PrimeVerba AI — Privacy Policy Effective date: 13-Aug-2026 Last updated: 6 September 2026 Welcome PrimeVerba AI is a Windows desktop application and Android application that corrects the grammar and spelling of text you select or submit. On Windows, PrimeVerba can be triggered when you press Ctrl+C three times within 800 milliseconds. On Android, PrimeVerba allows you to correct text by copying it into a text correction field in the app, or by selecting text and tapping "Correct!" in the context menu to replace the selected text with the corrected version. We make money when users purchase our paid products and not by selling or monetizing user content. PrimeVerba is also available as a Chrome extension, which provides grammar and spelling correction functionality substantially similar to the Windows application. This Privacy Policy explains what personal data PrimeVerba AI ApS collects, why, and how we protect it. It applies to all users of PrimeVerba globally. All personal data we process is collected directly from you or generated automatically when you use the service (such as IP address, device information, and log data). We do not buy personal data from third parties. If we make material changes to this policy, we will notify you by email. 1. Data Controller The data controller responsible for your personal data is: PrimeVerba AI ApS CVR: 46648986 Torben Alers Niels Bohrs Allé 23, 2. 3254 5230 Odense, Denmark support@primeverba.app PrimeVerba AI ApS is registered in Denmark and subject to Danish and EU data protection law, supervised by Datatilsynet (the Danish Data Protection Authority): datatilsynet.dk We do not currently have a designated Data Protection Officer. For all data protection questions and GDPR requests, contact us at support@primeverba.app We will respond within one month. In complex cases this period may be extended by up to two additional months, in accordance with Art. 12(3) GDPR. If we extend the deadline, we will inform you within the initial 30-day period and explain the reason for the delay. Corporate and enterprise customers If you represent a company, employer, or educational institution and require a custom data management or data processing agreement, please contact PrimeVerba AI ApS at support@primeverba.app to discuss this. If you use PrimeVerba on a device controlled by your employer or educational institution, that organisation may be a separate controller for data processed on that device. You should consult their privacy notices as well. 2. Information We Collect a) Account information When you create an account, we collect your email address and hashed password. We also store your account creation date and, each time you authenticate successfully, the date and time of your last sign-in. Providing your email and password is necessary to create an account. Without this, we cannot provide the service. Marketing opt-in is optional and is not required for using PrimeVerba. If you sign in using Google, we may also receive and store basic profile information made available by Google through our authentication provider, such as your profile picture, name and other authentication metadata associated with your account. b) Subscription and billing data We record your subscription plan (Free or Premium), character usage balance, credit reset dates, and Stripe customer and subscription IDs. For Stripe customers, we may also access and store basic billing information associated with your Stripe account, such as the country associated with your billing address and your default payment method identifier. If you subscribe through the Google Play Store version of PrimeVerba, we may also receive and record Google Play or Google Play Billing-related transaction data made available to us, including purchase tokens, linked purchase tokens, order IDs, product identifiers, subscription identifiers, subscription status, auto-renewal status, expiry timestamps, acknowledgement status, and the full subscription verification response returned by the Google Play API, which is retained for subscription management and abuse prevention purposes. We do not store your payment card details. These are handled exclusively by Stripe or by Google through Google Play billing and supported payment methods such as Google Play Billing. During the subscription activation process, we may temporarily store your email address together with your Stripe customer ID, Stripe subscription ID, subscription plan, character limit, and subscription end date in an internal staging record. This record is used solely to activate your subscription when your account is confirmed and is deleted once activation is complete. c) Usage logs Each time you use PrimeVerba to correct text, we track your user ID, the character count of text submitted, the character count of the corrected output, the format type of the submitted text (for example, plain text or markdown, used for service reliability and correct processing), and the timestamp of the event. We do not log or store the content of the text itself in our own systems. Usage data is also used to enforce usage-based rate limits and to detect abuse patterns across requests. d) Technical and session data Our authentication provider automatically collects your IP address, browser/device user agent string, and session timestamps when you sign in. This is used for security, fraud prevention, and abuse detection. This