# TypeSafe Privacy Policy Effective date: 22 September 2026 This policy covers the TypeSafe iPhone and iPad app (`pro.typesafe`) and its connection to `api.typesafe.pro`. ## Who is responsible **NEXABRIDGE LTD** is responsible for the processing described in this policy. 311 Shoreham Street SHEFFIELD S2 4FA United Kingdom Contact: [adm@nexabridge.tech](mailto:adm@nexabridge.tech) ## What stays on your device The app saves your current text and question drafts, named presets, the most recent 20 successful runs (including their requests and responses), appearance preference, and haptics preference in its local storage. These records are not uploaded as a workspace or synchronised by us between devices. Your device's backup settings may include app data in a device or cloud backup managed by Apple. You can remove presets and history entries individually. **Settings → Clear local data** resets your drafts and removes your saved presets and history from the app, while retaining appearance and haptics preferences. Local records remain until you remove them, clear local data, remove the app and its data, or, for history, replace them with newer runs beyond the 20-entry limit. Manage any existing device backups separately in Apple's settings. ## What happens when you run a question When you select **Run**, **Retry**, or pull to refresh, the app sends the current input text, question, criteria, model name, and generated question identifier over HTTPS to `api.typesafe.pro`. Our gateway forwards the evaluation to **TypeSafe AI, Inc.** at `api.typesafe.ai`, which processes it and returns the answer. Editing a draft or opening an example does not send an evaluation. The content you submit may contain personal data if you include it. Use fictional or non-sensitive examples, and only submit information you are entitled to share. The app does not require an account, request your contacts or location, or include advertising or third-party analytics SDKs. It does not send a saved workspace to us. Network services nevertheless receive connection information, including your IP address. Our gateway does not save request bodies or successful answer bodies in its application database. It does retain operational records: IP addresses, request identifiers, timestamps, routes, status and error codes, request sizes, timings, and token-usage statistics. Error diagnostics can contain a limited excerpt of an upstream error response, with credentials redacted. An error response could echo part of submitted content; redaction is not a guarantee that all personal data is removed. Cancelling a run stops the app from displaying or saving that result. It cannot retract a request that a server has already received. Clearing local data also does not delete server records. ## Why we process information We process submitted content to provide the evaluation you request. Where that content is personal data, our lawful basis is performance of the service contract with you. Providing input is voluntary, but the evaluation cannot run without it. We process limited technical records for our legitimate interests in keeping the service available, enforcing rate limits, preventing abuse, and diagnosing failures. If you contact us, we use your email address and message to respond and resolve your request, based on our legitimate interest in providing support. We may also process information when necessary to meet a legal obligation. We do not sell your personal data or use the app for targeted advertising. The model generates illustrative choices, scores, and probabilities. The app does not itself use these outputs to make decisions about you that have legal or similarly significant effects. ## Service providers and international processing Submitted content is shared with TypeSafe AI to perform the evaluation. Hosting and network-security providers, including Cloudflare, process data needed to deliver and protect the connection. Access to our operational records is restricted to authorised administrators. We may disclose information where required by law or necessary to investigate abuse and protect legal rights. TypeSafe AI states that its service is hosted in the United States. Its published policy says it does not train or fine-tune models on submitted input, but it does process and retain data for service, security, and other stated purposes. This is not a zero-retention service. See [TypeSafe AI's Privacy Policy](https://typesafe.ai/legal/privacy-policy) and [Master Customer Agreement](https://typesafe.ai/legal/mca). TypeSafe AI's [Data Processing Addendum](https://typesafe.ai/legal/data-processing) describes its processor obligations and international-transfer safeguards, including the EU Standard Contractual Clauses and UK Addendum. You can contact us to request information about applicable safeguards or a copy. Network providers can also process information internationally; see [Cloudflare's Privacy Policy](https://www.cloudflare.com/privacypolicy/). If you use a TestFlight build, Apple processes beta-testing information and may share crash reports, usage information, and feedback with us under [TestFlight & Privacy](https://www.apple.com/legal/privacy/data/en/test-flight/). Links to websites, documentation, and this policy open third-party services, whose own privacy policies apply to those visits. ## How long information is kept Our gateway's operational activity and database error records are configured to expire after **seven days**, with database deletion performed by periodic cleanup. Separate bounded server diagnostic logs rotate by size, so their duration depends on log volume rather than a fixed number of days. They can contain sanitised error excerpts if normal error recording is unavailable. We use these records for troubleshooting and security. TypeSafe AI does not publish a fixed retention period for all API data. Its policy bases retention on the purposes of processing, service needs, and legal requirements; our seven-day gateway setting does not control its retention. Infrastructure providers and Apple apply their own retention policies. We keep support correspondence only as needed to resolve the request, handle related disputes, and satisfy applicable legal obligations. ## Your choices and rights You can use the examples and edit drafts without submitting them. Stop making requests if you do not want further input sent to the API. Use the local deletion controls described above to remove information from the app. Depending on applicable law and the circumstances, you can request access, correction, deletion, restriction, or portability of personal data we process. **You can object to processing based on our legitimate interests.** Contact [adm@nexabridge.tech](mailto:adm@nexabridge.tech) to exercise these rights. Include an approximate request time and request ID, if available, rather than sending the original sensitive input again. We may need proportionate information to identify the relevant record and verify your request. We cannot access drafts held only on your device, and some records may already have expired. You may complain to the UK Information Commissioner's Office at [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/) or to the data-protection authority where you live or work. You do not need to contact us first. ## Children and policy changes This developer playground is not directed at children. TypeSafe AI's published policy states that its services are not directed at people under 18. Please do not submit children's personal information. Contact us if you believe such information has been provided so we can address it. We will publish changes to this policy here and update the effective date. The current policy is always available from the app's Settings.