PrivacyTerms
ENRU中文
Open HideGPT

LEGAL / PRIVACY

Privacy Policy

This policy explains what HideGPT collects, why we process it, who may receive it, how long it is kept and the choices available to you.

Last updatedAugust 26, 2026
On this page
Who we are and what this policy coversInformation we collectWhy we use informationHow text is processedWhen information is disclosedInternational transfersHow long information is keptYour privacy rightsCookies and local storageSecurityChildrenChanges to this policyContact and complaints
Legal contact
Operator
HideGPT
Email
info@hidegpt.app

1. Who we are and what this policy covers

HideGPT operates the HideGPT text humanization service. For applicable privacy law, the operator is the controller or personal information processor responsible for the processing described here.

This policy covers hidegpt.app, the web application, REST API, Telegram Bot and Telegram Mini App, and related support. It does not cover third-party websites or services that publish their own privacy notices.

2. Information we collect

We collect information you provide, information created when you use the service, and limited information received from service partners.

  • Account and profile data, such as email address, display name, authentication identifiers, language and account settings.
  • Content data, including source text, instructions, selected rewrite settings, generated output, feedback and humanization history.
  • Guest-use data, including a random browser visitor identifier, request identifiers, job status, access token metadata and the guest input and output.
  • Transaction data, such as purchased package, credits, price, currency, payment status and provider reference. HideGPT does not receive your full payment card number from Stripe.
  • Technical and usage data, such as IP address, approximate region, browser and device type, timestamps, requested URLs, diagnostics, security events and product interactions.
  • Communications, including support messages, survey responses and reports you send to us.
  • Telegram data made available when you use the Bot or Mini App, such as Telegram user ID, username, language and interaction data.
  • Cookie and local storage choices described in section 9.
HideGPT is not designed to receive sensitive personal information. Do not submit health, biometric, financial account, government ID or other sensitive data unless you have a lawful reason and authority to do so.

3. Why we use information

We process information only for defined service, security and business purposes. The legal basis depends on your location and the specific activity.

  • Provide the humanization service, process guest and account requests, preserve settings and deliver results. This is necessary to perform our contract or take steps you request.
  • Create and secure accounts, authenticate sessions, maintain history, credits and API access, and provide customer support.
  • Process purchases, prevent payment fraud, keep transaction records and meet accounting or legal obligations.
  • Protect the service against abuse, duplicate guest use, attacks and unauthorized access. We rely on legitimate interests or another permitted security basis where applicable.
  • Debug failures, monitor reliability and improve functionality using minimized operational data.
  • Measure product use with Google Analytics and PostHog only after analytics consent where consent is required.
  • Send service messages and, where permitted, product communications. You can opt out of non-essential communications.
  • Comply with law, enforce our Terms and establish, exercise or defend legal claims.

4. How text is processed

To generate a humanized result, HideGPT sends your source text, selected settings and required instructions through our service infrastructure to the configured AI processing provider. Current processing may use OpenRouter and the upstream model provider selected for the request.

Your text may therefore be processed in countries different from your own. Provider processing is governed by the applicable agreements, security settings and provider terms. Do not submit confidential or personal data unless you are authorized to share it and accept this processing path.

Generated output may be inaccurate or may reproduce information from the input. You remain responsible for reviewing facts, citations, personal data and final wording before use.

5. When information is disclosed

We do not sell personal information for money. We disclose only what is reasonably necessary to the following recipients:

  • Cloud hosting, database, storage, backup, content delivery and security providers.
  • OpenRouter and configured upstream model providers used to process humanization requests.
  • Stripe for payment checkout and payment administration, and Telegram for Bot, Mini App and Telegram Stars interactions.
  • Email delivery, authentication and customer support providers.
  • Google Analytics and PostHog for optional analytics, and Sentry for error and reliability monitoring.
  • Professional advisers, auditors, insurers, authorities or courts where required by law or necessary to protect rights and security.
  • A successor in a merger, financing, reorganization or sale, subject to appropriate confidentiality and notice requirements.