authentication data may also include the date and time of your most recent sign-in and provider-related account metadata. If you download PrimeVerba through GitHub or obtain it through the Microsoft Store, GitHub, GooglePlay or Microsoft may independently process technical, download, diagnostic, account, and security information in connection with their respective platforms. e) Consent records We record whether you agreed to this Privacy Policy and our Terms of Service at signup, including the policy version, consent text, timestamp, the method by which you signed up, and, where applicable, the timestamp at which consent was withdrawn. f) Text submitted for correction When you trigger or request a correction in PrimeVerba, the selected or submitted text is sent to Mistral AI to generate a corrected version. This process is described in full in Section 7 below. PrimeVerba AI ApS does not store the submitted text or the corrected output in its own database. The text is discarded from our systems immediately after the corrected result is returned to your device. Warning: do not submit sensitive personal data. PrimeVerba is not designed or intended for processing special categories of personal data as defined under GDPR Art. 9, such as health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, or similar sensitive information. Please do not submit text containing such data for correction. See also the warning in Section 7. 3. Cookies and Similar Technologies We use cookies and similar technologies on this website to ensure the website functions properly, maintain security, prevent fraud, improve user experience and, where applicable and with your consent, analyze traffic and support marketing activities. Our website is hosted on Wix, and Wix may place certain cookies and similar technologies that are necessary for the secure and technical operation of the website. These cookies may be used, for example, to maintain sessions, remember technical preferences, protect the website and support core platform functions. Depending on the features activated on our website, additional cookies may be set by Wix or by integrated third-party services, for example for analytics, payments, embedded content, chat functions, booking tools or marketing services. Some cookies are strictly necessary for the operation, security and stability of the website and may be used without prior consent where permitted by law. Other cookies, in particular functional, analytics and marketing cookies, are only used where you have given your consent through our cookie banner, to the extent such consent is required. You can accept, reject or adjust your cookie preferences at any time through the cookie settings available on our website. For more detailed information about the cookies currently used on this website, including their name, provider, purpose and storage period, please refer to the cookie settings presented in our cookie banner. For general information about cookies and how they work, you can also visit https://allaboutcookies.org/. If you have questions about our use of cookies, you can contact us at support@primeverba.app. We may host the PrimeVerba website on different platforms over time (for example, Wix or a static site). Some of these platforms may use cookies; others may not. If the version of the website you are visiting does not display a cookie‑consent banner, this means that, at that time, we are not using any non‑essential cookies or similar tracking technologies on that version of the website. In that case, only strictly necessary technical technologies may be used, such as those required for security or to provide a function you have expressly requested. If we later use non‑essential cookies or similar technologies on a particular website (including analytics, advertising, embedded third‑party content, chat tools, or marketing pixels), we will update this Privacy Policy as needed and obtain any consent required before those technologies are activated. 4. How We Use Your Data We use your data only for the following purposes, each with a defined legal basis under GDPR: Providing and operating the service: we use your account data, usage logs, and billing data because it is necessary to fulfil our contract with you (Art. 6(1)(b) GDPR). Enforcing usage limits and preventing abuse: we use usage logs, usage-based rate limiting, and abuse detection patterns based on our legitimate interest in keeping the service secure and fair (Art. 6(1)(f) GDPR). Processing payments: we use your Stripe customer and subscription IDs and, where applicable, Google Play or Google Play Billing-related subscription and transaction identifiers because payment processing and subscription management are necessary to fulfil our contract with you (Art. 6(1)(b) GDPR). Security and fraud prevention: we use IP address, session data, and device information based on our legitimate interest in protecting the service and our users (Art. 6(1)(f) GDPR). Sending transactional emails: we use your email address to send account confirmations, password resets, and billing receipts, as these are necessary for the service (Art. 6(1)(b) GDPR). Sending marketing emails: we only do this with your explicit consent, given via checkbox at signup (Art. 6(1)(a) GDPR). Legal compliance: we may use any data category where required by applicable law (Art. 6(1)(c) GDPR). We do not use your data for targeted advertising. We do not sell your personal data to third parties. We do not use submitted text content for AI model training. 