The short version
Guest text is not added to a VerbaSpaces project. Signed-in work is saved only when the feature or your action calls for it.
AI-backed tools send the content needed for the request to the relevant provider. Some providers may retain short-lived copies.
VerbaSpaces receives subscription references and status, not your complete card or bank-account details.
Ask for access, correction, export or deletion by emailing the privacy contact listed on this page.
Who we are and how to contact us
VerbaSpaces is the operator and data controller for the VerbaSpaces website, public tools, accounts and workspaces. VerbaSpaces operates from Kuwait. In this policy, “VerbaSpaces”, “we”, “us” and “our” refer to that service.
For privacy questions or requests concerning access, correction, deletion, restriction, objection or export, email verbaspaces@gmail.com. Put “Privacy request” in the subject line. We may ask for reasonable information to verify that the request relates to your account before disclosing or deleting data.
This policy applies to VerbaSpaces. A third-party website you choose to visit has its own privacy terms.
Information we collect
Account and identity
Email address, account identifier, authentication method and, when you choose Google sign-in, basic profile information made available through Google such as your name or profile image.
Your content
Prompts, pasted text, uploaded documents or images, assignment questions, rubrics, drafts, research notes, references, citation details, voice samples, AI conversations and generated results.
Projects and preferences
Project titles, folders, tags, favourites, deadlines, outlines, saved sources, document versions, citation style, subject settings and other workspace choices.
Usage and plan information
Plan, subscription status, AI-credit balance, tools used, action units, input word count, usage period and timestamps used to enforce limits, support billing and prevent abuse.
Payment references
PayPal subscription or transaction identifiers, payer email where returned by PayPal, plan, billing cycle and subscription status. VerbaSpaces does not receive or store your complete card number or bank-account credentials.
Technical and security data
IP address, browser or device information, session and authentication events, request timestamps, error codes and security logs generated by our hosting and authentication providers.
Research and imported data
Titles, URLs, DOI, ISBN, author terms and other search criteria, plus public scholarly metadata returned by research services. If you use Drive import, we receive the public Google Docs or Drive link you submit and the content available through that link.
Messages to us
Your email address and the content of support, billing, legal or privacy correspondence, together with the steps taken to resolve it.
Do not submit passwords, payment-card numbers, medical records, government identifiers, confidential third-party material or personal information you are not authorised to use. VerbaSpaces is not designed as a repository for high-risk or regulated records.
Why we process information
The lawful basis available depends on where you live. Where UK or similar data-protection law applies, the principal purposes and bases are:
| Purpose | Information involved | Basis |
|---|---|---|
| Provide tools, generate results and save requested work | Submitted content, settings, projects and account identifier | Performance of our contract with you |
| Create and secure an account | Email, profile, authentication and session data | Contract and legitimate interests in secure access |
| Manage subscriptions, credits and refunds | Account, usage and PayPal subscription references | Contract and legal obligations |
| Enforce limits, diagnose failures and prevent misuse | Usage events, technical data, security logs and limited request metadata | Legitimate interests in reliability, cost control, fraud prevention and safety |
| Answer support, privacy and legal requests | Contact information, correspondence and relevant account records | Contract, legal obligations and legitimate interests |
| Comply with law and establish or defend claims | Relevant account, payment, security and correspondence records | Legal obligations and legitimate interests |
VerbaSpaces does not sell personal information and does not use submitted academic work to build advertising profiles.
How different tools process your content
- Guest and public tools. Text entered into a public quick tool is not added to the VerbaSpaces project database. Some public tools temporarily keep the result in your browser session so you can move between sign-in and the result. AI-backed requests are still sent to the provider needed to return the result.
- Saved projects and workspaces. Project content, notes, sources, academic-workspace inputs, chat history and versions are stored when a signed-in user saves or uses a feature that clearly belongs to a saved workspace.
- Browser-based document and creative utilities. Where a PDF, colour, QR or similar utility states that it works locally, the file is processed in your browser and is not intentionally uploaded to VerbaSpaces. AI chat, extraction or analysis features are exceptions and clearly require server processing.
- Google Drive import. VerbaSpaces does not ask for your Google Drive password or broad Drive access. It fetches only the public document link you provide. Imported content becomes stored project content only when you save it.
- Research search. Search terms and identifiers are sent to scholarly metadata services. Results become stored account data only when you save them to a project or reference list.
