GenAnvil
Models Pricing Help
Sign in Get started

Privacy Policy

Last updated: 1 September 2026

This policy explains what GenAnvil collects about you, why, who else sees it and what you can ask us to do with it. It is written to be read, not to be survived.

1. Who is responsible

GenAnvil is the controller of the personal data described here. For anything in this policy, write to support@genanvil.com.

2. What we collect

  • Account details. Your email address, an optional name, and your password stored as a one-way hash — we never hold the password itself. If you turn on two-factor sign-in, the secret for your authenticator app.
  • What you write and what you get back. Your instructions, any files you upload for batch jobs, and the texts the models produce. These are kept so you can return to your work.
  • Usage records. Which model ran, when, how many characters it wrote, how many credits it cost, and whether it succeeded. This is what your balance and history are built from.
  • Payment records. What you bought, when, for how much, and the identifiers Creem gives us for the payment and subscription. We do not receive or store card numbers.
  • Technical details. The IP address and browser you signed in from, kept to spot account takeovers and abuse. Errors are written to a log that deliberately excludes your texts and personal details.
  • Visit counts. Which pages of the public site are viewed, and roughly how many people viewed them. How we do this without following you around is in section 8.

We do not ask for and do not want special categories of data — health, beliefs, and so on. Please do not put them into your prompts.

3. Why we use it

  • To provide the service you signed up for: running your account, generating text, keeping your history, counting credits, taking payment. Without this data there is no service.
  • To keep the service safe and working: spotting fraud and abuse, enforcing limits, diagnosing failures, keeping backups. This is our legitimate interest in running a service that does not fall over or get abused.
  • To meet legal duties: keeping accounting and tax records for as long as the law requires.
  • To write to you about your account: confirming your email, receipts, a warning when credits run low, notice that a plan has ended. These are part of the service, not marketing. We do not send marketing email unless you ask for it, and any such email carries an unsubscribe link.

4. Who else sees it

We do not sell your data and we do not share it for advertising. It reaches other companies only where the service cannot work otherwise:

  • AI model providers. Your instructions, and the context needed to continue a piece of work, are sent to the model you choose. Access to the models is routed through OpenRouter, which passes the request to the provider that runs the model. Without this, no text gets written.
  • Creem, our payment provider and merchant of record, which handles checkout, receipts and tax, and tells us that a payment succeeded.
  • Our hosting provider, which runs the servers the site and database sit on.
  • Email delivery, for the account emails listed above.
  • Authorities, where the law genuinely requires it.

Our own staff can reach customer data only for support and abuse investigations. Opening the text of a customer's generation requires a stated reason, and both the reason and who looked are written to an audit log.

5. Your texts are not used to train models

We do not use your prompts or your generated texts to train or fine-tune any model, and we do not hand them to anyone for that purpose. The providers who run the models operate under their own terms for API traffic, which generally exclude training on it; we choose providers on that basis but cannot audit them for you.

6. How long we keep it

  • Account, texts and history: for as long as your account exists.
  • Uploaded files for batch jobs: removed once the job is finished and exported.
  • Technical logs: 30 days.
  • Visit counts: kept as totals per page per day, with nothing that identifies a person.
  • Payment and accounting records: as long as tax law requires, typically several years, even after an account closes.
  • Backups: a rolling set of recent copies, overwritten in turn.

7. Your rights

You can ask us to show you the personal data we hold about you, correct it, delete it, give you a copy in a portable form, or stop a particular use of it. Write to support@genanvil.com and we will answer within a month.

Closing your account removes your texts and generation history. Financial records survive in a form stripped of personal detail, because we are required to keep them. If you think we have handled your data badly, tell us first — and you also have the right to complain to the data protection authority in your country.

8. Cookies and how we count visits

We set one cookie to keep you signed in, and a second if you ask to be remembered on your device. There are no advertising cookies, no third-party trackers and no analytics scripts from other companies. Nothing on the site follows you elsewhere on the internet.

Page views are counted on our own server. To tell one visitor from another without following anybody, we take your IP address and browser, mix them with a secret and today's date, and keep only the resulting hash. It cannot be turned back into an IP address, and it changes every day, so it cannot be used to track a person over time. If your browser sends a Do Not Track signal, we count nothing at all. More in the Cookie Policy.

9. How we protect it

The site is served over HTTPS. Passwords are hashed with argon2id and cannot be read back. Staff accounts can be required to use a one-time code as well as a password, and every administrative action is recorded in an audit log. Provider keys live in a file outside the web root with restricted permissions, never in the database. Backups run daily.

No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authority as the law requires.

10. Where your data is processed

Our servers, our payment provider and the model providers may be in different countries, so your data may be processed outside the country you live in — in practice, within the European Economic Area, the United Kingdom or the United States. Where data leaves the EEA or the UK, it is covered by the safeguards those laws require, such as standard contractual clauses.

11. Children

GenAnvil is not for people under 18, and we do not knowingly collect data about them. If you believe a child has an account, tell us and we will remove it.

12. Changes to this policy

If we change how we handle your data, we will update this page and, for anything significant, tell you by email before it takes effect. The date at the top shows when it last changed.

13. Contact

Privacy questions and requests: support@genanvil.com.

GenAnvil — one place for all your texts Help support@genanvil.com Pricing Terms Privacy