← Back to home

Privacy Policy

Last updated August 15, 2026

Update — August 15, 2026. We have added a section describing how our browser extensions, the Microsoft Word add-in and the integration API handle your text and session, alongside the existing cookies and local-storage inventory.

Summary (in plain English)

Bypassify stores your email, your drafts, your rewrites, and your settings so we can show you your history and bill you if you're on a paid plan. We do not sell your data. We do not use your drafts to train third-party AI models. We do not run advertising trackers. Row-level security means only your account can read your own drafts. You can delete drafts or your whole account any time.

Who we are

Bypassify ("we", "our", "us") operates the AI humanizer service at bypassify.online. We are the controller of the personal data described in this policy. Contact us at bypassify.ai@gmail.com.

What we collect

  • Account information: email address, display name, hashed password (if using email/password), and OAuth identifier if you sign in with Google.
  • Your drafts: the text you submit for humanization, the rewritten output we return, titles, and any assignment brief you paste.
  • Preferences & settings: default strength, tone, tone preset, voice sample (Ultra), toggles.
  • Subscription & billing metadata: plan tier, status, renewal date, and a payment identifier from Dodo Payments. We do not receive or store your card number.
  • Referral & usage data: referral codes you use or share, daily counts of humanizations for free-tier limits.
  • Operational logs: timestamps, IP address, user agent, request-level metadata, and error traces needed to run the service and prevent abuse. Retained ~90 days.

We do not knowingly collect precise location, biometric data, or special-category data.

How we use your data & legal bases (GDPR / UK-GDPR)

  • To provide the service (running the humanizer, saving your drafts, showing history) — legal basis: performance of a contract.
  • To bill and support you — performance of a contract.
  • To secure the service and prevent abuse (rate limits, fraud checks, chargeback defence) — legitimate interests.
  • To improve the product (aggregated metrics, our own learned-rule mining from your own rewrites within your account) — legitimate interests.
  • To send transactional email (receipts, password reset, security alerts) — performance of a contract / legal obligation.
  • To comply with law (tax records, subpoena response) — legal obligation.

We do not send marketing email without your explicit opt-in. We do not use your drafts to train third-party foundation models, and we do not sell or "share" your personal data as those terms are used under CCPA / CPRA.

Subprocessors we rely on

The following providers process personal data on our behalf under written data-processing terms:

  • Lovable Cloud (managed Postgres, authentication, email delivery, hosting) — stores your account, drafts, and settings.
  • Groq, NVIDIA, OpenRouter, and Lovable AI Gateway — process the text you submit to generate the humanized output. Each is contractually bound not to use your text for their own training or products.
  • Dodo Payments — merchant of record; processes card details, receipts, and tax.
  • Cloudflare — edge network, TLS termination, and DDoS protection.

The current list may change; the current list is the one in this policy. Material changes are announced in-app.

International transfers

Bypassify and its subprocessors may process data in the United States, the European Economic Area, and other jurisdictions. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or another lawful transfer mechanism, together with appropriate technical and organisational safeguards.

How long we keep it

We keep your drafts and rewrites for as long as your account is active so you can access them from History. Delete individual drafts any time from the History page, or delete your account from Settings — account deletion removes your drafts and settings within 30 days from active storage and from backups on the normal backup rotation. Operational logs are retained approximately 90 days. Billing records are kept for the period required by tax law (typically 6–10 years, depending on jurisdiction).

Where it lives & security

Your data is stored on a managed Postgres database protected by row-level security policies, so only you (when signed in) can read your own drafts and settings. Traffic is served over TLS 1.2+, data is encrypted at rest, and administrative access is limited to a small number of people using multi-factor authentication and least-privilege service keys. Passwords are hashed. We check new and changed passwords against known-breached password lists. No system is perfectly secure — if you suspect a security incident, email us at bypassify.ai@gmail.com.

Cookies & local storage

We use only the browser storage strictly necessary to run the service. Specifically:

  • Session storage (essential). Your authentication token is kept in your browser's local storage so you stay signed in between visits. Clearing it signs you out.
  • Preferences (essential). Your default tone, strength and preservation settings, plus whether you have dismissed notices such as the cookie bar or product announcements.
  • Your cookie choice. The Accept/Decline answer you give in the notice, so we do not ask again on every page.
  • Security and delivery cookies. Set by our hosting and payment providers to route requests, prevent abuse and complete checkout.

We do not run advertising trackers, cross-site tracking pixels or third-party analytics profiling. Because everything we store is essential, declining in the notice does not disable any tracking (there is none to disable) — it records your answer. You can remove everything at any time by clearing site data in your browser, which will sign you out.

Your rights

Depending on where you live you may have the right to access, correct, export, delete, object to, or restrict processing of your personal data, to withdraw consent where we rely on it, and to lodge a complaint with your local supervisory authority (in the EU/UK) or attorney general (in the US). You can export or delete individual drafts from the History page and update your profile in Settings, and you can exercise the rest by emailing bypassify.ai@gmail.com. We will respond within the timeframe your local law requires (typically 30 days). We will not discriminate against you for exercising these rights.

California residents (CCPA / CPRA): in the last 12 months we have collected the categories listed under "What we collect" for the purposes listed under "How we use your data". We do not sell or share personal information and do not use sensitive personal information for purposes requiring a right-to-limit disclosure.

Automated decision-making

Bypassify does not make legal or similarly significant automated decisions about you. The humanizer's rewrite is a text transformation you request; it is not a decision made about you.

Children

Bypassify is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. In the EU/UK, users under 16 need verifiable parental consent. If you believe a child has provided us data, email us and we will delete it.

Changes to this policy

We may update this policy. Material changes will be announced in-app or by email at least seven (7) days before they take effect (except changes required by law or security, which take effect immediately). The "Last updated" date at the top always reflects the current version.

Browser extensions, the Word add-in and the integration API

Our Firefox and Chrome/Edge extensions and our Microsoft Word task pane sign you in to the same Bypassify account you use on the website. They store only your authentication session and your last-used options in the browser's local extension storage; they do not read your browsing history, do not run on pages until you open them, and do not send page content anywhere on their own.

The only content that leaves your device is the text you explicitly select or paste and then submit by pressing Humanize, Rewrite or AI integrity. That text is handled exactly as text submitted on the website: processed to produce your result, saved to your history if saving is enabled, retained under the retention rules above, and never used to train third-party models. The same applies to requests made through our versioned integration API, which requires your own bearer token.

Uninstalling an extension or removing the add-in deletes its local session immediately. Text already saved to your history stays in your account until you delete it.

Contact

Privacy questions and requests: bypassify.ai@gmail.com.

See also our Terms of Service.