5. Marketing Communications We only send marketing emails to users who have explicitly opted in via a checkbox at signup. Every marketing email contains an unsubscribe link. You can also opt out at any time by contacting us at support@primeverba.app. Apart from marketing emails, we send transactional emails only (for example: account confirmation, password reset, and billing receipts). These cannot be opted out of as they are necessary for the service. 6. Third-Party Data Processors and Service Providers *(excluding Mistral AI)* We share your data with the following trusted service providers who act as data processors or service providers in connection with PrimeVerba. Where applicable, these providers are contractually bound to process your data only for the purposes described and in accordance with applicable data protection law. Supabase handles authentication and database hosting. Through Supabase Auth, we store your email address, account creation date, last sign-in timestamp, and, where applicable, basic Google account profile metadata such as your profile picture and, where applicable, the Google account name and profile picture returned during Google Sign-In. Supabase processes this information to authenticate users, maintain accounts, protect account security, and prevent abuse. We do not provide Google account information to advertisers or use it for targeted advertising. We do not use Google account information for AI model training. Supabase may process this information in accordance with its own privacy policy and applicable data-processing terms. We share your email address, hashed password, usage logs, consent records, and session/IP data with Supabase. Supabase also maintains an internal audit log of user authentication actions, which may include IP addresses and action payloads, for security and integrity purposes. Their servers are located in the EU (Ireland). Google API Services disclosure. PrimeVerba’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Stripe handles payment processing for subscriptions purchased through Stripe. We share your Stripe customer ID, subscription ID, and billing events with Stripe. Stripe does not receive your text content or usage logs. Google Play and Google Play Billing handle app distribution and subscription billing for users who subscribe through the Google Play Store version of PrimeVerba, including supported payment methods such as Google Play Billing. In that case, we receive and store transaction-related data returned by the Google Play API, including purchase tokens, linked purchase tokens, order IDs, product identifiers, subscription identifiers, subscription status, auto-renewal status, expiry timestamps, acknowledgement status, and the full API verification response. Google does not receive your text content from us for correction purposes. Railway hosts our backend API. Railway's servers may transiently process your IP address and server-side operational logs, which may include internal identifiers such as user IDs and Stripe customer IDs or Google Play subscription-related identifiers for debugging purposes. These are governed by Railway's data retention and privacy policies. Microsoft Store, Google Play and GitHub. PrimeVerba may be distributed through the Microsoft Store and may also be downloaded from GitHub or , including through GitHub-hosted release or download pages. Microsoft, Google Play and GitHub may independently collect and process personal data relating to their platforms and services, such as account information, IP address, device information, usage data, download activity, diagnostic data, and security logs, in accordance with their own privacy policies and terms. PrimeVerba AI ApS does not control or determine this independent processing. Please review Microsoft’s, Google Play’s and GitHub’s respective privacy policies for further information. PrimeVerba may receive only the information necessary to provide, authenticate, secure, update, or support the application, as described elsewhere in this Privacy Policy. The processing of text content by Mistral AI is described separately and in full in Section 7. 7. AI Processing Providers and Text Processing Warning: do not submit sensitive personal data. PrimeVerba is not intended for processing special categories of personal data under GDPR Art. 9. Do not submit text containing health data, biometric data, political opinions, religious beliefs, racial or ethnic origin, or similar sensitive information for correction. PrimeVerba AI ApS cannot guarantee how such data would be handled once transmitted to an external AI API. Role of the parties PrimeVerba AI ApS is the data controller for all user data processed through PrimeVerba. Mistral AI acts as a data processor for the specific purpose of generating grammar and spelling corrections through their API. Mistral AI processes your submitted text only on documented, lawful instructions from PrimeVerba AI ApS. What is sent and when When you use PrimeVerba's correction feature on Windows by pressing Ctrl+C three times within 800 milliseconds, or when you submit or select text in the Android app and tap "Correct!", the relevant text is transmitted to Mistral AI through its API for the purpose of generating a corrected version. The corrected text is returned to