Skip to content
← Legal

Privacy Policy

Last updated October 4, 2026

Bu metnin Türkçesi

In short

  • We collect only what we need to run the service: your account details, what you write in the app, and basic security logs.
  • Your text goes to AI model providers (through OpenRouter) only to generate what you asked for. We don't use it to train AI models, and we don't sell personal data.
  • You can try the writer without an account. We don't save trial text; we keep only a salted hash of your IP address to enforce the daily limit, and delete it within 24 hours.
  • Analytics run only if you say yes, and they don't use cookies.
  • You can download your data or delete your account in Settings at any time.

1. Who we are

AI Ghostwriter (the website at https://hidengpt.com and the app, together the "Service") is run by [Company legal name], [Street address, district/city, country] ("we", "us"). We're the controller of the personal data described in this policy, which means we decide why and how it's used.

This policy explains what we collect, why, who we share it with and the choices you have. Our Cookie Policy covers cookies and browser storage, and our subprocessor list names the companies that help us run the Service.

If you're in Türkiye, our notice under the Turkish Personal Data Protection Law No. 6698 (KVKK) is available in Turkish: KVKK Aydınlatma Metni.

2. What we collect

Account details. When you sign up, we collect your name, email address and password. We never store the password itself, only a salted hash of it. If you sign in with Google, Google shares your name, email address and Google account ID with us. We also keep your plan and a record of what you agreed to and when, such as accepting the Terms or opting in to product emails.

Onboarding answers and preferences. Your answers to our onboarding questions (such as your role or goal and the formats you plan to use) and your settings, such as your default writing language, interface language and red pen strength.

What you write. The topics, notes, reference text and drafts you enter, and the results we generate. When you're signed in, they're saved to your history so you can come back to them.

Voices. If you paste samples of your own writing, we turn them into a voice (a style profile): a short description of how you write plus a few short excerpts from your samples. We use it to make new drafts sound like you. You can edit or delete your voices in Voices.

Usage records. For each generation, we record which tool and AI model were used, the number of tokens, the cost, the credits it used and the time. We also log key account events, such as signing up, finishing onboarding, signing in and creating your first draft. We use these records to work out credit use, keep costs under control, understand how the product is used and fix problems.

Security data. To keep accounts safe and stop abuse, we record the IP address, browser and device details (user agent) and sign-in times of your sessions. We also keep short-lived counters to rate-limit sign-up, sign-in, password reset and contact attempts. They're keyed to a salted SHA-256 hash of your IP address or email address, never the address itself, and deleted within 24 hours. Our hosting provider keeps short-lived technical logs of requests and errors.

Messages to us. When you use the contact form or email us, we receive your name, email address, topic and message. For contact-form messages, we also store the IP address the message came from, to fight spam.

Payment and billing details. Payments are processed by Stripe. Stripe processes your payment card details and, as needed, your billing name, email address and billing address. We never see or store your full card number. We store your Stripe customer and subscription IDs, your plan and billing period dates, and your credit balances and credit usage records. From Stripe, we receive the result of each payment and the details we need for billing and invoices, such as the amount and the date.

Cookies, browser storage and analytics. We use only the cookies and browser storage the site needs to work, stay secure and remember your choices. Cloudflare Web Analytics, which doesn't use cookies, runs only if you agree. See our Cookie Policy for details.

We don't ask for special categories of data (such as health, religion, political opinions or biometric data), and the Service isn't designed to process them. Please don't enter such data, or other people's personal data, unless it's necessary for what you're writing and you have the right to share it.

3. How we use your data and why

We use personal data only for the purposes below. If you're in the EU, the EEA or the UK, the GDPR and the UK GDPR require a legal basis for each one:

