Privacy Policy
This policy describes what HandtextAI ("we", "us") stores when you use HandTextAI Business at business.handtextai.com, how long it is kept, and who it is shared with. We try to keep it concrete: this is what the product actually does.
1. What we store
- Account data. Your email address, sign-in method (Google or email magic link), and session records. There are no passwords — we never store one.
- Content you create and upload. The text of your letters, cards, and envelopes; letterhead images; and mail-merge lists you upload, which typically contain third-party personal data such as recipient names and postal addresses. For recipient data you are the controller and we process it only to render your documents.
- Rendered files. The print-ready PDF, PNG, and SVG files the service produces for you.
- Payment metadata. Purchases run through Stripe. We store the pack, amount, credit ledger entries, and Stripe identifiers (customer, checkout session). We never see or store card numbers — those go directly to Stripe.
- Product analytics. Internal usage events (for example "first render") tied to your account, and per-render technical metadata (document type, style, paper, page count, timing, error codes) used for reliability and product decisions.
- Web analytics. The marketing site may use self-hosted, cookie-less analytics (Umami) that records aggregate page views. No advertising trackers, no data sold or shared with ad networks.
2. How long we keep it
- Rendered files are deleted 30 days after completion. The library keeps a record that the render happened (type, style, cost) after files are gone.
- Free previews are cached for about 48 hours, then deleted.
- Render request logs have their free-text content (letter text, recipient blocks) scrubbed after 30 days; only structural metadata remains.
- Mail-merge lists are kept until you delete them (or your account); the underlying files are then removed from storage.
- Sessions expire automatically and expired sessions are purged. Delivery logs for outbound webhooks are deleted after 30 days.
- Purchase and credit-ledger records are retained as long as accounting and tax law requires, even after account deletion.
3. Who it is shared with
We share data only with the processors needed to run the service:
- Stripe — payments and invoicing.
- Resend — transactional email (magic links, notifications).
- Google — only if you choose Google sign-in.
- Our hosting provider — the servers and storage the service runs on.
We do not sell personal data and we do not share it with advertisers.
4. Cookies
The dashboard uses a single first-party session cookie, strictly necessary for sign-in. The marketing site sets no cookies; its analytics (if enabled) are cookie-less.
5. Security
Traffic is encrypted with TLS. API keys are stored hashed. Download links for rendered files are signed and time-limited. Access to production data is limited to what operating the service requires.
6. Your rights
You can request access to, correction of, or deletion of your personal data by emailing [email protected] from your account email. Account deletion removes your saved letters, cards, and envelopes, lists (including recipient data), renders, sessions, and keys; financial records that must be retained for accounting are anonymized instead of deleted. If you are in the EU/EEA or UK you may also lodge a complaint with your supervisory authority.
7. Recipient data (for your mailings' recipients)
If your details appeared in a mailing produced with HandTextAI Business, the sender of that mailing chose and controls that data; contact them first. We hold it only as part of the sender's list and their rendered files, under the retention rules above.
8. Changes
We will update this policy when the product's data handling changes and adjust the date at the top. Material changes are announced to account holders by email or in the dashboard.
9. Contact
HandtextAI — [email protected].