Legal

Privacy Policy

Last updated: August 20, 2026

The short version: we never store your text. It is processed only when you press a button, sent to an AI provider to produce the result, and immediately discarded. We keep your email, your devices and token counters — nothing you write.

1. Who is responsible

Corrigo, based in Serbia, is the data controller for the personal data described here. Contact: support@corrigo.me.

2. What we collect

DataWhat exactlyWhy
AccountEmail address, plan, trial and subscription statusSign-in, entitlements, billing state
DevicesDevice identifier, computer name, OS version, first/last seenEnforcing plan device seats; you can remove devices in Settings
UsageToken counters per day, timestamps, action countsEnforcing plan quotas, showing your usage bar
PaymentsHandled entirely by Paddle (merchant of record); we receive your email, plan and subscription status — never card detailsActivating the plan you paid for
SupportEmails you send usAnswering you
WebsiteGoogle Analytics (G-M7JDCJGSE0) and Vercel Analytics on corrigo.me. See the cookie policyUnderstanding site traffic; not used in the apps

3. What we never collect

  • Your text. When you request a correction, rephrase or translation, the text travels through our API to the AI provider and back to your device. It is not written to disk, not logged, and not kept in any database — we store token counts, not content.
  • We do not use your content to train AI models, and our provider agreements are configured so they don't either.
  • In bring-your-own-key (BYOK) mode on the Max plan, your text goes directly from your device to your chosen provider and never touches Corrigo servers at all.
  • The apps never read fields marked as passwords, and you can blocklist any application in Settings.

4. Who processes data for us

ProcessorPurposeWhat they see
OpenAI / AnthropicAI processing of your requestsThe text of the request you triggered (not stored by us; handled per their API data-usage policies)
PaddlePayments, tax, invoices (merchant of record)Email, purchase and card details (card stays with them)
ResendSending sign-in codesYour email address
VercelWebsite hostingStandard web server logs for corrigo.me
Google AnalyticsWebsite statisticsCookie-based aggregate visit data (website only; measurement ID G-M7JDCJGSE0)
Vercel AnalyticsWebsite statisticsAggregate page views (website only; no advertising cookies)

5. Security

  • All traffic uses TLS. Sign-in codes are stored only as hashes and expire in 10 minutes.
  • On your device, session tokens and any API keys are stored in the macOS Keychain or Windows DPAPI — never in plain files.
  • Our servers keep license keys and emails hashed or minimized wherever possible.

6. Retention and your rights

  • Account data is kept while your account is active. Email us to access, correct, export or delete your data — deletion removes your account, devices and usage counters.
  • Aggregate, non-personal statistics (e.g. total tokens served) may be retained.
  • If you are in the EU/EEA, you also have the right to complain to your local data-protection authority. Legal bases: contract performance (accounts, billing), legitimate interest (abuse prevention), consent (website analytics — see the cookie policy).

7. Children

Corrigo is not directed at children under 16, and we do not knowingly collect their data.

8. Changes

We will announce material changes to this policy on this page and, for account holders, by email. Questions? support@corrigo.me.

Terms · Privacy · Refunds · Cookies · Legal · Contact