Privacy
This notice describes what the service does today. Parts of the product are previews that store nothing; they are named below. It will be revised when they are connected.
Last updated
Who is responsible for your data
The controller is Bahri Labs, a société par actions simplifiée with its registered office at 47 rue Vivienne, 75002 Paris, France, registered under number 109 283 416.
Write to privacy@genpolish.app to exercise a right, or to contact@genpolish.app for anything else. The postal address above remains a formal route. The full publisher identification is on the Terms page.
What happens to the text you submit
Five of the tools never send anything. Inspecting, cleaning, comparing and counting text all happen in your browser, and nothing leaves it.
When you write a draft on the home page and continue in the editor, a cookie carries a short opaque handle. The text itself stays in server memory for ten minutes and is never written into the cookie.
Asking for a rewrite is the one action that sends your draft to our server. No rewriting provider is contacted at all unless one is configured, and there is no default provider in the code — we do not send your text to a third-party model vendor today.
While a rewrite is in progress, the working draft is stored for at most twenty-four hours and the result for at most twenty-four hours after the rewrite ends. The operation record itself keeps only cryptographic digests of your text, never the text.
History, and the ninety-day limit
If you have an account, a successful rewrite is saved to your history with the original and the result in full. Entries expire ninety days after they are created.
That limit is not a policy written on a page. It is a database constraint: a row cannot be written with any other expiry. You can delete an entry yourself at any time, and deleting your account removes the whole history with it.
Successes obtained without an account never enter this history, even if you create an account afterwards and claim the workspace. There is no backfill.
What we store about your account
Your name, your email address, whether it has been verified, and your plan. Passwords are never stored in readable form. Tokens sent in email links are stored hashed, not in the clear.
A session lasts up to seven days and is not extended by reading it. No IP address is recorded with a session: the identity layer is explicitly configured not to track one. The browser user-agent string may be stored alongside a session.
Visiting without an account
A cookie identifies an anonymous session for thirty days and carries a free trial of three successful rewrites. The server keeps only a digest of the secret, the state, the count and the expiry. No text is attached to it.
Your text is not analytics data
Drafts, rewritten results, text fingerprints, document titles, names, email addresses, passwords, payment identifiers and raw URLs are excluded from analytics. We do not install advertising trackers, session recording, heatmaps or automatic form capture.
The five browser-only tools are excluded from tracking even if you accept analytics elsewhere. Their text processing stays in your browser. The AI rewriter sends the draft to the rewriting service when you explicitly request a rewrite; that is separate from optional analytics.
What you can choose to share
Optional analytics is off by default, in the site and in the API, and requires an explicit server setting before it runs at all.
With your agreement, GenPolish records a small set of events such as a rewrite starting or succeeding, account creation, a visible paywall and a confirmed payment. Events use a random measurement identity and closed categories, not the contents of your fields. We do not retain IP addresses or browser fingerprints in analytics.
Events stay in our PostgreSQL analytics journal. Our self-hosted Metabase dashboard can read only aggregate reporting views, not your account or text records. There is no third-party analytics recipient.
Duration and withdrawal
Your explicit choice is remembered for up to six calendar months, without silently extending it on each visit. Events and private attribution are retained for at most ninety days. The conversion funnel uses a thirty-day window and represents consented, observed journeys, not all visitors or all devices.
You can refuse without losing access to any tool. Withdrawal stops collection in this browser immediately and, once the server confirms it, revokes pending attribution and excludes the associated data from reports immediately. Periodic cleanup then erases these records. If the server cannot confirm, the preferences below let you retry. New consent does not restore old events.
Deleting your account removes its linked analytics data. Application drafts, revision history and billing records have separate purposes and lifetimes. De-identified reporting is not a substitute for those business records.
IP addresses and logs
Our server sees your IP address in order to apply a per-minute request limit. It lives in a counter held in memory, which is reset when the process restarts. It is not written to the database, and it is not written to our logs.
Our log records have a fixed shape with no field for an address, a request body or a raw URL, so they cannot carry one.
This describes our application. It does not describe the network logs of our hosting provider, OVH, which operates the datacentre and sees traffic reach the machine before we do. Those logs are theirs, kept under their own terms, and we neither read them nor control how long they are held.
Your rights, and what you cannot do yet
You can withdraw consent to analytics at any time, from the controls below or from any page that shows them. You can delete a history entry yourself. Retention deletes the rest on a schedule you do not have to ask for.
Three things do not work yet, and we would rather write that than list a right you cannot exercise. Deleting your account from the interface is not connected. Correcting your name or email address from the interface is not connected. There is no export of your account or your history.
These are gaps in the product, not positions. They are recorded as such, and this notice will be revised when they close.
What we do not do
No advertising trackers, no session recording, no heatmaps, no automatic form capture, no third-party analytics, no cross-site tracking, and no consent banner because none is needed.
We do not sell data. We do not train models on your text. We hold no certification, and we do not display a badge suggesting otherwise.
Optional analytics
Help us measure the journey from a visit to rewriting and payment. Only explicit usage events are kept in our self-hosted statistics; never your drafts, results or email. The five browser-only tools are not tracked.
Privacy and analytics preferences