Privacy Policy

Last updated: July 2026

1. Introduction

ValidDraft ("Service") is a product of Sotolis ("Company", "we", "our", or "us"). This Privacy Policy describes how we collect, use, process, share, retain, and protect your personal information and behavioral (keystroke) data when you use our writing-verification service at validdraft.com and app.validdraft.com.

This Privacy Policy applies to all users of the Service worldwide and is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Illinois Biometric Information Privacy Act (BIPA), the Digital Personal Data Protection Act, 2023 (India) (DPDPA), and other applicable data protection laws. Where specific regulations grant you additional rights, those are detailed in dedicated sections below.

By using ValidDraft, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, you must not use the Service.

2. Information We Collect

Account information and behavioral (keystroke) data are required to use the Service — without them we cannot generate a verification certificate. All other data described below (social links, liveness verification) is optional and can be declined without affecting your ability to use the Service.

2.1 Account Information

When you create an account (via email and password registration, Google OAuth, or Sign in with Apple), we collect and store:

  • Email address (provided by you, or from your Google or Apple account)
  • Display name (provided by you, or from your Google or Apple account)
  • Profile avatar URL (from your Google account, if applicable; Apple does not provide an avatar)
  • Password (stored only as a securely hashed value; we never store plaintext passwords)
  • Social links (optionally added by you: Twitter, LinkedIn, GitHub, website)

For Google OAuth and Sign in with Apple users, we do not receive or store your Google account password or Apple ID password. Authentication is handled entirely by Google's OAuth 2.0 protocol or Apple's Sign in with Apple protocol, respectively; if you choose to hide your email from us, Apple may provide it to us as a private relay address instead. For email/password users, your password is hashed using bcrypt before storage and cannot be retrieved or viewed by anyone, including our staff.

2.2 Behavioral (Keystroke) Data

Behavioral Data Notice

ValidDraft collects behavioral data about how you write (keystroke timing and related signals). We do not collect any biometric identifier such as a fingerprint, voiceprint, retina or iris scan, or scan of hand or face geometry. Some jurisdictions treat behavioral data of this kind as biometric information, so we treat it with the safeguards required by biometric privacy laws including BIPA (740 ILCS 14), Texas Business & Commerce Code §503.001, and Washington RCW 19.375. Before your first tracked writing session we ask for your consent on a separate screen, unchecked by default and kept apart from your acceptance of our Terms; that consent is what permits the collection, storage, and processing of this data as described below. It is recorded against your account with its version, and you can withdraw it at any time from your profile. This data is analyzed to classify whether a piece of writing was produced by a human or an AI — it is not used, and is not designed, to determine which specific individual produced it. Under GDPR, biometric data is defined (Art. 4(14), Recital 51) as data processed to uniquely identify a natural person; because ValidDraft's processing does not do this, we treat it as ordinary personal data processed on the basis of contractual necessity rather than as a special category of data (see Section 3).

What We Capture While You Write

During every writing session, we collect the following behavioral data:

  • Key press timing: Duration each key is held down (dwell time)
  • Inter-key intervals: Time between consecutive keystrokes (flight time)
  • Typing rhythm: Overall cadence, velocity, and flow patterns
  • Revision behavior: Backspace frequency, deletion patterns, and rewrite sequences
  • Pause analysis: Duration, frequency, and positioning of pauses during writing
  • Cursor entropy: Mouse/trackpad movement patterns, velocity, and click behavior
  • Paste detection: External paste events, paste ratios, and content origin tracking

This data is transmitted to our servers as compressed event logs and processed in real time to generate your verification score. The raw event log is deleted as soon as analysis completes — whether the analysis succeeds or fails. If an analysis attempt fails outright, a transient copy of it can remain in our job-failure queue; that copy is bounded to a short window of up to 48 hours, after which automated cleanup removes it. The derived score, behavioral signals, and certificate are retained as described in Section 5.

