Privacy policy
Effective 4 August 2026.
The short version
TextLoupe sends the text you select to our server and on to OpenAI, which returns the result. That text is not stored and not logged, by us or in any database we run. It is not used to train anything. We keep a counting record of each request so quotas and costs add up. Everything else on this page is detail.
Who is responsible
TextLoupe is made and run by Irakli Kochua, a sole proprietor in Georgia, who is the data controller for everything described here. For anything on this page, write to [email protected].
What the app reads on your Mac
TextLoupe asks for the macOS Accessibility permission. It uses it for exactly two things: reading the text you have selected when you press the hotkey, and pasting the result back over that selection.
The hotkey is registered with the system rather than read from the keyboard stream, so the app is not able to observe what you type. It reads a selection only in response to the hotkey, and reads nothing at any other time.
What leaves your Mac
Six things, and this is the whole list. The app sends no analytics, no crash reports and no usage telemetry, because it contains none.
- The text you selected, when you run an action on it.
- Which action you asked for, plus the rewrite style or the target language when the action needs one.
- Your licence key or trial token, so the request can be authorised.
- A device identifier: a random UUID generated once by the app. It is not derived from your hardware, your serial number, or anything Apple assigns.
- The app version, so an out-of-date build can be told to update.
- Your IP address, which any server sees on any connection.
What we keep
One row per request, holding the licence key, the device identifier, the action name, the model used, the number of tokens in and out, an estimated cost, and the time. That is what quotas and costs are calculated from.
Alongside that: your licence record, which holds your email address as our payment provider supplied it, your plan, its status and its paid-through date; the device identifiers a licence has been activated on; and a running daily token count per licence.
If you start a free trial we store the device identifier, a hash of the trial token, the trial dates, and the IP address the trial was created from. The IP is there to cap how many trials one host can mint in a day, which is the only thing standing between the free tier and an automated farm.
What we never keep
Your text is not part of any of that. Neither is the model's answer. There is no column for either one in our database, and nothing writes them to our server logs, including when a request fails: an error is recorded as a failure code, never as the content that failed.
We do not build a profile of you, do not sell or share anything, and run no advertising.
How long we keep it
Licence and usage records are kept while your subscription is live and afterwards for accounting. There is no automatic deletion schedule today, so if you want your records removed, ask, and they will be. Trial records expire on their own dates and stop being usable then, though the row stays until deleted.
Why we are allowed to hold it
The processing above is what it takes to deliver software you asked for and to bill for it, which is a contract. The trial IP cap and the abuse counters exist because a public endpoint that spends money on model calls has to be defended, which is a legitimate interest. There is nothing here we would need consent for, and nothing here we would ask consent for and then use for something else.
Processors
- OpenAI performs the language work. OpenAI's API terms state that inputs sent through the API are not used to train their models. OpenAI does retain API inputs for a limited period for abuse monitoring under its own policy, which is separate from what we store. We store none of your text at any point.
- Supabase hosts the database and the functions that sit between the app and OpenAI. Our project runs in Supabase's Frankfurt region, so the records described above are held in the EU.
- Cloudflare provides DNS for textloupe.com and routes mail sent to our support address, so an email you send us passes through Cloudflare on its way to us.
- Vercel hosts this website. It serves static files and holds no account data.
- Paddle is the merchant of record for every purchase. Paddle runs the checkout, holds your billing details and issues your invoice. Card numbers never reach us; we receive your email address and a subscription reference.
Where it is processed
Our database and functions run in Supabase's Frankfurt region, so the records described above are stored in the EU. Model calls go to OpenAI in the United States, so your selected text is processed there for as long as the request takes. Payment records sit with Paddle, which operates internationally.
This website
No cookies of ours, no analytics, no tracking pixels, no embedded fonts. The animation libraries the pages use are served from this domain rather than a CDN.
There is one third-party script, and it is only on the home page: Paddle's checkout, loaded from cdn.paddle.com. Paddle is our payment provider, and their checkout has to come from them — it is what takes the payment. Loading it means your browser contacts Paddle when you open that page, and Paddle may set storage of their own once you actually open the checkout; what they do with it is covered by their own privacy notice. No other page on this site contacts anyone but us, and nothing on any page reports your visit to us.
After a purchase you land on a page that exchanges your Paddle order number for your licence key. That request goes to our own server. Your key is kept in that browser tab only, so a reload does not have to ask again, and it is gone when you close the tab.
What is stored on your Mac
Your licence key, trial token, trial expiry date and device identifier live in the macOS Keychain. If you use the app with your own OpenAI key, that key lives in the Keychain too and nowhere else. Your settings, a local token counter and the last quota figure the server reported live in the app's own preferences. None of it contains your text. Removing the app, its preferences and its Keychain entries removes all of it.
Your rights
You can ask what is held against your licence key or device identifier, ask for it to be corrected, ask for a copy of it, ask for it to be deleted, or object to us holding it. Write to [email protected] and you will get an answer within 30 days. There is no charge.
If you are in the EEA or the UK, those are your rights under the GDPR and we treat them as such wherever you live. You may also complain to your national data protection authority. One thing worth knowing before you ask: deleting your usage history ends any active subscription, because it is the same record.
Children
TextLoupe is not directed at children under 13 and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects what is collected or where it goes, the change will be dated here before it takes effect.