A*AIssistify
GuidesOpen workspace →
Privacy Effective 12 August 2026

Your draft is not an ad product.

This policy explains what stays in your browser, what is stored when you use Rewrite Studio, and which processors handle model and payment requests.

The important distinction

The free text inspector runs in your browser and does not send the pasted text to our servers. A signed-in rewrite sends the draft to our server and selected model route because processing cannot happen otherwise.

1. Information we process

Free inspector

The character and pattern inspection on the public homepage runs in your browser. We do not receive or store the text you paste into that inspector. When you carry a draft into the workspace, the browser temporarily keeps it in tab-scoped session storage.

Account and identity

When you sign in, we receive a stable account identifier, email address, and optional display name from the sign-in service. We store them to identify your wallet, history, and subscription. Authenticated workspace drafts, protected request recovery, and locally edited results in tab storage are bound to that stable account identifier; another account cannot restore them. Product sign-out clears those tab copies before leaving.

Rewrite content and history

When you approve a model run, we store the source text, settings, selected model and workflow, model result, timestamps, usage, price reservation, and final charge. This creates the run history shown in your workspace and supports billing disputes and safety investigations. Edits to a completed result recover only from account-bound storage in the current tab until you explicitly choose Save revision. Saved revisions are added to that account’s history without replacing the original model result. Copying or downloading text does not save a revision to our server.

MCP credentials

If you create an MCP access token, the reusable secret is shown once. We store a one-way SHA-256 digest, a short display prefix, fixed scopes, label, creation and expiry dates, last-used time, and revocation time. MCP rewrite requests create the same account history and usage records as workspace requests. Never put a token in a prompt or send it to support.

Billing

Stripe processes checkout and payment details. We receive identifiers, subscription status, invoice status, payment allocation, currency, and amount paid. We do not receive or store full card numbers.

2. How model processing works

Rewrite requests are routed through OpenRouter to the selected model provider. Requests ask OpenRouter to use provider routes that deny data collection. Providers still process the prompt and completion to fulfill the request, and their legally required security or abuse-retention practices may apply. We keep inference credentials on the server and do not expose them to the browser.

Do not submit secrets, regulated personal data, confidential client information, or material you are not authorized to process.

3. Why we use the information

  • Provide inspection, rewriting, copy-out, and history.
  • Authorize prepaid model spend and prevent negative balances.
  • Reconcile provider usage, investigate ambiguous requests, and prevent duplicate charges.
  • Operate security, rate limits, abuse prevention, and support.
  • Meet accounting and legal obligations.

4. Retention and deletion

Saved rewrite runs and explicitly saved revisions remain available until you ask us to delete them or the account. Unsaved drafts and local edits use the current tab’s session storage instead. Payment, wallet, and immutable ledger records may be retained as required for accounting, fraud prevention, disputes, and legal compliance. Provider records follow the relevant provider’s terms and the route selected at processing time.

To request access, correction, export, or deletion, email privacy@aissistify.com from the account email.

5. Sharing and international processing

We share information only with service providers needed to operate the product—currently identity hosting, infrastructure, model routing/providers, payment processing, and operational monitoring—or when required by law. These services may process data in other countries subject to their safeguards and applicable transfer mechanisms.

6. Security and choices

We use server-side secrets, access controls, encrypted transport, idempotent billing events, and a prepaid reservation ledger. No online service can guarantee absolute security. Use the free browser-local inspector when a task does not require a model, and avoid saving drafts you do not want retained.

7. Contact and changes

Questions and privacy requests can be sent to privacy@aissistify.com. Material changes will be dated on this page and, when appropriate, communicated in the product.

AIssistify · Evidence-first writing tools
PrivacyTermsAcceptable use