Skip to content
Cothyra

Privacy Policy

Last updated: 2026-08-11

This Privacy Policy explains what data Cothyra collects, why, and how it's used. We collect only what we need to run the Service and we don't sell anything to advertisers.

1. Account data

Accounts are managed by us directly — there is no external identity provider. What we store depends on how you sign in:

  • Email and password: your email address and a salted hash of your password (we never store the password itself). Verification and reset codes we email you are stored hashed and expire quickly.
  • Google or GitHub: those providers share your email, display name, and a unique ID with us when you authorize the sign-in. We store these; we never receive your password.
  • In all cases we keep your email, a display name, and a unique account ID so we know which content belongs to you.

2. Your content

  • Books, chapters, notes, and edits you create are stored on our servers and in your browser's IndexedDB cache.
  • Chat transcripts with the AI are stored per-session for your reference; you can delete them at any time.
  • We don't read your content for any purpose other than making the Service work — with one narrow exception: we may review specific content when investigating an abuse report, a security incident, or a suspected violation of the Terms. We don't share it with anyone outside the AI providers needed to fulfill your request.

3. AI processing

When you ask the AI a question, the relevant text (your prompt and the chapter content you're working on) is sent to the third-party provider of the model you selected — the available providers currently include Anthropic, OpenAI, Google, xAI, DeepSeek, and MiniMax. These providers process the request and return a response. Per their policies as documented in August 2026, paid API tiers are not used to train their models, though several retain prompts briefly for abuse monitoring (OpenAI, for example, documents ~30-day retention) — their linked policies below are authoritative and may change. If you enable OCR for scanned PDFs (off by default), those documents are sent to Mistral for text extraction.

Which provider receives your text is your choice of model, so each one's privacy and data-retention terms apply alongside ours:

The model picker in the app is the authoritative list at any moment; we update this page when the set of providers changes.

Practical advice: treat anything you type or import as text that will be sent to the provider of the model you select. Don't include data you wouldn't share with that provider — credentials, card numbers, medical records, or other people's sensitive personal data (see also Terms, "Your content").

4. Legal bases

Where GDPR or similar law applies, we process personal data on these bases:

  • Performance of a contract: running your account, storing your content, executing AI requests, billing and credits.
  • Legitimate interests: security monitoring, operational logs, abuse prevention, and defending legal claims.
  • Consent: optional features you switch on — OCR, third-party connections, and selecting an AI provider that processes data outside your region (see the next section). You can withdraw consent by turning the feature off or choosing a different model.
  • Legal obligation: retaining billing records for accounting law.

5. International data transfers

Our servers are currently hosted with Alibaba Cloud. The AI providers you can select operate from different jurisdictions — including the United States (Anthropic, OpenAI, Google, xAI) and China (DeepSeek, MiniMax; the Qwen models run on Alibaba Cloud Model Studio). Some of these countries have no data-protection adequacy decision from the EU/UK. Where that is the case, the transfer of your prompt and chapter text happens at your direction and with your consent — you choose the model, the app tells you where a provider processes data before you first select it, and you can use a different provider at any time. If you do not want your text processed in a particular country, do not select models from providers based there.

6. Payment data

We do not see, store, or process your card details. Payments are handled entirely by our merchant of record (Paddle.com), who collects what they need and shares only the result with us — your user ID and the credit amount to apply. Their privacy policy: paddle.com/legal/privacy.

7. Operational logs

  • HTTP request logs (path, status code, timestamp) for debugging and security monitoring. Retained ~90 days.
  • Per-AI-call billing records (timestamp, model, token counts, cost) for transparency and dispute resolution. Retained as long as your account exists.
  • No third-party analytics or advertising trackers.

8. Cookies and local storage

We set one functional cookie, which keeps you signed in. Beyond that, the app stores data locally in your browser so it loads fast and works offline:

  • Copies of your own content — books, chapters, notes, edit history, images, and generated audio — cached in your browser (IndexedDB);
  • Interface preferences such as theme, language, panel layout, and recent searches (local storage);
  • The app's own code and assets (service worker cache), so pages open offline.

All of this exists solely to deliver the service you signed in for. None of it is used for tracking, advertising, or analytics, and nothing about your browsing is shared with anyone — which is why there is no consent banner: consent rules (including the EU ePrivacy rules) apply to non-essential storage, and we set none. Clearing your browser data removes these local copies and signs you out; your content remains on our servers.

One exception involves a third party: when you open the payment checkout, Paddle (our merchant of record, see section 6) loads its own script and may set its own cookies for fraud prevention and checkout continuity. That happens only when you start a purchase, never while you read or write.

9. Data retention and account deletion

Your books and chats stay until you delete them or your account. Deleting your account (account menu → "Delete account") takes effect immediately and permanently removes:

  • All your content — books, chapters, edit history, chats, notes, images, and settings;
  • Your account record and credentials, and every active session on every device;
  • Connections to third-party services (we also revoke the tokens with the vendor where their API allows it), and any public share links you created.

Deletion removes your data from live systems immediately; residual copies in short-lived operational backups age out within about 30 days and are never restored to production. Two things survive deletion: billing records (purchases and usage), which we retain for accounting purposes under an account ID that no longer identifies you (typically 7 years where the law requires it), and any feedback messages you sent us, which are kept with your email address and diagnostic details removed. Server logs roll off after ~90 days. Copies of your content cached in your own browser remain on your device until you clear them.

10. Your rights

Depending on where you live (GDPR for EU/UK, CCPA for California, similar elsewhere) you may have the right to access, correct, delete, or export your data. The last two are self-service in the app, no request needed:

  • Export: account menu → "Download my data" gives you a zip of everything we hold — your profile, billing history, feedback, and all your content in its original files.
  • Deletion: account menu → "Delete account", as described in section 7.

You also have the right to lodge a complaint with your local data-protection supervisory authority. For anything else — or if you'd rather we handle a request for you — email [email protected] and we'll respond within 30 days.

11. Security

Data is transmitted over HTTPS. Stored data is access-controlled to the operator. We're a small operation, so we don't run a SOC 2 program — but we do follow standard practice (no shared accounts, no plaintext credentials in logs, regular dependency updates).

12. Children

The Service isn't intended for users under 13. Don't sign up if you are.

13. Changes

We'll update the date at the top when we change this. Material changes will be announced via email.

14. Contact

Privacy questions: [email protected].