This Privacy Policy explains what data textsummarizer.net ("Text Summarizer", "we", "us") collects
when you use our AI summarization and PDF chat features (collectively, the "Service"), how we use and share that
data, how long we keep it, and what rights you have.
What you should know up-front.
Text you submit for summarization and the contents of PDFs you upload to Chat with PDF are sent to
OpenAI for processing, and a copy of submitted summarization text is stored in our database for
service operations and abuse-prevention purposes. Don't submit content you wouldn't want a third-party processor
to handle.
1. Who we are
The Service is operated by the team behind textsummarizer.net. For any privacy-related question,
you can reach us at [email protected] or via our
Contact page.
2. Data we collect
2.1 Account data (only if you create an account)
- Name, email address, hashed password.
- Optional profile fields: company name and phone number.
- Billing address fields (address line 1 & 2, city, state/region, postal code, country) —
populated when you complete checkout with our payment processor.
2.2 Subscription data (only if you subscribe to a paid plan)
- Subscription status, plan (Starter or Pro), billing cycle (monthly or yearly), renewal and end dates,
trial-end date when applicable.
- Identifiers issued by our payment processor (Lemon Squeezy customer ID and subscription ID). We do not
store your card details — Lemon Squeezy handles that directly.
2.3 Content you submit
- Summarizer text and URLs. When you summarize pasted text or use the URL tab (URL summarizer / article summarizer) on
our home page, /tldr,
/ai-pdf-summarizer (file upload only), or the Pro Summarizer, we store the submitted
text, the URL (if any), the chosen mode, a word count, and the two-letter country code derived from your
request. We use this for service operations, debugging, and abuse-prevention.
- Files you upload. When you upload a PDF, DOCX, XLSX, PPTX or TXT file for summarization,
we extract its text on the fly. The extracted text is then handled the same way as 2.3 above.
- Chat with PDF. For Pro users, we persist your Chat-with-PDF session metadata
(filename, size, word count) and the full extracted text of the document, along with every message
you and the assistant exchange in that session. You can delete individual sessions or restart them
from the chat history at any time.
- Free Chat with PDF. The public /chat-pdf preview keeps uploads and messages only in temporary server cache for your session (with strict caps); nothing is saved to your account history.
2.4 Usage and technical data (collected automatically)
- Per-day usage rollups: number of summaries you've run today and the total words processed today.
For signed-in users this is keyed to your user account; for anonymous users we use a hashed
IP-derived bucket so we can enforce the free-tier daily cap without storing your raw IP.
- Standard request data: IP address, user-agent, browser/OS, referrer, timestamps. These are used for
rate-limiting, fraud detection and service reliability.
- Error logs — technical metadata about failed requests (e.g., stack traces). These may incidentally
contain excerpts of the content involved in the failure.
2.5 Information from third parties
- From Lemon Squeezy (webhooks): subscription status changes, renewals, cancellations,
and the billing address fields you entered at checkout.
3. How we use your data
We use the data described above to:
- Operate the Service (generate summaries, run Chat with PDF, extract file text, store chat history,
authenticate you, render dashboards).
- Enforce plan limits (e.g., the free 5/day cap, the Starter 50/day cap, the per-summary word limit) and
prevent abuse and fraud.
- Show you how much of your daily quota you've used.
- Process payments and manage your subscription via Lemon Squeezy.
- Improve the Service through aggregate analysis of usage patterns and the quality of our outputs.
- Respond to support requests.
- Comply with legal obligations (tax records, lawful requests, etc.).
We do not sell your personal information, and we do not use your submitted
content to train AI models — submitted content is sent to OpenAI only to generate your summary or chat
response (see section 6). See OpenAI's
API data-usage policy for how OpenAI handles API data.
4. Legal basis (EEA / UK users)
If you are in the EEA or UK, the legal bases on which we rely are:
- Performance of a contract — for delivering the Service to you and processing
payments.
- Legitimate interests — for service security, fraud prevention, rate-limit
enforcement, and aggregate analytics.
- Consent — where required (e.g., optional marketing emails); you can withdraw
consent at any time.
