Privacy Policy
- Effective
- 31 July 2026
- Version
- 2026-07-31
- Published by
- WithSocialAI, Inc.
Your drafts are private, they are never published because you analyzed them, and they are not used to train models.
To produce a report we send ideas drawn from your draft — not your verbatim text as content to be indexed — to a search provider, and passages of it to a language model. You can export or delete everything. We do not sell personal information.
1. Who this policy covers
IsThisOriginal is operated by WithSocialAI, Inc. (“we”). This policy covers the IsThisOriginal website and application. It is the controller of the personal information described below.
2. Your writing
When you submit a draft we store the text you submitted, any context and domain hint you added, and a title derived from it. From that we generate and store an idea fingerprint — the thesis, supporting claims, mechanism, assumptions and predictions the analysis extracted — along with the search queries planned for it, the sources retrieved, the baseline model generations, the per-claim comparisons, the scores and the finished report.
All of it is private to you. A draft is visible only to the account that owns it (or, in anonymous mode, to the browser that submitted it — see section 4). Running an analysis never publishes your draft, and it is not consent to publish a report, a score or a badge.
What leaves our systems during an analysis. Search queries are built from the ideas in your draft — your thesis, your mechanism, your concept combinations — and sent to a search provider. Your verbatim text is not submitted to a search provider as content to be published or indexed. Passages of your draft, and the fingerprint derived from it, are sent to a language model to perform the extraction and comparison. Prompts sent to build the model baseline deliberately do not contain your thesis or your vocabulary.
We do not train on your writing. Your drafts are not used to train, fine-tune or evaluate any model of ours, and model traffic is routed to providers on terms that do not permit training on the content of prompts.
3. Account information
If you sign in with Google we receive your name, email address, profile image and an account identifier. We request only the identity scopes (openid, email, basic profile). We do not request access to Google Drive, Gmail, contacts or your calendar, we do not request offline access, we never receive your Google password, and we hold no durable credential for your Google account. If you sign in by email link, we receive only your email address.
We store, against your account:
- your email address, display name, profile image URL and sign-in method;
- your access status and the record of how it changed;
- your onboarding answers — the format you write in, your subject areas and your intended audience — which are used to frame your first analysis;
- which versions of these documents you accepted and when, and when you acknowledged the product’s limitations;
- a deletion-request timestamp, if you ask for one.
Your email address is used to match an invitation to your account and to contact you about your account. It is never sold, and it is never placed into analytics events or page URLs.
4. Using the product without an account
Where sign-in is not enabled, the product runs on a browser-scoped owner token stored in a cookie. That token is what makes a draft yours: it is strictly necessary for the product to function and is not used for advertising or cross-site tracking. Anyone with access to that browser can reach analyses created in it, and clearing the cookie makes them unreachable to you. Signing in later transfers work created in that browser onto your account.
5. Waitlist requests
If you ask for early access we store the email address and name you gave, what kind of writing you do, how you heard about the product, and the status of the request. A waitlist entry is kept separate from any account: asking for access and having an account are different facts, and one does not create the other. These rows are never readable by other users.
6. Access records, logs and analytics
Changes to an account’s access — invitation, admission, suspension, a deletion request — are written to an audit log. Those entries hold a masked email address and the statuses moved between. They never contain authentication tokens or any of your writing.
We record coarse product events: that a call to action was selected, that the example was explored, that sign-in started, that onboarding finished. These carry a fixed vocabulary of short tokens and never carry draft text, claim text you typed, email addresses, referral codes or any identifier for you. We also collect aggregate performance measurements for the site.
Our hosting provider processes standard server request data, including IP address, to serve and secure the site. Authentication tokens never appear in analytics or in application logs.
7. Publishing: Best of the Best
Nothing you write is published unless you ask for it. If one of your analyses clears both thresholds, you may choose to list it on Best of the Best. A listing shows the title of the analysis, its Idea Originality score, its model-accessibility level, the date it was analyzed, and a link to the URL where you published the piece. Your draft text is never reproduced there. You can hide or remove a listing at any time from your account page, and a listing disappears on its own if a re-score drops it below either threshold.
8. Who else processes your data
We use the following processors, each for the stated purpose only:
- Supabase — authentication and the Postgres database that holds your profile, drafts, evidence and reports.
- Vercel — hosting and request serving, the durable workflow that runs an analysis, the AI Gateway that routes model calls, product analytics and performance measurement, and file storage for report exports where enabled.
- Language model providers — reached through the AI Gateway, on terms that do not permit training on prompt content. They receive passages of your draft and the fingerprint derived from it.
- A web search provider — receives the queries built from your argument so the public-search frontier can be assembled.
- Google — an optional sign-in provider, used only to establish who you are.
- Stripe — planned, not yet in use. The product does not currently charge for access and no payment information is collected. When paid plans are introduced, payments will be processed by Stripe: card details will be submitted directly to Stripe and will not reach our servers, and we will hold only a customer reference and the status of a payment. This policy will be updated and re-dated before that happens.
These providers operate in the United States and elsewhere, so your information may be processed outside the country you live in. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
9. How long we keep things
Drafts, evidence and reports are kept until you delete them or delete your account, because the point of the product is that you can return to a report later. Waitlist entries are kept until the request is fulfilled or withdrawn. Access-audit entries are kept as a security record for as long as the account exists.
Deletion is a request, not an instant wipe. Asking to delete your account from your account page records the request and marks the account; an operator process then removes the profile and every analysis attached to it, including drafts, fingerprints, retrieved sources, scores and reports. It works this way on purpose — deletion cascades through a body of work and an accidental click should not destroy it with no window to recover. If you need it done immediately, write to hello@withsocialai.com. Backups and provider logs may retain copies for a short period after removal.
10. Your choices and rights
You can export any analysis as Markdown or JSON from its report page, delete an individual analysis at any time, hide or remove a Best of the Best listing, and request deletion of your whole account.
Depending on where you live, you may also have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict a use of it, to receive it in a portable form, and to complain to your data protection authority. Write to hello@withsocialai.com and we will respond. We will not treat you differently for exercising any of these rights.
11. Security
Access to an analysis is checked on the server on every request, not in the browser. Administrative access is granted through deployment configuration rather than a database field, so it cannot be granted by anything holding a database connection. Database connections are encrypted in transit. No system is perfectly secure, and we do not claim otherwise.
12. Children
The service is not directed to children and is not intended for anyone under 16. We do not knowingly collect information from them. If you believe a child has given us information, write to us and we will remove it.
13. Changes to this policy
When this policy changes materially we publish a new version string and effective date. Acceptance is recorded against the version in force at the time, so the record of what you agreed to does not change when the document does. The current version is 2026-07-31.
Contact
IsThisOriginal is operated by WithSocialAI, Inc. For anything in this document — including a request about your data — write to hello@withsocialai.com.
Privacy · Terms · Methodology