If you choose public visibility for a verification, the certificate page also displays a derived, content-free behavioral process summary generated from this data — including a pace curve, pause map, paste markers, and, if liveness was used, a liveness digest. This summary never includes your written content or the raw keystroke log, which is deleted when analysis completes as described above.

2.3 Content Data

Text content you write in the editor is submitted as part of the verification process. Your content is stored alongside the verification certificate for as long as the certificate exists, so it stays verifiable. Content may be made publicly accessible if you choose "public" visibility for your verification. You can delete a verification at any time.

2.4 Technical & Usage Data

We automatically collect:

  • IP address (for security, rate limiting, and fraud prevention)
  • Browser type and version
  • Device type and operating system
  • Pages visited, features used, and timestamps
  • Referrer URL
  • Error logs and performance data

2.5 Payment Data

Payment processing is handled entirely by Dodo Payments. We do not receive, process, or store your credit card numbers, bank account details, or other financial instruments. We receive only: transaction confirmation, subscription status, invoice identifiers, and billing period dates.

2.6 Optional Liveness Verification (Author Plan, Desktop App)

The Author plan's desktop app includes an optional, off-by-default camera-presence check that can confirm a real person is at the keyboard while writing. This checks presence only — it does not identify who you are, and it never performs facial recognition or matches your face against any stored identity. You are asked to explicitly confirm before it is enabled. Your camera video is analyzed entirely on your device; the video itself is never transmitted to or stored on our servers. What is sent is a series of small presence confirmations — roughly one every few seconds while the check is on, each carrying only a timestamp, a presence yes/no, a confidence level, and a short cryptographic digest. No image, no video frame, and no facial features are ever included. You may decline this feature and continue using the Service normally.

2.7 Messages and Requests You Send Us

If you send us a message, we keep what you wrote. This covers three things:

  • In-product feedback: the free-text message you type into a feedback form inside the app (up to 2,000 characters), which surface it came from, and your account, so we can follow up if you asked us to.
  • Rights requests: if you object to processing or ask us to restrict it (see Section 8.2), we record the type of request, the date, the reason you optionally write for us, and the note we write back when we resolve it. No IP address or browser information is stored on these records.
  • Disputes about a verification result: if you ask for human review of a score (see Section 10), we record which verification it concerns, the reason you select, the description you optionally write for us (up to 1,000 characters), and the outcome and note from our review. No IP address or browser information is stored on these records.

These boxes are free text, so we cannot control what goes into them. Please do not include sensitive information — about yourself or anyone else — that you would not want us to keep for the retention periods in Section 5. Tell us what you need in as little detail as it takes.

2.8 Certificate Sharing & Viewing

When a certificate of yours is viewed, shared, embedded, or has its code copied, we record that the action happened. Two kinds of record result: a running count of views, shares, and embeds shown on the certificate itself, and a per-event row holding the event type, the platform, the referring page, the browser user-agent, and a one-way hash of the requester's IP address (we do not store the IP itself). Anyone can verify a public certificate without an account, and we do not ask verifiers to identify themselves. We use this to show you that your certificate is being checked and to detect abuse of the public verification endpoint. Retention for both is in Section 5.

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following legal bases:

Processing ActivityLegal Basis
Account creation and managementPerformance of contract (Art. 6(1)(b))
Keystroke behavioral analysisNecessary for performance of contract (Art. 6(1)(b))
Payment processingPerformance of contract (Art. 6(1)(b))
Service improvement & analyticsLegitimate interest (Art. 6(1)(f))
Security & fraud preventionLegitimate interest (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))

“Service improvement & analytics” means analyzing aggregated, anonymized usage patterns (see Section 4) to refine verification accuracy. “Security & fraud prevention” means monitoring for abuse patterns such as credential stuffing, multi-accounting, and API misuse. You may object to processing under either legitimate interest at any time (see Section 8.2).

Keystroke behavioral analysis is processed because it is objectively necessary to deliver the verification you request — without it, we cannot generate a humanity score or certificate. This processing classifies writing as human- or AI-authored; it does not identify you as an individual (see Section 2.2), so we do not treat it as special-category data requiring separate explicit consent under Art. 9. We still obtain your informed consent to this processing as a matter of transparency and to satisfy biometric privacy laws in other jurisdictions (see Section 8.4).

