Privacy Policy

How Suikou AI collects, uses, shares, and protects your personal data.

This Privacy Policy explains how Suikou AI ("we", "us", "the Service"), operated by Suikou AI, collects, uses, shares, and protects your personal data. It is designed to be readable for our users worldwide, and to satisfy the disclosure requirements of the EU GDPR and California CCPA where applicable.

1. What we collect

We collect the minimum necessary to operate the Service:

  • Account data: email address, display name, password hash (when using email/password sign-in), OAuth identifiers (when using social sign-in), preferred locale.
  • Verification data: if you use the student discount, the email domain you verify and the MX-record check result.
  • Submitted text: the text you paste into the humanize and detector tools, the rewritten output we return, the mode and intensity you select, and timestamps.
  • Usage data: chars processed per day, plan, subscription status, requests per endpoint, errors.
  • Billing data: customer identifiers, invoices, and last 4 digits of payment instruments — handled by our payment processor (Stripe). We do not store full card numbers.
  • Technical data: IP address, browser user-agent, device type, referrer.
  • Cookies: a session cookie for authentication, and limited functional cookies (locale, theme).

2. Why we use it (purposes)

PurposeLegal basis (GDPR)
Provide the Service (run humanize / detect, deliver output)Contract
Enforce quotas and prevent abuseLegitimate interest
Bill subscriptionsContract
Improve the Service (aggregate analytics, error monitoring)Legitimate interest
Send transactional emails (account, billing, security)Contract
Send product updates (optional, with consent only)Consent
Comply with law / respond to lawful requestsLegal obligation

3. Third parties we share with (processors)

We share the minimum necessary with the following processors:

  • DeepSeek (LLM inference) — receives submitted text for the humanize pipeline.
  • OpenRouter (LLM router) — receives submitted text routed to detector and refinement models.
  • Supabase (hosting / database) — stores accounts, documents, rewrites, usage, subscriptions.
  • Stripe (payments) — processes subscription payments and stores billing data.
  • Cloudflare (CDN / DNS / DDoS protection) — sees request metadata.

By using the Service you consent to the cross-border transfer of your data to these processors, which may operate servers in the United States, Singapore, China (for DeepSeek), and other regions.

4. We do not sell your data

We do not sell, rent, or trade your personal data to third parties for their own marketing. We do not train any model on your submitted text without explicit, separate consent.

5. Retention

  • Account data: retained while your account is active and for up to 90 days after deletion to handle disputes.
  • Submitted text and rewrites: retained for the history window of your plan (Free: same-day; Basic: 30 days; Pro: 90 days). You may delete documents at any time from the dashboard.
  • Usage data: aggregated and retained indefinitely for analytics; raw daily rows pruned after 365 days.
  • Billing data: retained for the period required by tax and accounting law (typically 7 years).

6. Your rights

Depending on your jurisdiction, you have rights including:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure ("right to be forgotten"): delete your account and associated data.
  • Portability: export your documents and rewrites in a machine-readable format.
  • Objection / restriction: object to certain processing, including profiling.
  • Withdraw consent: where processing is based on consent.

EU/UK residents also have the right to lodge a complaint with their local Data Protection Authority. California residents have additional rights under CCPA, including the right to know and the right to delete.

To exercise any right, email [email protected]. We respond within 30 days.

7. Security

We protect your data with industry-standard measures: TLS in transit, encrypted storage at rest, scoped database access, hashed credentials, audit logging, and least-privilege secrets management. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

8. Children

The Service is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect data from such users. If you believe we have, please email [email protected].

9. Changes

We may update this Policy. Material changes will be announced via the Service or email at least 14 days before taking effect.

10. Contact

Questions? Email [email protected]. Mailing address: Contact via email. Governing law: Hong Kong SAR.

Privacy Policy