NewYour Exa or Tako SDK, 5× cheaper.

Legal

Privacy Policy

What personal data we handle when you visit typesearch.ai, use the dashboard or call the API, and what you can do about it.

Last updated September 23, 2026Draft

This page is a draft until we complete the seller’s legal details: legal name, tax ID and address.

In short

  • We collect what we need to run the Service and nothing for advertising. We don’t sell personal data.
  • The queries and parameters you send are deleted after 7 days.
  • API keys are stored only as hashes. Card numbers go to Paddle; we never see them.
  • Cookies only for your session and your language. Our analytics don’t use cookies.
  • You can access, correct, delete or export your data by writing to privacy@typesearch.ai.

Who is responsible

The controller of your personal data is [legal name], CUIT [tax ID], [address], Argentina, who runs typesearch (“we”, “us”). For anything about privacy, write to privacy@typesearch.ai.

When a customer sends us queries that include personal data about its own users, we process that data on the customer’s behalf and following its instructions; the customer is the controller. Enterprise customers can sign a data processing agreement (DPA) with us.

What we collect

  • Account. Your name and email. If you sign in with Google or GitHub, the name, email and profile picture they share with us. Sign-in codes are sent by email and expire after 10 minutes.
  • Organization and team. Your organization’s name, the names, emails and roles of its members, and pending invitations.
  • API keys. A hash of each key — never the key itself — plus its name, its last four characters, when it was created and last used, and its spend limit.
  • Request logs. For each API request: the time, the key, the endpoint, the status, how long it took and what it cost, plus the queries and parameters you sent. The queries and parameters are deleted after 7 days; the rest of the record after 35, to apply spending limits and answer billing questions. You can review them in the dashboard, and they help us fix problems.
  • Aggregated usage. Requests and spend per day, key and endpoint, without the content of your queries. Kept while your account exists, for billing and for your usage charts.
  • Support messages. What you write to us through the Support page or by email, and our replies.
  • Billing. Paddle collects your payment and billing details (card, billing address and tax ID if you give one). It shares with us what we need to manage your credit: the amount, date, currency and country of each transaction, your card brand and last four digits, and refunds. We never see or store card numbers.
  • Website visits. Page views, referrers, countries, browsers and device types, in aggregate, through Vercel Web Analytics. It doesn’t use cookies and doesn’t follow you from one site to another.
  • Technical logs. Like any server, ours and our hosting providers’ record technical data such as IP address, browser and requested URL, to keep the Service secure and fix errors. These logs are kept for a short time.

Why we use it

  • To provide the Service (account, keys, requests, credit, support and service emails): because it’s necessary to perform our contract with you.
  • To keep it secure and working (preventing abuse and fraud, fixing errors, measuring quality and capacity): our legitimate interest in running a reliable service. Aggregated analytics rely on it too.
  • To meet legal obligations (tax and accounting records, requests from authorities): because the law requires it.
  • To send you product news: only if you ask for it. Every such email has a one-click unsubscribe link.

We don’t sell personal data, we don’t use it for advertising, and we don’t build profiles about you.

Queries and the language model

To judge how relevant each result is to your query, we send the query and the candidate articles to a language model through Vercel AI Gateway, which passes them to the model provider. They process them to return the judgment to us. For this reason, avoid putting personal data in your queries unless your use case needs it.

Cookies

We only use the cookies the Service needs: one that keeps you signed in to the dashboard, and one that remembers your language. There are no advertising or cross-site tracking cookies, and our analytics work without cookies.

Paddle’s checkout and Cloudflare’s bot check may use their own strictly necessary cookies, or similar technologies, to prevent fraud, under their own privacy policies.

Who processes data for us

We use these providers to run the Service. Each receives only what it needs for its task and is bound by contract to protect it:

  • Supabase: the database for accounts, teams, keys (as hashes), usage and logs.
  • Vercel: hosting for the website and the dashboard, and cookieless analytics.
  • DigitalOcean: hosting for the API servers that run your requests.
  • Vercel AI Gateway and the language model provider it routes to: judging the relevance of results to your queries.
  • Paddle: payments, invoices, sales tax and payment support. As Merchant of Record, Paddle is also responsible for the payment data it collects, under its own privacy policy.
  • Resend: sending email, such as sign-in codes, alerts and notices.
  • Cloudflare: telling people from bots on forms such as sign-in.

We may also disclose data when the law requires it, to protect the rights and safety of our users or our own, or to a company that takes over the Service, which would remain bound by this policy.

International transfers

We are based in Argentina, and our providers process data in the United States, the European Union and other countries. When data leaves your country, we rely on the safeguards the law recognizes: the European Commission considers that Argentina offers an adequate level of protection, and our providers’ data processing agreements include standard contractual clauses for transfers to countries without that recognition.

How long we keep it

  • Request logs: the queries and parameters, 7 days; the rest of each record (time, key, endpoint, status, cost), 35 days.
  • Aggregated usage: while your account exists.
  • Account, team and keys: while your account exists. When you close it, we delete them within 30 days, backups included.
  • Support messages: while your account exists or, if you don’t have one, up to two years after the last message.
  • Billing records: as long as tax and accounting law requires; in Argentina, up to 10 years.
  • Technical logs: rotated automatically, usually within a few weeks.

Your rights

Wherever you live, you can ask us to:

  • access the personal data we hold about you and get a copy;
  • correct data that is wrong or incomplete;
  • delete your data, except what the law requires us to keep, such as billing records;
  • export it in a structured, machine-readable format (portability);
  • object to processing based on our legitimate interests, or ask us to restrict it while we look into a request;
  • withdraw your consent where we rely on it, such as for product news.

These rights come from the European Union’s General Data Protection Regulation (GDPR) and from Argentina’s Personal Data Protection Law 25.326, and we extend them to everyone.

How to exercise them

Write to privacy@typesearch.ai from the email on your account, or tell us which account it’s about. We may ask you to confirm your identity. It’s free.

We answer within the time the law sets: 10 calendar days for access requests and 5 business days for corrections and deletions under Law 25.326, and in any case within one month.

You can do much of this yourself in the dashboard: edit your profile, revoke keys, remove team members and review your logs.

If you’re not satisfied with our answer, you can complain to a data protection authority: in Argentina, the Agencia de Acceso a la Información Pública (AAIP); in the European Union, the authority in your country.

As required in Argentina: the data subject may exercise the right of access free of charge at intervals of no less than six months, unless a legitimate interest is shown (Law 25.326, article 14, section 3). The AAIP, as the supervisory body of Law 25.326, has the power to handle complaints and claims from anyone whose rights are affected by a breach of the rules on personal data protection.

Security

Traffic is encrypted with TLS, keys are stored only as hashes, and access to production data is limited to the people who need it to run the Service. No system is perfectly secure: if we learn of a breach that affects your data, we’ll tell you and the authorities as the law requires.

People in the news

Our index holds links, headlines, dates and short excerpts of articles published on public news sites, and those articles can mention people. We only return what publishers made public. If you want something about you removed from our results, write to privacy@typesearch.ai with the links, and we’ll review it under the applicable law.

Children

typesearch is a service for developers and businesses. It isn’t directed at children, and you must be 18 or older to create an account. If you believe a child has given us personal data, write to us and we’ll delete it.

Changes to this policy

We’ll update this page when our practices change, along with the date at the top. If a change significantly affects how we use your data, we’ll email the owners of each organization before it takes effect.

Contact

[legal name] · CUIT [tax ID] · [address], Argentina. Privacy: privacy@typesearch.ai.