4. How We Use Your Information

We use collected information for the following purposes:

  • Verification: Generate humanity scores, verification reports, and certificates
  • Service delivery: Manage your account, process subscriptions, allocate credits
  • Communication: Send transactional emails (verification results, billing confirmations, security alerts)
  • Improvement: Analyze aggregated, anonymized usage patterns to improve our algorithms and user experience
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Legal: Comply with applicable laws, respond to legal requests, and enforce our Terms

We do not:

  • Use your content or behavioral data for advertising or marketing purposes
  • Sell, rent, or trade your personal data to third parties
  • Use your content to train general-purpose AI or machine learning models
  • Create persistent biometric identity profiles for tracking across sessions
  • Share individual verification results publicly without your explicit visibility choice

5. Data Retention

Data TypeRetention Period
Raw keystroke event logsDeleted as soon as analysis completes, whether it succeeds or fails. If an attempt fails outright, a transient copy in our job-failure queue is cleared within 48 hours (see Section 2.2)
Derived behavioral aggregates & verification reports (scores, signals, process statistics)Retained for the life of the certificate so it stays verifiable; deleted on request
Written contentRetained for the life of the certificate so it stays verifiable; deleted on request
Verifications, manuscripts, and documents you deleteRemoved from the Service immediately and permanently erased from our systems within 30 days
Account informationUntil account deletion, plus a limited additional period covered by our database provider's automated backup retention
Consent and terms-acceptance evidenceA de-identified record of your consent decisions survives account deletion, and is then deleted 6 years after that deletion — see “Consent evidence” below
In-product feedback you send us (Section 2.7)12 months from submission
Rights requests and our resolution notes (Section 2.7)Kept as the record that we received and answered your request, for up to 6 years from the date we resolve it (or from the date you sent it, if it is never resolved); deleted sooner if you delete your account
Disputes you file against a verification result, and the outcome of our human review (Section 10)Once we have reviewed and answered it, kept as the record of that review for 6 years from the date we resolved it. A dispute we have not yet answered is kept until we do — we will not delete it for having gone unanswered. Either way it is deleted sooner if you delete your account or delete the disputed verification
Certificate share, embed, and copy events (Section 2.8)180 days for the per-event records carrying hashed IP, user-agent, and referrer. The view, share, and embed counts shown on a certificate are kept for the life of the certificate
Payment records & invoices7 years (legal/tax compliance requirement)
Server access logs90 days
Anonymized analyticsIndefinitely (cannot be linked to individuals)

Verification data (content, derived behavioral aggregates such as scores and process statistics, and certificates) is retained for as long as the certificate exists, so that a certificate stays independently verifiable by anyone you share it with. The raw keystroke event log itself is not part of this retained set — it is deleted as soon as analysis completes, on the success and failure paths alike, subject only to the 48-hour job-failure window described in Section 2.2. See our Terms of Service (Section 12) for our service discontinuation policy, including 90 days' advance notice and data export capabilities.

Deletion on request: You may delete your verifications, manuscripts, and documents, or request deletion of your data, at any time through your account settings or by contacting us. Deleting a verification removes its content, derived behavioral aggregates, scores, and certificate from the Service immediately, and we permanently erase it from our systems within 30 days. (Its raw event log will already have been deleted at analysis time, as described above.) Deleting your account also immediately clears the temporary draft-sync cache that keeps your work in step across devices.

Consent evidence: One record survives account deletion, and we want you to know exactly what it is. Data protection law requires us to be able to show that consent was properly obtained — a dispute about that can surface after an account is gone. So when you delete your account, we first keep a de-identified snapshot of your consent decisions: which consent it was, whether it was granted or withdrawn, when each of those happened, and which version of the notice applied. That is all. We deliberately do not keep your IP address, your browser user-agent, your name, or your email on this record, and the internal account number attached to it no longer points to anyone once your account row is gone. We keep this record for 6 years from the date your account is deleted, and then delete it automatically. Six years is the general limitation period for civil claims in England and Wales, which is the longest window in which a dispute about your consent could realistically still be brought against us.

