Skip to content

Privacy policy

Last updated October 7, 2026

The short version: we use your text only to rewrite it for you, we never train models on it, we do not sell data, and you can delete everything yourself. The long version follows, because the law (the EU General Data Protection Regulation and the French Data Protection Act, and where it applies the UK GDPR) asks for it.

1. Who is responsible

Samesay, France ("Samesay", "we") is the controller of the personal data described here. Contact: hello@samesay.app. For text you submit that contains personal data of other people, you are the controller and we process it only on your instructions to provide the service (see section 10).

2. What we collect, why, and on what basis

  • Account data: email address, a salted hash of your password (never the password itself) or the identifier Google gives us if you sign in with Google, display name, plan, account settings, sign-in sessions (with IP address and browser type for security). Basis: performance of the contract; legitimate interest in securing accounts.
  • Your text: the drafts you submit and the versions we produce, with the tone, language, rounds and versions you chose, the scores and checks we computed, and your thumbs up or down. Basis: performance of the contract. If history is on, text stays in your history until you delete it, for at most 90 days. If history is off, neither the draft nor the versions are written to our database: only the word count and timestamp remain for metering. Text sent through the API is handled the same way.
  • Usage and metering: word counts, number of rewrites, rounds and versions, timestamps, credits and words used, free retries. Basis: performance of the contract; legitimate interest in preventing abuse.
  • Billing: plan, subscription status, invoices and amounts, the Stripe customer and payment identifiers. Card numbers are entered on Stripe's pages and never reach us. Basis: performance of the contract; legal obligations (accounting and tax records).
  • Security: if you turn on two-factor sign-in, the secret shared with your authenticator app and your backup codes, stored encrypted; the devices you chose to trust (a cookie); failed attempts, to lock the account briefly after too many. If you add a phone number in your settings, that number, used only to reach you about your account. Basis: performance of the contract; legitimate interest in account security.
  • Referral programme: the code of your link, how many times it was opened, which account referred you (set from a cookie when you sign up through a referral link), the payments your referrals made (amounts, dates, Stripe identifiers, never their text), your commissions and, if you ask for a transfer, the account holder name and bank details you give us. Bank details are seen only by the operator, used for the transfer and kept with the accounting records. Basis: performance of the contract; legal obligations.
  • Without an account: the editor on our home page keeps the draft you typed in your browser's session storage until you create an account, so that it is waiting for you afterwards. Nothing is sent to our servers before you have an account. If we offer free tries without an account, we limit them with salted hashes, rotating monthly, of the IP address and network, a device cookie, a browser storage identifier and browser characteristics (user agent, language, screen, time zone, graphics renderer); these identify a browser, not a person, and are deleted after 40 days. Basis: legitimate interest in preventing abuse of free allowances.
  • Technical logs: our hosting providers keep request logs (IP address, time, URL, status, browser type) for a short period for security and debugging. Basis: legitimate interest in running and securing the service.
  • Support: what you write to us by email, kept for as long as needed to handle the request and for our records. Basis: legitimate interest; performance of the contract.

We do not use your text, drafts or versions to train, fine-tune or evaluate language models, ours or anyone else's. We do not profile you for advertising. We do not sell or rent personal data.

3. Where the processing happens

Your text is rewritten on GPU servers we rent and control, running open-weight models we host ourselves; it is not sent to a third-party AI service or to any AI detection company. Rewriting servers and our database are hosted in the United States. Transfers of personal data outside the European Economic Area rely on the EU Standard Contractual Clauses entered into with each provider, on the EU-US Data Privacy Framework where the provider is certified, or on an adequacy decision where one exists, and on additional safeguards such as encryption in transit and at rest.

4. Processors we use

  • Modal Labs, Inc. (United States): GPU servers that run the rewriting model. Text is processed in memory for the duration of the request and is not stored there.
  • Vercel Inc. (United States): web hosting, request logs.
  • Neon, Inc. (United States): database.
  • Stripe Payments Europe, Ltd. and Stripe, Inc.: payments, invoices, fraud prevention. Stripe is an independent controller for the payment data it collects; see Stripe's privacy policy.
  • Resend, Inc. (United States): transactional emails (password reset, email changes) when enabled.
  • Google LLC: only if you choose to sign in with Google; Google tells us your email and name.
  • Cloudflare, Inc.: bot protection on free tries, when enabled.

Each processor acts on our instructions under a data processing agreement. We may change providers; this list is kept current.

5. Who else may see data

Nobody, except: authorities when the law obliges us; professional advisers bound by confidentiality; a successor if the business is sold or merged, under the same commitments; and anyone you ask us to share with. We will challenge requests for your text that we consider unlawful or excessive, to the extent the law allows.

6. How long we keep data

  • Text in history: until you delete it, at most 90 days; with history off, it is never stored. Deleted text is purged from backups within 30 days.
  • Account data, history and metering rows: for the life of the account and 30 days after deletion (backups). Deleting the account deletes them all.
  • Invoices and payment records: kept by Stripe and in our accounting for 10 years, as accounting law requires; they contain your email and the amounts, never your text.
  • Free-try identifiers: 40 days. Hosting logs: as set by the provider, typically days to weeks.
  • Email exchanges: up to 3 years after the last message.

7. Security

Data is encrypted in transit (TLS) and at rest at our providers. Passwords are hashed. Access to production systems is limited to the people who need it, with strong authentication. API keys are stored hashed and shown once. No system is perfectly secure; if a breach affects you we will inform you and the competent authority as the law requires.

8. Your rights

You can see your history, export any version (text, Word, Markdown, PDF), delete entries, turn history off, change your email and password, and delete your whole account yourself from the account page. Deleting the account removes your data from our live systems at once and from backups within 30 days, except billing records we must keep. Depending on where you live, you also have the right to access, rectify, erase, restrict or object to processing, to data portability, to withdraw consent where processing rests on consent, and to complain to a supervisory authority (in France, the CNIL, www.cnil.fr; elsewhere in the EU, your national authority), and to give instructions on what happens to your data after your death. Write to hello@samesay.app; we answer within 30 days and may ask you to prove your identity. If you are in the EU or UK, you may also contact us at the same address as the point of contact for data protection matters.

9. Children

The service is not intended for children under 16. We do not knowingly collect their data; if you believe a child has created an account, tell us and we will delete it.

10. Text about other people

If the text you submit contains personal data of other people (names, facts about them), you must have the right to process it. For that data you are the controller and we are your processor: we process it only to produce your rewrite, we do not use it for anything else, we keep it as described in section 6, we apply the security measures in section 7, we use the sub-processors in section 4, and we help you answer requests from the people concerned where we reasonably can.

11. Cookies and browser storage

We use only what the service needs, described in the cookie policy: a sign-in cookie, and browser storage for the draft you typed before signing up. No advertising or cross-site tracking cookies.

12. Automated decisions

Rewrites, scores and checks are produced automatically, as the service you asked for. Limits on free use may be applied automatically based on the signals in section 2. We make no automated decision with legal or similarly significant effects on you; if we ever suspend an account automatically for abuse, you can ask a person to review it.

13. Changes

We may update this policy. Material changes are announced by email or in the service at least 14 days before they apply, unless the law requires otherwise. The date at the top tells you when it last changed.

14. Contact

Samesay, France. hello@samesay.app.