- AI images and reference photos. Prompts and any supplied reference image are sent to OpenAI. Generated images are returned to your browser and are not intentionally retained in the VerbaSpaces project database unless a future save feature clearly tells you otherwise.
Yes, in limited circumstances. OpenAI and Groq may keep customer content in safety, reliability or abuse-monitoring logs for up to 30 days under their standard settings. Winston AI may retain submitted scan content and reports under its own policy. Provider retention is separate from whether VerbaSpaces saves a project.
Providers and other recipients
VerbaSpaces shares information only as needed to operate a feature, process a payment, secure the service, comply with law or respond to a request. The principal recipients are:
| Provider | Purpose and information | Provider retention and controls |
|---|---|---|
| OpenAI Sites and CloudflareHosting and infrastructure | Application requests, saved workspace data, database records, network and diagnostic information. | Operational logs and recovery copies follow platform settings. Cloudflare D1 recovery history is normally 7 or 30 days depending on the hosting plan. Cloudflare privacy |
| SupabaseAuthentication | Email, account identifier, authentication provider, sessions and authentication audit information including IP address, device/browser and event timestamps. | Account data remains while the account is active. Auth logs and backups follow the configured Supabase plan and project settings. Supabase privacy |
| GoogleOptional sign-in and public Drive import | Google sign-in supplies basic identity information. A Drive import sends Google the public document link requested by the user. | Google handles information under its own account and service policies. VerbaSpaces requests only the sign-in scopes needed for identity. Google privacy |
| GroqText AI processing | Prompts, selected text, project context needed for the chosen writing, research, academic, PDF or assistant feature, and generated output. | Groq says inference content is not retained by default, but it may temporarily log input and output for reliability or suspected abuse for up to 30 days. Groq data controls |
| OpenAIImage generation and image analysis | Image prompts, creative settings, reference images and generated output. VerbaSpaces sends reference-photo analysis through the Responses API with storage disabled. | OpenAI states API content is not used to train its models unless the API customer opts in. Standard abuse-monitoring logs may contain prompts or responses for up to 30 days. Images flagged by safety systems may be retained for manual review. OpenAI data controls |
| Winston AIAI-content and plagiarism checks | Text submitted specifically for an AI-content or plagiarism scan and the resulting report. | Submitted content and reports may be retained by Winston under its policy. Winston states that content associated with a deleted provider account is removed from active storage within 30 days. Winston privacy |
| PayPalSubscriptions and payments | PayPal account information, payment instrument, transaction and fraud-prevention data. VerbaSpaces receives subscription identifiers, plan/status and limited payer information, not full card details. | PayPal acts under its own privacy statement and may retain relationship information for the relationship plus 10 years, or longer where law or claims require. PayPal privacy |
| OpenAlex, Crossref and Europe PMCScholarly metadata | Title, URL, DOI, ISBN, author or keyword search terms. These services return public source metadata. VerbaSpaces does not intentionally send your account identity with the search. | Each service may keep ordinary server and request logs under its own privacy terms. Search metadata saved to VerbaSpaces follows the project-retention period. |
Information may also be disclosed to professional advisers, regulators, courts, law enforcement or another business owner where reasonably necessary and permitted by law, including in a genuine business reorganisation. VerbaSpaces does not disclose user content to universities, employers or other users merely because they request it.