your device and either pasted in place of the original, inserted back into the relevant text field, or otherwise returned through the relevant app workflow. No other action is taken with the text. What data categories are involved The following data is involved in each correction request: The selected or submitted text you provided for correction. This may contain personal data if you have included names, addresses, or other identifying information in the text. The corrected output returned by Mistral AI. Operational data connected to the API request, such as a request identifier and timestamp, which are necessary for service reliability and debugging. Providing the selected or submitted text is strictly necessary to use the correction feature. If you do not submit text, PrimeVerba cannot perform a correction. Purpose of processing The text is sent to Mistral AI solely for the following purposes: delivering the grammar and spelling correction to you, ensuring service reliability, enabling debugging and testing. We do not use submitted text, corrections, or associated input/output for any service improvement purpose beyond delivering the correction itself. If this ever changes, we will update this policy and identify the legal basis before doing so. Legal basis The primary legal basis for sending your text to Mistral AI is performance of a contract (Art. 6(1)(b) GDPR). The correction cannot be provided without processing the submitted text. Where we also process operational logs for security, abuse prevention, rate limiting, or fraud control, this processing relies on our legitimate interests (Art. 6(1)(f) GDPR) in maintaining a secure and reliable service. Training and data retention We have disabled the use of submitted text for model training by Mistral AI. By default, text sent to Mistral AI through its APIs may be retained for the time necessary to generate the output and then for up to thirty (30) rolling days for abuse monitoring. Where data is processed Mistral AI hosts data in the European Union by default. Some of Mistral's own subprocessors may involve temporary data transfers outside the EU. Mistral states that such transfers are covered by Article 46 GDPR safeguards, including Standard Contractual Clauses. Mistral maintains a subprocessor list which may be updated over time. You can request information about current subprocessors by contacting us at support@primeverba.app Retention PrimeVerba AI ApS does not retain submitted text or corrected output in its own systems. These are discarded immediately after the correction is returned to your device. Backend server logs are retained according to Railway's platform log retention policy. We do not currently store structured operational logs in our own database beyond the usage logs described in Section 2c. By default, text sent to Mistral AI through its APIs may be retained for the time necessary to generate the output and then for up to thirty (30) rolling days for abuse monitoring. Automated decision-making The grammar and spelling correction produced by Mistral AI is a textual suggestion only. PrimeVerba does not use correction output to make automated decisions that produce legal or similarly significant effects on you. GDPR Article 22 does not apply to this processing. Data breach notification In the event of a personal data breach involving text you submitted through PrimeVerba, PrimeVerba AI ApS will handle all notifications to you and to the relevant supervisory authority as required by GDPR. Mistral AI is contractually required to notify PrimeVerba AI ApS without undue delay after becoming aware of a breach involving API data. PrimeVerba AI ApS will then notify affected users and Datatilsynet within the timeframes required by law. Your rights regarding Mistral AI processing All data subject rights requests relating to text processed through PrimeVerba should be directed to PrimeVerba AI ApS at support@primeverba.app. Mistral AI forwards any data subject requests it receives directly to PrimeVerba AI ApS as the responsible controller. Your rights are described in full in Section 9 below. 8. International Data Transfers Some of our processors and service providers (including Stripe, Google, and Railway) may process data outside the European Economic Area (EEA). Where this occurs, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46 as the transfer mechanism. In addition to SCCs, we have performed transfer risk assessments for relevant third-country transfers and implement appropriate technical and organisational measures to ensure that the level of protection guaranteed by GDPR is not undermined in practice. For Mistral AI, data is processed as described in Section 7. Temporary transfers involving Mistral's subprocessors are also covered by SCCs. This policy addresses the following legal frameworks: GDPR (EU/EEA), UK GDPR, and US state privacy laws including the California Consumer Privacy Act (CCPA). We do not make general claims of compliance with all international laws. If you are located in a jurisdiction not covered above and have questions about how your data is handled, contact us at support@primeverba.app 9. Data Retention We keep different types of data for different periods of time: Account data (email, password) is retained for as long as your account is active, or up to 30 days after you request deletion. Account data for this purpose also includes your account