Backup Systems: Our database provider maintains encrypted, automated backups of our production systems for disaster recovery, with a limited retention window set by the provider. Data may briefly persist in these backups after deletion from production systems; backups are rotated out on the provider's standard schedule and are not used for any purpose other than disaster recovery.

We periodically review whether this retention approach remains necessary, including when we make significant changes to the Service, rather than treating it as fixed indefinitely.

6. Data Sharing & Third-Party Processors

We do not sell your personal data. We share data only in the following limited circumstances:

6.1 Service Providers (Sub-Processors)

We use the following third-party service providers who process data on our behalf:

ProviderPurposeData Shared
Google (OAuth)AuthenticationOAuth tokens (we receive name, email, avatar)
Apple (Sign in with Apple)Authentication — independent identity provider, not a processor acting on our instructions (see note below the table)Identity token exchange (we receive an Apple user identifier, and your email address — or Apple's private relay address if you choose to hide it). No behavioral or content data is shared with Apple (US)
Google (Gemini API)AI-assisted behavioral analysisWritten content and behavioral event logs for verification scoring. Data is processed per Google's API data usage policies and is not used by Google for model training.
Dodo PaymentsPayment processing (merchant of record)Email, subscription plan, payment method (handled by Dodo). For the payment-processing itself — fraud checks, sanctions screening, tax — Dodo acts as an independent controller under its own privacy policy, not on our instructions; it processes our subscription records on our instructions
DigitalOceanCloud infrastructure, hosting & managed databaseAll data stored on encrypted servers (DigitalOcean Droplets & managed PostgreSQL database, data center region: US)
ResendTransactional email deliveryName and email address, for account, verification, and billing emails (US)
SentryApplication error monitoringError reports, which may include IP address and account context (US)
CloudflareCloud storage & CDN infrastructureFiles served over Cloudflare's global network, and request metadata for the traffic it fronts. Cloudflare's edge network is multi-region by design and is not US-only; object storage sits at rest in Asia-Pacific
Google AnalyticsUsage analytics (only with your cookie consent)Anonymized IP address and website usage data; collected only if you consent via the cookie banner (US)

With the exception of Apple, noted below, every provider in this table is a sub-processor: contractually bound to process data only as instructed by us, to maintain appropriate security measures, and to delete data when it is no longer needed. Our AI-analysis infrastructure is built to support multiple AI providers, but only Google Gemini is configured and active in production today. If we activate an additional or alternative AI provider for analyzing your content, we will update this table before doing so.

Sign in with Apple is different. Apple does not process data on our behalf and is not our sub-processor. It is an independent identity provider: the identifier and email address involved are data Apple already holds and controls as your Apple ID, and Apple discloses them to us only when you authorize the sign-in. We do not send Apple anything to process on our instruction. We list Apple here anyway, because you deserve to see every company your data reaches — but the contractual commitments described in the paragraph above are made by our sub-processors, not by Apple, whose handling of your Apple ID is governed by Apple's own privacy policy.

6.2 Legal Requirements

We may disclose your data if required to do so by law, or if we reasonably believe that disclosure is necessary to: (a) comply with a legal obligation, court order, or governmental request; (b) protect the rights, property, or safety of Sotolis, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues.

6.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your data may be transferred as part of the transaction. We will notify you via email and/or prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy. See our Terms of Service (Section 12) for our service discontinuation commitments.

7. International Data Transfers

ValidDraft is operated from India. If you are accessing the Service from outside India, please be aware that your data may be transferred to, stored, and processed in India or other countries where our service providers operate. In practice that means principally the United States, where our hosting, email, error-monitoring, and analytics providers hold data; the Asia-Pacific region, where our object storage sits at rest; and, for content delivery, Cloudflare's global edge network, which is multi-region by design rather than tied to a single country. See the table in Section 6.1 for which provider holds what.

