Privacy Policy
What we collect. Your email address (to sign you in), a session cookie, your credit balance and ledger, and Stripe's payment identifiers (not card data). Server logs record request paths, timing and the client address for rate limiting.
Your text. Text you submit is processed in memory on our server to measure and rewrite it. We do not store submitted text or rewrites after the response is sent, except: detector scores for text judged with the operator's own GPTZero key are cached on the server, keyed by a hash of the text, so a repeated request is not billed twice; text judged with your own key is not cached. If you supply your own GPTZero key, your text is sent to GPTZero under their privacy policy; without a key nothing leaves our server.
Email. Sign-in is by email and password, or through Google or Apple if you choose them; we do not send marketing email. We do not send marketing email.
Cookies. One HttpOnly session cookie, `longhand_session`, needed to keep you signed in. No analytics or advertising cookies.
Retention and deletion. Accounts and ledgers are kept while the account exists. Email aniket_b@berkeley.edu to delete your account; we remove the account, sessions and keys and keep only the ledger rows needed for accounting.
Security. TLS in transit, credentials hashed at rest, payments handled by Stripe. No system is perfectly secure; we will notify affected users of any breach as the law requires.
Contact. aniket_b@berkeley.edu