Last updated: 1 September 2026
This policy explains what GenAnvil collects about you, why, who else sees it and what you can ask us to do with it. It is written to be read, not to be survived.
GenAnvil is the controller of the personal data described here. For anything in this policy, write to support@genanvil.com.
We do not ask for and do not want special categories of data — health, beliefs, and so on. Please do not put them into your prompts.
We do not sell your data and we do not share it for advertising. It reaches other companies only where the service cannot work otherwise:
Our own staff can reach customer data only for support and abuse investigations. Opening the text of a customer's generation requires a stated reason, and both the reason and who looked are written to an audit log.
We do not use your prompts or your generated texts to train or fine-tune any model, and we do not hand them to anyone for that purpose. The providers who run the models operate under their own terms for API traffic, which generally exclude training on it; we choose providers on that basis but cannot audit them for you.
You can ask us to show you the personal data we hold about you, correct it, delete it, give you a copy in a portable form, or stop a particular use of it. Write to support@genanvil.com and we will answer within a month.
Closing your account removes your texts and generation history. Financial records survive in a form stripped of personal detail, because we are required to keep them. If you think we have handled your data badly, tell us first — and you also have the right to complain to the data protection authority in your country.
We set one cookie to keep you signed in, and a second if you ask to be remembered on your device. There are no advertising cookies, no third-party trackers and no analytics scripts from other companies. Nothing on the site follows you elsewhere on the internet.
Page views are counted on our own server. To tell one visitor from another without following anybody, we take your IP address and browser, mix them with a secret and today's date, and keep only the resulting hash. It cannot be turned back into an IP address, and it changes every day, so it cannot be used to track a person over time. If your browser sends a Do Not Track signal, we count nothing at all. More in the Cookie Policy.
The site is served over HTTPS. Passwords are hashed with argon2id and cannot be read back. Staff accounts can be required to use a one-time code as well as a password, and every administrative action is recorded in an audit log. Provider keys live in a file outside the web root with restricted permissions, never in the database. Backups run daily.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authority as the law requires.
Our servers, our payment provider and the model providers may be in different countries, so your data may be processed outside the country you live in — in practice, within the European Economic Area, the United Kingdom or the United States. Where data leaves the EEA or the UK, it is covered by the safeguards those laws require, such as standard contractual clauses.
GenAnvil is not for people under 18, and we do not knowingly collect data about them. If you believe a child has an account, tell us and we will remove it.
If we change how we handle your data, we will update this page and, for anything significant, tell you by email before it takes effect. The date at the top shows when it last changed.
Privacy questions and requests: support@genanvil.com.