TextPatrol — Privacy Policy

Last updated: Aug 21, 2026

Version 1.0 · Effective Date: 21 August 2026 · Last Updated: 21 August 2026

KEY POINTS: When you use the Service we automatically collect device and usage data (IP address, language settings, time zone, device type and model, operating system, browser, unique identifiers, and cookies) to provide the Service, analyse usage, and measure advertising. If you make a purchase, we ask for your email; card data is collected by our payment processors, not stored by us. We use named third-party providers listed in this Policy. We do not sell your personal data for money and do not use your content to train generalised AI models. You can exercise your privacy rights at any time by contacting support@textpatrol.pro.

This Privacy Policy explains what personal data is collected when you use the website and services made available at textpatrol.pro (the "Website", and together with the products and services provided through it, the "Service"), how such personal data is processed, and your rights. The data controller is Imponilox Limited (reg. No. HE 405373), Themistokli Dervi 39, 1st floor, Office 104, 1066, Nicosia, Cyprus (the "Company", "we", "us").

BY USING THE SERVICE, YOU CONFIRM THAT (I) YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY, AND (II) YOU ARE AT LEAST 18 YEARS OF AGE. If you do not agree, you must not use the Service; in such case, please contact us to request deletion of your data and cancel any active subscriptions.

Any translation from the English version is provided for convenience only. In the event of any difference in meaning or interpretation, the English version prevails and is the sole legally binding version. "GDPR" means Regulation (EU) 2016/679; "EEA" includes EU and EFTA member states and, for the purposes of this Policy, the United Kingdom. "Process" includes to collect, store, use, and disclose.

1. Personal Data We Collect

1.1 Data you provide directly

Account and checkout data: email address ("Access Email") and, where applicable, name; onboarding and quiz answers used to personalise your experience; content and information you submit to the Service ("User Content"); communications you send to our support team. Payment information: card and payment data are collected and processed by our payment processors (Solidgate and/or other processors identified at checkout). We do not store full card data; we retain only transaction identifiers and subscription status.

1.2 Data collected automatically

Language settings, IP address, time zone, type and model of device, device settings, operating system, browser type, Internet service provider or mobile carrier, hardware identifiers, advertising identifiers, other unique identifiers, cookie data, and usage data (pages viewed, features used, purchase events, session data).

1.3 Data from third parties

We may receive data from analytics providers, attribution partners, advertising platforms, and payment processors, as described in Sections 3 and 4.

2. For What Purposes and Under What Legal Bases We Process Your Personal Data

Purpose

Data categories

Legal basis (GDPR)

Providing the Service, delivering purchased access, customer support

Account/checkout data, User Content, transaction identifiers

Performance of a contract (Art. 6(1)(b))

Personalising your experience (onboarding answers, recommendations)

Onboarding data, usage data

Performance of a contract; legitimate interests (Art. 6(1)(f))

Analytics, research, and improving the Service

Usage and device data

Legitimate interests (Art. 6(1)(f))

Serving, measuring, and attributing advertising (including showing ads only to particular user groups)

Device identifiers, advertising IDs, usage/purchase events

Consent (Art. 6(1)(a)) where required; otherwise legitimate interests

Marketing communications (email)

Email address

Consent (Art. 6(1)(a)); you may opt out at any time

Payment processing, fraud prevention, chargeback handling

Transaction data, device data

Performance of a contract; legitimate interests; legal obligation (Art. 6(1)(c))

Compliance with law, responding to lawful requests, establishing or defending legal claims

Any of the above, as relevant

Legal obligation (Art. 6(1)(c)); legitimate interests

Where we rely on legitimate interests, those interests are: operating, securing, and improving the Service; measuring and improving marketing efficiency; and preventing fraud and abuse. You may object as described in Section 6.

3. Third-Party Solutions We Use

For providing the Service, analytics, and advertising, we use third-party solutions. As a result, we may process data using solutions developed by the following providers (the list may be updated from time to time): Amazon Web Services (cloud hosting), Google (analytics, BigQuery, Firebase, advertising), Amplitude (product analytics), AppsFlyer (attribution), Meta (advertising and measurement), TikTok (advertising and measurement), Solidgate (payment processing), OpenAI or other AI model providers (generation of Output), Hotjar (experience analytics), Iterable or similar (email communications), and Zendesk or similar (customer support). Some data is stored and processed on the servers of such providers.