- Legal obligation — for tax records and responses to lawful requests.
5. Who we share data with
We share data only with the third parties needed to run the Service, and only the minimum necessary:
- Our hosting provider (to store the data described above).
- OpenAI — for AI text generation (see section 6).
- Lemon Squeezy — as merchant of record for payment processing, taxes and invoices.
- Cloudflare (when applicable) — for CDN, DDoS protection, and country-code
geolocation of incoming requests.
- Authorities, when required to do so by law.
6. Sub-processors
The following sub-processors are core to how the Service works today:
| Provider | Purpose | Data shared |
| OpenAI, L.L.C. (USA) |
Generate summaries; answer Chat-with-PDF questions. |
The text or PDF extract you submit, plus your follow-up messages in Chat with PDF. |
| Lemon Squeezy (USA) |
Payment processing, taxes, invoices, billing portal, subscription webhooks. |
Name, email, billing address, payment-method details (entered directly with them), subscription history. |
| Cloudflare, Inc. (USA) |
CDN, traffic protection, country-code header. |
IP address and request metadata. |
If we add or replace a sub-processor that materially changes the nature of the data we share, we will update
this page.
7. How long we keep data
| Data | Retention |
| Account & profile fields (name, email, hashed password, company, phone, billing address) |
For as long as your account is active. Deleted within 30 days of an account-deletion request, except
where we must retain records for tax, legal or fraud-prevention reasons. |
| Subscription records (status, plan, renewal dates) |
Retained for up to 7 years after the subscription ends, to satisfy tax and accounting
requirements. |
Submitted summarization text and URLs (content_logs) |
Retained up to 90 days for service-operation, abuse-prevention and quality-improvement
purposes, then deleted or anonymized. |
| Chat-with-PDF sessions, extracted PDF text and chat messages |
Retained for as long as you keep them. You can delete individual sessions from the chat-history
sidebar at any time, and they're hard-deleted from our database. Sessions older than
180 days may be deleted automatically. |
Daily usage rollups (usage_daily) |
Retained for up to 12 months, then aggregated or deleted. |
Error logs (logs) |
Retained for up to 30 days, then deleted. |
| Server access / rate-limit caches |
Short-lived (typically 24 hours). |
If you want everything deleted earlier than the schedule above, email
[email protected] — see section 11.
8. International transfers
Our sub-processors (OpenAI, Lemon Squeezy, Cloudflare) are based in the United States, so personal data is
transferred outside the EEA/UK when you use the Service. We rely on the providers' own safeguards (such as
Standard Contractual Clauses where applicable) for those transfers.
9. Security
We protect data in transit with HTTPS, store passwords using one-way hashing (bcrypt), and limit administrative
access to those who need it. No system is 100% secure; we encourage you to use a strong, unique password and
to keep it confidential.
10. Cookies and similar tech
We use a small number of strictly necessary cookies:
- Session cookie — keeps you signed in.
- CSRF token — protects forms and AJAX requests from cross-site request forgery.
We do not use third-party advertising cookies. Lemon Squeezy and Cloudflare may set their own cookies on
their checkout and edge endpoints; see their privacy notices for details.
11. Your privacy rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, etc.) you have some or all of the following rights:
- Access — a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data (you can edit name, company, phone
and billing address yourself in your dashboard).
- Deletion — ask us to delete your data, subject to retention required by law.
- Portability — receive your data in a structured, machine-readable format.
- Objection / restriction — object to or restrict certain processing activities.
- Withdraw consent — for processing based on consent.
- Complain — lodge a complaint with your local data-protection authority.
To exercise any of these rights, email [email protected]. We
will respond within 30 days. We may ask you to verify your identity before releasing or deleting data.
12. Children
The Service is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect
personal information from such children. If you believe a child has provided us data, please contact us so we
can delete it.
13. Changes to this policy
We may update this Privacy Policy when we change how the Service works or add new sub-processors. The
"Last updated" date at the top of the page reflects the most recent change. We'll do our best to highlight
any material changes.
Questions, requests, or complaints about this Privacy Policy can be sent to
[email protected], or via our
Contact page.