Privacy Policy
Last updated: February 2026
1. What We Collect
When you use Copy Machine, we collect:
- Account information: your name, email address, and hashed password
- Organization data: organization name, plan, and usage statistics
- Brand content: brand guidelines, products, buyer personas, documents, swipe files, and other content you upload or create
- Generated copy: AI-generated drafts and your edits to them
- Usage data: pages visited, actions taken, and feature usage (for improving the product)
- IP addresses: logged for security and audit purposes
2. How We Use Your Data
We use your data to:
- Provide and operate the Copy Machine service
- Generate copy using AI. Your brand context is sent to the AI model to produce relevant output
- Send transactional emails (account verification, password reset, team invitations, approval notifications)
- Process payments and manage your subscription via Stripe
- Monitor for abuse, security incidents, and enforce our Terms of Service
- Improve the product based on aggregate, anonymized usage patterns
3. What We Do Not Do
- We do not sell your data to third parties for any purpose
- We do not train AI models on your content. Your brand guidelines, products, and generated copy are sent to our AI provider solely to generate output for you. Our AI provider does not use API inputs to train its models.
- We do not share client data with other Copy Machine customers
4. Third-Party Services
Copy Machine uses the following third-party services to operate:
- AI Provider: AI model for generating copy. Your brand context is sent to the AI provider during generation.
- Stripe: Payment processing and subscription management. We do not store your card details.
- Resend: Transactional email delivery (verification, invitations, notifications).
5. Data Security
We use industry-standard security practices including encrypted passwords (bcrypt), HTTPS-only connections, JWT-based authentication, and role-based access controls. Organization data is isolated. One organization cannot access another's brands, drafts, or documents.
6. Data Retention
We retain your data for as long as your account is active. If you cancel your account, we retain data for a reasonable period before deletion in case you wish to reactivate. You may request earlier deletion by contacting us.
7. Your Rights
You have the right to:
- Export your data at any time via Settings > Data & Privacy
- Request deletion of your account and associated data by contacting us
- Correct your account information via the Settings page
- Object to processing your data by closing your account and requesting deletion
If you are located in the EU or UK, you may have additional rights under GDPR. Please contact us to exercise these rights.
8. Cookies
Copy Machine uses only essential cookies required for authentication (NextAuth session tokens). We do not use tracking, advertising, or analytics cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email. Continued use of the Service after updates constitutes acceptance of the revised policy.
10. Contact
For privacy questions, data requests, or concerns, please contact us at hello@trycopymachine.ai.