Privacy Policy
Lightphrase rewrites text you have already selected. This policy sets out what it collects, where that text goes, who else handles it, how long anything is kept, and what you can ask us to do about it.
The short version
The short version. The full policy follows, and it governs.
-
Text goes out only on request
Your selection is sent only when you pick an action. Lightphrase does not watch keystrokes, and it sends nothing while the wheel is merely open.
-
Your clipboard, returned
Lightphrase snapshots the clipboard before it copies your selection and restores it after it pastes. You get back exactly what you had.
-
Nothing overwritten by accident
Move the cursor or change the selection while a rewrite is underway and the replacement is cancelled, rather than landing in whatever field you moved to.
-
Your settings stay on the machine
Tones, shortcuts, and rewrite history live on this computer and are never uploaded or synced. What we do hold on our servers is your account and its sessions, set out in full below.
1. Who we are #
Lightphrase is a desktop writing utility published by Mason Solutions, based in the Philippines. Mason Solutions is the data controller for the processing described here, and can be reached at support@mail.mason.ph.
In this policy, "we" and "us" mean Mason Solutions; "the app" means the Lightphrase desktop application; and "the API" means the Lightphrase service at api.lightphrase.com that the app talks to.
2. What this policy covers #
This policy applies to three things:
- The Lightphrase desktop app, however you installed it
- The Lightphrase API at api.lightphrase.com, which the app calls
- The website at lightphrase.com
It does not cover the other applications you use Lightphrase inside, or the services of the companies listed in section 5, each of which handles data under its own privacy policy.
3. Information we collect #
Account information
Lightphrase requires an account, because the daily rewrite allowance is applied per person. When you sign up with an email address we store that address and a hash of your password — never the password itself. If you sign in with Google or Facebook instead, we store the email address, name, and profile picture URL that provider returns to us, along with the access and refresh tokens it issues so we can verify your session. This is held in our database on Cloudflare. If you create an account with email and password, we send a transactional email with a one-hour link so you can verify that address before you log in. If you ask to reset a password, we send a transactional email with a one-hour link to the address on the account. Those messages are sent through Cloudflare Email Sending. We do not use that address for marketing.
Session records
Each time you sign in we create a session record containing a session token, its expiry, the time it was created, and the IP address and user agent of the device that signed in. We keep these to hold you signed in between launches and to recognise abuse of the service.
The text you submit for a rewrite
When you pick an action on the wheel, the app sends three things to our API: the text you had selected, up to 8,000 characters; the instruction for the action or tone you chose; and your speed setting. It sends nothing else — no file name, no window title, no name of the application you were writing in, and no device identifier. Section 5 describes who processes that text on our behalf.
We do not store the text you submit or the result we return. Both exist only for the length of the request. We do not use them to train models, ours or anyone else's.
Service logs
Our API records a line for each request so we can keep the service working. Those lines contain: your account identifier, the kind of request, the speed mode, the model and the provider that served it, the number of characters you sent, token counts, the cost of the request, how long it took, how much of your daily allowance remains, why the generation finished, and any error.
They record how many characters you sent, never the characters themselves. Neither your text nor the rewritten result appears in any log we keep. Our application code does not log IP addresses; our hosting provider keeps its own network logs, as any host does.
Your daily allowance
We count generations against a limit of 1,000 per account per day. The counter stores only your account identifier, the date in UTC, and the number used.
Feedback you choose to send
If you report a bug or suggest an improvement from inside the app, we file it as an issue in the Lightphrase repository on GitHub. That issue contains your title and description, your email address, your account identifier, and version numbers for the app, Electron, Chrome, Node, and your operating system. Please do not paste anything confidential into a report.
Visiting lightphrase.com
The website sets no cookies, runs no analytics, and loads no tracking pixels or third-party scripts. Our web host records standard server logs, including IP addresses, to serve and protect the site.
What stays on your computer
Three files live in the app's data folder on your machine:
- A history of your last 50 rewrites, holding the text you sent and the result. It is stored in plain text and you can clear it at any time from Settings.
- Your settings: the active and custom tones, the summon shortcut, the wheel layout, and display preferences. Also plain text.
- Your sign-in token, encrypted at rest by your operating system's own credential protection and readable only by your user account.
None of these are uploaded or synced to us. Signing out clears the token; uninstalling the app removes the files from your computer.
Clipboard
To replace text inside another application, Lightphrase copies your selection and pastes the result over it. Before that copy it snapshots whatever was already on the clipboard and puts it back when the rewrite is done. The snapshot is held in memory for the length of the operation and is never written to disk or sent anywhere.
What we never collect
Lightphrase contains no advertising, no analytics or crash-reporting service, and no payment processing. It does not use your camera, microphone, or location, does not capture your screen, does not read your files, and does not log keystrokes.
