Privacy policy

Last updated: September 7, 2026

The privacy of your data — and it is your data, not ours — is a big deal to us. In this policy we lay out what data we collect and why, how it is handled, who else sees it, and your rights with respect to it. We never sell your data.

This policy applies to DetEdit, operated by ESILEVICH SOFTWARE UNIPESSOAL LDA (“we”, “us”), including the desktop application, the web application at detedit.ai, and the website itself.

What we collect and why

Our guiding principle is to collect only what we need.

Identity and access

When you create a DetEdit account we ask for your email address, and store a password that is hashed and never kept in readable form. If you sign in with Google instead, we receive your email address, name, profile picture URL, and the identifier Google uses for your account; we do not receive your Google password and we do not read your Gmail, Drive, or any other Google data.

We use your email address to sign you in, to verify your address, to let you reset your password, and to send you essential information about the service. We will only send you product news or other optional email if you ask for it.

Your documents and chat messages

DetEdit stores the documents you upload or create in the app, together with the chat messages and the results of the AI actions you run on them. This is the content the product exists to work with; we keep it so that it is available to you across sessions and devices. It stays until you delete it, or until you delete your account.

You can also work on documents that are only stored on your own machine. Those never reach our servers unless you use an AI feature on them, which necessarily sends the relevant text for processing (see below).

Settings and AI actions

We store your application settings on our servers so that they follow you between devices, along with the list of AI actions available in the editor, including any action you create or edit yourself and the prompt text it runs. Documents keep their own settings in the same way.

AI processing

When you run an AI action, ask a question in chat, or use any other AI feature, the text that the feature needs — the selected text, the document, or the conversation so far — is sent to OpenAI, which runs the model that produces the result. OpenAI processes this text on our behalf as a sub-processor under a data processing agreement. Under OpenAI’s API terms this content is not used to train their models; OpenAI retains it for a limited period for abuse monitoring, and stores the conversations belonging to your chat sessions until we delete them.

For chat sessions, the conversation history is held on OpenAI’s side so that the assistant can refer to earlier messages. Deleting a chat session deletes that conversation as well, and deleting your account deletes all of them.

Usage and service data

We record how much you use the service so that we can operate it: the number and type of AI requests, the model used, the number of tokens consumed and their estimated cost, the amount of document storage you use, and the days on which your account was active. We keep a short record of each API request — the operation, an identifier, and a hash of the payload — so that a request interrupted by a network failure is not executed twice.

Security and sign-in records

For each signed-in device we store a hashed session key, the device name, the browser or client user agent, the IP address the session was created from, and when it was last used. This lets you see and revoke your active sessions and lets us detect account abuse. Our servers also produce ordinary operational logs, which include IP addresses.

Website analytics and cookies

On our website we use Google Analytics to understand how visitors find and use the site — which pages they open, how long they stay, which site referred them, the approximate location derived from a truncated IP address, and the browser and device type. Google Analytics sets cookies in your browser to recognise a returning visit.

These cookies are not set until you agree to them. When you first visit the site you are asked whether to allow analytics cookies; if you decline, or ignore the banner, none are set and we receive no analytics data about your visit. You can change your choice at any time through the cookie settings link on the site, and you can delete the cookies in your browser at any point. We do not use advertising or cross-site tracking cookies.

The applications themselves — the desktop app and the web app — do not use tracking cookies. The web app stores your sign-in key and your preferences in your browser’s local storage so that you stay signed in; that data never leaves your browser except as the sign-in header sent to our own servers.

Voluntary correspondence

When you email us with a question or for help, we keep that correspondence, including your email address, so we have a history to refer to if you contact us again.

When we access or disclose your information

To provide the service. We use a small number of sub-processors, each under a data processing agreement:

Sub-processorPurposeLocation
OpenAIAI processing of document text and chat messagesUnited States
BrevoTransactional email (verification, password reset)European Union
GoogleSign in with Google, if you choose to use itUnited States
Google AnalyticsWebsite usage statistics, only with your consentUnited States
[hosting provider]Application and database hosting[location]

No one at ESILEVICH SOFTWARE UNIPESSOAL LDA reads your documents except in limited cases with your explicit permission — for example when you ask us to look into a problem with a specific document — or where we are legally required to (see below).

