Privacy Policy

Last updated: 10/13/2025

1. Introduction

At refine.so, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI text humanization service.

By using refine.so, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

2.1 Account Information

When you create an account using Google OAuth, we collect:

  • Email address from your Google account
  • Name and profile picture from your Google account
  • Google account identifier (used for authentication purposes)

We do not store passwords. All authentication is handled securely through Google's OAuth 2.0 system.

2.2 Content Data

To provide our AI humanization service, we collect and process:

  • Text submissions: The content you submit for humanization
  • Generated output: The humanized text produced by our AI models
  • Usage metadata: Word counts, tone preferences, timestamps

2.3 Usage and Analytics Data

We collect information about how you use our Service:

  • IP addresses (for rate limiting and security)
  • Browser type and user agent
  • Request timestamps and frequency
  • Usage statistics (words processed, requests made)
  • Plan information and subscription status

2.4 Payment Information

Payment information is processed securely by our payment provider, Polar. We do not store your full credit card details on our servers. We receive limited information such as payment status, subscription tier, and billing cycle.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Providing the Service: Processing your text through AI models to generate humanized content
  • Account Management: Creating and maintaining your account, authenticating users
  • Billing and Subscriptions: Processing payments, managing subscriptions, tracking usage limits
  • Rate Limiting: Enforcing usage limits based on your plan tier
  • Security: Detecting and preventing fraud, abuse, and unauthorized access
  • Service Improvement: Analyzing usage patterns to improve our Service
  • Communication: Sending important service updates, security alerts, and billing notifications
  • Compliance: Meeting legal obligations and responding to lawful requests

4. Data Sharing and Third-Party Services

We share your data with third-party services that help us operate refine.so:

4.1 Infrastructure and Hosting

  • Vercel: Hosting and content delivery for our application
  • Database Provider: Secure PostgreSQL hosting for user accounts and usage data
  • Umami Analytics (Self-Hosted): We use a self-hosted instance of Umami for privacy-respecting web analytics. Umami collects anonymized usage statistics (page views, referrers, device types) without using cookies or collecting personally identifiable information. All analytics data is stored on our own servers.

4.2 Authentication Services

  • Google OAuth 2.0: All user authentication is handled exclusively through Google's secure OAuth system. We receive your profile information (name, email, profile picture) from Google to create and manage your account.

By signing in with Google, you agree to Google's Privacy Policy and Terms of Service.

4.3 Payment Processing

  • Polar: Subscription billing and payment processing. Polar handles payment information securely and according to PCI DSS standards.

We do not sell your personal data to third parties. Data sharing is limited to the services necessary to operate refine.so.

5. Data Retention

We retain your data for the following periods:

  • Account Information: Retained while your account is active and for 90 days after deletion (for recovery purposes)
  • Text Submissions: We do not permanently store your text submissions or generated output after processing, except for temporary caching for performance optimization (typically 24-48 hours)
  • Usage Logs: Retained for up to 90 days for security and billing purposes
  • Billing Records: Retained for 7 years for tax and accounting compliance

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data is encrypted in transit using TLS/SSL and at rest in our databases
  • OAuth Authentication: We use Google's secure OAuth 2.0 system for authentication, eliminating the need to store passwords
  • Access Controls: Strict access controls limit who can access user data
  • Secure Infrastructure: Our hosting providers meet SOC 2 and ISO 27001 standards
  • Monitoring: We monitor for suspicious activity and security threats

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to improve our security measures.

7. Your Rights and Choices

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct your account information
  • Deletion: Delete your account and associated data at any time
  • Data Portability: Request export of your account data
  • Opt-Out: Unsubscribe from marketing emails (service-related emails may still be sent)

To exercise these rights, please contact us at support@refine.so.

8. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Authentication: Maintaining your login session
  • Preferences: Remembering your settings (theme, tone preferences)
  • Security: Preventing fraud and abuse

Essential cookies are necessary for the Service to function. You can control non-essential cookies through your browser settings, though this may limit some functionality.

Analytics: We use self-hosted Umami Analytics to understand how the Service is used. Umami is a privacy-focused analytics platform that:

  • Does not use cookies
  • Does not collect personally identifiable information
  • Does not track you across websites
  • Collects only anonymized data (page views, referrers, device types, countries)
  • Stores all data on our own servers (not shared with third parties)

9. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure that such transfers comply with applicable data protection regulations and that your data receives adequate protection.

10. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at support@refine.so.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

We encourage you to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: support@refine.so