Copyrightable
Privacy

Privacy Policy

Version v1 - Effective June 13, 2026

Plain version: you own everything you write. We keep your record so you can show you wrote it. We never sell it, never share it, never publish it. Our team can look at it, and we use it to improve how our system reads authorship. We do not train AI models on your writing, and we will not unless you turn that on yourself. The short, human version is our Pledge.

This Privacy Policy explains what Copyrightable, operated by Interactive Technology, LLC ("we", "us"), collects when you use copyrightable.app, the dashboard, the hook, the API proxy, the import tools, and any related software and services (together, the "Service"), and what we do with it. By using the Service, you agree to the practices below.

1 What we collect from you directly

When you create an account we collect your email address, a display name, an optional full name, and the password you choose (stored only as a salted hash by our auth provider). If you sign in with Google we receive the email and name on your Google profile and a provider id. We never see your Google password.

2 What we collect from your work

The Service captures the inputs and outputs of your AI-assisted work so that a record of your authorship exists. Depending on which capture surface you install, that may include: your prompts to the AI, the AI's responses, the tools the AI calls on your behalf, file edits you make, timestamps, working directory paths, and a derived "methodology" score. Secrets and credentials are detected and replaced with redaction markers before any data is written or transmitted. We capture only from projects you have enrolled.

3 What we never do

We do not sell your data. We do not rent your data. We do not share your captured content with third parties except as described under "Subprocessors" below or where compelled by valid legal process. We do not publish your content. We do not scan your work for advertising signals. We do not claim ownership of anything you make. These commitments do not change based on your settings.

3b How we use your content to run and improve the Service

To operate the Service and make our authorship assessment better, our authorized team may view your captured content, including full conversation threads, and we use real content to test and tune how our methodology system reads and classifies authorship. This is tuning our own deterministic system, not training an AI model on your writing. We do this only with your own content, never to build a product out of it, and never in a way we would share or sell. It is what lets the assessment stay accurate and honest. This use is part of running the Service and applies to all accounts.

3c Training AI models: off by default, only with your consent

We do not use your writing to train artificial intelligence models, ours or anyone else's. That is off by default for every account. We will only ever train on your content if you affirmatively turn it on, and we record the exact date you turned it on or off and the precise policy language in force at that moment, so consent is always traceable. There is no setting to enable this yet, which means today the answer is simply no for everyone. If we ever offer it (for example, a free tier in exchange for opting in), it will be your clear, separate choice, and your existing content stays excluded until you say otherwise.

4 Where your data lives

Captured content is stored in Supabase (PostgreSQL) hosted in the United States, encrypted at rest, and isolated per client account through database-level row-level security so that one customer cannot read another's rows. Backups follow Supabase's standard retention. The web application is served by Vercel. Transactional emails are sent through Resend. Methodology classification is performed by Google Gemini under API terms that prohibit Google from training its models on the content we send for classification.

5 Retention

We retain captured content for as long as your account is active. The value of the Service is the ongoing record of authorship, so we do not auto-delete. You can delete a specific Work, a session, or your entire account at any time from the dashboard. Deletion is immediate from the application and propagated to backups within thirty days. Some metadata required for billing and legal compliance is retained for as long as the law requires.

6 Subprocessors

We use these companies to operate the Service: Supabase (database, auth, file storage), Vercel (web hosting), Resend (transactional email), Google Gemini (methodology classification on demand), Stripe (payment processing - we never store your card number), and Cloudflare (DNS and bot mitigation). Each subprocessor receives only the data necessary to perform its function. If we add a subprocessor that handles your captured content, we will update this page and notify active accounts by email at least thirty days before they begin processing.

7 Legal process and law enforcement

We will comply with valid legal process from a court of competent jurisdiction. If we receive a subpoena, warrant, or court order seeking your data, we will notify you so that you can object or seek a protective order, unless we are legally prohibited from doing so. We push back on overbroad requests. We have not received a National Security Letter; we will update this page if that changes within the limits allowed by law.

8 Your rights

You can export everything we have about you at any time from the dashboard. You can correct your account information from the dashboard. You can delete your data from the dashboard. If you are in California, the EU, the UK, or another jurisdiction with additional privacy rights, those rights apply to you as the law requires. Email us with a request and we will respond within thirty days.

9 Cookies and similar technologies

We use first-party cookies to keep you signed in and to remember your settings. We use local storage to cache state that improves the dashboard experience. We do not use third-party advertising cookies. We do not embed third-party trackers.

10 Children

The Service is not intended for and may not be used by anyone under the age of thirteen. We do not knowingly collect data from children under thirteen. If you believe a child has provided us with personal information, contact us and we will delete it.

11 International transfers

The Service is operated from the United States. If you access it from outside the United States, your data will be transferred to and processed in the United States. Standard contractual clauses or equivalent transfer mechanisms apply where required.

12 Security

We use industry-standard encryption in transit (TLS 1.2+) and at rest. Access to production systems is restricted to the operator and is gated by multi-factor authentication. We follow the principle of least privilege internally. No system is perfectly secure; we will notify affected users of any material breach within seventy-two hours of confirming it.

13 Changes to this Policy

When we make a material change we will publish the updated Policy with a new version number and effective date, and existing account holders will see a non-dismissable banner on the dashboard prompting them to review and accept the new terms before continuing. A full version history is preserved in our records.

14 Contact

Privacy questions, deletion requests, and legal notices go to ryan@thedevelopers.dev. Operator: Interactive Technology, LLC.

This Policy is provided for transparency and is not itself legal advice. Read it alongside our Terms of Service.