Skip to content
IsThisOriginal

Privacy Policy

Effective
14 August 2026
Version
2026-08-14
Published by
WithSocialAI, Inc.

Your drafts are private, they are never published because you analyzed them, and they are not used to train models.

To produce a report we send ideas drawn from your draft — not your verbatim text as content to be indexed — to a search provider, and passages of it to a language model. You can export or delete everything. We do not sell personal information.

1. Who this policy covers

IsThisOriginal is operated by WithSocialAI, Inc. (“we”). This policy covers the IsThisOriginal website and application. It is the controller of the personal information described below.

2. Your writing

When you submit a draft we store the text you submitted, any context and domain hint you added, and a title derived from it. From that we generate and store an idea fingerprint — the thesis, supporting claims, mechanism, assumptions and predictions the analysis extracted — along with the search queries planned for it, the sources retrieved, the baseline model generations, the per-claim comparisons, the scores and the finished report.

All of it is private to you. A draft is visible only to the account that owns it (or, in anonymous mode, to the browser that submitted it — see section 4). Running an analysis never publishes your draft, and it is not consent to publish a report, a score or a badge.

What leaves our systems during an analysis. Search queries are built from the ideas in your draft — your thesis, your mechanism, your concept combinations — and sent to a search provider. Your verbatim text is not submitted to a search provider as content to be published or indexed. Passages of your draft, and the fingerprint derived from it, are sent to a language model to perform the extraction and comparison. Prompts sent to build the model baseline deliberately do not contain your thesis or your vocabulary. One further piece of your text leaves by a different route once the run is over: the notice telling you the analysis has finished names it by its title, so that title reaches our email provider — see section 7b.

We do not train on your writing. Your drafts are not used to train, fine-tune or evaluate any model of ours, and model traffic is routed to providers on terms that do not permit training on the content of prompts.

3. Account information

If you sign in with Google we receive your name, email address, profile image and an account identifier. We request only the identity scopes (openid, email, basic profile). We do not request access to Google Drive, Gmail, contacts or your calendar, we do not request offline access, we never receive your Google password, and we hold no durable credential for your Google account. If you sign in by email link, we receive only your email address.

We store, against your account:

  • your email address, display name, profile image URL and sign-in method;
  • your access status and the record of how it changed;
  • your onboarding answers — the format you write in, your subject areas and your intended audience — which are used to frame your first analysis;
  • which versions of these documents you accepted and when, and when you acknowledged the product’s limitations;
  • a deletion-request timestamp, if you ask for one.

Your email address is used to match an invitation to your account and to contact you about your account. It is never sold, and it is never placed into analytics events or page URLs.

4. Using the product without an account

Where sign-in is not enabled, the product runs on a browser-scoped owner token stored in a cookie. That token is what makes a draft yours: it is strictly necessary for the product to function and is not used for advertising or cross-site tracking. Anyone with access to that browser can reach analyses created in it, and clearing the cookie makes them unreachable to you. Signing in later transfers work created in that browser onto your account.

5. Waitlist requests

If you ask for early access we store the email address and name you gave, what kind of writing you do, how you heard about the product, and the status of the request. A waitlist entry is kept separate from any account: asking for access and having an account are different facts, and one does not create the other. These rows are never readable by other users.

6. Access records, logs and analytics

Changes to an account’s access — invitation, admission, suspension, a deletion request — are written to an audit log. Those entries hold a masked email address and the statuses moved between. They never contain authentication tokens or any of your writing.

We record coarse product events: that a call to action was selected, that the example was explored, that sign-in started, that onboarding finished. These carry a fixed vocabulary of short tokens and never carry draft text, claim text you typed, email addresses, referral codes or any identifier for you. We also collect aggregate performance measurements for the site.

Our hosting provider processes standard server request data, including IP address, to serve and secure the site. Authentication tokens never appear in analytics or in application logs.

7. Publishing: Best of the Best

Nothing you write is published unless you ask for it. If one of your analyses clears both thresholds, you may choose to list it on Best of the Best. A listing shows the title of the analysis, its Idea Originality score, its model-accessibility level, the date it was analyzed, and a link to the URL where you published the piece. Your draft text is never reproduced there. You can hide or remove a listing at any time from your account page, and a listing disappears on its own if a re-score drops it below either threshold.

7a. Free report codes

An administrator may issue a free report code granting one complete originality report. A code is a grant of access to the service. It is not a payment instrument: it has no cash value, is not transferable, cannot be exchanged for money, and starts no subscription.

To send you one we store the email address it was issued to, optionally your name and a personal message written by whoever sent it, and the code itself — kept encrypted rather than in readable form, so that it can be re-sent to you but is not simply sitting in a table. A code is redeemable only by an account with the verified email address it was assigned to, which is why the address is stored alongside it.

Sending the invitation involves our email provider (see section 8). We keep an operational record of each attempt — when it was requested, the provider’s message identifier, and whether it was sent, delivered, delayed, bounced, failed, suppressed or reported as spam — on the terms section 7b sets out for every message we send. A code’s record is kept apart from the rest because it also carries which code was sent and by which administrator; it holds no address of its own. Receiving an invitation does not add you to any marketing list.

If you redeem a code we record that it was redeemed, by which account, and the report credits it granted. Credits are held while a report runs, spent when it completes, and returned if it fails. This history is an accounting record: it says how many reports were granted and used, never what you wrote.

