Skip to content

Privacy

What Typoza collects, what it does with it, who it transmits it to, how long it keeps it, and how you take it all back or have it all erased.

Last updated: September 29, 2026 — This date is derived from our list of subprocessors. It changes as soon as that list changes.

This page translates the French original, which is the version that prevails in case of difference.

The principle

Typoza is a writing tool. It collects what is needed to open an account, publish a site and bill for it — nothing more, and nothing serving any other purpose.

  • No sale of data, to anyone, in any form.
  • Every company that keeps data for us is named, with what it receives and where it hosts it.
  • No analytics cookie on a workspace's public site.
  • No training of artificial intelligence models on your text: not at our provider, and — by default — not by the crawlers that visit your site.
  • No access on our part to the content of your drafts, absent a legal order.

What we collect

Six families, and what the sections below describe.

  • Your account: name, email address, hashed password — never readable, including by us. If you sign in with GitHub, the public name, email address and avatar URL that GitHub transmits to us.
  • What you write: posts, pages, drafts, successive versions, uploaded images and files, workspace settings.
  • What is billed: billing address, country, subscription history. Your card details are entered at Stripe and never reach us.
  • Your workspace newsletter's subscribers: their email address, the date they confirmed, the cadence they chose. Those addresses are yours, not ours — we host them for you, and the next section says exactly what happens to them.
  • Your readers, when they react or comment under your posts: their email address, the name they chose, what they wrote and the date they confirmed. What is shown and what is not is said in the section on reactions and comments.
  • Your notifications: what happened in your workspaces — a post submitted, a comment, an invitation — and whether you read it. And, only if you switched them on, the subscription address of each device you want us to send those notifications to.

Where it is kept

Typoza runs on Vercel, in its Paris region. What it keeps is entrusted to three companies: Prisma Postgres keeps the database — accounts, texts, subscribers, statistics —, Vercel Blob the files — images, attachments, encrypted backups —, and Upstash, for a few minutes or a few hours, the counters that limit sending and a copy of the public map of workspaces. Vercel, Prisma and Upstash are American companies.

Some companies receive part of it to do one job each: delivering an email, taking a payment, rewriting a paragraph you asked us to rewrite. Each one, with what it receives and where it operates, is listed on the Subprocessors page.

The newsletter, and what happens to its subscribers

A workspace may offer a newsletter to its readers. The people who subscribe are not our customers: they are the workspace's, and we merely carry out what the workspace asks. We never write to them on our own initiative, and we reuse their addresses for nothing — not for another newsletter, not for Typoza.

  • Nothing goes out without a double opt-in: a newly entered address receives one message only, the one asking it to confirm. Until that link is clicked, it receives nothing else, ever.
  • Every send goes through Resend, our delivery provider, which receives the recipient's address and the message's content: the titles, excerpts and links of the posts concerned.
  • Resend reports back what became of the message: delivered, rejected by the recipient's server, delayed, or marked as spam. An address permanently rejected, or one that reports us, drops out of later sends with nobody having to intervene.
  • We do not measure opens. Doing so would require an invisible image in every message, telling the sender when you opened it and from which IP address. We measure visits without cookies; opening that door by email would contradict us.
  • Every send carries, in its footer and in its headers, the means to change its cadence, pause it or leave. Your mail client's unsubscribe button works, and it works in one click.
  • The log of a send — which post went out on which day, to whom, and what became of it — is erased after twelve months by a task that runs nightly.

A workspace's contact page, and what gets written there

A workspace may open a contact page on its site. What you write there is not addressed to us, but it is kept: your message opens a conversation the workspace reads and answers, and an exchange nobody keeps is an exchange nobody can come back to. We host it; the workspace answers for it.