What we do Legal basis
Create your account, sign you in and keep you signed in Performance of our contract with you (Art. 6(1)(b))
Generate drafts, build and apply your voices, run the red pen and keep your history Contract (Art. 6(1)(b))
Run the trial without an account Steps you ask us to take (Art. 6(1)(b)); for the hashed IP counter, our legitimate interest in preventing abuse (Art. 6(1)(f))
Meter credits, apply plan and trial limits, track AI costs and fix bugs Contract (Art. 6(1)(b)) and our legitimate interest in running a reliable, affordable service (Art. 6(1)(f))
Understand how the product is used, through account events and anonymous counts Our legitimate interest in improving the product (Art. 6(1)(f))
Protect the Service with security logs, rate limits and bot protection, and prevent fraud and abuse Our legitimate interest in keeping the Service and its users safe (Art. 6(1)(f)); legal obligation where the law requires logs (Art. 6(1)(c))
Send service emails: email verification, password resets, and security, account and billing notices Contract (Art. 6(1)(b))
Answer support and contact requests Our legitimate interest in replying to you (Art. 6(1)(f)); contract, if it's about your account (Art. 6(1)(b))
Send product news and offers, only if you opt in Consent (Art. 6(1)(a))
Measure site traffic with Cloudflare Web Analytics, only if you opt in Consent (Art. 6(1)(a))
Take payments, manage subscriptions and credits, issue invoices and keep accounting records Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Keep records of your consents, comply with the law, answer lawful requests from authorities, and establish or defend legal claims Legal obligation (Art. 6(1)(c)) and our legitimate interest (Art. 6(1)(f))

Where we rely on legitimate interests, we've weighed them against your rights, and you can object at any time (see "Your rights" below).

We don't sell your personal data, use it for targeted advertising or build advertising profiles. We don't make decisions about you that have legal or similarly significant effects based solely on automated processing. We do use automatic limits and safety checks to prevent abuse; if you think one got it wrong, write to us and a person will look at it.

4. How AI processing works

When you ask for a draft:

  1. We combine your inputs (topic, notes, reference text), your selected voice, if any, and the tool's instructions into a request.
  2. We send the request to OpenRouter, Inc., which routes it to a company that runs the AI model we use (currently Moonshot AI's Kimi, with DeepSeek as a backup, run by hosting companies such as Fireworks, Together AI or DeepInfra). Your prompt and the output pass through OpenRouter and that model provider.
  3. The model writes a draft. If the red pen is on, the draft goes through one more model pass so it reads more naturally.
  4. We show you the result. If you're signed in, we save it to your history.

Creating a voice works the same way: your writing samples are sent to a model, which describes your style.

What this means for you:

  • We send your content to model providers only to generate what you asked for.
  • We don't use your content to train AI models.
  • Model providers process requests under our agreements with them and their own terms. Some may keep requests for a limited time, for example to detect abuse.
  • A small number of authorized team members can access your content, and only when it's needed for support, security or legal reasons.
  • Please don't enter passwords, ID numbers, health information or other sensitive data unless you really need to.

5. Trying it without an account

You can try the writer from the homepage without signing up, for a small number of generations per day (currently 2).

  • Your text isn't stored. What you type is sent through OpenRouter to the model provider to generate your result. We don't save it in our database or in any history.
  • A hashed counter enforces the limit. To enforce the daily limit and prevent abuse, we store a salted SHA-256 hash of your IP address (not the address itself) as a counter. It's deleted within 24 hours.
  • Anonymous statistics. We record that a trial generation happened, which tool was used and the interface language, with no text and no IP address.

If you sign up to keep going. If you type a request on the homepage and then create an account, we keep your text in your browser's local storage (under gw_pending_draft) so it isn't lost. It stays on your device and isn't sent to us until you submit it after signing up. It's removed once it's sent, or after 24 hours at most.

The trial is only for people aged 18 or over. By using it, you accept our Terms of Service and Acceptable Use Policy.

6. Who we share data with

We don't sell your personal data, and we don't share it with advertisers. We share it only with the companies that help us run the Service, and each one gets only what it needs:

  • Cloudflare, Inc.: hosting, serverless compute (Workers), our database (D1), content delivery and bot protection, plus Web Analytics if you agree to it.
  • OpenRouter, Inc.: routes generation requests to AI model providers.
  • AI model providers, reached through OpenRouter: generate the text you ask for.
  • Resend: sends service emails, such as email verification and password resets, and forwards contact-form messages to our inbox.
  • Google LLC: only if you choose "Sign in with Google".
  • Stripe: payments, subscriptions and the customer portal where you manage or cancel your plan.

Most of these providers process data only on our instructions. Google (for sign-in) and Stripe (for payments) also process some data under their own privacy policies. Each provider's purpose, the data it handles and its location are on our subprocessor list.

