Legal
Privacy Policy
Last updated: August 20, 2026
The short version: we never store your text. It is processed only when you press a button, sent to an AI provider to produce the result, and immediately discarded. We keep your email, your devices and token counters — nothing you write.
1. Who is responsible
Corrigo, based in Serbia, is the data controller for the personal data described here. Contact: support@corrigo.me.
2. What we collect
| Data | What exactly | Why |
|---|---|---|
| Account | Email address, plan, trial and subscription status | Sign-in, entitlements, billing state |
| Devices | Device identifier, computer name, OS version, first/last seen | Enforcing plan device seats; you can remove devices in Settings |
| Usage | Token counters per day, timestamps, action counts | Enforcing plan quotas, showing your usage bar |
| Payments | Handled entirely by Paddle (merchant of record); we receive your email, plan and subscription status — never card details | Activating the plan you paid for |
| Support | Emails you send us | Answering you |
| Website | Google Analytics (G-M7JDCJGSE0) and Vercel Analytics on corrigo.me. See the cookie policy | Understanding site traffic; not used in the apps |
3. What we never collect
- Your text. When you request a correction, rephrase or translation, the text travels through our API to the AI provider and back to your device. It is not written to disk, not logged, and not kept in any database — we store token counts, not content.
- We do not use your content to train AI models, and our provider agreements are configured so they don't either.
- In bring-your-own-key (BYOK) mode on the Max plan, your text goes directly from your device to your chosen provider and never touches Corrigo servers at all.
- The apps never read fields marked as passwords, and you can blocklist any application in Settings.
4. Who processes data for us
| Processor | Purpose | What they see |
|---|---|---|
| OpenAI / Anthropic | AI processing of your requests | The text of the request you triggered (not stored by us; handled per their API data-usage policies) |
| Paddle | Payments, tax, invoices (merchant of record) | Email, purchase and card details (card stays with them) |
| Resend | Sending sign-in codes | Your email address |
| Vercel | Website hosting | Standard web server logs for corrigo.me |
| Google Analytics | Website statistics | Cookie-based aggregate visit data (website only; measurement ID G-M7JDCJGSE0) |
| Vercel Analytics | Website statistics | Aggregate page views (website only; no advertising cookies) |
5. Security
- All traffic uses TLS. Sign-in codes are stored only as hashes and expire in 10 minutes.
- On your device, session tokens and any API keys are stored in the macOS Keychain or Windows DPAPI — never in plain files.
- Our servers keep license keys and emails hashed or minimized wherever possible.
6. Retention and your rights
- Account data is kept while your account is active. Email us to access, correct, export or delete your data — deletion removes your account, devices and usage counters.
- Aggregate, non-personal statistics (e.g. total tokens served) may be retained.
- If you are in the EU/EEA, you also have the right to complain to your local data-protection authority. Legal bases: contract performance (accounts, billing), legitimate interest (abuse prevention), consent (website analytics — see the cookie policy).
7. Children
Corrigo is not directed at children under 16, and we do not knowingly collect their data.
8. Changes
We will announce material changes to this policy on this page and, for account holders, by email. Questions? support@corrigo.me.