  • The form asks for a name, an email address and a message, and nothing else. Your name, your address, the text of your messages and their dates are kept for as long as the workspace keeps the conversation.
  • Your address is not handed over so the workspace can write to you elsewhere: it is shown in the notification it receives, and it serves to carry its replies to you. Nor does it ever see your address in a “reply to” — an address of ours carries both directions.
  • Every reply that reaches you carries a link to your conversation: you can read it again, answer, and end it without creating an account. Ending it cuts the return paths; the form itself stays open.
  • The form is rate-limited per IP address and per workspace. That limit says nothing about what you wrote, and is held only long enough to count.
  • The registered office shown on that page is the workspace's, not yours. The map beside it is an image we produced once: opening it contacts nobody, and your browser speaks to no mapping provider unless you choose to open the address in a maps application.
  • That choice is entirely yours. The links offered — Apple Maps, Google Maps, OpenStreetMap, Waze — open only on a click, in a new tab, and it is then the service you picked that sees you arrive, under its own policy.

Reactions and comments under a post

A workspace may let its readers react to its posts and comment under them. Those readers are the workspace's, not ours, and a comment is addressed to the workspace, in public. We host it; the workspace answers for it.

  • Nothing appears without a confirmed address. The first reaction or comment from a browser sends a single message, a link to click; the click publishes what was waiting. What nobody confirms is erased after seven days, along with the address if it carries nothing else.
  • A published comment is part of the page: anyone can read it, search engines included. It shows the name the reader chose, the text, its date and, for a reply, the name it answers. Never the email address — not on the site, not in the page's code, not in the notice the author receives.
  • A reaction is counted, not signed: under the post, readers see how many chose each of the six, never who.
  • The address serves to confirm and — only if the reader ticked the box — to say someone replied. Those messages go through Resend, like all of ours, and each reply notice carries the link that stops them.
  • Once confirmed, the reader is recognised on that site by one cookie, for six months — the Cookies page lists it. “Not you?”, under the form, forgets it on the spot.
  • Reactions and comments are rate-limited per IP address and per workspace. That limit says nothing about what was written, and is held only long enough to count.
  • Closing comments, under one post or for the whole workspace, takes them off the pages without erasing them. To have one of yours erased, write to contact@typoza.com.

Before a comment appears, it goes through a filter of our own — rules we can read, no artificial intelligence and no outside service. It adds up signals that nobody typed the comment by hand, or that it advertises: a hidden field filled in, a form sent in two seconds, links, the same text sent to other workspaces, a disposable address, a burst of sends, a term the site refuses. From that score, the comment appears, waits for a person at the workspace to read it, or is set aside.

  • What only robots do is set aside without a word, and the source is blocked for twenty-four hours, then seven days, then thirty. These automatic blocks hold a keyed fingerprint of the IP or email address, never the address itself, and never a named person.
  • Every other refusal is explained. A comment refused for a term, or taken down by the workspace, earns its author an email that says why, whether a filter or a person decided, and how to ask a person for a second look.
  • Any reader can report a comment from under it. A name and an address are optional; with an address, the reader receives an acknowledgement, then the workspace's decision. A person at the workspace examines every report.
  • The workspace can block a reader for good: that reader can no longer comment or react on its site. It is always a person's decision, notified with its reason, and the workspace can lift it.
  • To spot bursts, we keep a keyed fingerprint of the IP address for thirty days. A comment set aside as spam is erased after thirty days; a report, twelve months after its decision. The retention table below gives every duration.

Notifications on your devices

You can ask to be alerted on your phone or computer when something happens in one of your workspaces. It is optional, off until you ask for it, and undone in one click from your settings.

  • Switching on notifications registers the device with your browser's service: Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge. We do not choose which — your browser gives us the address to write to.
  • That service receives the address, the date of each send and our server's IP address. It receives nothing of what the notification says: the title, the sentence and the link are encrypted with a key only your device holds. It carries a sealed envelope.
  • With notifications off, none of those four services is ever contacted about you.
  • Removing a device erases its subscription. It also disappears on its own if you uninstall, clear the browser's data or withdraw the permission: the push service tells us, and the record goes.
  • What happened in your workspaces stays readable in Typoza for six months, whether or not you switched notifications on, then is erased nightly.

