When you send text to the API
Rewrites run as jobs, so a finished result has to wait somewhere until your system collects it. Your text is used to run the job and deleted when processing finishes. The result waits, encrypted at rest, until your webhook receives it or you fetch it, then it's deleted. Anything not collected is deleted after 60 minutes.
POST
Request
Your text arrives over HTTPS.
/v1/rewrite202
Job runs
The input is kept only while the job is queued or running, then deleted.
job_01JD…≤ 60 min
Held, encrypted
Only the finished result waits, and only until collected.
encryptedDelivered
Webhook or GET
Your webhook receives it, or you fetch it once.
200 OKThen
Deleted
Gone from our database. Uncollected results go after 60 min.
deleted
How long an API result can exist
Hard limit: 60 minutes
The result is deleted as soon as your webhook receives it or you fetch it. If nobody collects it, it is deleted at 60 minutes.
Short requests can also run synchronously with async: false, and Detect does by default. Then the result goes back on the open connection instead of waiting to be collected. The async jobs guide has the details.
Our model provider
Editing, style analysis and fact checks use OpenAI's API, so the relevant part of your text, candidate rewrites and voice samples pass through OpenAI while a job runs. Rewrites use OpenAI's API with storage turned off (store: false). OpenAI doesn't train on API data by default, but under its policy abuse-monitoring logs can keep content for up to 30 days. We haven't been approved for zero data retention, so we don't claim it.
Detection scoring runs on our own servers in the United States.
Voice profiles
Writing samples are deleted once the profile is built. The profile is kept until you delete the voice. It holds style measurements and may include short excerpts the model uses to match your voice.
Your samples
Deleted after the profile is built
What the profile keeps Example
- Sentence lengthavg 14 words, varied
- Punctuationfew semicolons, no em dashes
- Phrase habitsshort openers, plain verbs
- Paragraphs1 to 3 sentences
Style measurements, plus a few short excerpts at most
You can delete a voice in the dashboard at any time. Deleting it removes the profile.
What we keep, and what we delete
What we keep
What an account can't run without.
- Account details: email, workspace name and sign-in records (Supabase)
- Billing records, held by Stripe (we never see full card numbers)
- Usage records: time, endpoint, status, word counts and timing. Never the text
- API keys, stored hashed
- Voice profiles you create, until you delete them
What we delete
Your content, as soon as the job no longer needs it.
- The text you send, once processing finishes
- Rewrites and scores, once delivered, or after 60 minutes if nobody collects them
- Writing samples, once a voice profile is built
- Your text in request logs: logs keep metadata only
- Idempotency records after 24 hours (they never held text)
Who handles it
These services run IntactVoice. Two of them handle your text: OpenAI and our own API and inference servers, and only while a job runs.
Vercel
Website hosting
Never sees your text
Supabase
Sign-in and application database (US East, North Virginia)
Never sees your text
OpenAI
Editing, style analysis and fact checks (API, storage off)
Handles your text during a job
Our API and inference servers
Run rewrites and detection in the United States
Handles your text during a job
Resend
Sign-in and account email
Never sees your text
Stripe
Checkout, subscriptions and invoices
Never sees your text
Training and selling
No training
We don't train models on your content.
No selling, no sharing
We never sell or share your content with advertisers, data brokers or anyone else.
Ads on our marketing pages
The Privacy Policy explains what they receive and how to opt out, and the Cookie Policy lists each cookie.
Questions and deletion requests
Ask us anything about how your data is handled at support@intactvoice.com. To close your account and delete its data, email us from the address on the account; we delete it within 30 days. The Privacy Policy and Terms of Service are the binding versions of this page.