1. Data Controller & Scope
This Privacy Policy applies to the web application, APIs, and services operated under Authormity ("Authormity", "we", "our", or "us") accessible via authormity.space.
Authormity acts as the Data Controller (under EU/UK GDPR) and the Data Fiduciary (under the India Digital Personal Data Protection Act, 2023) for personal data collected directly through your use of our platform.
Your Voice DNA profiles, linguistic tones, interview recordings, drafts, and scheduled posts are used strictly to synthesize content for your private account. We utilize enterprise API endpoints with zero data retention terms. We do not sell, do not share, and never use your private data or writing samples to train public or shared foundational AI models.
3. Categories of Personal Data We Collect
- Account & Identity Data: Full name, email address, password hash (managed securely by Supabase Auth), profile avatar URL, and user ID.
- LinkedIn Profile & OAuth Data: LinkedIn public profile identifier, handle, and OAuth access tokens (which are cryptographically encrypted using AES-256-GCM prior to database persistence).
- Voice DNA & Content Data: Writing tone samples, sentence length patterns, content pillar preferences, niche keywords, scheduled posts, generated post drafts, and first-comment queues.
- Billing & Commercial Data: Subscription tier (Free Explorer, Creator, Pro Suite, Teams), renewal date, and billing customer identifier (processed securely by Dodo Payments; we do not store full credit card numbers).
- Technical & Log Data: IP address (hashed/anonymized for rate limiting), browser user-agent, operating system, and error diagnostic traces via Sentry.
4. Lawful Bases for Processing (EU/UK GDPR)
Contractual Performance (Art. 6(1)(b))
To provide Voice DNA generation, schedule your posts to LinkedIn, manage subscriptions, and maintain account access.
Explicit Consent (Art. 6(1)(a))
When you authenticate via LinkedIn OAuth or opt into diagnostic telemetry cookies.
Legitimate Interests (Art. 6(1)(f))
To detect fraud, enforce API rate limits, troubleshoot service outages, and secure our cloud infrastructure.
Legal Obligation (Art. 6(1)(c))
To maintain tax, accounting, and payment audit logs as required by applicable commercial and financial laws.
5. Notice to Data Principals in India (DPDP Act 2023)
In compliance with the Digital Personal Data Protection Act, 2023 (India), we notify all Indian Data Principals:
- Purpose of Processing: Your personal data is processed solely to synthesize personal authority content, grade posts, and schedule to LinkedIn.
- Withdrawal of Consent: You may withdraw consent at any time directly through the Settings page or by deleting your account.
- Right to Correction & Erasure: You have the legal right to rectify inaccurate data or request complete data erasure.
- Right of Grievance Redressal: You may submit any grievance regarding data processing to our designated Grievance Officer at
privacy@authormity.space. We are committed to responding to and resolving grievances within 30 calendar days. - Right to Nominate: You have the right to nominate an individual who, in the event of your death or incapacity, may exercise data rights on your behalf.
6. California Consumer Privacy Rights (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents are entitled to specific disclosures:
Do Not Sell or Share My Personal Information:
Authormity DOES NOT SELL and DOES NOT SHARE personal information of consumers to third parties for cross-context behavioral advertising, monetary, or other consideration.
Your California Rights:
- Right to Know: Request details on the categories and specific pieces of personal data collected.
- Right to Delete: Request deletion of your personal data collected by us.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Non-Discrimination: We will never discriminate against you for exercising your privacy rights.
7. Sub-processors & International Transfers
We partner with trusted third-party sub-processors to deliver cloud hosting, AI processing, and payments under strict Data Processing Addenda (DPAs) incorporating standard contractual safeguards.
| Sub-processor | Role & Purpose | Data Categories | Safeguards & Location |
|---|---|---|---|
| Supabase Inc. | Primary Database, Authentication & User Record Storage | User profile, email, authentication tokens, post drafts, Voice DNA parameters | United States / AWS (SOC 2, ISO 27001, Standard Contractual Clauses) |
| Amazon Web Services (AWS) | Secure Cloud Infrastructure, S3 Media Storage, CloudFront CDN, SSM Secret Storage | Uploaded images, carousel PDF files, encrypted environment secrets, system logs | US-East (us-east-1) (ISO 27001, SOC 1/2/3, PCI-DSS Level 1) |
| Dodo Payments Inc. | Billing, Subscription Management, Invoicing & Payment Processing | Customer email, billing name, payment tokens, subscription status | United States (PCI-DSS Level 1 Compliant Service Provider) |
| Upstash Inc. | Serverless Redis for Rate Limiting & Background Task Scheduling | Hashed user identifiers, scheduling job metadata, ephemeral IP hashes | US / EU (Encryption at rest, TLS in transit) |
| OpenRouter & OpenAI | AI Text Generation & Voice DNA Linguistic Tone Synthesis | Prompt content, writing samples, post generation drafts (Zero-Retention API) | United States (Zero Data Retention / No Model Training on User Data) |
| LinkedIn (Microsoft Corporation) | OAuth 2.0 User Authentication & LinkedIn Post Publishing API | Public profile information, encrypted OAuth tokens, published post IDs | United States (Governed by LinkedIn Developer Terms & User Consent) |
| Resend Inc. | Transactional System Emails & Security Notifications | User email address, transactional notification content | United States (DPA with Standard Contractual Clauses) |
| Functional Software Inc. (Sentry) | Application Error Monitoring & Performance Diagnostics | Client error stack traces, browser user-agent, anonymized diagnostic metadata | United States (Privacy Shield / Standard Contractual Clauses) |
8. Exercising Your Rights (Self-Serve & Automated)
We provide instant, self-serve tools directly in your Authormity dashboard under Settings > Danger Zone:
Instant Data Export (Portability)
Click "Download my data" in Settings to download your entire account history, Voice DNA models, posts, and CRM in standardized JSON.
Permanent Cascading Deletion
Click "Delete my account" to permanently purge your database records, S3 media files, scheduled queues, and revoke LinkedIn OAuth tokens instantly.
9. Technical Security Standards (Article 32)
- Encryption at Rest: Sensitive access tokens are encrypted with authenticated AES-256-GCM.
- Encryption in Transit: HTTPS/TLS 1.3 enforced across all web traffic and API endpoints.
- Tenant Isolation: PostgreSQL Row-Level Security (RLS) ensures users cannot access or view another user's data.
- Content Security Policy: Strict CSP headers preventing clickjacking, frame injection, and unauthorized script execution.
10. Contact Us & Grievance Officer
For privacy inquiries, Data Subject Access Requests (DSAR), or Grievance Redressal under the India DPDP Act 2023:
Email: privacy@authormity.space
Resolution Timeline: Within 30 days