The directory, and nothing else public

Typoza publishes a directory of workspaces on its marketing site. You appear only if you asked to: it is a checkbox in the workspace settings, unticked by default, and unticking it removes the workspace immediately — not on a crawler's next pass.

  • What appears: the workspace's name, its description, the address of its public site and the number of published posts. Nothing from your account, never your email address.
  • A workspace with no published post does not appear, even if listed.
  • No paid placement and no ranking by audience: the order is that of listing, the most recent first.
  • No other screen in Typoza publishes anything about you without an action from you.

Traffic measurement, and its boundary

This section matters most to anyone trusting us with a site, so it is the most precise. Two measurements exist, they do not cover the same pages, and the boundary between them is a design decision, not a setting.

On a workspace's public site the measurement is ours and ours alone: a small script counts page views without setting a cookie, without keeping an IP address, and without building a reader identifier. No third-party tool is loaded there. Your readers are therefore never measured by an outside company, and you do not have to ask them for consent to a measurement we do not carry out.

A post shared from the “Share” button is counted the same way, more briefly still: the network chosen, the day and the post — no fingerprint, no address, no country. The links to the networks load nothing from them: their page opens only if the reader clicks.

The country of a visit is the one our host infers from the IP address and attaches to each request it passes on to us: no other service is asked. We keep only the two letters of the country; the address serves the day's fingerprint, is then forgotten, and is never written down.

On the Typoza site, its documentation and in the application — that is, at our place, not yours — we use Vercel Analytics and Vercel Speed Insights. Neither sets a cookie. Here is exactly what they collect, audited at Vercel rather than summarised.

  • Vercel Analytics: timestamp, page URL and path, referrer, filtered query parameters, country, region and city, operating system and version, browser and version, device type, script version. The visitor is identified by a hash of the incoming request, discarded after twenty-four hours.
  • Vercel Speed Insights: route and URL, network speed as declared by the browser, browser, device type, operating system, two-letter country, the performance measurement and the selector of the element it points at. No cookie, no session reconstruction.
  • Both send their readings to an address on our own domain, never to a third-party domain.

Writing assistance, and what the AI reads

None of your texts goes to a model without a gesture of yours: a button in the editor, or an assistant you plug in yourself with an API key (next section). Typoza never sends a post, a draft, a page, a comment or a message to a model of its own accord — not to summarise it, sort it, rank it or moderate it. Reported content is reviewed by hand, by a person.

Four functions call a model, all four from the editor, and this is what each one sends to Anthropic:

  • The title and summary suggestion, a button in the search panel: the post's title and its first five hundred words.
  • The alternative text, a button on an image: the image, and its caption if you wrote one.
  • Rewriting, a button on a selected passage: that passage, and nothing around it.
  • Sentence completion, after a short pause in the middle of a sentence: the last four hundred words before the cursor. It only runs while its box is ticked on the Writing assistance screen — it is not ticked when an account opens: you switch it on yourself, and unticking it is enough for nothing to leave without a button.

Each call spends the workspace's credits, which the counter in the side menu shows. No account identifier, no name and no email address go with the text.

Use of AI in a workspace. The owner of a workspace sees how many AI credits each member has spent this month: the number, never the text. Once a night, we look at each member's AI use over the last seven days through six counts: what it cost compared with the other members of the workspace, the busiest minute, the share of calls made at night, the share of drafts deleted, the words generated for each word published, and the longest run of rewrites of the same post. We never read your texts for this. If the counts cross a threshold, the workspace owner is told, and so are you, with the same figures. Nothing is suspended automatically: a person decides.

