Last updated: August 31, 2026
1. What Information We Collect
When you use WerdSpark, we collect:
- Account data: email address and password (hashed). Optional Google sign-in, if you use it.
- Generation inputs: the situation, recipient, and tone you provide, used to produce your message.
- Technical data: IP address, browser type, and device information, used for security and rate limiting.
- Payment data: processed entirely by Stripe. We do not see or store your card number.
- Session cookies: a signed session token only. No third-party advertising or tracking cookies.
2. How We Use Your Information
- Generate your messages
- Process payments and manage your account tier
- Prevent abuse, fraud, and rate-limit abuse
- Operate and improve the Service
- Comply with legal obligations
3. Message Processing and Where It Goes
Messages are generated by a local AI model first. If that local model is unavailable and an external provider is configured for that deployment, your prompt (situation, recipient, tone) may be sent to that provider solely to produce the message. We do not use your message content for model training and we do not sell it. In the current production configuration the local model is used.
4. Data Retention
- Message content: not retained as a record after it is generated and returned to you.
- Session tokens: expire automatically (30 days).
- Account and purchase records: retained while your account exists and as required for payment and legal obligations.
5. Who We Share Data With
- Stripe: payment processing. See Stripe’s privacy policy.
- Google: only if you sign in with Google. See Google’s privacy policy.
- An external AI provider: only if configured for a deployment and the local model is unavailable, and only to generate your message. See OpenAI’s privacy policy where applicable.
- Legal authorities: only when required by law.
6. Security
- HTTPS/SSL encryption for all data in transit
- Security headers via Helmet.js
- Rate limiting to prevent abuse
- Input validation to prevent injection
7. Your Rights
EU users (GDPR)
You have the right to access, correct, delete, export, and withdraw consent for your personal data.
California users (CCPA)
You have the right to know what personal information is collected, to delete it, and to opt out of selling or sharing. We do not sell your personal information.
Exercise any right by contacting [email protected].
8. Children (COPPA)
The Service is not intended for children under 13. We do not knowingly collect personal information from children and comply with COPPA.
9. Changes to This Policy
We may update this policy and will note the date above. Material changes will be announced on the site.
10. Contact
Privacy questions: [email protected]