For users in the EEA, UK, or Switzerland: where we transfer personal data outside of your jurisdiction, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms. You may request a copy of the applicable safeguards by contacting us.

India (S.16, DPDPA 2023): for transfers of personal data relating to Data Principals in India, Section 16 of the DPDPA 2023 permits transfer to any country or territory outside India by default, except where the Central Government restricts a specific country by notification. As of this writing, no country has been so restricted. See Section 8.5 for the fuller Indian Users disclosure.

Brazil (LGPD): for transfers of personal data relating to individuals in Brazil, we rely on the Standard Contractual Clauses approved by Brazil's National Data Protection Authority (ANPD, Resolution CD/ANPD No. 19/2024), in addition to or in place of the European Commission SCCs referenced above, as applicable.

The Service is not directed at or marketed to users in certain countries. See Terms of Service Section 2A for the current list. This is a statement of where we offer the Service, not a technical block: we do not geo-restrict access, so if you use the Service from one of those countries this Privacy Policy still governs how we handle your data.

8. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

8.1 Rights for All Users

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated data. One de-identified record of your consent decisions survives — see “Consent evidence” in Section 5 for exactly what it contains and what it deliberately leaves out
  • Export: Request an export of your verification data (JSON format) from Privacy & Data in your account settings, or by contacting us
  • Stop processing: Turn off behavioral tracking at any time from Privacy & Data in your account settings — you do not have to delete your account to do it — or stop by ceasing use and deleting your account. Where consent is the applicable basis in your jurisdiction (see Section 8.4), either route also withdraws that consent

8.2 Additional Rights for EEA/UK Users (GDPR)

  • Right to restrict processing: Request that we limit how we process your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to lodge a complaint: File a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France, or BfDI in Germany)
  • Right not to be subject to automated decision-making: Our verification scores are generated algorithmically. You may request human review of any verification result — either with the Dispute this verification control in the app, or by contacting us (see Section 10)

8.3 Additional Rights for California Residents (CCPA/CPRA)

  • Right to know: Request disclosure of the categories and specific pieces of personal information collected, the purposes of collection, and third parties with whom data is shared
  • Right to delete: Request deletion of personal information, subject to legal exceptions
  • Right to opt-out of sale: We do not sell personal information. If this changes, we will provide a "Do Not Sell My Personal Information" mechanism
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights
  • Right to correct: Request correction of inaccurate personal information
  • Right to limit use of sensitive personal information: Our use of the behavioral data described in Section 2.2 is limited to providing the verification service

CCPA Categories Collected: Identifiers (email, name); biometric information (keystroke dynamics); internet/electronic activity (usage logs); professional information (if provided). We collect these directly from you or your device when you use the Service.

“Biometric information” above is California's statutory category label, not our description of what we collect. Cal. Civ. Code §1798.140(c) names keystroke rhythms within that category, so we list our behavioral data under it in order to give you the fullest set of CCPA rights. It does not mean we collect a biometric identifier — we do not (see Sections 2.2 and 8.4).

We do not offer a separate "Limit the Use of My Sensitive Personal Information" control because we believe our processing qualifies for the exemption under the CPRA's implementing regulations (11 CCR §7027) for sensitive personal information collected or processed without the purpose of inferring characteristics about you and used solely to provide the verification service you requested. If you believe this exemption does not apply to your circumstances, contact us at hello@sotolis.com.

