Undetectify Privacy Policy
On this page
This Privacy Policy explains how Undetectify ("we," "us," or "our") collects, uses, and protects information when you use our service at undetectify.com.
1. Information We Collect
Information from Google OAuth: When you sign in, we receive your Google account email address and a unique Google identifier (sub). We do not receive your Google password, phone number, or any other personal data beyond what you explicitly authorize.
Usage data: We store your plan type, monthly credit balance, credit reset date, anonymous word-count usage per request, and device identifiers used for abuse prevention. We do not store the content of any text you submit or receive.
Device and IP data: We record device identifiers and IP addresses for the sole purpose of detecting and preventing abuse of the free tier. This data is not shared with third parties and is deleted when your account is removed.
2. How We Use Your Information
We use the information we collect to operate and maintain the Service, manage your credit balance and plan, prevent abuse and enforce fair-use policies, respond to support requests, and improve the Service.
We do not sell, rent, or share your personal information with any third party for marketing purposes.
3. Data Retention
Account and usage metadata is retained for as long as your account is active. If you request account deletion, we will remove your data within 30 days. Text submitted for processing is never stored and exists only in memory during the processing window, typically under 30 seconds.
4. Third-Party Services
We use the following third-party services to operate:
- Google OAuth2 - Authentication, governed by Google's Privacy Policy
- Cloudflare Workers and D1 - Serverless compute and database, governed by Cloudflare's Privacy Policy
We have no control over the data practices of these providers and encourage you to review their respective policies.
5. Cookies and Local Storage
We use browser localStorage, not cookies, to store your session token and device identifier on your device. This data never leaves your browser except as part of authenticated API requests to our service. You can clear this at any time by logging out or clearing your browser storage.
6. Security
Session tokens are signed with HMAC-SHA256. All API communication is encrypted via HTTPS/TLS. We implement rate limiting, cooldowns, and device-level abuse detection to protect all users. No system is perfectly secure, and we cannot guarantee absolute security of data in transit or at rest.
7. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support.undetectify@gmail.com.
8. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by emailing support.undetectify@gmail.com. We will respond within 30 days.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy-related questions: support.undetectify@gmail.com
Copyright 2026 Undetectify. All rights reserved.