Privacy Policy
En vigueur le 2026-09-20
Bypass AI is a tool you hand something to. This policy is about what happens to the thing you hand over — where it travels, who processes it, what is left behind afterwards, and how you get rid of it. "We", "our" and "us" mean Bypass AI. This covers the mobile app and this website.
The one-paragraph version
Text and images you submit are sent to specialist providers, scored or rewritten, and handed back to you. They are not filed away afterwards, and they are never fed into model training. Your account holds your sign-in details, a short excerpt of each past result, and ordinary device diagnostics. Any of it, or all of it, can be erased on request. Everything below is this paragraph with the details filled in.
Following one submission from end to end
The clearest way to describe what we hold is to trace a single scan.
- You paste, import or upload something. The app checks the length threshold locally, before anything leaves the device — short input never becomes a scan.
- The submission travels over an encrypted connection to whichever provider handles that content type.
- That provider returns a likelihood score and a confidence level, or a rewritten draft. It is contractually barred from retaining the submission for training.
- We pass the result back to you and write one history entry: a short excerpt or thumbnail, the score, the confidence level, and the timestamp. Not the submission itself.
- That closes the loop. Nothing about the submission is stored for any later purpose.
What sits on your account
Three things, and nothing beyond what running the service requires.
- Sign-in details — the email address and display name released by Apple or Google when you sign in. Your Apple or Google password never reaches us.
- Result history — the excerpt-or-thumbnail, score, confidence level and timestamp described above, so a past result can be reopened. The original text or image is not part of this.
- Device diagnostics — device model, OS version, app version, language, approximate region, crash reports, and anonymous counts of which features get used. These arrive through analytics and crash-reporting SDKs.
What that account data does
It is used to return the result you asked for, to rewrite a passage when you explicitly press Humanize, to keep your history reachable from your other devices, to count your free daily scans and check your subscription state, to find and fix crashes and see which features people actually use, and to answer you when you write to support. That list is exhaustive.
Lines we do not cross
Stated plainly, because it is the question people are really asking.
- Your submissions are not training data. Not for our models, not for anyone else's.
- Nobody here reads through your content for marketing, profiling or product research.
- Your content and personal information are not for sale, rent or trade, on any terms.
- Nothing is passed to a third party except to carry out the scan or rewrite you asked for.
- Nothing you submit is published, surfaced to other users, or shown anywhere outside your own account.
Who else handles it
We do not build every model in-house. Producing a result means routing your submission to a specialist provider, which processes it and discards it under its own terms. None of them is authorised to use your content for training, or for anything other than returning your result.
- Detection and rewriting of text — third-party AI-detection and language-model providers
- Image scanning — third-party synthetic-image detection providers
- Video scanning — third-party video-forensics providers, once video scanning ships; it is not available today
- Account sign-in — Apple and Google identity services
- Payments — handled end to end by the Apple App Store and Google Play. Your card details never pass through us.
- Hosting and storage — Amazon Web Services, United States
- Analytics and crash reporting — app-health and anonymous usage data only
Where it is kept, and what guards it
Account data and result history live on Amazon Web Services infrastructure in the United States. Traffic is encrypted with TLS; stored data is encrypted with AES-256. Internal access is limited to the few people who need it to keep the service running. No system is perfectly secure and we will not pretend otherwise, but these safeguards are real and we treat them as such.
Erasing things
A submission exists only long enough to produce your result; past that point there is nothing left to retain. Your result history stays until you remove it — one entry at a time, all at once from the History tab, or wholesale by closing your account. Once you ask for deletion, the account and everything attached to it are permanently gone within 30 days. Records of payments and transactions may outlive that where tax or accounting law requires them to.
- From inside the app — Settings, then your profile, then Delete Account
- By email — write to support@bypassai.app from the address the account uses
What you can require of us
Regardless of where you live, you can ask for a copy of the data we hold on you, ask us to correct what is wrong, ask us to erase it, ask for it in a portable machine-readable form, or tell us to stop processing it for a particular purpose. If you are in the EEA or the UK the GDPR puts those rights on a statutory footing; in California the CCPA does the same. Write to support@bypassai.app and you will hear back within 30 days. Exercising any of this costs nothing and changes nothing about how the service treats you.
Age
You must be at least 13 to use Bypass AI. We do not knowingly take account details from anyone below that age. If you believe a younger child has signed up, write to support@bypassai.app and the account will be removed.
Detection is an estimate, not a verdict
Both the scoring and the rewriting are done by AI systems, third-party ones included, so two things need saying outright. Your submission is transmitted to those systems for processing in real time, and they are not permitted to keep it for training. And detection is statistical by nature: what comes back is how strongly your text matches patterns associated with machine generation, plus a confidence level describing how much weight that particular estimate can bear. It informs a judgement a person still has to make. It does not establish who wrote something, and it errs in both directions.
Crossing borders
We run the service from Hong Kong and keep data in the United States, so information about you will cross out of the country you live in. Where the law demands safeguards for that, we rely on the appropriate mechanisms, standard contractual clauses among them.
If this policy changes
A revised policy gets a new effective date at the top, and anything material is announced inside the app before it takes effect. Carrying on with Bypass AI after that point means the revised policy applies to you.
Talking to us
Anything about this policy, or about data we hold on you, goes to support@bypassai.app. Every message is read.
Bypass AI publishes this policy in several languages. Where a translation and the English text disagree, the English text governs.