Our team reviews a flagged week too: when it is still open three days after the owner was told, when its counts are very high, or when the owner could not be told. The owner's own use, and that of a one-person workspace, is never reported to anyone: only our team sees it, and only when its counts are very high. For a first period, while we set the thresholds on real figures, nobody is told at all: only our team sees the flagged weeks. It sees the member's name and email address next to the figures. A person on our team may ask a model to summarise a week in three sentences; the model receives the counts alone — no text, no name, no workspace —, the call is paid by Typoza and never with a workspace's credits, and the summary is not a decision. We keep a flagged week for twelve months after it ends, then erase it, whatever became of it. We rely on our legitimate interest in protecting the credits a workspace pays for and the service's own costs (article 6(1)(f) GDPR).

What goes to Anthropic does not train its models. Its commercial terms say so in section B — “Anthropic may not train models on Customer Content from Services” —, read on 18 September 2026. We check that clause at every change of provider or contract, and we will rewrite this page if it changes — that is a working rule recorded in our internal documentation, not an intention.

What a workspace publishes is also kept away from the crawlers that train AI models. By default, its site's robots.txt refuses them — GPTBot, ClaudeBot, Google-Extended and some fifteen others, a list we survey again every quarter — and each of its pages reserves text and data mining in a machine-readable form, as article 4 of directive 2019/790 allows. Answer engines, which quote a site and send readers to it, remain welcome.

A robots.txt is respected, not enforced: the operators we name say they read it, and a crawler that lies about its name gets around it — the reservation is what remains when it does. A workspace can lift both from its settings; it is its texts, and its decision.

API keys, and the assistants you plug into them

From a workspace's Settings → Integrations screen, you can create an API key: a script, an automation tool or an AI assistant uses it to read and write in that workspace on your behalf, through our API or our MCP server.

  • A key opens one workspace, and never more than your own role in it — often less: you choose its role. It stops working on its own if you leave the workspace, if your role drops below the key's, or on the expiry date you set.
  • We do not keep the key, only its fingerprint: it is shown to you once, when it is created. We also keep its name, its role, its first characters, and the dates it was created, last used, expires and was revoked.
  • Every write made with a key goes into the workspace's activity log, under your name and with the key's name. The workspace's owner and admins see everyone's keys, and can revoke them.
  • A revoked or expired key is deleted a year later; the log then keeps the action, without the key's name. Deleting your account deletes all your keys.

**An AI assistant plugged in with a key** — Claude, ChatGPT or another — reads what the key opens when you ask it to, and what it reads goes to its provider, under that provider's policy. You choose that provider and what you ask of it; we only receive the requests it makes with your key, and we send it nothing else. To stop, revoke the key: the assistant loses access on its next request.

Embedded content

When you paste the address of a video or a public post into an article, our server fetches the preview from the service concerned, and the reader of the post then loads the content from that service. It therefore sees your reader's IP address and may set its own cookies.

Those services do not appear in our list of subprocessors, and the omission is deliberate: we do not choose them, you do, post by post. We cannot keep a list of what we do not decide — but you can, by embedding only what you stand behind.

Mentions from other sites

When another site publishes a link to one of our workspaces, it may announce it to us — a web convention as old as blogging. Our server then reads the page that claims to cite, to check that the link is really there, and keeps enough of it to make the mention legible.

  • We keep the page's address, the name of the site, its title, the author name it displays and the passage surrounding the link. All of it is information that page publishes itself, and we collect nothing else.
  • The site we go and read is not in our list of subprocessors, and the omission is deliberate, as it is for embedded content: we do not choose it. The difference is one word — here it is not the workspace that chooses it either, it is the site that decides to cite. All we send that page is the request that reads it: it sees our server's IP address, and nothing of you or of a reader.
  • A mention is never shown on a workspace's public site. It stays inside the workspace, visible to its owner and administrators.
  • If you wrote a page that cites us and would rather not appear, removing the link is enough: we revisit citing pages and the mention is marked as gone. You may also write to us, and we erase it.

The same convention runs the other way, and it belongs here because no automated check will say it: when you publish an article that cites another site, our server goes and tells that site. It therefore calls addresses nobody here chose — they are the ones you wrote into your text.