6. International transfers

HideGPT and its providers may process information outside your country. Where the law requires transfer safeguards, we use an available lawful mechanism, such as contractual protections, adequacy decisions, consent or another permitted basis.

If Russian, EEA, UK, Swiss or Chinese transfer rules apply, additional localization, assessment, notification, contractual or separate-consent requirements may also apply. Contact us for information relevant to your request and location.

7. How long information is kept

We keep personal information only for as long as needed for the purposes above, then delete or anonymize it unless law requires a longer period. Retention is determined by account status, the feature used, legal obligations, dispute periods and security needs.

  • Account content and humanization history are kept while your account is active and until you delete the content or account, subject to limited backup and legal retention.
  • Guest jobs are available only for the expiration period assigned to the job. If claimed after sign-in, the job becomes part of account history.
  • Authentication cookies last up to 7 days for access and 30 days for refresh unless refreshed, revoked or deleted earlier.
  • Consent, locale, region and interface preference records may remain for up to 12 months.
  • Transaction and tax records are kept for the period required by applicable finance and tax laws.
  • Security, diagnostic and support records are kept for a limited period based on risk and operational need.

8. Your privacy rights

Depending on your location, you may ask to access, correct, delete, restrict or receive a copy of your information, object to certain processing, withdraw consent, or complain to a data protection authority. Email info@hidegpt.app to make a request. We may verify your identity and may retain data where a lawful exception applies.

EEA and UK users may also request portability and object to processing based on legitimate interests. California residents may request to know, correct or delete covered information and opt out of sale or sharing without discrimination. We do not sell personal information for money. Russian and Chinese users have the rights provided by applicable personal data laws, including rights to information, correction, deletion or withdrawal of consent where available.

You can delete your HideGPT account and associated profile data from the account settings. Some transaction, security and backup records may remain where law or technical lifecycle requires it.

9. Cookies and local storage

HideGPT uses cookies and browser storage. Necessary storage operates without optional consent because it supports security, language selection, session continuity, consent records and the one-free-rewrite entitlement. Optional analytics and marketing storage stays disabled until you consent where required.

  • Necessary: token and refresh_token for authentication, locale and region for language and service routing, zt_cookie_preferences for your consent choice, and a random guest visitor identifier in local storage for the free rewrite and abuse prevention.
  • Functional: theme, sidebar and other interface preferences requested by you. These typically remain for up to 12 months.
  • Analytics: Google Analytics and PostHog identifiers that help measure product use. These are enabled only after analytics consent where required.
  • Marketing and attribution: referral and campaign parameters such as ref and _utm. These are used only on a permitted basis and can be disabled in cookie settings where applicable.
You can accept, reject or customize optional categories in the cookie banner and reopen Cookie settings from the footer at any time. Browser controls can also remove stored data, but blocking necessary storage may prevent sign-in or the free guest rewrite from working correctly.

10. Security

We use reasonable technical and organizational safeguards designed to protect information, including access controls, encrypted transport, restricted service credentials, monitoring and backups. No internet service can guarantee absolute security. Protect your account credentials and notify us if you suspect unauthorized use.

11. Children

HideGPT is not directed to children under 18 and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and take appropriate action. Where local law permits use by a minor only with guardian authorization, that authorization is required.

12. Changes to this policy

We may update this policy when the product, providers or legal requirements change. We will post the new date and provide additional notice when a change materially affects your rights or requires new consent.

13. Contact and complaints

Send privacy questions and rights requests to info@hidegpt.app. Include enough detail for us to identify the feature and request, but do not email passwords, access tokens or sensitive source text. You may also complain to the competent data protection authority in your place of residence where that right applies.

© 2026 HideGPT. All rights reserved.
Back to HideGPTPrivacyTerms