Last updated: 15 September 2026
ControlG is built to minimize data collection. The built-in AI requires a ControlG account and securely processes the text you choose to rewrite through our Azure service. We do not store that text or use it for training, advertising, or profiling.
When you use the built-in AI, the selected text, your chosen instruction, and a device identifier are sent over HTTPS to our Azure Functions backend and then to Azure OpenAI to generate the rewrite. The text is handled in memory for that request and is not written to our database or application logs. If you choose a bring-your-own-key provider, the app sends the text directly to that provider under its own terms.
Google sign-in is provided by Clerk. We store your Clerk user id, email address, plan, free-rewrite count, prompt settings, registered device identifiers, licence status, and related timestamps in Azure Cosmos DB. An account receives one active device slot for each supported platform; signing out releases that installation's slot.
Your optional third-party API keys are stored locally and encrypted on your device (Keychain on macOS, Android Keystore-backed encrypted preferences, and DPAPI on Windows). They are sent only to the provider you selected. If Android secure storage is unavailable, keys remain in memory for that app session and are not written in plaintext.
On Android, ControlG uses the Accessibility Service for a single purpose: to read the text you select or type and to write the rewritten result back into the field. It is not used for any other data collection.
To fix crashes and rewrite failures, the app keeps a small on-device diagnostics log. It records technical information only — error and status codes, the AI model used, timing, network type, the app and field type where a rewrite ran, and the length (a number) of the text — and never your selected or typed text, the rewritten result, your prompts, or your API keys. This log stays on your device unless you turn on “Send diagnostics automatically” in the app's Diagnostics screen, which is off by default. When enabled, the same technical-only events are sent to us with a random, non-identifying id so we can diagnose problems. You can view, share, or clear the log, and turn sending off, at any time.
International payments are processed by Paddle, our Merchant of Record; Bangladesh payments may be processed by EPS. Card and wallet details never reach us. We receive the buyer email, transaction id, product and payment status needed to create and support the licence. Licence records are stored in Azure Cosmos DB.
Your activation code is shown on-screen immediately after payment. If email delivery is enabled, we may also send it (and support replies) via a transactional email provider (Resend). We never send marketing email and there is no mailing list.
The website stores a random, anonymous id in your browser's local storage to count unique visits, and records the host name of the site that referred you (e.g. “google.com”) — never full URLs, and never anything that identifies you. We use no advertising cookies, no cross-site trackers, and no third-party analytics. Your IP address is processed transiently to detect your country (to show the right price and payment method) and to help prevent fraud; it is not stored alongside your identity.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the following applies.
Data controller. For the license-delivery data (your email and order id), the controller is ControlG — Mehedi Shoron, reachable at shoron@getcontrolg.com. For payment data, Paddle is the Merchant of Record and acts as controller.
What we process and why (legal basis):
The optional app diagnostics (off by default) contain technical error information and a random identifier, never the text you rewrite, results, prompts, or API keys.
Retention. Rewrite text is not retained by ControlG. Account, licence, device and order records are kept while the account or lifetime licence remains active and as required for legal/accounting duties. We delete eligible records on request, subject to records payment providers must retain.
Sub-processors. Microsoft Azure (API hosting, database and Azure OpenAI), Clerk (identity), Vercel (website hosting), Paddle and EPS (payments), and — if enabled — Resend (transactional email).
International transfers. Some of these providers are based in the United States and process data under Standard Contractual Clauses or an equivalent safeguard.
Your rights. You have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and to data portability. To exercise any of these, email shoron@getcontrolg.com from your purchase address and we'll action it, usually within 30 days. You also have the right to lodge a complaint with your local data protection authority.
No profiling or sale of data. We do not sell your data and we do not carry out automated decision-making or profiling. ControlG is not directed at children under 16, and we do not knowingly collect their data.
ControlG is open source, so these claims are verifiable. You're welcome to read the code.
Contact: shoron@getcontrolg.com
← Back to ControlG