and save copy, enforce plan allowances, export data, process a deliberate purchase and provide support.
Legitimate interests: prevent abuse, diagnose failures, protect accounts, measure aggregate service reliability and, where lawful without prior consent, understand aggregate website usage. We use the minimum data reasonably needed and do not use this basis for behavioural advertising.
Consent: send an optional newsletter or paid-plan launch notification. You can withdraw by using the unsubscribe instruction in the message or contacting us.
Legal obligation and legal claims: retain or disclose records when required for tax, accounting, fraud prevention, disputes or a valid legal process.
4.AI processing
Product facts and prompt instructions are sent over HTTPS to whichever configured API provider completes a generation. The code supports OpenAI, Google Gemini and Groq; fallback attempts may contact more than one configured provider when an earlier attempt fails.
CopyForge AI does not use your generations to train a CopyForge model. We do not claim that every provider offers zero retention in every account or region. Provider API retention, abuse-monitoring and training terms depend on the provider and the operator’s account settings and must be verified before production deployment.
Do not submit secrets, payment-card data, private health records or other information unnecessary for product copy.
5.Processors and international transfers
The Service can use Supabase for authentication/database/storage, Upstash for rate limiting and queues, Resend for transactional email, Sentry for error reporting, Google Analytics 4 for website measurement, configured AI API providers for generation, Vercel for application hosting and Gumroad when paid checkout is enabled.
Each provider receives only the data needed for its role. Infrastructure regions and international-transfer safeguards depend on the projects and contracts selected by the operator; the source code alone cannot prove a deployment region. Production settings and data-processing terms must be reviewed before commercial launch.
7.Retention
Account content remains until you delete individual content or the account, subject to technical and legal exceptions. Fixed-window rate-limit keys expire automatically after their window. Bulk export files expire according to the job expiry shown in the dashboard.
Evidence files remain until you delete the evidence record or the account; expired evidence is flagged by date but files are not auto-deleted, so removal stays an explicit choice. Catalog listings, scan history, monitoring alerts, claim versions and approval records remain until deleted or until account deletion removes them through database cascades. Revoked API key hashes are retained only as inert audit rows.
Unconfirmed newsletter and paid-plan launch-list requests are deleted after 30 days. Unsubscribed rows are retained as suppression and consent-audit records for one year, then deleted by the authenticated daily maintenance job. Contact, security, payment and other operational records are kept only as long as needed for their purpose, disputes, security and legal duties. Backup retention follows the configuration of the infrastructure provider rather than a fixed number of days, so this policy states a practice instead of a number it cannot verify.
After primary deletion, encrypted disaster-recovery backups may retain residual copies until they age out under the infrastructure provider’s configured schedule. Backups are not used for ordinary processing and deleted data is not restored except as part of disaster recovery.
8.Your rights, export and deletion
Every plan can download an account-data export from Dashboard > Settings. The JSON Lines export includes profile, plan, payment, brand-profile, generation, bulk-job and launch-list rows linked to the immutable account id, plus the compliance-workflow records: structured products, claims, evidence metadata (the exported file contains metadata and excerpts — documents themselves stay downloadable from the vault until deletion), catalog listings with scan results, monitoring alerts and API key records with revoked status. Pro/Agency copy-library CSV is a separate convenience feature; account privacy access is not paywalled.
You can delete your account from Dashboard > Settings after confirming the account email. Primary account content is removed through database cascades — including products, facts, claims, claim versions, approvals, evidence records and their links, catalog listings, scan history, monitoring alerts, API keys and webhook configurations — and stored user folders (including evidence files) are removed. The deletion trigger removes waitlist rows linked to the Auth user id. Email-only contact/newsletter records are not exposed or deleted solely on a typed-email match; request those separately so we can verify ownership. Records subject to a legal retention duty may be retained only to satisfy that duty.
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. We verify requests to protect the account. You may also complain to your local data-protection authority.
CopyForge AI does not sell personal information or share it for cross-context behavioural advertising. California residents may still contact us to exercise applicable access, correction or deletion rights.
9.Business transfer or change of operator
If CopyForge AI, the Service or substantially all related business assets are sold, acquired, reorganised or transferred, account, product-workflow, support and other records described in this policy may be transferred to the successor operator as part of that transaction, but only as permitted by applicable law.
Any successor that receives personal data must use it consistently with the notices, rights and legal obligations that apply at the time of transfer. Where applicable law requires notice, consent or another choice before a transfer, that requirement must be satisfied before the affected data is transferred. You may use the export, deletion and privacy-request options described above before closing where they apply.
10.Security, children and changes
We use authentication, row-level security, explicit ownership filters, private export storage, signed download URLs, rate limits and restricted service credentials. No system is perfectly secure; report concerns through /security.
The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child submitted data, contact us for deletion.
We update the date above when this policy changes. Material changes affecting active users will be communicated through the Service or account email where reasonably possible.
11.Contacting us
Submit privacy questions or rights requests through /contact and write “Privacy request” in the message. We aim to respond within 30 days, subject to identity verification and any lawful extension.
Questions about this document? Contact us and we will answer in plain language.