4. With Whom We Share Your Personal Data

Recipient category

Purpose

Data shared

Cloud and infrastructure providers (e.g. AWS, Google Cloud)

Hosting and operating the Service

All categories, under processing agreements

AI model providers (e.g. OpenAI)

Generating Output from your requests

User Content necessary for generation; not used by us to train generalised models

Analytics and attribution (Amplitude, AppsFlyer, Google Analytics)

Usage analytics; ad attribution

Device, identifier, and event data

Advertising platforms (Meta, Google, TikTok)

Serving and measuring ads; audience building

Identifiers and event data (may constitute "sharing" under CCPA)

Payment processors (Solidgate and/or others identified at checkout)

Payment processing, billing, refunds

Transaction data; card data handled by the processor

Support and communications tools (Zendesk, email providers)

Customer support; transactional and marketing email

Email, support communications

Public authorities

Where required by law or to protect rights

As legally required

Successors in a business transfer

Merger, acquisition, or asset sale

Relevant categories, subject to this Policy

We do not sell personal data for monetary consideration. Certain disclosures to advertising platforms may qualify as "sale" or "sharing" under the CCPA/CPRA; you can opt out as described in Section 7.

5. International Data Transfers

We are based in Cyprus (EU) and use providers located in various countries, including the United States. Where personal data of EEA or UK residents is transferred to countries without an adequacy decision, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and the UK Addendum or IDTA, as applicable), together with supplementary measures where required.

6. Your Privacy Rights (EEA/UK)

Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict processing; data portability; object to processing based on legitimate interests (including profiling) and to direct marketing; and withdraw consent at any time (without affecting prior processing). To exercise your rights, contact support@textpatrol.pro. We may need to verify your identity. You also have the right to lodge a complaint with a supervisory authority, in particular the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or the authority of your habitual residence.

7. U.S. States Privacy Notice

If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the right to: know/access the personal information we collect; delete it; correct it; opt out of "sale" or "sharing" of personal information (including for cross-context behavioural advertising); limit use of sensitive personal information (we do not use sensitive personal information for purposes requiring a limit right); and non-discrimination for exercising your rights. Categories collected are described in Section 1; purposes in Section 2; disclosures in Section 4. To exercise rights or opt out, contact support@textpatrol.pro or use the "Do Not Sell or Share My Personal Data" mechanism on the Website. Authorised agents may submit requests with proof of authorisation. If we deny your request, you may appeal by replying to our decision; if the appeal is denied, you may contact your state attorney general.

8. Age Limitation

The Service is intended for persons 18 years of age or older. We do not knowingly collect personal data from persons under 18. If we learn that we have collected personal data from a person under 18, we will delete it. If you believe a minor has provided us personal data, contact support@textpatrol.pro.

9. Data Retention

Data category

Retention period

Reason

Account and checkout data

While your access is active + up to 30 days after deletion request

Service provision

User Content and Output

While your access is active; deleted or de-identified within 30 days of deletion request

Service provision

Transaction records

Up to 7 years

Tax, accounting, and legal obligations

Analytics data

Rolling periods set by provider (typically 2–25 months)

Analytics

Support communications

Up to 3 years

Support quality; legal claims

Data under legal hold

Duration of the hold

Legal obligation

We delete or irreversibly de-identify personal data within approximately 30 days of a verified deletion request, except where law requires longer retention.

10. Data Security

We apply reasonable technical and organisational measures to protect personal data, including encryption in transit, access controls, and least-privilege access. No method of transmission or storage is completely secure; you are responsible for keeping your credentials and access links confidential. In the event of a personal data breach affecting your rights, we will notify you and the competent authority as required by law.

11. Cookies and Tracking Technologies

We use cookies, SDKs, and pixels in four categories: strictly necessary (Service operation), functional (preferences), performance/analytics, and targeting/advertising. Where required by law, non-essential cookies are set only with your consent, which you can manage via the cookie banner or your browser settings. See our Cookie Policy (if published separately) for details. "Do Not Track" browser signals are not currently responded to; where required, we honour opt-out preference signals such as the Global Privacy Control for U.S. state opt-outs.

12. AI-Generated Content and Your Data

Your requests and User Content are processed by AI model providers solely to generate Output for you, to enforce our terms, and to maintain safety. We do not use your User Content to train generalised AI models made available to other customers, except with your consent or in de-identified, aggregated form. Where required, AI-generated content includes labels and/or provenance metadata (such as C2PA content credentials).

13. Third-Party Links

The Service may contain links to third-party websites or services. This Policy does not apply to them; review their privacy policies.

14. Changes to This Privacy Policy

We may update this Policy from time to time. If changes materially affect your rights, we will notify you at least 14 days before they take effect via your Access Email or prominent notice within the Service. The "Last Updated" date reflects the latest version.

15. Data Controller; Contact Us

Imponilox Limited

reg. No. HE 405373

Themistokli Dervi 39, 1st floor, Office 104, 1066, Nicosia, Cyprus

Email: support@textpatrol.pro

EEA residents may also contact the supervisory authority of their habitual residence.