8.4 Illinois Residents (BIPA)

We do not collect any biometric identifier as defined by BIPA (740 ILCS 14/10) — no retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. The behavioral data we collect (keystroke timing and related writing signals) is described in Section 2.2. We nonetheless apply the following BIPA-aligned safeguards to that behavioral data:

  • We inform you in writing that behavioral data is being collected and the purpose of collection (verification of human authorship)
  • We obtain your informed, written consent before collection through a separate, affirmative, unchecked-by-default behavioral-tracking consent screen shown before your first tracked writing session — deliberately not bundled into acceptance of these terms, and enforced server-side, so no tracked writing is accepted without it
  • We publish this data retention policy, and behavioral data is retained as specified in Section 5
  • We do not sell, lease, trade, or profit from your behavioral data
  • We store, transmit, and protect behavioral data using a standard of care no less than that used for other confidential information, including encryption at rest and in transit
  • We permanently destroy behavioral data on request, per the retention policy in Section 5

8.5 Indian Users (DPDPA 2023)

Digital Personal Data Protection Act, 2023 (India)

Sotolis is a Data Fiduciary under the DPDPA 2023. As a Data Principal, you have the following rights with respect to your personal data processed by ValidDraft. The DPDPA's substantive provisions — including the rights, notice, and breach-notification obligations described in this Privacy Policy — are being phased in and commence on 13 May 2027 under the notified DPDP Rules, 2025. We describe and provide these rights to you now, ahead of that date, as a voluntary early-compliance commitment layered on top of the data-protection obligations that bind us today under the Information Technology Act, 2000, Section 43A, and the Sensitive Personal Data or Information (SPDI) Rules, 2011.

Under the Digital Personal Data Protection Act, 2023 (India):

  • Right to access (S.11(1)): You may request a summary of your personal data being processed and the processing activities undertaken
  • Right to correction and erasure (S.12): You may request correction of inaccurate or misleading data, completion of incomplete data, updating of outdated data, and erasure of data no longer necessary for the stated purpose
  • Right to grievance redressal (S.13): You may raise a grievance with our Grievance Officer (see Section 15 below). If unsatisfied with our response, you may file a complaint with the Data Protection Board of India
  • Right to nominate (S.14): Once this right takes effect, you will be able to nominate another individual to exercise your data rights in the event of your death or incapacity. We are building the self-service mechanism for registering a nominee ahead of that date; until it is available, contact us at hello@sotolis.com and we will handle a nomination request manually
  • Consent withdrawal (S.6(6)): You may withdraw your consent at any time via your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal

Purpose of processing: Your personal data is processed solely for the purpose of providing the ValidDraft verification service, as described in Section 4 above. We will not process your data for any purpose beyond what has been communicated to you in this notice.

Legal basis for analytics and security processing under DPDPA: the DPDPA's lawful-basis structure (Sections 6–7) is narrower than GDPR's — consent, or one of a fixed list of “legitimate uses,” with no open-ended equivalent to GDPR's legitimate-interest basis. We rely on Section 7(a) (data voluntarily provided for a specified purpose) for the core verification flow. For security and fraud-prevention processing, we treat it as inseparable from delivering that same verification purpose, since a service that authenticates human writing cannot function without also screening for abusive or automated use of it. For product analytics specifically, we will either obtain your separate consent under Section 6 or narrow this processing before the DPDPA's substantive provisions commence on 13 May 2027.

Cross-border transfers (S.16): Your data may be processed in India and in countries where our service providers operate. We will comply with any restrictions on cross-border data transfers that may be notified by the Central Government under Section 16 of the DPDPA.

Data Protection Board of India: If you are unsatisfied with our response to your grievance, you may file a complaint with the Data Protection Board of India as constituted under the DPDPA 2023.

8.6 Canadian Users (PIPEDA)

For users in Canada, we process personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA). The Office of the Privacy Commissioner of Canada's biometric-data guidance (2025) identifies keystroke patterns as behavioral biometric information and treats identifying-capable biometric data as sensitive by default, while recognizing that a non-biometric alternative may not be necessary where the biometric signal is integral to the service itself. ValidDraft's behavioral analysis is exactly that case: the keystroke and typing-behavior signal is not an add-on to the verification service, it is the verification service, so no non-biometric alternative is offered. Consistent with PIPEDA's expectations, we obtain express, unbundled consent before capture (see Section 8.1 and the behavioral-tracking consent screen shown before your first tracked session) and destroy the raw keystroke event log once it is no longer necessary for the purpose it was collected for (Section 5).