Delivery and redemption records are kept while the account exists, as the record of what access was given and used. If you received an invitation and never redeemed it, you can ask us to delete the record of it at hello@withsocialai.com.

7b. Email we send you

We send email about your account and about things you did: a confirmation that your waitlist request was received, an invitation when a place opens, a free report code (section 7a), the outcome of a Best of the Best submission, a notice when an analysis you started has finished, a notice when your access status changes, and a confirmation once your account has been deleted. None of it is marketing, we operate no newsletter, and receiving any of it does not add you to a list.

What these messages contain. The notice that an analysis has finished names it by its title — which is your own text — so that title reaches our email provider along with your address. No other part of your draft is ever put into an email: not the report, not the score, not a passage of what you wrote. A Best of the Best outcome refers to the site you submitted, not to your writing.

We keep a delivery record for each one. It holds which kind of message it was, a masked form of the address it went to (a…a@example.com, never the full address), the provider’s message identifier, and whether it was queued, sent, delivered, delayed, bounced, failed, suppressed or reported as spam. That record is what lets a bounce or a spam report be traced back to an attempt, and what stops a repeated internal step from sending you the same message a second time. We deliberately do not track whether you opened a message or clicked anything in it, and our email carries no tracking pixel.

These records are not attached to your account — a masked address is all that identifies them — so they are kept as an operational record and are not removed when an account is deleted. That is deliberate, and the account-deleted confirmation shows why: it is sent to an address the product has just finished erasing everywhere else, and writing that address back down in order to record the send would make the deletion untrue.

8. Who else processes your data

We use the following processors, each for the stated purpose only:

  • Supabase — authentication and the Postgres database that holds your profile, drafts, evidence and reports.
  • Vercel — hosting and request serving, the durable workflow that runs an analysis, the AI Gateway that routes model calls, product analytics and performance measurement, and file storage for report exports where enabled.
  • Language model providers — reached through the AI Gateway, on terms that do not permit training on prompt content. They receive passages of your draft and the fingerprint derived from it.
  • A web search provider — receives the queries built from your argument so the public-search frontier can be assembled.
  • Google — an optional sign-in provider, used only to establish who you are.
  • Resend — delivers our transactional email: waitlist confirmations and invitations, free-report-code invitations, Best of the Best outcomes, the notice that an analysis has finished, and notices that your access changed or your account was deleted. It receives the recipient address and the message — which for a finished analysis includes that analysis’s title — and reports back whether delivery succeeded. No marketing email is sent through it. Section 7b describes each message and the record we keep of it.
  • Stripe planned, not yet in use. The product does not currently charge for access and no payment information is collected. When paid plans are introduced, payments will be processed by Stripe: card details will be submitted directly to Stripe and will not reach our servers, and we will hold only a customer reference and the status of a payment. This policy will be updated and re-dated before that happens.

These providers operate in the United States and elsewhere, so your information may be processed outside the country you live in. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

9. How long we keep things

Drafts, evidence and reports are kept until you delete them or delete your account, because the point of the product is that you can return to a report later. Waitlist entries are kept until the request is fulfilled or withdrawn. Access-audit entries are kept as a security record for as long as the account exists, and in masked, non-identifying form after it does not: deleting an account removes the profile those entries point at, so what remains is an identifier that resolves to nobody, the kind of event and its date — never your address in readable form, your name, or any of your writing. They outlive the account because they are the record of what access decisions were made, and a security record that disappears along with the account it describes is not one. Free-report-code and credit records are kept on the same basis: they are the record of what access was granted and used. The delivery records described in section 7b outlive the account for the same reason and in the same form — a masked address, and no link to an account to remove.

Deletion is a request, not an instant wipe. Asking to delete your account from your account page records the request and marks the account; an operator process then removes the profile and every analysis attached to it, including drafts, fingerprints, retrieved sources, scores and reports. It works this way on purpose — deletion cascades through a body of work and an accidental click should not destroy it with no window to recover. If you need it done immediately, write to hello@withsocialai.com. Backups and provider logs may retain copies for a short period after removal.

10. Your choices and rights

You can export any analysis as Markdown or JSON from its report page, delete an individual analysis at any time, hide or remove a Best of the Best listing, and request deletion of your whole account. From your account page you can also download everything held against the account itself — your profile and onboarding answers, your waitlist request, the record of every change to your access, your credit history, and a list of your analyses — and correct the details you gave when you signed up. Those controls stay available if your access is suspended or closed: the rights below belong to the account, not to being able to open the app.

Depending on where you live, you may also have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict a use of it, to receive it in a portable form, and to complain to your data protection authority. Write to hello@withsocialai.com and we will respond. We will not treat you differently for exercising any of these rights.

11. Security

Access to an analysis is checked on the server on every request, not in the browser. Administrative access is granted through deployment configuration rather than a database field, so it cannot be granted by anything holding a database connection. Database connections are encrypted in transit. No system is perfectly secure, and we do not claim otherwise.

12. Children

The service is not directed to children and is not intended for anyone under 16. We do not knowingly collect information from them. If you believe a child has given us information, write to us and we will remove it.

13. Changes to this policy

When this policy changes materially we publish a new version string and effective date. Acceptance is recorded against the version in force at the time, so the record of what you agreed to does not change when the document does. The current version is 2026-08-14.

Contact

IsThisOriginal is operated by WithSocialAI, Inc. For anything in this document — including a request about your data — write to hello@withsocialai.com.

Privacy · Terms · Methodology