Policy

Privacy

Effective August 17, 2026.

Stylome operates this service from Pennsylvania, United States. This policy describes the information Stylome handles through the website, account system, paid browser extension, public paste box, and developer API.

Information Stylome handles

Account information includes the name and email address returned by Google sign-in, browser-session records, plan and entitlement state, and support communications. Standard-retention scan records include the submitted text, classifier result, timestamps, model and tokenizer-contract versions, and allowance-accounting records. Operational and security records can include IP address, browser or device information, request timing, error details, and abuse-prevention events. The developer API exception for zero-retention keys is described below.

Scans, history, and sharing

When a user selects a DOCX or EPUB file in the public scanner, the browser extracts its text on the user's device. EPUB books are read in their declared reading order and shown as selectable sections. Stylome does not receive the source file. Only the text shown in the scan form is submitted when the user chooses to scan it. Images, comments, scripts, navigation, and document styling are not submitted by the file importer.

Except for developer requests made with a zero-retention key, Stylome stores the complete text submitted for a scan together with its result in account history. Results are not public unless the user chooses to publish a receipt. Publishing a receipt makes its submitted text and result available to anyone with the public link. Removing or unsharing a receipt ends public access through Stylome, but Stylome cannot recall copies someone else already made.

When a person requests a public receipt page, Stylome records an aggregated receipt view. This uses a random first-party, HTTP-only visitor cookie, a one-way daily network and browser hash, and the referring hostname when available. Campaign ownership comes from the account that created the receipt; public links contain no employee or campaign tracking tag. Stylome does not retain the raw IP address or full referring URL in receipt-view analytics. Known automated link previews and crawlers are excluded.

Zero customer-content retention API keys

Where this option is available, a developer can choose zero customer-content retention when an API key is commissioned. The setting is fixed for that key. Eligible requests are normalized, sent over HTTPS to Stylome's private inference service, analyzed in transient memory, and returned to the caller. Stylome does not read or write the shared result cache for these requests.

Stylome does not store the submitted text, an excerpt, a content hash, the classifier result, a receipt, the exact input length, or an idempotency record for a zero-retention request. The response can contain a content hash and classifier result for the caller's use, but Stylome does not retain them after the request. The response includes X-Stylome-Data-Retention: none and Cache-Control: no-store. Because replay requires stored request-derived data, these keys reject Idempotency-Key.

Stylome retains limited account, security, and operating metadata: the key's retention mode, request ID, timestamp, selected model and scoring contract, HTTP status, latency, billable unit, key last-used time, and rate-limit state. This metadata does not contain the submitted text or classifier output. Zero-retention keys support Stylome Large 1.0, Stylome 1.0, and Stylome Fast 1.0. The capacity-aware automatic-routing alias is unavailable in this mode.

Browser extension scanning

The extension displays badges on content it knows how to scan. With automatic scanning off, no discovered page text is sent until the user clicks a badge or requests a selected-text scan. If the user turns automatic scanning on, each scannable post or article they view is transmitted to Stylome over HTTPS, normalized, tokenized, analyzed, and stored with the result in account history. Automatic scanning can be turned off from the extension popup at any time.

The extension keeps its display cache and per-domain activity statistics in trusted browser storage. Stylome does not receive those locally stored domain statistics or collect page domains or URLs for billing analytics.

How information is used

Stylome uses this information to authenticate accounts, provide and improve the requested scanning features, maintain history and public shares, enforce plans and rolling allowances, provide support, secure the service, prevent abuse, comply with law, and maintain reliable operations. Submitted text is not sold, used for advertising, or used to train models without a separate explicit opt-in.

People do not review submitted text except when the user specifically authorizes access for support, when access is necessary to investigate security or abuse, or when access is legally required. Analytics and operational events do not contain submitted documents, document excerpts, or receipt access tokens.

Service providers

Stylome uses Google for optional account sign-in, Resend for account verification and security email, Google Cloud for hosting, Cloudflare for network delivery and Turnstile abuse prevention, Hugging Face for private model artifact storage, RunPod infrastructure for classifier inference, and Stripe and Link for Checkout, billing, tax, receipts, subscription support, and payment processing. These providers receive the information necessary to perform their respective functions. Stylome may also disclose information when legally required or necessary to protect users, the service, or others.

Billing information

Link is the merchant of record for Managed Payments purchases. Stripe and Link receive the identity, address, payment, tax, and transaction information needed to sell and manage the subscription. Payment-card details are not sent to Stylome's servers. Stripe can cancel a subscription and remove associated Stripe records when it honors a Managed Payments deletion request.

Retention and deletion

Account information and standard-retention scans, results, and shares are retained while needed to provide the account and until the user deletes them or asks Stylome to delete the account. Zero-retention requests do not add customer content to these stored records or to ordinary database backups. Until self-service deletion controls are available, requests can be sent to [email protected]. Deleting an account will cancel its subscription, revoke browser sessions, remove its active scan and receipt records, and remove public access to shared receipts, subject to records Stylome or its providers must retain for legal, tax, fraud, accounting, dispute, or security purposes.

Disaster-recovery backups can retain residual copies until they are overwritten through ordinary backup rotation; they are isolated from normal product use. Stylome may retain a one-way account identifier solely to enforce the one-trial-per-account rule without retaining the original sign-in identifier in that record.

Pseudonymous receipt-view rows are retained for up to 13 months for campaign measurement, fraud review, and compensation disputes. Aggregate counts that no longer identify a browser may be retained longer.

Children

Stylome subscriptions are intended only for people who are at least 18 years old and have reached the age of legal majority where they live.

Browser-store limited use

Stylome's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser permissions and website content are used only for the disclosed scanning feature, related product operations, security, and support.

Human verification

The scan form uses Cloudflare Turnstile in invisible mode to distinguish legitimate visitors from automated abuse. No verification control is normally shown. Cloudflare processes browser and network signals for this purpose under its Turnstile Privacy Addendum.

Policy changes and contact

Stylome may update this policy by posting a revised version and effective date. Additional notice or consent will be provided only where applicable law or browser-store rules require it. Privacy and deletion questions can be sent to [email protected].