Back

Privacy Policy

Effective 3 August 2026 · Last updated 3 August 2026

Your conversation history is indexed only on your device. We never store your conversation data.

1. Who we are

CatchMyWords is a browser extension that builds a private, local memory of your AI conversations and turns it into the email, reply, explanation or briefing you need, inside whatever text field you are already typing in.

The data controller responsible for your personal data is Ibrahim Kako, a sole trader based in Ireland. You can reach us about anything in this policy at support@catchmywords.com.

2. Joining the waitlist

The extension is not released yet. If all you have done is join the waitlist, this section is the only part of this policy that applies to you.

DataWhyWhere
Your email addressTo tell you when CatchMyWords opens up, and occasional progress notesKit (ConvertKit)
Your IP address, brieflyTo rate-limit the signup form against bots. Held as a counter for one hour, then discardedCloudflare

The lawful basis is your consent (Article 6(1)(a) GDPR), given when you submit the form. You can withdraw it at any time using the unsubscribe link in any email we send, or by writing to support@catchmywords.com — we will delete your address and confirm.

We will not sell or share your address, and we will not send you anything unrelated to CatchMyWords. If the product never launches, the list is deleted.

3. What stays on your device

Everything CatchMyWords indexes — the captured text, the chunks it is split into, the summaries derived from it, and the search index itself — is written to your browser's Origin Private File System on your own machine. It is never uploaded, never backed up by us, and never readable by us. We have no copy and no way to obtain one.

Because of that, if you uninstall the extension or clear your browser storage, your index is gone permanently. There is nothing on our side to restore it from.

4. What we do store

Only what an account and a subscription actually require:

DataWhyWhere
Email address, from Google sign-inTo identify your accountSupabase
Plan and subscription statusTo know what you are entitled toSupabase, Stripe
A generation countTo apply your plan's limitSupabase
Stripe customer and subscription referenceTo manage billingSupabase, Stripe

The generation count is a single integer — for example 17. It records that something was generated, never what was generated, asked, or retrieved.

Our lawful basis for holding this is performance of our contract with you (Article 6(1)(b) GDPR): we cannot operate an account or a subscription without it.

5. What we never collect

  • Conversation text, transcripts or chat history
  • What you ask CatchMyWords for, or what it drafts in reply
  • The passages retrieved from your index
  • Your browsing history, keystrokes or screenshots

6. What leaves your device when you generate

This is the one part worth reading carefully, because "indexed only on your device" is true but is not the whole picture.

When you ask for a draft, the extension searches your local index and sends the passages it found, plus your instruction, to our proxy. The proxy attaches our API key and forwards the request to Anthropic, which generates the response. It exists because the API key must never sit inside a browser extension where anyone could extract it.

So, plainly:

  • Your index never leaves your device. Not on install, not on a schedule, not ever.
  • The excerpts needed for one draft do leave your device, for that request only.
  • Our proxy stores none of it. It holds nothing after the response is returned, and its logs record only that a generation happened.

You control this: nothing is sent unless you press the shortcut and ask for something.

7. Who processes data for us

ProcessorRoleWhere
Kit (ConvertKit)Holds the waitlist and sends its emailsUS
SupabaseSign-in and account recordsEU
CloudflareHosts the proxy and this siteGlobal edge
StripePaymentsEU / US
AnthropicGenerates drafts from the excerpts you sendUS

We do not sell, rent or share your data with anyone else.

8. Transfers outside the EEA

Kit holds the waitlist in the United States. Anthropic processes generation requests there too, and Stripe may process payment data there. Those transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses otherwise. Your index is not part of any transfer, because it never leaves your device at all.

9. No cookies, no analytics, no tracking

CatchMyWords sets no cookies, embeds no tracking pixels, and runs no third-party analytics — not in the extension and not on this website. We do not measure which features you use, and there is no profile of you anywhere in our systems. There is nothing here to opt out of.

10. Your controls

In the extension you can:

  • Pause capture, so nothing further is indexed
  • Remove a source — deleting a platform removes everything indexed from it, and revokes the permission that allowed it
  • Erase your entire index in one action, from the options page

These act on your device and take effect immediately. They need no request to us, because we were never holding the data.

Before anything is indexed, the extension also scans it for credentials, API keys and card numbers and redacts them, so those cannot later be retrieved or sent for generation.

11. Your rights

Under the GDPR you have the right to access, correct, erase, restrict or object to our processing of your personal data, and to receive it in a portable form. In practice the data we hold about you is your email address, your plan, and a counter.

To exercise any of these, email support@catchmywords.com. We will respond within 30 days. Account deletion is currently handled by email rather than a button in the app — write to us and we will erase your account and all associated records, and confirm when it is done.

If you believe we have handled your data improperly, you may complain to the Irish Data Protection Commission at dataprotection.ie.

12. How long we keep it

  • Your index: on your device, until you delete it. We hold no copy.
  • Waitlist address: until you unsubscribe, or until the list is no longer needed.
  • Account data: while your account exists, then erased on request.
  • Billing records: retained by Stripe, and by us where tax law requires it.

13. Security

  • API keys exist only on our server, never inside the extension.
  • Sign-in tokens are cryptographically verified on every request.
  • Rate limiting protects accounts from abuse.
  • Your index is protected by your browser's sandbox and your own device security.

14. Children

CatchMyWords is not intended for anyone under 16, and we do not knowingly hold data about children.

15. Changes

If we change this policy in a way that matters, we will tell you by email or in the extension before it takes effect. The date at the top always reflects the current version.

16. Contact

support@catchmywords.com · See also our Terms of Service.

© 2026 CatchMyWords. All rights reserved.
Privacy Policy Terms of Service