Privacy Policy
1. Scope
This Privacy Policy describes what personal information u22a8.ai (the "Service") collects, how it is used, how long it is kept, and your rights in respect of it. It applies to personal information the Service collects from visitors and API users.
2. Controller and Privacy Officer
The controller and responsible party for personal information processed by the Service is Taras Yanchynskyy, a sole proprietor located in Ontario, Canada (the "Operator"). The Operator also serves as the designated Privacy Officer for the purposes of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Contact: [email protected].
3. What we collect
When you use the Service we may process:
- Request metadata: timestamp, path, HTTP method, response status, user-agent string, and a hashed representation of the source IP address.
- Submitted content: the text or URL you submit for scoring. Submitted content may be held in transient caches and in application logs for operational purposes.
- Cookies: the Service uses no advertising, analytics, or tracking cookies.
4. Purposes
We use the information identified in §3 only for the following purposes:
- Operating, debugging, and securing the Service.
- Producing aggregate, non-identifying usage metrics.
We do not use submitted content to train models unless a specific model's page explicitly declares so in its additional terms.
5. Legal basis (applicable to visitors in the EEA and UK)
Where the GDPR or UK GDPR applies, the legal bases for our processing are: (a) our legitimate interests in operating and securing the Service; and (b) compliance with our legal obligations, where applicable.
6. Sharing
We do not sell personal information. We do not share it with third parties except: (a) infrastructure providers strictly necessary to operate the Service, (b) upstream dataset licensors upon demonstrated contractual need, and (c) in response to valid legal process.
7. Retention
- Request logs: up to 30 days, then rotated.
- Transient score caches: up to 24 hours, best-effort.
8. Security
We apply reasonable technical and organizational safeguards appropriate to the sensitivity of the information, including hashing IP addresses at ingress and transport encryption (HTTPS). No internet service can be guaranteed secure; users assume residual risk.
9. International transfers
The Service's infrastructure operates primarily in North America. Personal information may be processed in Canada and the United States. Where the GDPR or UK GDPR applies, such transfers rely on recognised transfer mechanisms (e.g., Canada's adequacy decision; standard contractual clauses where adequacy does not apply).
10. Your rights
Subject to applicable law, you may have rights to access, correct, or delete personal information associated with you, and to lodge a complaint with a supervisory authority. To exercise these rights, contact the Privacy Officer (see §2). Because we hash source IP addresses at ingress and do not attach identifiers to submitted content, many requests will result in our informing you that no personal information associated with your identifier is retained. Canadian residents may also file a complaint with the Office of the Privacy Commissioner of Canada.
11. Children
The Service is not directed at children under the minimum age of digital consent in your jurisdiction, and we do not knowingly collect personal information from such children.
12. Changes
We may update this Policy from time to time; the "Last updated" date will change accordingly. Material changes will be surfaced prominently on the Service.
13. Contact
Privacy Officer: [email protected]. Public repositories are hosted at github.com/u22a8.
See also: Terms of Use