Privacy Policy

Last updated: January 1, 2025

How Does This Sound is a personal project. This policy explains how your data is handled when you use the service.

The Short Version

  • Your messages are sent to AI providers for analysis
  • Messages are logged for debugging (see details below)
  • Analytics cookies track basic usage
  • You can use your own API key for more control
  • Your data is not sold

What Data Is Collected

Message Content

When you analyze a message, your text is:

  1. Sent to an AI provider (Anthropic, OpenAI, or Google depending on your choice)
  2. Logged in the observability system (Langfuse) for debugging and quality monitoring

This applies to all usage, including BYOK. Even if you use your own API key, message content is still logged to Langfuse for service monitoring.

Important: Message content is retained in Langfuse logs. While this data is only used for debugging and improving the service, you should not submit sensitive personal information, passwords, or confidential business information.

Device Fingerprint

A temporary hash of your device is generated to enforce rate limits (5 free analyses per day). This cannot identify you personally and is deleted after 24 hours.

Analytics

PostHog is used to understand how people use the site. This collects:

  • Pages visited
  • Browser and device type
  • General location (country level)

You can block this with any standard ad blocker.

API Keys (BYOK)

If you use your own API key, it's stored only in your browser's local storage. It is transmitted to the AI provider but not stored on the server.

IP Addresses

IP addresses are processed by Cloudflare for hosting and security purposes. They are not separately logged or stored by this service.

Third-Party Services

Service What They Receive Their Privacy Policy
Anthropic Message text (default) anthropic.com/privacy
OpenAI Message text (BYOK) openai.com/privacy
Google Message text (BYOK) policies.google.com/privacy
Langfuse Message text, AI responses langfuse.com/privacy
Cloudflare IP address, request data cloudflare.com/privacy
PostHog Anonymous usage data posthog.com/privacy

Your Choices

  • Use BYOK: Bring your own API key for a direct provider relationship (note: Langfuse logging still applies)
  • Block Analytics: Use an ad blocker to prevent PostHog tracking
  • Avoid Sensitive Data: The safest approach for confidential information

Data Retention

  • Langfuse logs: Retained per Langfuse's policies (typically 30-90 days)
  • Rate limit data: 24 hours
  • Analytics: Per PostHog's retention settings

Security

All data is transmitted over HTTPS. API keys are stored only in your browser.

International Data Transfers

This service uses infrastructure and third-party services based in the United States, including Cloudflare, Anthropic, OpenAI, Google, Langfuse, and PostHog. By using this service, your data may be transferred to and processed in the United States.

Where applicable, these transfers rely on adequacy decisions such as the UK-US Data Bridge, or the data protection commitments of the respective providers. The third-party providers listed above maintain their own data protection practices as described in their respective privacy policies.

AI Model Training

Message content is not used to train AI models. However, this cannot be guaranteed for the third-party AI providers (Anthropic, OpenAI, Google) - refer to their respective privacy policies for their data usage practices.

Children

This service is not intended for children under 13.

Changes

This policy may be updated occasionally. Check back for the latest version.

Contact

Questions? Email: hello@howdoesthissound.com