  • What leaves is the public address of your article and that of the page you cite. Nothing else: not your name, not your email address, nothing of a reader. The site being told also sees our server's IP address, as does any site we call.
  • Those sites are not in our list of subprocessors, and the omission is deliberate, as it is for embedded content and for the pages that cite us: we do not choose them. Here it is you who chooses them, by deciding to cite.
  • A link to one of your own Typoza sites does not leave: we do not announce ourselves to ourselves.
  • Nothing leaves the moment you press Publish: the notice is queued and sent afterwards, and it is given up after a few attempts if the site on the other end does not answer.

Who we transmit to

The full list, with what is transmitted to each, where they host and on what legal basis, is published on the Subprocessors page. It is kept in the same place as the code: a dependency added without its company being declared fails our continuous integration, and the version containing it does not reach production.

How long we keep it

Stated durations, including where the honest answer is that no automatic purge exists.

  • The account: name, email address, hashed password

    Retained for
    As long as the account exists
    Why
    Performance of the contract — without them, no sign-in is possible
  • A workspace's texts, pages, versions and media

    Retained for
    As long as the workspace exists
    Why
    This is the very purpose of the service
  • The second factor: the TOTP secret and the ten backup codes, encrypted

    Retained for
    As long as the second factor is active
    Why
    Turning it off erases the entire record; regenerating the codes replaces the ten old ones, which stop being valid
  • A passkey: its public key, its counter, its name and the authenticator model

    Retained for
    Until the key is revoked, and never beyond the account
    Why
    A public key cannot be used to sign in — it only serves to verify a signature produced by the device, which keeps the private key and never gives it out
  • An API key: its name, its role, its first characters, the fingerprint of its secret, and the dates it was created, last used, expires and was revoked

    Retained for
    While it is valid, then one year after it is revoked or expires; deleted with the account
    Why
    The activity log names the key an action came through; a year after the key has died, nobody reads those lines any more, and the name goes without the action. The secret itself is never kept, only its fingerprint
  • A write made through the API under an `Idempotency-Key` header: the header's value, the request's fingerprint and the response returned

    Retained for
    24 hours, then deleted by the nightly task
    Why
    A script that resends its request after a network cut gets the same response instead of creating a second post; it does so within the minute, never the next day
  • The sign-in session

    Retained for
    7 days, extended on each use after 24 hours
    Why
    So that a password is not asked for again on every page
  • The email address verification token

    Retained for
    24 hours
    Why
    Beyond that, an intercepted link would still work
  • The password reset token

    Retained for
    1 hour
    Why
    The most sensitive link in the product, hence the shortest
  • The passwordless sign-in link

    Retained for
    15 minutes
    Why
    For as long as it lives, it is worth a password
  • A workspace's activity log: who did what, and when

    Retained for
    24 months, then erased by the nightly task
    Why
    To trace the actions taken in a workspace shared by several people — to know who published, removed a member or changed an address — and to be able to read them back afterwards; beyond two years, nobody asks the question any more, and keeping the log would be keeping for its own sake
  • What a workspace's plan lets you see of this log

    Retained for
    30 days, 12 months or 24 months depending on the plan
    Why
    A reading window, not a retention period: nothing is deleted earlier, and a higher plan shows the rest the same day — like the statistics history
  • A workspace's backups, encrypted: its content, its members, and its subscribers if the owner ticked them

    Retained for
    14 days on the Collective plan, 60 days on Studio; none on the free plan
    Why
    A safety net has a size, not an infinite lifetime: past that period a snapshot is no longer of use as a fallback, and storing it would cost for nothing. A downgrade does not shorten the life of a snapshot already taken — cutting the net on the day one stops paying would be the worst moment
  • An invitation to join a workspace

    Retained for
    7 days
    Why
    After that, it has to be requested again
  • Reading statistics

    Retained for
    Kept with no time limit
    Why
    They designate no one: no cookie, no IP address kept, no reader identifier — so there is no one to forget
  • A subscription to a workspace's newsletter: email address, date of consent, chosen cadence

