Privacy Policy

What RetypeWords does with your images and your account data

2026/09/07

Introduction

RetypeWords is an online tool that replaces text inside images. To do that we have to receive your image, process it, and give you back an edited version. This policy explains exactly what happens to it and to the rest of your data.

The short version: your images are processed to produce your result, expire after 48 hours, and are never used to train models. You can optionally allow our team to inspect a sample of your images and results for quality checks during that same retention window.

What We Collect

Images you upload

The image file itself, plus what the tool derives from it in order to work: the position of the text it found, the text it read, and the replacement text you typed.

Account information

Your email address, and a password hash if you set a password. If you sign in with Google, we receive your email address and basic profile information from Google — not your Google password.

Usage and billing

Credit balance and transaction history. If you buy Credits, our payment processor handles the card details; we never receive or store your full card number.

Technical data

IP address, browser and device information, and pages visited. We also use a device fingerprint and IP to enforce the one-free-edit-per-device limit and to detect abuse of free usage.

How We Use It

PurposeWhat it covers
Providing the ServiceReading the text in your image, producing the edited result, letting you review and download it
Your accountAuthentication, credit balance, job history, support
BillingProcessing purchases, preventing payment fraud
Abuse preventionEnforcing free-usage limits, detecting automated abuse, responding to reports
Legal obligationsResponding to lawful requests, keeping records we are required to keep
Improving the ServiceUsage and processing statistics, structured feedback, and optional image quality reviews described below

We do not use your images to train models. They are not added to a training set, used to train or fine-tune models, or sold or licensed to anyone.

We do not sell personal information, and we do not use your images or account data for advertising.

Optional Quality Reviews and Feedback

You can rate a generated version without sharing its image with a reviewer. We store the rating, selected issue category and task identifiers. These help us understand whether results meet users’ needs.

The separate image-review checkbox is off by default. If you enable it for a task, authorized team members may inspect its original image, generated results and edit instructions to assess text accuracy, visual style and unintended changes. We review a random sample of eligible tasks and may also review retries or negative feedback. This helps improve the product’s processing and user experience; it does not authorize model training.

You can uncheck the option in that task’s result panel to stop future access for quality review, or contact us to withdraw it. A reviewer may already have seen the image. Review files are not copied into a separate image archive and the existing 48-hour expiry is not extended. Structured review results contain task identifiers and quality labels, not image contents or edit text.

We use PostHog to collect usage events, processing outcomes, timing and structured feedback. Images, OCR text and replacement text are not sent to PostHog by these analytics features. Analytics records are linked to pseudonymous identifiers; they are not necessarily anonymous.

We also use masked session replay to understand navigation, clicks, scrolling and layout problems. Replay is configured to mask page text and block input elements, images, uploaded artwork, generated results, dialogs and account/admin content before capture. Console logs, canvas content, and network request headers and bodies are not recorded. Page URL queries and fragments are removed from replay metadata. Replay recordings are retained for 30 days and are separate from the 48-hour image storage period.

Who Else Processes Your Image

Producing an edited image requires third parties. Each receives only what it needs:

ProcessorWhat it receivesWhy
Cloud hosting and storageThe image file, encrypted at restRunning the Service and storing your upload for the retention window
Database providerAccount data, job records, credit ledger — not image filesPersisting your account and job state
OCR providerThe image, to read the text in itFinding the words and their positions
Image model providerThe image and your replacement textProducing the edited result
Payment processorYour payment details, directlyTaking payment; we never see the card number
Email providerYour email address and message contentVerification and notification emails

These are processors acting on our instructions, not independent controllers using your data for their own purposes. We do not otherwise share your images.

We may disclose data where legally required, or to investigate a report of abuse under the Acceptable Use Policy.

How Long We Keep It

DataRetention
Uploaded images and results48 hours, then deleted automatically
Structured quality reviews and feedbackRetained with the associated task; no additional image copy
Job records (status, region text, credit outcome)Retained for support, billing and abuse response
Account dataUntil you delete your account
Billing recordsAs long as tax and accounting law requires
Abuse and safety recordsUp to 12 months

Deleting a job deletes the image bytes, not merely the database row pointing at it. Deleting your account removes your account data and any remaining images.

Security

Data is encrypted in transit and at rest. Images are held in private storage that is not publicly addressable — there is no shareable link to your upload, and every request for an image is checked for authorization. Optional quality-review access additionally requires an authorized team member, your active task-specific permission and an unexpired file. Access is limited to what is needed to operate the Service.

No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority as required by law.

Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive a copy in a portable format, and to withdraw consent. Under GDPR our legal bases are performance of a contract (providing the Service), legitimate interests (security and abuse prevention), legal obligation, and consent where it applies.

If you are in California, you may request disclosure of the categories of personal information collected and request deletion. We do not sell personal information, so there is nothing to opt out of on that front.

To exercise any of these, use the contact form. We do not discriminate against you for exercising a right.

International Transfers

Our infrastructure and processors may be located outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

Children

The Service is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

Changes

We may update this policy. Material changes will be notified through the Service or by email before they take effect, and the date at the top of this page will change.

Contact

Questions, or to exercise a right: use the contact form.

This policy describes our actual practices for a small independent product. It has not been reviewed by a lawyer and is not legal advice.