This Privacy Notice explains what personal data MaybeCopyThis ("we", "us") collects when you use our website and Service, why we collect it, and the choices you have. We are the data controller of the personal data described below.
1. Data we collect
Account data
- Email address (required to sign in).
- Authentication identifiers from sign-in providers (e.g. Google) if you use them.
- Account preferences and entitlement state (free credits, paid credits, subscription status).
Service usage data
- The copy you paste into the optimizer and the output we generate from it.
- Logs of optimization requests for billing and abuse prevention.
- Standard server logs (IP address, browser/device, timestamps, error traces).
Payment data
- Payments are processed by Paddle, who acts as the Merchant of Record. Card details and billing addresses are collected and stored by Paddle, not by us. We receive limited data such as transaction IDs, plan, and subscription status from Paddle to manage your account.
Support data
- Messages you send us by email and any information you include in them.
2. Why we use your data
- Provide the Service — create your account, run optimizations, manage credits and subscriptions (legal basis: performance of a contract).
- Process payments — share necessary information with Paddle so they can charge you and handle refunds (legal basis: performance of a contract).
- Security and fraud prevention — detect abuse, debug errors, protect the Service (legal basis: legitimate interests).
- Improve the Service — analyze aggregated usage to understand what's working (legal basis: legitimate interests).
- Customer support — respond to your questions (legal basis: legitimate interests / performance of a contract).
- Legal compliance — meet our tax, accounting, and other legal obligations (legal basis: legal obligation).
We do not use your input or output to train AI models, and we do not sell your personal data.
3. Who we share data with
We share personal data only with the following categories of recipients:
- Paddle — our Merchant of Record, who processes payments, manages subscriptions, handles tax compliance, and issues invoices.
- Hosting and infrastructure providers — including our cloud hosting and database provider, who store and process data on our behalf under contractual safeguards.
- AI model providers — we send the copy you submit to a third-party large language model provider in order to generate the optimization output. The provider processes the data to return a result and does not use it to train its models.
- Authentication providers — if you sign in with Google, that provider receives standard authentication signals.
- Professional advisors — accountants, lawyers, where reasonably necessary.
- Authorities — when required by law or to protect rights, safety, and security.
4. How long we keep your data
- Account data: kept while your account is active and for a reasonable period after you close it, to handle disputes and meet legal obligations.
- Optimization input/output: stored to populate your account history and for abuse prevention; deleted on request or when your account is closed.
- Payment records: retained as required by tax and accounting law (typically 7 years).
- Server logs: retained for a short period (typically 30–90 days) for security and debugging.
5. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and regular review of our systems. No system is perfectly secure, so we cannot guarantee absolute security.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, and to withdraw consent. To exercise any of these, email support@maybecopythis.com. We will respond within the timeframe required by applicable law (typically within one month). You also have the right to complain to your local data protection supervisory authority.
7. International transfers
Your data may be processed in countries other than the one you live in, including by our hosting and AI model providers. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) for these transfers.
8. Cookies
We use a small number of essential cookies and similar technologies to keep you signed in, remember your preferences, and operate the Service. We do not use advertising or third-party tracking cookies. Payment pages operated by Paddle may set their own cookies — see Paddle's privacy notice for details.
9. Changes to this notice
We may update this Privacy Notice from time to time. If we make material changes, we will provide reasonable notice. The "Last updated" date at the top reflects the most recent revision.
10. Contact
For questions about this notice or your data, email support@maybecopythis.com.