Residents of Quebec: Quebec's Law 25 imposes additional obligations, including a designated “person in charge of the protection of personal information,” which in a sole proprietorship defaults to the proprietor personally. Contact us at hello@sotolis.com to reach that person.

8.7 Brazilian Users (LGPD)

For users in Brazil, we process personal data under the Lei Geral de Proteção de Dados (LGPD). The legal bases described in Section 3 apply substantially the same way under LGPD Art. 7 (contractual necessity for account creation, verification, and payment processing). You have the rights described in LGPD Art. 18 — confirmation of processing, access, correction, anonymization, portability, and deletion — which you may exercise using the same channels described in Section 8.8 below. For cross-border transfers of your data, see Section 7. Given the current scale of our operations, the Grievance Officer identified in Section 15.2 also serves as our data-protection contact for Brazilian users.

8.8 How to Exercise Your Rights

To exercise any of these rights, you may:

  • Use the self-service options in your account settings (delete account, manage visibility)
  • Email us at hello@sotolis.com

We will respond to verifiable requests within 30 days (or 45 days for complex requests, with notice). We may need to verify your identity before processing a request. We will not charge a fee for reasonable requests unless they are manifestly unfounded or excessive.

9. Data Security

We implement comprehensive technical and organizational measures to protect your data:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS 1.2 or higher
  • Encryption at rest: All data stored in our databases is encrypted at rest
  • Access controls: Strict role-based access controls limit employee access to personal data on a need-to-know basis
  • API authentication: All API endpoints require authentication via secure tokens (Laravel Sanctum)
  • Webhook verification: All incoming payment webhooks are cryptographically verified before processing
  • Rate limiting: API rate limits protect against abuse and brute-force attacks
  • Secure infrastructure: Our servers are hosted in secure data centers with physical and network security controls

Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users and relevant authorities in the event of a data breach in accordance with applicable law (within 72 hours for GDPR-covered breaches).

10. Automated Decision-Making

ValidDraft uses AI-assisted analysis (a large language model) to generate humanity scores and verification results. Your written content and behavioral event log are evaluated together against known patterns of human and AI-assisted writing; this process does not involve human reviewers by default.

Significance: Verification scores may be used by you or third parties (e.g., editors, educators, employers) to make decisions about content authenticity. We strongly recommend that verification scores are used as one factor among many and that important decisions include human review.

Your right to contest: Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. You can ask for human review of any verification result in two ways: open the verification in the app and use Dispute this verification, or email us at hello@sotolis.com. Either route reaches the same place.

What we record when you dispute a result: the verification concerned, the reason you pick from the list, any description you choose to write, and the outcome and note from our review. A reviewer looks at the evidence recorded for that writing session and can correct the score if it supports doing so, though a change is not guaranteed. Any correction is shown on the certificate. Retention for these records is in Section 5.

Australian users: in accordance with the Privacy Act 1988 (Cth) as amended, we disclose the following about our use of automated decision-making that could reasonably be expected to significantly affect your rights: the kind of personal information used is the behavioral/keystroke data and written content described in Section 2 above; the kind of decision made is the automated humanity score and verification result described above, which (per Section 7 of our Terms of Service) may be relied on by third parties for decisions including academic, employment, publication, or legal-proceedings purposes. We recommend, and the Terms of Service require, that any such decision not rely on a verification score as the sole factor.

11. Cookies & Tracking Technologies

We use cookies and similar technologies to provide and improve our Service:

Essential Cookies

Required for the Service to function. These include authentication tokens (stored in localStorage), session identifiers, and CSRF protection tokens. You cannot opt out of essential cookies while using the Service.

Analytics Cookies

Help us understand how visitors interact with our website, using Google Analytics (pageview/event analytics). Analytics data is aggregated and anonymized where possible. You can decline analytics cookies when you first visit, and change your mind afterwards at any time using the controls below; see Section 6.1 for what this provider receives.

