Plain-English. Honest. The version of this document we'd write even if no regulator existed.
Both switches live in the app: Settings → Privacy & data on mobile, or Settings → Privacy on the web.
This policy covers the TextSight web app, browser extensions, mobile apps, and API — anything operated by Lacewing Technologies ("we", "us", "TextSight"). It doesn't cover third-party services that link to us.
We never sell your data, and we never share it with advertisers.
The short version: your text is scored by our own detection models, and for the rewriting and writing tools it is also sent to third-party AI providers in the US — Cerebras, Anthropic (Claude) and, for the web voice humanizer, OpenAI — which process it to generate your result and do not train on it. Scans are saved to your history by default so you can reopen them — switch that off with "Store my scan history", and delete any saved scan (or all of them) whenever you like. Your text is excluded from our model training by default — every account is opted out, and it stays that way unless you deliberately turn "Exclude my content from training" off.
Where it goes. To check a voice, the app uploads your audio over an encrypted connection to TextSight AI, where a machine-learning model analyses it. Nothing is analysed on your device. The model runs on our own servers — no other company receives your audio.
How long we keep it. The audio itself is never stored. It is held only for as long as the analysis takes and is then gone. What we keep is the result — the verdict, the confidence score, the filename and how long the clip was — in your scan history, until you delete it or delete your account.
What we never do with it. Your audio is never sold, never used to advertise to you, and never used to train a model. Audio that is never stored cannot become training data.
The microphone. The app asks for microphone access only so that you can record a clip to check. It records when you tap record, and at no other time. Before the first clip ever leaves your device the app shows you what is sent, who receives it and what happens to it afterwards, and asks you to allow it — you can withdraw that at any time under Privacy & data.
Analytics and crash reporting. The Truthring iOS app ships no analytics SDK and no crash-reporting SDK. The Firebase and Sentry integrations described under Data we collect apply to our other mobile apps and not to it.
A result is an estimate, not proof. Verdicts are statistical confidence scores from a machine-learning model. They can be wrong, and must not be the sole basis for any legal, academic or employment decision.
Our Google Workspace add-on reads the document you have open in Google Docs, and only when you ask it to by pressing Scan or Humanize. It uses the documents.currentonly permission, which means it cannot see any other file in your Google Drive, cannot list your files, and cannot read your Gmail.
Document text sent from the add-on is processed to return your result and then discarded. If you are not signed in to a TextSight account, nothing from the add-on is stored at all. If you are signed in, the scan saves to your private history exactly as a scan made on the website would, and the same controls apply.
| Purpose | Legal basis |
|---|---|
| Running your account | Contract (Art. 6(1)(b)) |
| Billing & tax | Legal obligation (Art. 6(1)(c)) |
| Product analytics | Legitimate interest (Art. 6(1)(f)) — anonymous & aggregated |
| Marketing emails | Consent (Art. 6(1)(a)) — opt-in only |
| Abuse prevention | Legitimate interest (Art. 6(1)(f)) |
These are the sub-processors we use. The Your text? column is the one that matters most: it says whether that vendor can see the content you submit, or only your account and usage data.
| Vendor | Purpose | Your text? | Location |
|---|---|---|---|
| Cerebras | The AI model that generates most rewrites in the humanizer. We use a paid API tier; Cerebras processes your text to return the rewrite and does not use it to train models. | Yes | US |
| Anthropic (Claude) | The AI model behind paraphrasing, summaries, grammar, citations and plagiarism-risk checks, a fallback for humanizing when the primary model is unavailable, and a backup scorer when our own detector is unavailable. Anthropic does not use it to train their models. | Yes | US |
| OpenAI | The AI model behind the voice humanizer on the web app, and a fallback scorer when our own detection models are unavailable. Not used by the mobile apps. OpenAI does not use API content to train their models. | Yes | US |
| Hetzner | Servers running our own AI-detection models | Yes | Germany |
| Vast.ai | Rented GPU running our own AI-detection models | Yes | US / EU |
| DigitalOcean | API hosting | Yes (in transit) | US |
| Supabase | Database — your account and your saved scan history | Yes (saved scans) | US |
| Vercel | Web app and website hosting | No | Global edge |
| Cloudflare | DNS, DDoS protection | No | Global edge |
| Stripe | Payments (web) | No | US |
| RevenueCat | Subscriptions bought inside the mobile apps | No | US |
| Apple / Google | App Store and Play billing, and sign-in if you use it | No | US |
| Postmark | Transactional email | No | US |
| PostHog Cloud | Product analytics | No | US |
| Sentry | Error logging (no submitted text is attached to reports) | No | EU |
| Google Firebase | In the mobile apps only: crash reports (Crashlytics), which screens are opened and which features are used (Analytics), how long requests take (Performance), and the settings that let us change the app's behaviour without shipping an update (Remote Config). Your submitted text is never attached to any of it. | No | US |
What we require of them. Every vendor above is engaged under a written data-processing agreement that obliges them to protect your data to at least the standard set out in this policy: to process it only on our documented instructions, to keep it confidential and secure, not to use it for their own purposes or to train their own models on it, to engage sub-processors only under equivalent terms, and to delete or return it when the service ends. Where a vendor is outside the EEA or the UK, those transfers are made under Standard Contractual Clauses.
We do not share data with anyone else — including law enforcement — without a valid legal order. When we do, we tell you (unless legally gagged).
You have the right to:
To exercise any of these, email privacy@textsight.ai. We respond within 72 hours; we resolve within 30 days.
We use the minimum number of cookies needed to keep you logged in and tell us aggregate funnel info. Full cookie policy →
TextSight is not directed to children under 13. If you're 13–18, you can use the service with parental consent. We don't knowingly collect data from children under 13; if you believe we have, email privacy@textsight.ai and we'll delete it.
We process data in both the EU and the United States — see the Location column in the table above for where each vendor sits. Our detection models run in Germany (Hetzner); our database, API and AI providers are in the US. Where personal data is transferred outside the EEA or the UK, we rely on Standard Contractual Clauses (2021/914) and additional safeguards.
We may update this policy as we change the product. Material changes get notified 30 days in advance by email. Cosmetic edits (typo fixes, clarifications) don't trigger a notice. We do not yet publish an archive of past versions; if you need the wording as it stood on a particular date, email privacy@textsight.ai and we will send it to you.
Privacy questions, DPA requests, GDPR rights:
We have not appointed a Data Protection Officer. We are not required to under GDPR Art. 37, and we would rather say so than name one we do not have. Privacy requests go to the address above and are handled by the founder.
We have not yet appointed an EU or UK representative under GDPR Art. 27. If you are an EU or UK data subject, contact us directly at privacy@textsight.ai and we will handle your request without one.