Legal

Privacy Policy

Last updated 24 July 2026

1. What we collect

Account data (email, password hash, tier), content you submit for audit (pasted text, uploaded files, or URLs you ask us to scrape), and your audit history and scores. If you subscribe, Stripe collects and processes your payment details directly - we never see or store your card number.

2. How we use it

To run your audits, show your history, manage your subscription, and email you transactional messages (confirmation, password reset, billing receipts). We don't sell your data or use your submitted content to train models.

3. Who we share it with

Sub-processors we use to run the Service: OpenAI (to generate scores from your submitted content), Firecrawl (to fetch a URL you ask us to scrape), Stripe (billing), Resend (transactional email), and our infrastructure host. Each only receives what it needs to perform its function.

4. Data retention

We keep your account and audit history for as long as your account is active. You can delete individual audits from your history, or ask us to delete your account entirely by emailing us.

5. Security

Data is encrypted in transit (HTTPS) and access to production systems is restricted. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

6. Your rights

You can access, correct, export, or delete your personal data at any time by contacting us. If you're in the UK/EU you also have rights under GDPR, including the right to lodge a complaint with your local data protection authority.

7. Cookies & analytics

We use only essential cookies required to keep you signed in. No third-party advertising or tracking cookies. We log anonymous, aggregate page-visit analytics (country and device type, derived from your IP address and browser at request time) to understand traffic - your IP address itself is never stored, and this isn't tied to your account or any individual visitor.

8. Contact

Questions or data requests: chris@total-applications.com.