4. How we use it, and why #
We use what we collect only for the purposes below. For people in the European Economic Area and the United Kingdom, the last column gives our legal basis under the GDPR.
| Purpose | What we use | Legal basis |
|---|---|---|
| Produce the rewrite you asked for | Selected text, instruction, speed mode, account identifier | Performance of a contract |
| Create your account and keep you signed in | Account information, session records | Performance of a contract |
| Send a verification email when you create an account | The email address on the account | Performance of a contract |
| Send a password reset email when you ask | The email address on the account | Performance of a contract |
| Apply the daily allowance and prevent abuse | Account identifier, allowance counter, session IP address | Legitimate interests |
| Keep the service reliable and diagnose faults | Service logs | Legitimate interests |
| Answer a bug report or suggestion you sent | Your message, email address, account identifier, version details | Legitimate interests |
| Meet legal and regulatory obligations | Whatever the obligation requires | Legal obligation |
We do not use the text you submit to train models. We do not build profiles of you, we do not serve advertising, and we make no automated decisions that produce legal or similarly significant effects.
6. International transfers #
Mason Solutions is in the Philippines, and the providers in section 5 operate in the United States, the European Union, and elsewhere. Using Lightphrase therefore involves transferring information across borders, including out of the European Economic Area and the United Kingdom.
Where such a transfer needs a safeguard, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the recipient's own adequacy or certification, as applicable. Write to us at the address in section 12 if you would like details of the safeguard used for a particular provider.
7. How long we keep it #
| Information | How long we keep it |
|---|---|
| Text you submit, and the rewrite returned | Not stored. It exists only in memory for the length of the request. |
| Account information | Until you ask us to delete your account. |
| Session records, including IP address and user agent | Until the session expires or you sign out, and in any case removed with the account when you ask us to delete it. |
| Daily allowance counter | Keyed to a single UTC day and replaced the next day. |
| Service logs | Held for the log retention window of our hosting provider, a matter of days, then discarded automatically. |
| Bug reports and suggestions | Kept while the issue is open. Ask us and we will delete yours, or redact your email address from it. |
| History and settings on your computer | Until you clear the history, sign out, or uninstall the app. We cannot reach these files. |
8. How we protect it #
- All traffic between the app and our API runs over HTTPS. The app refuses any endpoint that is not HTTPS, apart from a local address used during development.
- Your session token never leaves the main process of the app. It is not exposed to any web content the app renders.
- The stored token is encrypted at rest using the credential protection built into your operating system, in a file readable only by your user account.
- Passwords are stored as hashes. We never see or store the password itself.
- Access to production data is limited to the people who need it to run the service.
No service can promise perfect security, and we do not. If we ever discover a breach affecting your personal information, we will notify you and the relevant regulator within the time the law allows.
9. Your rights and choices #
Whatever country you are in, you can write to support@mail.mason.ph to exercise any right below. We reply within 30 days. We may ask you to write from the email address on the account so we can be sure the request is yours, and we will never charge you or treat you differently for asking.
Deleting your account
Email us from the address on the account and ask for deletion. We remove the account, its sessions, and its allowance records within 30 days, and confirm when it is done. The history on your own computer is yours to clear from Settings, or by uninstalling the app.
If you are in the European Economic Area or the United Kingdom
Under the GDPR and the UK GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to how we process it, and to receive it in a portable form. Where we rely on consent you may withdraw it at any time. You also have the right to complain to your local supervisory authority.
If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and disclose, to have it deleted, to have it corrected, and to be free from discrimination for exercising those rights.
In the past twelve months we collected these categories: identifiers, meaning your email address, account identifier, and IP address; internet or network activity, meaning your user agent and the service logs described in section 3; and your own content, meaning the text you submitted for a rewrite. We disclosed those categories to the service providers listed in section 5, for the business purposes given there.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past twelve months or at any other time. We do not use or disclose sensitive personal information for purposes that require an opt-out.
If you are in the Philippines
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the rights to be informed, to access, to object, to correct, to erasure or blocking, to data portability, and to be indemnified for damages. You may also lodge a complaint with the National Privacy Commission.
10. Children #
Lightphrase is a tool for adults at work and is not directed to children. We do not knowingly collect personal information from anyone under 13, or under 16 in the European Economic Area. If you believe a child has given us information, write to support@mail.mason.ph and we will delete the account and its data.
11. Changes to this policy #
When this policy changes we post the new version on this page and revise the date at the top. If a change materially affects how we handle your information, we will say so here, and where we can we will tell you in the app before it takes effect. Continuing to use Lightphrase after a change means you accept the revised policy.
12. How to contact us #
Mason Solutions is the publisher of Lightphrase and the data controller for everything described here. For any question about this policy, a request about your data, or a complaint, write to support@mail.mason.ph.
If you are unhappy with our answer, you may complain to your local data protection authority, or to the National Privacy Commission in the Philippines.