Log in Start subscription

Privacy Policy

What data Ungippity collects, what it does not, and how we handle what we have.

Effective Date: 2026-07-07

data

1. Data We Collect

  • Email address: collected when you create an account. Used to identify your account and send transactional emails (magic-link sign-in, receipts).
  • Payment information: billing is handled by Polar. We do not store card numbers or payment credentials. Polar provides us with a transaction record and your subscription state is updated accordingly.
  • Submitted text and its output: text you paste into Ungippity, and the rewritten version we return, are logged and deleted after 30 days. We use these logs for quality and training while we hold them. We do not sell submissions or share them with advertisers. To perform the transformation we send your text to third-party model providers; their retention policies apply to that data, see section 3 below.
cookies

2. Cookies

  • We set a session cookie when you sign in. This cookie is used solely to keep you logged in and expires when your session ends or you sign out.
  • We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
third parties

3. Third Parties

  • Polar handles payment processing. When you subscribe, you interact with Polar checkout. Their privacy policy governs how they handle your payment data.
  • Resend sends transactional emails (magic-link sign-in). Email addresses are passed only when sending those emails.
  • Model providers: text you submit is sent to third-party LLM providers to perform the rewrite. Those providers may retain submissions according to their own policies. We choose providers with short retention windows where possible; the specific provider mix may change over time as models improve.
  • Amazon Web Services (AWS) hosts our servers. Traffic and infrastructure logs may be retained by AWS according to their own policies.
  • Cloudflare sits in front of the Service as a CDN, caching layer, and DDoS-protection proxy. As a result, traffic to Ungippity passes through Cloudflare's edge network, and Cloudflare may retain request metadata (IP address, user agent, timing) according to their own policies.
  • We do not sell, rent, or share your personal data with any other third parties.
retention

4. Data Retention

  • Submitted text and its output are logged and deleted after 30 days. We use these logs for quality and training while we hold them.
  • Account data (email address, token balance, transaction history) is retained as long as your account is active or as required to fulfill our legal obligations.
  • You can request deletion of your account and all associated data at any time from the Your Account page.
your rights

5. Your Rights (GDPR)

  • If you are in the UK or European Economic Area, you have rights under the UK GDPR and General Data Protection Regulation, including the right to access, correct, or delete your personal data.
  • To delete your account and data, visit the Your Account page. To make other requests, contact us and we will respond within the timeframes required by applicable law.
security

6. Data Security

  • We use HTTPS all data in transit. Magic-link tokens are hashed (SHA-256) before storage; the raw token only lives in the email and the URL you click.
  • No method of transmission over the internet is completely secure. We take reasonable precautions but cannot guarantee absolute security.
changes

7. Changes to This Policy

  • We may update this policy from time to time. When we do, we will update the effective date at the top of this page.
  • Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
contact

8. Contact

Questions about this policy or how we handle your data? Contact us.