Last updated August 15, 2026
Update — August 15, 2026. We have added a section describing how our browser extensions, the Microsoft Word add-in and the integration API handle your text and session, alongside the existing cookies and local-storage inventory.
Bypassify stores your email, your drafts, your rewrites, and your settings so we can show you your history and bill you if you're on a paid plan. We do not sell your data. We do not use your drafts to train third-party AI models. We do not run advertising trackers. Row-level security means only your account can read your own drafts. You can delete drafts or your whole account any time.
Bypassify ("we", "our", "us") operates the AI humanizer service at bypassify.online. We are the controller of the personal data described in this policy. Contact us at bypassify.ai@gmail.com.
We do not knowingly collect precise location, biometric data, or special-category data.
We do not send marketing email without your explicit opt-in. We do not use your drafts to train third-party foundation models, and we do not sell or "share" your personal data as those terms are used under CCPA / CPRA.
The following providers process personal data on our behalf under written data-processing terms:
The current list may change; the current list is the one in this policy. Material changes are announced in-app.
Bypassify and its subprocessors may process data in the United States, the European Economic Area, and other jurisdictions. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or another lawful transfer mechanism, together with appropriate technical and organisational safeguards.
We keep your drafts and rewrites for as long as your account is active so you can access them from History. Delete individual drafts any time from the History page, or delete your account from Settings — account deletion removes your drafts and settings within 30 days from active storage and from backups on the normal backup rotation. Operational logs are retained approximately 90 days. Billing records are kept for the period required by tax law (typically 6–10 years, depending on jurisdiction).
Your data is stored on a managed Postgres database protected by row-level security policies, so only you (when signed in) can read your own drafts and settings. Traffic is served over TLS 1.2+, data is encrypted at rest, and administrative access is limited to a small number of people using multi-factor authentication and least-privilege service keys. Passwords are hashed. We check new and changed passwords against known-breached password lists. No system is perfectly secure — if you suspect a security incident, email us at bypassify.ai@gmail.com.
We use only the browser storage strictly necessary to run the service. Specifically:
We do not run advertising trackers, cross-site tracking pixels or third-party analytics profiling. Because everything we store is essential, declining in the notice does not disable any tracking (there is none to disable) — it records your answer. You can remove everything at any time by clearing site data in your browser, which will sign you out.
Depending on where you live you may have the right to access, correct, export, delete, object to, or restrict processing of your personal data, to withdraw consent where we rely on it, and to lodge a complaint with your local supervisory authority (in the EU/UK) or attorney general (in the US). You can export or delete individual drafts from the History page and update your profile in Settings, and you can exercise the rest by emailing bypassify.ai@gmail.com. We will respond within the timeframe your local law requires (typically 30 days). We will not discriminate against you for exercising these rights.
California residents (CCPA / CPRA): in the last 12 months we have collected the categories listed under "What we collect" for the purposes listed under "How we use your data". We do not sell or share personal information and do not use sensitive personal information for purposes requiring a right-to-limit disclosure.
Bypassify does not make legal or similarly significant automated decisions about you. The humanizer's rewrite is a text transformation you request; it is not a decision made about you.
Bypassify is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. In the EU/UK, users under 16 need verifiable parental consent. If you believe a child has provided us data, email us and we will delete it.
We may update this policy. Material changes will be announced in-app or by email at least seven (7) days before they take effect (except changes required by law or security, which take effect immediately). The "Last updated" date at the top always reflects the current version.
Our Firefox and Chrome/Edge extensions and our Microsoft Word task pane sign you in to the same Bypassify account you use on the website. They store only your authentication session and your last-used options in the browser's local extension storage; they do not read your browsing history, do not run on pages until you open them, and do not send page content anywhere on their own.
The only content that leaves your device is the text you explicitly select or paste and then submit by pressing Humanize, Rewrite or AI integrity. That text is handled exactly as text submitted on the website: processed to produce your result, saved to your history if saving is enabled, retained under the retention rules above, and never used to train third-party models. The same applies to requests made through our versioned integration API, which requires your own bearer token.
Uninstalling an extension or removing the add-in deletes its local session immediately. Text already saved to your history stays in your account until you delete it.
Privacy questions and requests: bypassify.ai@gmail.com.
See also our Terms of Service.