Privacy Policy

Learn how Summdy collects, uses, and protects your personal information

Last Updated: July 31, 2025

1. Introduction

This Privacy Policy describes how Summdy ("we," "us," or "our") collects, uses, and protects your personal information when you use our AI-powered content summarization service, including our website and browser extension (collectively, the "Service").

Contact Information:

  • Email: privacy@summdy.ai
  • For general inquiries: contacts@summdy.ai

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address for account registration and authentication
  • Content Data: Web page content you choose to summarize using our browser extension
  • Chat Messages: Your conversations with AI summaries

2.2 Information Automatically Collected

  • Cookies and Similar Technologies: We use cookies for authentication, session management, and user preferences (such as theme settings)
  • Usage Information: Service usage patterns, feature interactions, and technical performance data
  • Technical Information: Browser type, device information, and IP address for service delivery

2.3 Information We Do NOT Collect

  • We do not collect your browsing history
  • We do not track web pages unless you actively choose to summarize them
  • We do not use analytics tools like Google Analytics
  • We do not record detailed error logs beyond standard system logs

3. How We Use Your Information

We use your personal information to:

  • Provide Core Services: Generate AI summaries and enable chat functionality
  • Account Management: Authenticate users and manage subscriptions
  • Service Improvement: Enhance our AI models and user experience
  • Communication: Send service-related notifications and respond to inquiries
  • Legal Compliance: Meet regulatory requirements and protect our rights

Important: We do not use your chat history or content to train AI models.

4. Third-Party Services

We integrate with the following third-party services that may process your data:

4.1 Essential Service Providers

  • Supabase: Database hosting and user authentication
  • Google Gemini AI: Content summarization processing
  • Stripe: Payment processing and subscription management
  • Vercel: Web hosting and application delivery

4.2 Data Processing Locations

Your data may be processed in:

  • Japan (Tokyo) - Supabase database servers via AWS ap-northeast-1
  • United States - Google Gemini AI, Stripe payment processing, Vercel hosting

We ensure all third-party processors maintain adequate data protection standards.

5. Legal Basis for Processing (GDPR)

For EU residents, we process your data based on:

  • Contract Performance: To provide our summarization service
  • Legitimate Interests: To improve our service and ensure security
  • Consent: For optional features and communications
  • Legal Obligations: To comply with applicable laws

6. Your Rights

6.1 All Users

  • Access: View your account information in dashboard settings
  • Correction: Update your email address and preferences
  • Deletion: Delete your account and all associated data via Settings > Account
  • Data Portability: Request a copy of your data by contacting privacy@summdy.ai

6.2 EU Residents (GDPR Rights)

You have additional rights including:

  • Right to object to processing
  • Right to restrict processing
  • Right to lodge complaints with supervisory authorities
  • Right to withdraw consent at any time

6.3 California Residents (CCPA Rights)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (Note: We do not sell personal information)
  • Right to non-discrimination

7. Data Retention

  • Account Data: Retained while your account is active
  • Content and Chat Data: Retained until account deletion or service termination
  • Inactive Accounts: Automatically deleted after 24 months of inactivity
  • Deleted Accounts: Data permanently removed within 30 days of deletion request

8. Data Security

We implement appropriate technical and organizational measures including:

  • Encryption of data in transit and at rest
  • Secure authentication systems
  • Regular security assessments
  • Limited access controls

However, no internet transmission is 100% secure. We cannot guarantee absolute security.

9. Children's Privacy

Our service is not intended for users under 16 years old. We do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will delete it promptly.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure adequate protection through:

  • Standard Contractual Clauses for EU data
  • Service provider certifications and safeguards
  • Regular privacy impact assessments

11. Cookies and Tracking

11.1 Types of Cookies We Use

  • Essential Cookies: Required for authentication and core functionality
  • Preference Cookies: Remember your settings (theme, language)
  • Session Cookies: Maintain your login state

11.2 Managing Cookies

You can manage cookies through your browser settings. Disabling essential cookies may affect service functionality.

12. Changes to This Policy

We may update this Privacy Policy to reflect service changes or legal requirements. We will:

  • Post the updated policy on our website
  • Update the "Last Updated" date
  • Notify users of material changes via email

13. Contact Us

For privacy-related questions or requests:

  • Privacy Email: privacy@summdy.ai
  • Response Time: We aim to respond within 30 days

For EU residents: If you're not satisfied with our response, you may lodge a complaint with your local data protection authority.