Skip to main content

What is stored

Your drafts and rewrites are not stored. Not for a retention window, not for training, not in a log. The text exists in memory for the length of the request and is gone when the response ends.

This page is the engineering version. The binding one is the privacy policy.

Not stored at all​

  • Drafts and rewrites
  • Protected spans
  • Prompts and model output
  • Help assistant conversations
  • Anything posted to /api/detect — the scoring happens in your browser and only the resulting numbers are sent

Stored, and for how long​

WhatHow long
Request metadata — tokens, cost, status, model tier90 days, deleted automatically
Detection records — scores and counts, never text90 days, deleted automatically
Support tickets180 days, deleted automatically
Rate-limit countersMinutes
Account, plan, usage countersUntil you delete your account
Custom templatesUntil you delete them
Voice profiles, and samples if you stored anyUntil you delete them
API keysUntil you revoke them
Connected accountsUntil you disconnect them or delete your account. Disconnecting deletes the stored credentials
What a connected account was used for90 days, deleted automatically. Never what you searched for or what a source said
Anonymous device cookie365 days

Expiry is enforced by the database, not by someone remembering to run a job.

The Chrome extension​

The extension is the surface with the most access, so it is worth being exact about what it does with it.

Checking never leaves your machine. The Check tab scores text in the panel itself — the same code the website runs, running in your browser. No request is made, no account is needed, and there is nothing to store because nothing is sent. Typing in that box with the network off works exactly as well.

Rewriting sends the text you asked to rewrite, to /api/humanize, under your API key. Same handling as everywhere else on this page: in memory for the length of the request, gone when it ends.

Stored on your device, and nowhere else: the API base URL and your API key, in chrome.storage.local. That is the entire list. It is local rather than sync deliberately — sync would replicate your key to every machine that browser profile touches. No draft, no rewrite, and no history is ever written; the panel forgets everything when you close it.

The page it can read. Content scripts run only on Gmail and LinkedIn, and only to find the composer, read what is in it, and write a rewrite back. The extension reads the active tab's hostname — not its URL, not its contents — to guess what kind of writing you are doing, and that guess is made in the panel. The hostname is not sent anywhere on its own.

What is reported back. Pressing Insert records that a rewrite was accepted, against the id of that rewrite. The text is not part of it. Copying is deliberately not reported.

Two things worth understanding​

The anonymous device cookie is signed and holds no identity. Its only job is to remember that this browser has used its three rewrites today.

IP addresses are hashed, never written down in a replayable form. They exist to make a per-network rate limit possible.

Voice profiles are the exception​

Every other feature is stateless with respect to your writing. A voice profile is not — that is the point of it.

  • A measured-only profile (Free) is computed in your browser and posted as numbers. No sample text reaches a server.
  • An inferred profile (Pro) requires storing the writing you gave it, because a model has to read it.

Deleting the profile deletes its samples. See Voice profiles.

What that means for you​

  • There is no draft history to export, because there is none to hold.
  • There is no draft history to delete, for the same reason.
  • If you need something removed, the things that exist to remove are your account, your profiles, your templates, and your keys.