MergeDraft
← Home

Privacy Policy

Last updated: 17 June 2026

This policy explains what personal data we process when you use MergeDraft, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR) and German data-protection law.

The short version

  • Your documents are not stored. We process the file you upload in memory to generate the edits, return the result to you, and keep no copy.
  • We keep the minimum needed to run accounts and payments – your email and credit balance.
  • We don’t sell your data, and your documents are never used to train AI models.

Controller

The controller responsible for processing your data is:
Ilona Lazoryshyna
Cimbernstraße 53, 81377 München, Germany
lazoryshynailona@gmail.com – see our Imprint for full details.

What we process, why, and on what legal basis

  • Account data (your email; your password is stored hashed by our authentication provider) and your credit balance – to create and run your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Documents you upload. When you process a document, its text and the comments in it are transmitted to our AI provider to generate the suggested edits, and the edited file is returned to you. The document is handled in memory only – we do not save it and we do not log its contents. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Payment data. Card payments are handled by Stripe; we never receive or store your full card details, only a record that a purchase occurred and how many credits to add. Legal bases: performance of a contract (Art. 6(1)(b)) and compliance with legal retention obligations (Art. 6(1)(c) GDPR).
  • Technical data. Your IP address is used transiently to prevent abuse and to rate-limit free usage (kept only as a short-lived counter), and we use cookieless analytics to count page views. Legal basis: our legitimate interest in securing and improving the service (Art. 6(1)(f) GDPR).

Service providers (processors) and international transfers

We share data only with the providers that make the service work. Some are located in the United States; where data is transferred outside the EU/EEA, it is safeguarded by appropriate measures such as the EU Standard Contractual Clauses or an adequacy decision (e.g. the EU–U.S. Data Privacy Framework).

  • OpenAI (OpenAI Ireland Ltd. for EU/EEA users) – generates the edits from your document text and comments. We have a Data Processing Agreement in place with OpenAI under which it acts only as our processor; it does not use data submitted via its API to train its models, and any transfer to the United States is covered by the EU Standard Contractual Clauses. OpenAI’s current sub-processors are listed at platform.openai.com/subprocessors.
  • Supabase – stores your account (email, credit balance).
  • Stripe – processes payments.
  • Vercel – hosting and cookieless analytics.

How long we keep data

  • Documents: not retained – discarded as soon as processing finishes.
  • Account data: kept while your account exists, then deleted on request.
  • Payment records: retained by us and/or Stripe for as long as tax and commercial law require (in Germany, generally up to 10 years).
  • Rate-limit counters: expire automatically within hours to a day.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time. To exercise any of these, email lazoryshynailona@gmail.com.

You also have the right to lodge a complaint with a data-protection supervisory authority. In our case the competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA); you may also contact the authority where you live.

Cookies

We use only the essential cookies needed to keep you signed in. Our analytics are cookieless, so we don’t set tracking cookies and no cookie banner is required for them.

Changes

We may update this policy; we’ll change the “last updated” date above when we do, and note material changes in the app.

Privacy·Terms·Imprint·Contact
© 2026 MergeDraft