Home › Legal › Privacy Policy

Privacy Policy.

Plain-English. Honest. The version of this document we'd write even if no regulator existed.

Effective May 1, 2026 Version 3.2 Operator Lacewing Technologies

TL;DR

Plain English:
  • Your text is processed in memory and discarded the moment we return your result.
  • We never use your text to train our models. Never. Not even anonymized.
  • Account data (email, payment) is encrypted at rest and only used to run your account.
  • EU customers' data stays in EU regions. US customers can opt for EU pinning too.
  • You can delete everything in one click. We honor that within 24 hours.

Scope

This policy covers the TextSight web app, browser extensions, mobile apps, and API — anything operated by Lacewing Technologies ("we", "us", "TextSight"). It doesn't cover third-party services that link to us.

Data we collect

You give us:

We observe:

We DON'T collect:

How we use it

We never sell your data. We never share it with advertisers. We never use it to train models.

Your text content (special rules)

This is the part most people care about. We've split it out into a separate document: Content Handling Policy. It covers exactly what happens to your text from the moment you paste it to the moment we discard it.

The short version: zero retention by default. Your text exists in our memory only long enough to compute the result. We never persist it unless you explicitly opt in to "Save to history" — and even then, you can delete any saved scan with one click.

PurposeLegal basis
Running your accountContract (Art. 6(1)(b))
Billing & taxLegal obligation (Art. 6(1)(c))
Product analyticsLegitimate interest (Art. 6(1)(f)) — anonymous & aggregated
Marketing emailsConsent (Art. 6(1)(a)) — opt-in only
Abuse preventionLegitimate interest (Art. 6(1)(f))

Sharing & processors

We use a short list of sub-processors. Each one has signed a DPA with us, and we audit them annually.

VendorPurposeLocation
AWS (eu-west-1, us-east-1)Hosting, inference computeIreland / Virginia
StripePaymentsUS (DPA + SCCs)
PostmarkTransactional emailUS
PostHog (self-hosted)Product analyticsFrankfurt, Germany
Sentry (self-hosted)Error loggingFrankfurt, Germany
CloudflareDNS, DDoS protectionGlobal edge

We do not share data with anyone else — including law enforcement — without a valid legal order. When we do, we tell you (unless legally gagged).

Retention

Security

Your rights

You have the right to:

To exercise any of these, email privacy@textsight.ai. We respond within 72 hours; we resolve within 30 days.

Cookies

We use the minimum number of cookies needed to keep you logged in and tell us aggregate funnel info. Full cookie policy →

Children

TextSight is not directed to children under 13. If you're 13–18, you can use the service with parental consent. We don't knowingly collect data from children under 13; if you believe we have, email privacy@textsight.ai and we'll delete it.

International transfers

EU customer data stays in our Ireland region (eu-west-1) by default. Where transfer to a non-EU country is necessary (e.g. Stripe in the US), we rely on Standard Contractual Clauses (2021/914) and additional safeguards.

Changes

We may update this policy as we change the product. Material changes get notified 30 days in advance by email. Cosmetic edits (typo fixes, clarifications) don't trigger a notice. Past versions are archived here.

Contact

Privacy questions, DPA requests, GDPR rights:

For EU representative under GDPR Art. 27, see our contact page.