1. Who we are
The Service is operated by Overwing (operated by its owner as a sole proprietor). For any privacy question or request, email support@overwing.ai.
2. What we collect
- Account data. Email address, password hash (held by our authentication provider), organization name, and the IP address used at programmatic signup, kept only to throttle abuse.
- API content. The text you submit for evaluation, any metadata you attach, and the resulting verdicts, scores, and confidence values. We store these so you can retrieve and audit evaluations.
- Usage data. Request counts, verdict counts, latency, token counts, timestamps, and API key identifiers, aggregated per organization per day.
- Billing data. Plan, subscription status, and Stripe customer and subscription identifiers. Card numbers never reach our servers; Stripe holds them.
- Technical data. Standard server logs (IP address, user agent, request path, status) retained briefly for security and debugging.
We do not use cookies for advertising. The dashboard uses only the session cookies needed to keep you signed in.
3. Why we process it
- To provide the Service you asked for: evaluating text, storing results, enforcing plan limits, and delivering webhooks (performance of a contract).
- To bill you and prevent fraud and abuse (contract and legitimate interests).
- To secure and improve the Service, including debugging failed requests (legitimate interests).
- To meet legal obligations such as tax and accounting rules.
We do not sell personal data and we do not use your submitted text to train models.
4. Who else processes it
We use these subprocessors. Each receives only what its role requires.
- TypeSafe — Evaluates submitted text with the Jev model (United States).
- Supabase — Database and authentication hosting (United States).
- Vercel — Application hosting and edge network (United States).
- Stripe — Payments, invoicing, and card storage (United States).
Text you submit is sent to TypeSafe to produce the evaluation. Do not submit data you are not permitted to share with these providers. If you need to evaluate regulated data, redact it first or contact us before doing so.
5. Retention
- Evaluation records (input text, results, metadata) are kept while your organization exists, so you can retrieve them, and deleted within 30 days of a deletion request or account closure.
- Daily usage aggregates are kept for accounting for up to 7 years, without input text.
- Server logs are kept for up to 30 days.
- Billing records are kept as long as tax law requires.
6. Your rights
Depending on where you live you may have rights to access, correct, export, restrict, or delete your personal data, to object to processing, and to complain to a supervisory authority. To exercise them, email us from the address on the account. We will respond within 30 days. You can delete API keys, rule sets, and webhooks yourself in the dashboard or through the API.
7. International transfers
Our providers are located in the United States. If you are outside the United States, your data is transferred there and protected by our contracts with those providers, including standard contractual clauses where they apply.
8. Security
API keys are stored only as SHA-256 hashes. Traffic is encrypted in transit. Webhooks are signed so you can verify they came from us. Access to production data is limited to the operator. No system is perfectly secure; if we learn of a breach affecting you we will notify you without undue delay.
9. Children
The Service is not directed at children and we do not knowingly collect data from anyone under 18.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced by email to account holders.