We may also share data:

  • with our professional advisers, such as lawyers and accountants, when needed;
  • with public authorities, when the law requires it, for example to comply with a valid court order;
  • to protect the rights, property or safety of our users, the public or us;
  • with a buyer or successor if we're involved in a merger, acquisition or sale of assets. This policy will keep protecting your data, and we'll tell you before it becomes subject to a different policy.

7. International transfers

We're based in Türkiye, and most of our providers are based in the United States or run global networks. So your data is processed outside the country you live in, including in Türkiye and the United States.

Where the GDPR or the UK GDPR requires safeguards for these transfers, we rely on:

  • adequacy decisions where they exist, such as the EU–US Data Privacy Framework (and its UK extension) for certified recipients; or
  • the European Commission's Standard Contractual Clauses (with the UK addendum for UK data), together with additional measures where needed.

Transfers out of Türkiye follow Article 9 of the KVKK, as explained in the KVKK notice. To get a copy of the safeguards we use, email privacy@example.com.

8. How long we keep data

We keep personal data only as long as we need it for the purposes above or the law requires:

Data How long
Account details and preferences While your account is open. Deleted when you delete your account, except records we must keep by law
Consent records While your account is open, and afterwards for as long as we need them to show that we complied with the law
History (inputs and outputs), voices and usage records Until you delete them or your account
Account events While your account is open. When you delete your account, they're unlinked from you and kept only as anonymous statistics
Security logs (IP address, user agent, sign-in times) Up to 1 year, or longer if the law requires it (for example, Turkish Law No. 5651)
Rate-limit counters (salted SHA-256 hashes of IP or email addresses), including the trial counter Deleted within 24 hours
Technical request and error logs at our hosting provider A few days
Text you enter in the trial Not stored; used only to generate your result
Pending draft (gw_pending_draft) Only in your browser, until it's sent or for 24 hours at most
Contact messages Up to 2 years
Invoices and accounting records 10 years, as required by the Turkish Commercial Code and Tax Procedure Law

When a retention period ends, we delete or anonymize the data. Deleted data can stay in backups for a limited time and is removed in the normal backup cycle. Aggregate statistics that can't identify you may be kept longer.

9. How we protect your data

  • All traffic between your browser and the Service is encrypted (HTTPS).
  • Passwords are stored only as salted hashes.
  • The session cookie is httpOnly, so scripts on the page can't read it, and we store only a hash of the session token.
  • Access to admin tools is limited to authorized people.
  • Rate limits and Cloudflare's security services protect against automated attacks.

No system is perfectly secure. If a breach affects your personal data, we'll notify the relevant authorities and you, as the law requires. To protect your account, use a strong password that you don't use anywhere else.

10. Your rights

Depending on where you live, you have the right to:

  • access your personal data and get a copy of it;
  • correct data that's inaccurate or incomplete;
  • delete your data;
  • restrict how we use it;
  • port it: get it in a machine-readable format or have it sent to another service;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • withdraw consent at any time, without affecting what we did before you withdrew it.

You can do much of this yourself:

  • In Settings, you can download a copy of your data as a JSON file, change your email preferences and delete your account.
  • In History, you can delete individual drafts.
  • Every product email has an unsubscribe link.
  • The "Cookie settings" link in the footer lets you turn analytics on or off.

For anything else, email privacy@example.com from the address on your account. We'll reply within one month. For complex requests, we may need up to two more months; if so, we'll tell you why. Requests are free, and we may ask you to confirm your identity first.

Complaints. If you're unhappy with how we handle your data, please tell us first so we can try to fix it. You can also complain to a data protection authority: in the EU or EEA, the authority where you live, work or think the problem happened; in the UK, the Information Commissioner's Office (ICO); in Türkiye, the Personal Data Protection Board (KVKK Kurulu), after applying to us first.

11. Children

The Service is for adults. You must be at least 18 to create an account or use the trial. If we learn that someone under 18 has given us personal data, we'll close the account and delete the data. If you think this has happened, contact privacy@example.com.

12. Changes to this policy

We'll update this policy when the Service or the law changes. If we make material changes, we'll tell you by email or in the app before they take effect. The date below shows when this policy last changed.

Last updated: October 4, 2026

13. Contact us