aiStructEditor
Privacy Policy
This Privacy Policy ("Policy") explains how aiStructEditor ("we", "the Service") processes personal data when you use the aiStructEdit web application and related pages. This Policy forms part of your agreement with us together with the Terms and Conditions.
1. Operator and contact
Data controller: aiStructEditor.
Privacy inquiries, deletion requests, and data subject rights: legal@aistructedit.com. We respond within timeframes required by applicable law.
2. Scope
This Policy applies when you register, sign in, use the editor, cloud storage (paid plans), subscription checkout, and AI settings.
By using the Service, you acknowledge this Policy. If you disagree, do not use the Service. The Service is not intended for anyone under 18.
3. Data we process
We may process the following categories:
- Account data: email address, user ID, OAuth provider data (e.g. Google) when you use social sign-in.
- Profile data: display name, interface language, appearance preferences.
- Content: projects, documents, sections, editor settings — in the cloud (Pro/Ultra) or locally in your browser (Free).
- AI settings: chosen provider, API keys, and parameters you save in the Service.
- Subscription data: plan, expiry, payment order IDs and amounts, blockchain transaction hash (TRC20), payment status.
- Technical data: IP address, browser type, cookies, hosting logs — as needed for operation and security.
4. Purposes
We process data to:
- register, authenticate, and manage your account;
- provide editor features, cloud sync, and plan limits;
- process payments and activate subscriptions;
- store your settings and content;
- send service messages (email confirmation, password reset);
- maintain security, prevent abuse, and improve the Service;
- comply with applicable law.
5. Legal bases
Processing is based on: performance of the Terms and Conditions; your consent (e.g. at registration or when saving an API key); our legitimate interests (security, subscription accounting); and other grounds required by law, including GDPR where applicable.
6. Storage and location
On the Free plan, projects and settings may stay in your browser (localStorage) and are not sent to our servers until you use cloud features.
Cloud account, profile, and document data is stored in Supabase infrastructure. The app is hosted on Vercel. Processor servers may be located outside your country.
AI API keys are stored encrypted in the database and used only to fulfill your requests to the chosen provider.
7. Third parties
We do not sell personal data. We may share data with the following — only as needed to run the Service:
- Supabase — authentication, database, profile and cloud content storage.
- Vercel — web app and server route hosting.
- Google — OAuth sign-in (if you use it).
- TronGrid — verification of incoming USDT (TRC20) crypto payments via public blockchain data.
- AI providers (OpenAI, Anthropic, etc.) — only when you provide an API key and initiate a request; request data is handled under the provider's policy.
8. Sensitive information in content
You decide what to include in documents and prompts. Do not place third-party personal data, payment details, passwords, or other sensitive information in the Service without necessity and a legal basis.
The Service is not designed to process special categories of personal data (health, biometrics, political views, etc.). If you upload such data anyway, you do so at your own risk and responsibility.
9. AI features
Parts of your documents and prompts may be sent to your chosen AI provider for responses, analysis, or graph generation. You are responsible for what you send and for complying with the provider's terms.
We do not use your content to train our own models.
11. Retention
Account data is kept while the account is active. After deletion or upon request, we delete or anonymize data within a reasonable period unless longer retention is required by law (e.g. payment records).
Hosting logs are retained for limited periods defined by infrastructure providers.
12. Security
We use organizational and technical measures including HTTPS, database row-level security, and separation of public and server credentials. No method of transmission over the Internet is 100% secure.
If we identify an incident affecting personal data, we will take reasonable steps to notify users and authorities where required by law.
13. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, or withdrawal of consent. Contact us at the email above. We will respond within legally required timeframes.
You may lodge a complaint with a supervisory authority if you believe processing violates your rights.
14. Automated decision-making
We do not make decisions with legal or similarly significant effects on you based solely on automated processing of personal data.
15. Age restrictions
The Service is not intended for anyone under 18. We do not knowingly collect their data. If we become aware of such data, we may delete the account.
16. Changes
We may update this Policy. The current version is published on this page with the date below. Material changes may also be communicated through the Service.