Legal
Textmolt Privacy Policy
Last updated: Version 1.2.0
1. Overview
This Privacy Policy explains how Textmolt collects, uses, stores, and protects your personal information. By using Textmolt, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Account Information
We collect your email address during registration for identity verification and account management.
2.2 Conversations, Documents, and Attachments
AI requests include your question and the context supplied by the feature you use, such as selected text, nearby text, or a full document. Text attachments are read on your device and their extracted text is sent with the request; the original file is not uploaded by the attachment reader. Image attachments are sent through the gateway to your selected provider when using a supported Bring Your Own Key (BYOK) request. Conversation history, source labels, document indexing, and memory involve storage as described in Sections 6 and 8.
2.3 Usage Data
We collect operational usage data, such as feature use, model call counts, errors, and response times. Telemetry removes designated original-text fields and redacts identifiers; remaining metadata may still relate to an account or request. This telemetry is separate from conversation and memory storage.
2.4 Device Information
IP address (for security and regional services), browser/host type (WPS/Word).
2.5 Payment Information
Payment transactions are securely processed by our certified third-party payment provider. We never access or store your payment details.
3. How We Use Your Information
- Providing and maintaining the AI writing assistant service;
- Processing payments and managing credits;
- Improving product features and user experience;
- Security: anomaly detection, anti-abuse, and account protection;
- Complying with applicable laws and regulations.
4. Data Sharing
Necessary data is shared with the services used for your request:
- AI Model Providers: Your question, supplied context, relevant conversation history, and memory may be sent to the selected AI provider, including through a routing service. BYOK requests use the endpoint you configure.
- Literature Research: Local Zotero research reads information within the selected scope through the connected Companion. Retrieved literature metadata and text used in the answer are sent through the gateway to the model. Online literature search sends search terms to Crossref.
- Infrastructure Providers: Cloud service providers for database hosting, authentication, content delivery, storage, and backend operations.
- Payment Provider: A third-party payment processor handles transactions.
We do not sell your personal information to third parties for advertising or marketing purposes.
5. Sub-processors (GDPR Art. 28)
Textmolt engages the following sub-processors to deliver the AI completion service. The list is kept in sync with Annex II of our Data Processing Addendum (DPA).
| Sub-processor | Country | Purpose | Transfer Mechanism |
|---|---|---|---|
| OpenRouter, Inc. | United States | LLM API aggregation and routing | SCC Module 2 + EU-US Data Privacy Framework |
Categories of personal data shared with sub-processors: user prompts, AI-generated content, request metadata.
Sub-processor change procedure: We notify users 14 days in advance of any new sub-processor activation via in-app banner and email. During this period, users may object via [email protected] or the in-app feedback channel. The full controller authorization mechanism is set out in Annex II of our DPA, in line with GDPR Art. 28(2).
6. Data Storage & Security
6.1 Account data is stored in our cloud database with row-level access controls. Server-side conversations store user questions, AI replies, and session summaries. Memory features also store user, organisation, or document memory. These records use database or server-file storage according to the deployment configuration.
6.2 Production connections to our gateway and external AI services use HTTPS. Connections between local components, including Zotero and Companion, may use a local loopback connection.
6.3 Operational telemetry uses local or cloud storage according to configuration. Its retention controls are separate from those for conversations and memory; a telemetry cleanup interval does not apply to all user data.
6.4 In standard hosted chat, selecting full-document context also stores document text on the server for indexing and later retrieval. Other document context and extracted attachment text are used for the current request rather than stored as a separate user message. Content copied into your question, AI replies, summaries, or memory can remain in those records. The attachment feature does not store image data in conversation history.
6.5 Conversation, memory, and document-index stores do not currently have a uniform automatic expiry. Where backups are enabled, copies may remain under the configured backup rotation after removal from active storage. Deleting local history or using Temporary Chat does not by itself delete server records or backups. For access or deletion requests, contact [email protected].
7. Your Rights
You have the following rights:
- Right of Access: View the personal information we have collected about you;
- Right to Rectification: Correct inaccurate personal information;
- Right to Erasure: Request deletion of your account and associated data;
- Right to Data Portability: Export your session history in a standard format.
To exercise these rights, please contact us through the in-product feedback channel or email [email protected].
8. Cookies & Local Storage
Textmolt uses browser localStorage for authentication tokens, preferences, debug settings, and BYOK endpoint settings and API keys when configured. BYOK keys accompany requests to the gateway for the selected provider; they are not stored by the gateway as account credentials.
IndexedDB stores local conversation history, document associations, and source labels, including selection snapshots and attachment names. Attachment file contents and image data are not included in these source labels. Temporary Chat skips saving local conversation history; server-side processing and storage described in Section 6 still apply.
Textmolt does not use third-party tracking cookies.
9. Children's Privacy
Textmolt is not intended for users under 16 years of age. If we discover that we have inadvertently collected information from a minor, we will promptly delete the relevant data.
10. Policy Updates
This Privacy Policy may be updated from time to time. Users will be notified of updates within the product and may be asked to re-acknowledge. Material changes will be communicated prominently.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: [email protected]
Last updated: September 26, 2026 | Version 1.2.0