Trust & Governance · Last updated June 2026
Security & Privacy Practices
A practical summary of how RewriteAIForMe protects the content you submit, the account you sign in with, and the metadata generated as you use the product.
Encryption
All traffic between your browser and our servers is encrypted in transit using current TLS versions. Stored content — including your drafts, rewrites, and account metadata — is encrypted at rest on managed infrastructure using provider-managed keys.
Access
Production data is accessed only by personnel with a specific operational reason, through audited administrative paths. We do not browse customer drafts. Engineers debug aggregated behaviour, not the substance of your writing.
Data minimisation
We collect what we need to run your account and improve the product, and not more. We do not enrich your account with third-party identity data, we do not load advertising trackers on the product surface, and we do not sell or share signals with data brokers.
Retention & deletion
Rewrites are stored in your private history so you can revisit and refine prior work. You can delete any rewrite individually, or request full account deletion from your settings; we process deletion requests within thirty days. Backups roll off on a defined schedule and are not used to revive deleted content.
Model providers
We work with leading model providers under zero-retention terms. Content you submit is forwarded to underlying models only for the duration of the request, is not retained by those providers, and is never used to train any model — ours or a third party's.
Incident response
If we identify a security incident that materially affects user data, we will notify affected account holders by email and post a public summary on the Transparency Center within the timeframes required by applicable law. We prefer to over-disclose rather than under-disclose.
Reporting a vulnerability
Security researchers can report suspected vulnerabilities through the contact page. Please describe the issue, the steps to reproduce, and the potential impact. We acknowledge reports within three business days and will not pursue legal action against researchers acting in good faith under common coordinated-disclosure norms.