Skip to main content
OpenDraft
Back to Home

Privacy Policy

Last updated: December 2024

1. Introduction

OpenDraft ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI research draft generation service.

2. Data We Collect

Account Information

  • Email address
  • Name (if provided)
  • Profile picture (from OAuth providers)
  • Payment information (processed securely by Stripe)

Usage Data

  • Research topics and draft content you create
  • Service usage patterns and preferences
  • Device and browser information
  • IP address (for security and rate limiting)

3. How We Use Your Data

  • To provide and improve our draft generation service
  • To process payments and manage subscriptions
  • To send service-related communications
  • To prevent fraud and ensure security
  • To comply with legal obligations

4. Data Sharing

We do not sell your personal data. We may share data with:

  • Service Providers: Supabase (database), Stripe (payments), Google (AI processing)
  • Legal Requirements: When required by law or to protect our rights

5. Data Retention

We retain your account data for as long as your account is active. Generated drafts are stored for your convenience and can be deleted upon request. We retain minimal logs for security purposes for up to 90 days.

6. Your Rights (GDPR)

Under GDPR and similar regulations, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a portable format
  • Objection: Object to processing of your data
  • Restriction: Request restricted processing

To exercise these rights, contact us at privacy@opendraft.xyz

7. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS) and at rest
  • Secure authentication via Supabase Auth
  • Regular security audits
  • Access controls and monitoring

8. Cookies

We use essential cookies for authentication and session management. Analytics cookies are only used with your consent.

9. International Transfers

Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place for such transfers.

10. Children's Privacy

Our Service is not intended for users under 16 years of age. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.

12. Contact Us

For privacy-related inquiries, please contact: privacy@opendraft.xyz