How long information is retained
We keep identifiable information only for as long as needed for the stated purpose, a legal requirement, security, dispute resolution or enforcement. Current operational periods are:
| Data type | VerbaSpaces retention |
|---|---|
| Guest quick-tool text and temporary results | Not stored in the project database. Browser-session copies expire when the session is cleared or closed. AI-provider retention may still apply. |
| Account and authentication profile | For the life of the account, then removed from active account systems within 30 days of a verified deletion request, subject to security logs, backups and legally required records. |
| Saved projects, academic workspaces, notes, sources, chat history and uploaded/imported content | Until you delete the relevant project or request account deletion. Active copies are removed immediately where the in-product control does so, or otherwise within 30 days. Recovery copies expire within the provider backup cycle, normally within a further 7–30 days. |
| Project versions | Up to the latest 40 versions for each project. Older versions are automatically removed. Remaining versions are deleted with the project, subject to the backup period above. |
| My Voice samples and derived profile | Until you delete the voice profile or account. Active copies are then removed within 30 days, with recovery copies expiring within the normal backup cycle. |
| AI image outputs and reference photos | Not intentionally retained in the VerbaSpaces project database after the request. OpenAI may retain relevant content in standard abuse-monitoring logs for up to 30 days, with limited safety exceptions. |
| Usage events and allowance records | VerbaSpaces keeps no more than the latest 200 detailed usage events per account, together with the counters needed for current plan periods, billing, credits and refund eligibility. These are removed within 30 days of account deletion unless a billing or legal record must remain. |
| Authentication and security logs | Normally up to 12 months, subject to shorter platform-plan settings. Logs connected to a security incident, abuse investigation or legal claim may be retained until the matter is closed. |
| Subscription, transaction and refund records | Up to 7 years after the last transaction or the end of the subscription, unless applicable law requires a different period. PayPal applies its own retention period separately. |
| Support, legal and privacy correspondence | Up to 24 months after the request is closed. A minimal record may be kept longer when necessary to show that a legal request was completed. |
Deletion from an active system does not always remove the same record instantly from an isolated recovery backup. Backups are not used for ordinary product access and are overwritten through the normal recovery cycle. We may suspend deletion where preservation is required by law, a court order, fraud prevention or an unresolved claim, and will limit the information to that purpose.
International data transfers
VerbaSpaces operates from Kuwait, while its providers may process information in the United States, Europe and other countries. This means personal information may be transferred to a country whose privacy law differs from the law where you live. Cloud hosting may also route network traffic through distributed infrastructure.
Where transfer rules apply, VerbaSpaces uses providers that publish data-protection terms and relies on available safeguards such as data-processing agreements, adequacy decisions and standard contractual clauses where appropriate. Provider-specific locations and controls can change; the links in the provider table contain their current information.
Your rights, deletion and export
Depending on your location and the reason for processing, you may have the right to:
- Receive a copy of your personal information.
- Correct inaccurate or incomplete information.
- Request deletion where no overriding reason requires retention.
- Restrict particular processing while an issue is examined.
- Receive eligible data in a portable, commonly used format.
- Withdraw consent for future processing based on consent.
- Complain to the privacy regulator available in your country.
Tell us what processing you object to and why it affects you. You may always object to direct marketing, and VerbaSpaces will stop it.
Project tools provide export options such as Word, PDF, Markdown or text where shown. For a broader account export or deletion, email verbaspaces@gmail.com. We aim to respond within one month where UK data-protection law applies, or within the period required by the law that applies to your request. Verification, complex requests or multiple requests may affect timing where the law permits.
Deleting a project does not close the authentication account. An account-deletion request covers the authentication record and linked VerbaSpaces workspace data, except for billing, fraud, security or legal records that must be retained. Closing VerbaSpaces does not automatically delete information held independently in your Google or PayPal account.
If UK data-protection law applies, you may also complain to the UK Information Commissioner’s Office.
Age requirements
VerbaSpaces accounts are intended for people aged 16 or older. A person under 16 must not create an account or submit personal information. Paid subscriptions may be purchased only by someone aged 18 or older who is legally able to enter the payment agreement, or by an authorised parent or guardian where permitted.
If you believe a child below the permitted age has supplied information, contact us. After reasonable verification, we will remove it unless law requires otherwise.
How information is protected
VerbaSpaces uses encrypted network connections, server-side ownership checks, private server credentials, authenticated access to saved work, request validation, rate limits and provider security controls. Payment credentials are handled by PayPal rather than stored by VerbaSpaces. Access to production services is limited to the people and providers that need it.
No internet service can guarantee absolute security. Keep your login method secure, sign out on shared devices, avoid placing secrets in documents, and contact us promptly if you believe your account has been accessed without permission.
AI and automated processing
VerbaSpaces uses automated systems to generate text and images, analyse writing, estimate AI or plagiarism signals, organise research, check citations, enforce usage limits and detect possible misuse. These tools can be incomplete or wrong. Academic scores, source-support labels, AI-detection results and submission-readiness indicators are guidance, not university grades or findings of fact.
VerbaSpaces does not use these tools to make a solely automated decision that produces a legal or similarly significant effect about you. A human should review important academic, employment, financial, medical or legal decisions.
Changes to this policy and contact
We will update this policy when data practices, providers, features or legal requirements change. The “Last updated” date at the top shows the current version. If a change materially affects how account data is used, we will provide a prominent website notice or contact account holders where reasonably possible before the new use begins.