Draft. This page is a scaffolded placeholder. Final body copy is owed by snizzly Trust; entity, signatory and DPO names are owed by Mohammad (DECISIONS-QUEUE #19). Until then, the page is published only at the engineering-preview layer and is not binding on any party.
Policy · MVP

Privacy Policy

snizzly is operated by {{ENTITY_NAME}} (“snizzly”, “we”, “us”). This policy describes the personal data we process when you visit snizzly.com, create an account, or use the AI humanizer / detector / writing tools, and the rights you have over that data.

Last reviewed · 2026-05-24

1 · Data we collect

1.1 Account data

When you create an account, we collect your email address, hashed password (or Google identity token if you sign in with Google), the time the account was created, and a per-account unique ID.

1.2 Document content

Text you submit to the humanizer, detector, grammar checker, citation generator, plagiarism checker, summarizer or coach is processed in order to return a result. We store submitted documents and their results so you can revisit them in your dashboard.

1.3 Usage and operational data

Standard server logs (timestamps, IP address, user agent, route, HTTP status), product analytics events captured in our own first-party AnalyticsEvent table, API request counters, and rate-limit state.

1.4 Billing data

Transaction IDs, pack identifiers, amounts and statuses from Ziina or PayPal. We never see or store full card numbers.

2 · Why we use it

  • To provide the service you asked for (humanize, detect, etc.).
  • To bill you for credit packs and to honour refunds.
  • To investigate abuse, rate-limit per-API-key usage and protect the service against fraud and brute-force.
  • To improve the product (de-identified, aggregated usage telemetry only — we do not train detection models on your documents).
  • To respond when you contact us via support or legal channels.

Pending Trust draft · Lawful-basis table to be drafted by Trust per UAE PDPL Art. 5 + (where applicable) GDPR Art. 6 mapping. Tracking under DECISIONS-QUEUE #19.

4 · Retention

  • Account records: retained while the account is active and for 12 months after closure, then deleted.
  • Submitted documents and results: retained while the account is active; you may delete any document from your dashboard at any time.
  • Server logs: 30 days rolling window.
  • Free-tier daily abuse counters: 7 days rolling window (see HumanizeUsageDaily purge job).
  • Billing records: retained for 5 years in line with UAE tax law.

5 · Who we share it with

We use a limited set of sub-processors to deliver the service. The full list — including the legal basis for each transfer — is published at /sub-processors. We do not sell your data and we do not share it for cross-context behavioural advertising.

6 · Your rights

Depending on your jurisdiction (UAE PDPL Federal Decree-Law 45/2021, KSA PDPL, Lebanon Law 81/2018, Egypt Law 151/2020, or, where applicable, the GDPR) you may have the right to access, rectify, delete, port or restrict processing of your personal data, and to object to processing or withdraw consent.

To exercise any of these rights, write to privacy@snizzly.com. We respond within 30 days per UAE PDPL Art. 13(4).

7 · Security

TLS in transit; encrypted database at rest; access on a need-to-know basis. Suspected vulnerabilities go to security@snizzly.com.

8 · International transfers

Pending Trust draft · Cross-border transfer-basis paragraph to be drafted by Trust; sub-processor locations are listed at /sub-processors.

9 · How to contact us

Data Protection Officer: {{DPO_NAME}}

Email for privacy matters: privacy@snizzly.com. Email for general legal matters: legal@snizzly.com.

10 · Changes to this policy

Material changes will be notified by email to active account holders at least 14 days before they take effect. Non-material edits will be reflected in the “Last reviewed” date above.