When required under applicable law. We will disclose information if we are compelled by valid legal process. Our policy is to notify you before we do so, unless we are legally prohibited from notifying you.

Aggregated and de-identified data. We may use aggregated statistics that cannot identify you — for example the total number of AI requests per day — for capacity planning and reporting.

If the company is acquired. If ESILEVICH SOFTWARE UNIPESSOAL LDA is acquired by or merges with another company, we will notify you before any personal information is transferred or becomes subject to a different privacy policy.

Your rights with respect to your information

Wherever you live, we apply the following rights to your data:

  • Right to know and to access. You can ask what personal information we hold about you and obtain a copy of it.
  • Right to correction. You can ask us to correct information that is wrong, and you can change your account details yourself in the application.
  • Right to erasure. You can delete individual documents and chats in the application, and you can delete your account, which removes your content from our systems and from OpenAI.
  • Right to portability. You can export your documents from the application at any time.
  • Right to object and to restrict processing. You can object to processing based on our legitimate interests, and ask us to restrict processing in the cases the law provides for.
  • Right to complain. You can lodge a complaint with your data protection authority.
  • Right to non-discrimination. Exercising these rights never costs you a different price or a lower level of service.

To exercise any of these, write to contact@detedit.ai. We answer within one month. We may need to verify your identity first, normally by confirming control of the account’s email address.

The legal bases on which we process your data are: performance of our contract with you, for your account, your documents, your chats and the AI features; our legitimate interests, for security, abuse prevention and operational logs; your consent, for anything optional such as newsletters; and compliance with legal obligations, where the law requires us to keep records.

How we secure your data

All traffic between the application and our servers is encrypted with TLS. Passwords are stored as salted hashes, and API session keys are stored as hashes rather than in usable form; neither can be recovered from our database. Database backups are encrypted. Access to production systems is limited to the people who need it to operate the service.

What happens when you delete content

Deleting a document removes it from our database. Deleting a chat session removes its messages and deletes the corresponding conversation held by OpenAI.

Deleting your account removes your documents, chats, sessions and account record, and deletes your conversations at OpenAI. Copies may remain in encrypted database backups for up to 30 days, after which they are overwritten by the backup rotation. We do not restore deleted data from backups.

Data retention

DataRetention
Documents, chats and AI resultsUntil you delete them, or you delete your account
Settings and AI actionsUntil you delete them, or you delete your account
Conversations held at OpenAIDeleted with the chat session or the account
Account recordLife of the account, purged within 30 days of deletion
Sign-in sessionsUntil revoked or expired
Server and security logsUp to 90 days
Usage and quota recordsRetained in aggregated form for capacity planning and reporting
Website analytics data14 months
Analytics cookiesUp to 13 months, or until you delete them
Backups30-day rotation
Correspondence with supportUp to 2 years

OpenAI additionally retains API request data for up to 30 days for abuse monitoring under its own terms as our processor. We cannot delete those records earlier.

Location of site and data

DetEdit’s servers and database are operated in [location]. If you are outside that country, the information you provide is transferred there, and to the sub-processors listed above, in order to provide the service.

When transferring personal data from the EU

Personal data transferred out of the EU must receive the same level of protection that EU law grants. Where our sub-processors are outside the EU — OpenAI and Google are in the United States — transfers are covered by the Standard Contractual Clauses in our agreements with them, and by their certification under the EU-US Data Privacy Framework.

Changes and questions

We may update this policy to reflect changes in the service or in the law. When we make a significant change we will update the date at the top of this page and take other appropriate steps to notify you.

Questions, comments or concerns about this policy, your data, or your rights? Write to contact@detedit.ai and we will be glad to answer.


Adapted from the 37signals policies, used under CC BY 4.0. Modified for DetEdit: the data categories, sub-processors, retention periods and AI-processing sections describe ESILEVICH SOFTWARE UNIPESSOAL LDA’s own practices and are not those of 37signals.