Privacy Policy
Last updated 16 August 2026
This policy describes what Elevate Copy AI collects, why, and who else touches it. It is written to match what the software actually does. If you find a gap between this page and the product, tell us and we will fix whichever one is wrong.
Who we are
Elevate Copy AI is operated by K Foster Marketing, LLC (“we”, “us”). For anything in this policy, including data requests, contact support@elevatecopyai.com. We are the data controller for the information described below.
What we collect
| Data | Why we have it | Legal basis (UK/EU) |
|---|---|---|
| Your email address | It is your account. We email you a sign-in link because there is no password. | Performance of a contract |
A session cookie (eca_session) | Keeps you signed in. Strictly necessary; it is not used to track you. | Performance of a contract |
| Monthly usage counts | Enforcing the monthly write-up allowance on your plan. | Performance of a contract |
| Stripe customer and subscription identifiers, plan, status | Knowing what you have paid for. We never see or store card details. | Performance of a contract |
| Product text you submit | Generating your copy. Sent to our AI provider to produce the result. | Performance of a contract |
| Name, email and message, if you use the contact form | Replying to you. | Legitimate interests (responding to enquiries) |
What we do not collect
This list is as important as the one above, and it is accurate as of the date at the top:
- No analytics or advertising trackers. There is no Google Analytics, no advertising pixel, no session recorder, and no third-party marketing cookie anywhere on this site. The single cookie we set is the sign-in session above.
- No passwords. Sign-in is a one-time emailed link, so there is no password to store or leak. Link tokens are stored only as a hash.
- No card details. Payment happens on Stripe’s own hosted checkout. Card numbers never reach our servers.
- No competitor scraping. We do not query third-party search or marketplace APIs on your behalf. If you paste a competitor’s listing in for positioning, that text is processed with your request and not stored separately.
- Nothing from the page check. When you paste a page into “Check it”, the analysis runs entirely in your browser. That text is never sent to us, and we could not read it if we wanted to.
Who else processes your data
We use these providers to run the service. Each receives only what it needs, and none of them sell your data:
- Vercel — hosting and content delivery
- Turso — the database holding your account and usage records
- Anthropic — generates the copy from the product text you submit
- Stripe — payments and subscription management
- Resend — delivers sign-in emails
- Brevo — delivers contact-form messages
These providers may process data outside your country, including in the United States. Where that involves transfers out of the UK or EEA, we rely on the providers’ standard contractual clauses or equivalent safeguards.
We do not sell your data
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. We run no advertising on this site.
How long we keep it
- Account records — while your account exists, then deleted on request.
- Sign-in link tokens — expire after 15 minutes and are single-use.
- Sessions — 30 days, or until you sign out.
- Usage counts — kept per calendar month for allowance enforcement and billing history.
- Billing records — retained by Stripe as long as tax and accounting law requires, typically seven years.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send you a copy. If you are in the UK or EEA you also have the right to object to or restrict processing, and to complain to your data protection authority. If you are in California you may request disclosure of the categories and specific pieces of information we hold, request deletion, and you will not be treated differently for exercising those rights.
Email support@elevatecopyai.com from the address on your account. We respond within 30 days. There is no charge, and the data model here is small enough that deletion is genuinely complete rather than a soft flag.
Security
Traffic is encrypted in transit. Session cookies are signed, HTTP-only, and marked secure. Sign-in tokens are stored hashed and burned after a single use. API credentials live in server-side environment variables and are never included in anything sent to your browser.
Children
This is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
Changes
If we change what we collect or who processes it, we update this page and the date at the top. Material changes affecting existing accounts are emailed to you.