Managing Cookies

Saying yes to analytics is not a one-way door. You can change your answer at any time, and turning analytics off is exactly as easy as turning it on:

  • On this website, use the Cookie preferences link in the footer of any page. It reopens the consent banner with your current choice, so you can switch to "Necessary Only" whenever you want
  • In the app, open Profile → Privacy & Data, where an analytics control lets you allow or turn off analytics. Turning it off stops analytics loading from that point on and clears the analytics cookies we can reach from that browser
  • Adjusting your browser settings to block or delete cookies
  • Clearing browser storage to remove authentication tokens

One thing worth knowing: your analytics choice is stored in the browser you made it in, and this website (validdraft.com) and the app (app.validdraft.com) keep that choice separately. So declining on one does not carry over to the other, and a new browser or device will ask you again. Each surface has its own control, listed above.

If you are signed in to the app when you change this choice, we also write a record of the change against your account — the choice you made, when you made it, and the IP address and browser user-agent it came from — so that we can demonstrate that consent was given or withdrawn, as data protection law requires us to be able to do. That record is evidence only: the setting stored in your browser is what actually switches analytics on or off, so this never changes the outcome of your choice. Signed-out visitors to this website have no such record, because there is no account to attach it to.

Do Not Track: We currently do not respond to "Do Not Track" (DNT) browser signals, as there is no industry-standard protocol for DNT compliance. We will update this policy if a standard is adopted.

12. Children's Privacy

ValidDraft is not directed to anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@sotolis.com. If we discover that we have collected personal information from someone under 18, we will take steps to delete that information within 30 days. For UK users, we have assessed the Service against the ICO's Age Appropriate Design Code (the “Children's Code”): ValidDraft is a professional, invited-adult product with no design, content, or marketing directed at or likely to appeal to children, so we do not consider it “likely to be accessed by children” under the Code's multi-factor test.

13. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required by GDPR)
  • We will notify the Data Protection Board of India and each affected Data Principal as required under Section 8(6) of the DPDPA 2023
  • We will notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Notification will include: the nature of the breach, the data affected, potential consequences, and measures taken or proposed to address the breach
  • We will also comply with any additional breach notification requirements under applicable state or national laws (e.g., CCPA, BIPA, IT Act 2000 S.43A)

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes that affect your rights or how we process your data, we will provide at least 15 days' advance notice via email or a prominent notice within the Service. Non-material changes will be reflected by updating the "Last updated" date.

Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you must stop using the Service and may request deletion of your data.

15. Contact Us

For privacy-related inquiries, data subject requests, or concerns about our data practices:

15.1 Company Information

Sotolis

Sole Proprietorship, India

Email: hello@sotolis.com

15.2 Grievance Officer (IT Rules 2021 / DPDPA 2023)

Grievance Officer: Deepika Divya

Email: hello@sotolis.com

Response time: Acknowledgment within 24 hours, resolution within 15 days

Designated under Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Our response-time commitments above are voluntary and go beyond what Section 8(10) of the Digital Personal Data Protection Act, 2023 itself specifies (Section 8(10) requires only an effective grievance-redressal mechanism, without prescribing these figures).

15.3 Contact Channels

Privacy inquiries: hello@sotolis.com

General support: hello@sotolis.com

Security issues: hello@sotolis.com

Legal: hello@sotolis.com

15.4 EU/EEA & UK GDPR Representatives (Article 27)

If you are located in the EU/EEA or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representatives:

EU Representative

Euverify Ltd (Ireland)

Unit 3D North Point House

North Point Business Park

New Mallow Road, Cork

T23 AT2P, Ireland

Email: gdpr@euverify.com

UK Representative

Euverify Ltd (UK)

3rd Floor, 86-90 Paul Street

London, EC2A 4NE

United Kingdom

Email: gdpr@euverify.com

To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, you may also use our secure GDPR verification portal to verify our appointed representatives and submit requests directly. Requests submitted through this portal are logged and tracked to help ensure a timely response.

If you are in the EEA and are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. If you are in India, you may file a complaint with the Data Protection Board of India.