Who handles your data.
Textumi is responsible for personal data handled to operate textumi.com. Contact privacy@textumi.com about privacy, or support@textumi.com for product and payment help. This notice covers visitors and account holders. Paddle handles purchase and payment data under its own privacy policy.
What we collect.
We process account email, password hashes or Google sign-in identity, language settings, submitted text, generated results, writing-style examples and guidance, request timing and usage, subscription and transaction references, and messages you send support. Security controls process network information and hashed identifiers to limit abuse. We do not receive full card numbers. If you connect an AI application, we keep its name, its return address, hashed access tokens and the time it was last used.
Why we use it.
Where GDPR applies, account access, text processing and service support rely on performing our contract with you or steps you request before it. Security, abuse prevention and service reliability rely on our legitimate interests, balanced against your rights. Accounting and lawful disclosure rely on legal obligations. Creating an optional personal style profile relies on your consent; you may withdraw it by deleting the profile without affecting earlier lawful processing.
Images and text recognition.
When you choose Enhanced recognition, sanitized image pixels are sent to DeepSeek to transcribe the visible text. Standard recognition uses Tesseract on Textumi’s server without sending the image to an external AI provider. Image files are kept only in temporary storage during processing and removed when the request ends; Textumi does not save them in the account database or backups. Recognized text is returned for your review and is saved under the usual text-retention rules only if you submit it to a tool. External provider retention and international processing are described below. Neither mode guarantees a complete or accurate transcription.
Imported files and web pages.
When you import a document, the file is read on Textumi’s server in a temporary isolated process and only its text is returned to your editor; the file is not saved. When you import a web page, Textumi’s server requests the address you entered, so the site that hosts the page receives a request from our server, without your cookies or device details, and may log it; the page is not saved. Imported text is stored under the usual text-retention rules only if you submit it to a tool. An import can miss or misread parts of a document, so review the text before using it.
AI applications you connect.
You can let your own AI assistant use Textumi through the Model Context Protocol (MCP), with an access token you create or a connection you approve. A connected application can check and rewrite text using your account’s allowance; it cannot open requests you made on the website, your billing or your settings. For a rewrite, Textumi returns parts of your text and their drafts to that application so that it can review them; on this route the review is done by your assistant instead of our model provider. How the application and its provider handle that content is governed by their terms, not ours. Requests made this way are saved in your History like any other. You can remove a connection in Settings at any time, and changing your password ends all connections.
Where processing happens.
Detection runs on our Avrora server infrastructure. Rewriting and style analysis send the required text and instructions to the configured model provider, currently DeepSeek; alternative configurations can use OpenAI, Google or Cursor and its selected model provider. Cloudflare delivers and protects the website and routes support email. Google services receive routed email and encrypted offsite backups. Google sign-in, when available, requests identity only, not Gmail access. Resend sends account verification and password recovery emails. It processes the recipient address, message content including the temporary action link, and delivery information.
International processing.
Providers may process data outside your country, including in the United States and China. DeepSeek’s published policy describes processing in China. Provider retention and use depend on the service terms and account settings; our local deletion does not erase independently held provider data. Contact us for details of the providers and transfer arrangements relevant to your request. Do not submit sensitive personal data or content you are not authorized to share.
Your writing and personal style.
Textumi does not sell your personal data or automatically add your writing to shared training datasets. An optional style analysis creates instructions for future rewrites; it does not train separate model weights. Raw style examples are removed from the active database after analysis; the guide and short evidence excerpts remain until you delete the style or account. Approved guidance accompanies rewrites when you select My style. Provider handling is governed separately by its terms; we do not promise zero provider retention.
Active data retention.
Saved requests, their text and results, and access requests are retained for 30 days; hourly cleanup may add up to one hour. Usage records and in-app support messages remain for 90 days. Account and style data remain until deletion. Sessions last up to seven days, password-reset links 30 minutes and verification links one hour. Payment references are retained for accounting, fraud prevention and resolving disputes for the period those duties require. Email correspondence is kept while resolving the case and any related complaint or legal obligation. Connections of AI applications remain until you remove them or delete your account. An access token you created works until then; for a connection approved by sign-in, access tokens expire after one hour and renewal tokens after 60 days.
Recovery copies.
Encrypted infrastructure backups and restricted release-recovery copies are stored separately from the active database. They can contain data already deleted from your account. Copies are retained while needed for verified disaster recovery or release rollback, and may be kept longer for an identified incident or legal obligation. They are not accessible through your workspace. Restoration requires applying retention and recorded deletion requests before reopening user access.
Your choices and rights.
Delete completed requests in History, export your data in Settings, or request account deletion. If active work or a subscription prevents immediate deletion, contact us. Depending on applicable law, you may request access, correction, erasure, restriction, portability or object to processing, withdraw consent, and complain to a supervisory authority. We may verify ownership without asking for your password. Where GDPR applies, we respond within one month, notifying you of any permitted extension and its reason.
Access, security and updates.
HTTPS protects transport; submitted text and results are encrypted in the application database and passwords are hashed. Authorized administrators may access records for support, security and operating the service. No system is risk-free. Textumi is intended for adults. We use necessary login, security and language storage, with no advertising or optional analytics in the current site. Material changes to this notice will be communicated before they apply.
Service operator
Textumi
- Product and billing support
- support@textumi.com
- Privacy requests
- privacy@textumi.com