    Retained for
    As long as the subscription lasts
    Why
    Unsubscribing removes the address from that workspace's list; the date of consent is what proves it was given, and it lives and dies with it
  • The sending log: which post went out on which day, to whom, and what became of it

    Retained for
    12 months
    Why
    Long enough to see a sending reputation deteriorate over several seasons, and short enough not to keep who received what indefinitely. Erased every night by the clean-up task
  • Your notifications: what happened in your workspaces, and whether you read it

    Retained for
    6 months
    Why
    Less than the sending log, because a notification bell is not consulted in hindsight: past two months, the screen in fact stops writing “three days ago” and shows a date. Erased every night by the clean-up task, read or not
  • A device subscribed to notifications: its subscription address and its two encryption keys

    Retained for
    As long as the subscription is valid
    Why
    It is removed as soon as you remove it, and automatically as soon as your browser's push service declares it dead — uninstallation, data cleared, permission withdrawn. No purge by age: a two-year-old subscription that still works is a valid subscription
  • A workspace's registered office address, and the map image drawn from it

    Retained for
    As long as the workspace displays it
    Why
    It is entered to be published on the site's contact page, and erasing it from the form removes the map and deletes the image from the file store. The coordinates are obtained once from Geoapify and kept by us: the map is requested again only when the address changes
  • A conversation with a reader: their name, their email address, the text of the messages exchanged and their dates

    Retained for
    As long as the workspace keeps the conversation; deleted on request
    Why
    It is an exchange, not a send: reading it means keeping it, and answering it three weeks later means finding it again. Closing a conversation does not erase it — it stays readable by the workspace, and its return paths are cut. Erasure is requested at the contact address, and takes the whole thread with it
  • A conversation's reply address: its hash, the dates it was opened and last used

    Retained for
    As long as the conversation exists; the hash survives revocation
    Why
    The address itself is never stored — only its hash is, like a password. The revoked record remains so that we can answer “this address existed, and it was cut off on that day”, which a deletion would make impossible
  • The email address a member chooses to receive a workspace's mail

    Retained for
    As long as the person is a member of that workspace
    Why
    It is entered for that and for nothing else, it is removed with one button, and it disappears with the membership — leaving a workspace means no longer receiving its mail
  • A mention: the address of the citing page, its title, its author name and the passage around the link

    Retained for
    As long as the workspace exists, with no automatic purge
    Why
    It is the record of what another site published, and it has value only if kept — a citation from three years ago counts as much as one from yesterday. A link removed from the source page turns the mention to “gone” within thirty days at most, without erasing it; erasure is requested at the contact address
  • A comment under a post, published, under review or hidden: the name chosen, the text, its date, and whether its author wants to be told of a reply

    Retained for
    As long as the workspace keeps it; deleted on request, or by the workspace
    Why
    It is written to be read, and a reply makes sense only next to what it answers. Closing comments on a post or on the workspace takes them off the pages without erasing them — reopening shows them again. Erasure is requested at the contact address
  • The address of a reader who reacts or comments, the date they confirmed it, and their reactions

    Retained for
    As long as it carries a reaction or a comment, or the workspace blocks it, then erased by the nightly task
    Why
    It proves that the text comes from someone who clicked the link, and it carries the reply notice if one was asked for. A reaction is counted without being named: under the post, you see how many, never who. An address that no longer carries anything has no reason to be kept
  • A reaction or a comment awaiting confirmation, and the link sent to confirm it

    Retained for
    7 days, then erased by the nightly task
    Why
    The link lives seven days; what nobody confirmed within that time will never appear, and keeping an address nobody has proved would mean keeping just anyone's
  • The fingerprint of the IP address of a comment or a report — never the address itself —, and what the filter noted about it: its score and its signals

