Privacy Policy
Last updated: December 2024
1. Introduction
OpenDraft ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI research draft generation service.
2. Data We Collect
Account Information
- Email address
- Name (if provided)
- Profile picture (from OAuth providers)
- Payment information (processed securely by Stripe)
Usage Data
- Research topics and draft content you create
- Service usage patterns and preferences
- Device and browser information
- IP address (for security and rate limiting)
3. How We Use Your Data
- To provide and improve our draft generation service
- To process payments and manage subscriptions
- To send service-related communications
- To prevent fraud and ensure security
- To comply with legal obligations
4. Data Sharing
We do not sell your personal data. We may share data with:
- Service Providers: Supabase (database), Stripe (payments), Google (AI processing)
- Legal Requirements: When required by law or to protect our rights
5. Data Retention
We retain your account data for as long as your account is active. Generated drafts are stored for your convenience and can be deleted upon request. We retain minimal logs for security purposes for up to 90 days.
6. Your Rights (GDPR)
Under GDPR and similar regulations, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a portable format
- Objection: Object to processing of your data
- Restriction: Request restricted processing
To exercise these rights, contact us at privacy@opendraft.xyz
7. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS) and at rest
- Secure authentication via Supabase Auth
- Regular security audits
- Access controls and monitoring
8. Cookies
We use essential cookies for authentication and session management. Analytics cookies are only used with your consent.
9. International Transfers
Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place for such transfers.
10. Children's Privacy
Our Service is not intended for users under 16 years of age. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.
12. Contact Us
For privacy-related inquiries, please contact: privacy@opendraft.xyz