Draft — pending legal review
This document describes how Analogize actually works, but it has not been reviewed by a lawyer and is not yet binding. Have counsel review it before launch.
Privacy Policy
Last updated: 20 August 2026
1. What this covers
This policy explains what Analogize collects, why, who else sees it, and what you can demand of us. The operator of Analogize is the data controller for this processing.
2. What we collect
- Account data — your email address, and the authentication identifiers created when you sign in.
- Content you submit — topics, pasted text, uploaded documents, uploaded images, and URLs you ask us to read.
- Generated content — the analogies produced for you, and any you pin, publish or add to collections.
- Usage records — a timestamped row per generation, used to enforce daily limits.
- Anonymous allowance data — before you sign in we store a one-way SHA-256 hash of your IP address, so that the free preview cannot be replayed indefinitely. We do not store the IP address itself, and these rows are deleted after 7 days.
- Product analytics — which features you use, and when generation succeeds or fails.
3. Why we are allowed to process it
- Performance of a contract — generating, storing and displaying analogies; running your subscription.
- Legitimate interests — preventing abuse of the free allowance, and understanding which features work. You can object to analytics processing by contacting us.
- Legal obligation — retaining billing records.
4. Who else receives your data
We use the following processors. Content you submit is sent to whichever AI provider is needed for the feature you used:
- OpenAI (United States) — receives your topic or content to generate analogies, and to generate illustrations. Analogize uses OpenAI’s API, where submissions are not used to train their models by default.
- Anthropic (United States) — receives images you upload, to describe them before an analogy is generated.
- OpenRouter (United States) — used as a fallback route for illustration generation, forwarding to Google’s Gemini image models.
- Supabase (hosted in the region selected for this project) — database, authentication and storage of your account and saved analogies.
- Stripe (United States / Ireland) — payment processing. We never see or store your card details.
- PostHog (United States) — product analytics.
- Vercel — application hosting and request logs.
Where these processors are outside the EEA, transfers rely on Standard Contractual Clauses. We do not sell your data, and we do not use your content to train our own models.
5. URLs you ask us to read
When you use the URL input, our server fetches that page and extracts its text. The request comes from our infrastructure, not your browser, so the destination site sees us rather than you. Do not submit URLs to private or internal systems.
6. How long we keep things
- Account, saved analogies and collections: until you delete them or delete your account.
- Generation usage rows: retained while your account exists, for limit enforcement.
- Hashed-IP rows for the anonymous allowance: 7 days.
- Billing records: as long as tax and accounting law requires, typically 6 years.
- Published analogies: until you unpublish them or delete your account.
7. Your rights
If you are in the EU, EEA or UK you have the right to access, correct, export, restrict, object to, and erase your personal data, and to complain to your national data protection authority.
You can exercise erasure yourself: Dashboard → Delete account immediately and permanently removes your account, saved analogies, collections and usage history. It cannot be undone. For any other request, email us and we will respond within 30 days.
8. Cookies
We set a session cookie so you stay signed in, a cookie storing your chosen interface language, and — before sign-in — a cookie recording that the free preview has been used. These are necessary for the Service to function. PostHog sets analytics cookies.
9. Children
The Service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We will announce material changes in the app before they take effect.
11. Contact
Privacy questions and data requests: ignatovich.dm@gmail.com.