Legal

Privacy Policy

Last updated 16 August 2026

This policy describes what Elevate Copy AI collects, why, and who else touches it. It is written to match what the software actually does. If you find a gap between this page and the product, tell us and we will fix whichever one is wrong.

Who we are

Elevate Copy AI is operated by K Foster Marketing, LLC (“we”, “us”). For anything in this policy, including data requests, contact support@elevatecopyai.com. We are the data controller for the information described below.

What we collect

DataWhy we have itLegal basis (UK/EU)
Your email addressIt is your account. We email you a sign-in link because there is no password.Performance of a contract
A session cookie (eca_session)Keeps you signed in. Strictly necessary; it is not used to track you.Performance of a contract
Monthly usage countsEnforcing the monthly write-up allowance on your plan.Performance of a contract
Stripe customer and subscription identifiers, plan, statusKnowing what you have paid for. We never see or store card details.Performance of a contract
Product text you submitGenerating your copy. Sent to our AI provider to produce the result.Performance of a contract
Name, email and message, if you use the contact formReplying to you.Legitimate interests (responding to enquiries)

What we do not collect

This list is as important as the one above, and it is accurate as of the date at the top:

  • No analytics or advertising trackers. There is no Google Analytics, no advertising pixel, no session recorder, and no third-party marketing cookie anywhere on this site. The single cookie we set is the sign-in session above.
  • No passwords. Sign-in is a one-time emailed link, so there is no password to store or leak. Link tokens are stored only as a hash.
  • No card details. Payment happens on Stripe’s own hosted checkout. Card numbers never reach our servers.
  • No competitor scraping. We do not query third-party search or marketplace APIs on your behalf. If you paste a competitor’s listing in for positioning, that text is processed with your request and not stored separately.
  • Nothing from the page check. When you paste a page into “Check it”, the analysis runs entirely in your browser. That text is never sent to us, and we could not read it if we wanted to.

Who else processes your data

We use these providers to run the service. Each receives only what it needs, and none of them sell your data:

  • Vercel — hosting and content delivery
  • Turso — the database holding your account and usage records
  • Anthropic — generates the copy from the product text you submit
  • Stripe — payments and subscription management
  • Resend — delivers sign-in emails
  • Brevo — delivers contact-form messages

These providers may process data outside your country, including in the United States. Where that involves transfers out of the UK or EEA, we rely on the providers’ standard contractual clauses or equivalent safeguards.

We do not sell your data

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. We run no advertising on this site.

How long we keep it

  • Account records — while your account exists, then deleted on request.
  • Sign-in link tokens — expire after 15 minutes and are single-use.
  • Sessions — 30 days, or until you sign out.
  • Usage counts — kept per calendar month for allowance enforcement and billing history.
  • Billing records — retained by Stripe as long as tax and accounting law requires, typically seven years.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send you a copy. If you are in the UK or EEA you also have the right to object to or restrict processing, and to complain to your data protection authority. If you are in California you may request disclosure of the categories and specific pieces of information we hold, request deletion, and you will not be treated differently for exercising those rights.

Email support@elevatecopyai.com from the address on your account. We respond within 30 days. There is no charge, and the data model here is small enough that deletion is genuinely complete rather than a soft flag.

Security

Traffic is encrypted in transit. Session cookies are signed, HTTP-only, and marked secure. Sign-in tokens are stored hashed and burned after a single use. API credentials live in server-side environment variables and are never included in anything sent to your browser.

Children

This is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.

Changes

If we change what we collect or who processes it, we update this page and the date at the top. Material changes affecting existing accounts are emailed to you.