    Retained for
    30 days for the fingerprint, then erased by the nightly task; the score and the signals, as long as the comment
    Why
    It serves to recognise a burst of sends and block it; after a month, an IP address has changed hands. The fingerprint is computed with a secret key, so that the address cannot be traced back
  • An unwanted comment — advertising, a robot's send —, whether set aside by the filter or by the workspace

    Retained for
    30 days, then erased by the nightly task
    Why
    Time for the workspace to recover a mistake of the filter; what never appeared has no reason to be kept any longer
  • A report: its reason, its details, and the name and address the reader chose to leave

    Retained for
    Until the decision, then 12 months, then erased by the nightly task
    Why
    The address serves to acknowledge receipt and to give the decision, as article 16 of the Digital Services Act requires. A year later, the record of the decision has served its purpose: to answer for a removal, or for a refusal to remove
  • An automatic block: the fingerprint of an IP address or an email address, and its warnings

    Retained for
    24 hours, 7 days or 30 days depending on repeat offences; erased 30 days after the last warning
    Why
    It is triggered only by robots' sends, and never targets a named person. A warning a month old is forgotten
  • A workspace's block on a reader: its date, its reason, and who set it

    Retained for
    Until the workspace lifts it
    Why
    It is a human decision, notified to the reader with its reason; it does not lapse on its own, because it answers what a person wrote
  • Invoices and payment records

    Retained for
    10 years
    Why
    French accounting obligation (article L123-22 of the Commercial Code). This period prevails over a request for erasure
  • An invitation to a protected name: the address, the name, the written reason

    Retained for
    7 days if unused; 1 year after use
    Why
    The nightly clean-up erases an invitation that has expired or been withdrawn as soon as it lapses, and a used invitation one year later, so that we can find out who granted a name and why. When the account is deleted, the address on a used invitation is erased, and those still waiting at that address disappear
  • A deleted account

    Retained for
    Anonymised immediately
    Why
    Name, address, avatar, biography and handle are erased on the spot, sessions and third-party connections deleted. The technical record remains without any personal data, because a post keeps an author
  • A closed workspace

    Retained for
    Removed from every public page immediately
    Why
    Its records remain in the database, marked as deleted; their permanent erasure is requested at the contact address, since no automatic task performs it today
  • The rate-limit counters: an IP address, an account or API key identifier, and a number of hits

    Retained for
    2 hours
    Why
    Long enough to count, and no longer: a window lasts one hour at most, and each counter erases itself two hours after its first hit
  • A week flagged by abuse detection: a member's AI usage counts — credits, calls, deleted drafts, words — and the summary a model made of them, if one was requested

    Retained for
    12 months after the end of the week, then erased by the nightly task, whether or not the case is closed; a week without an alert leaves no record
    Why
    To revisit a disputed decision, and to see that the same account does it again. Never a text: detection reads only numbers
  • The host's logs: application errors, reports of background tasks, and the requests served, with their IP address

    Retained for
    1 day — ** to be confirmed **
    Why
    To diagnose an outage; beyond that, a log serves only to keep watch. We export them nowhere: they live only at the host

Your rights, and where to exercise them

A right mentioned without saying where to exercise it is not a right. Here are the screens, each by its name and by the link that opens it.

  • Take back your data: Security exports your account; a workspace's Data screen, in its settings, exports its content in Markdown and JSON, with the address of each of its media files. Both are available on the free plan.
  • Correct your data: Profile for your identity, Security for your email address and password.
  • Have your account erased: Security. Name, address, avatar, biography and handle are erased immediately, your sessions and third-party connections deleted.
  • Object to writing assistance: Writing assistance switches it off for the whole account.
  • Write to contact@typoza.com for any request these screens do not cover, in particular the permanent erasure of a closed workspace's records.

If an answer does not satisfy you, you may refer the matter to the French data protection authority, the Commission nationale de l'informatique et des libertés, at cnil.fr.

Changes to this page

The date shown at the top is derived from our list of subprocessors: it cannot be forgotten, because nobody types it. A substantive change is announced in the product changelog before it takes effect.