creation date, last sign-in timestamp, and any basic Google profile metadata that we retain through our authentication provider, such as your profile picture. Usage logs (character counts, format type, and timestamps) are retained for up to 12 months, then automatically deleted. Session and IP address data is retained for up to 90 days. A 90-day period is appropriate because fraud patterns, billing disputes, and subscription abuse often only become visible across full monthly billing cycles. Shorter retention would prevent us from detecting and responding to such patterns effectively. Billing and payment records, including relevant Stripe and Google Play or Google Play Billing-related transaction records made available to us, are retained for 5 years, as required by Danish Bookkeeping Law (Bogfoeringsloven). Billing data for this purpose may also include country from your billing address and default payment method identifiers where accessed from Stripe or Google Play for subscription management.” Consent records are retained for the duration of your account plus 5 years as legal evidence. Text submitted for correction is not retained by PrimeVerba AI ApS. It is discarded immediately after processing. Corrected output is not retained by PrimeVerba AI ApS. It is delivered to your device and discarded. Backend server logs are retained according to Railway's platform log retention policy. We do not currently store structured operational logs in our own database beyond the usage logs described in Section 2c. We retain records of your marketing opt-ins and opt-outs for as long as reasonably necessary to honor your preferences and to establish, exercise, or defend compliance-related legal claims. 10. Your Rights Depending on where you live, you have the following rights regarding your personal data: Right of access: request a copy of the data we hold about you. Right to rectification: request correction of inaccurate data. Right to erasure: request deletion of your account and associated data. Right to restrict processing: ask us to pause processing in certain circumstances. Right to data portability: receive your data in a machine-readable format. Right to object: object to processing based on legitimate interest, including marketing. Right to withdraw consent: where processing is based on consent (for example marketing emails), you can withdraw at any time without affecting prior lawful processing. All rights requests, including requests to delete your account and those relating to text processed by Mistral AI, should be sent to PrimeVerba AI ApS at support@primeverba.app. The Windows version of PrimeVerba does not currently include an in-app account-deletion button on Windows. To request account deletion, please email support@primeverba.app and include the email address associated with your PrimeVerba account. We will respond within one month. In complex cases this period may be extended by up to two additional months in accordance with Art. 12(3) GDPR. We will inform you of any extension within the initial 30-day period and explain the reason. We will respond within one month. In complex cases this period may be extended by up to two additional months in accordance with Art. 12(3) GDPR. We will inform you of any extension within the initial 30-day period and explain the reason. 11. Children's Privacy PrimeVerba is not intended for users under the age of 16. We do not knowingly collect personal data from children under 16. We do not collect or use any personal data for advertising purposes, for users of any age. If you believe we have inadvertently collected data from a child under 16, please contact support@primeverba.app and we will delete it promptly. 12. US Users (California and Other States) US users have rights under applicable state privacy laws including the California Consumer Privacy Act (CCPA). These include the right to know what personal data we collect, the right to delete your personal data, the right to correct inaccurate data, and the right to opt out of the sale or sharing of personal data. We do not sell your personal data. We do not share your personal data for cross-context behavioural advertising. Mistral AI also does not sell or share personal data under CCPA and does not process it outside the direct business relationship except as permitted by law. To exercise your rights as a US user, contact us at support@primeverba.app 13. Security We protect your data using the following measures: HTTPS/TLS encryption for data in transit. Hashed passwords. We never store or access your plaintext password. Row-Level Security (RLS) on database tables. We validate JWT signatures. Text corrections are processed only and never permanently stored by PrimeVerba AI ApS. 14. Changes to This Policy If we make material changes to this Privacy Policy, we will notify you by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of PrimeVerba after the effective date constitutes acceptance of the updated policy. 15. Complaints EU/EEA users: You have the right to lodge a complaint with the Danish Data Protection Authority. Website: datatilsynet.dk Email: dt@datatilsynet.dk UK users: You may contact the Information Commissioner's Office. Website: ico.org.uk US users: You may contact the attorney general in the state where you reside. You are always welcome to contact us first at support@primeverba.app and we will do our best to resolve your concern directly.