Permitext is operated by Higinio Jimenez Manzano. This policy explains what information Permitext processes in its web and iOS applications, why it is used, and the choices available to you.
Information Permitext processes
- Account information: identifiers used to sign in with email or through Apple, Google, or Microsoft using Clerk, and any name or email address you or those services provide. Existing iOS builds may also use direct Sign in with Apple, including an Apple private relay address. Permitext may store a display name, public username, optional professional role, and product-email preference you choose.
- Workspace content: saved code sections, notes, tags, projects, project names and addresses, comments, legacy Workboards, images, Notebook content, report drafts and exports, and related activity records.
- Research content: questions, selected code evidence, project context you choose to include, generated answers, citations, conversation history, and feedback.
- Usage and continuity data: searches, recently viewed sections, saved reading state, sync timestamps, and identifiers needed to keep your work consistent across devices.
- Purchase and entitlement information: subscription status, Research turn balance, and transaction identifiers supplied by Apple or Stripe. Permitext does not receive or store your complete payment-card number.
- Security and operational information: hashed session credentials, request timestamps, release identifiers, and limited, redacted error and request metadata used to authenticate requests, prevent abuse, troubleshoot failures, and operate the service. Infrastructure providers may process IP addresses and technical logs under their own retention practices.
- Anonymous website analytics: aggregated page views and limited technical context, such as the page path, referring site, general region, browser, operating system, and device type. Permitext removes query strings and URL fragments before a page view is sent and does not send Research questions, notes, project details, email addresses, or transaction-confirmation page views to this analytics service.
Beta 1 content restriction
Permitext Beta 1 is not approved for confidential, regulated, or sensitive personal information, such as government identification numbers, financial-account information, health records, passwords, or private information about clients or occupants. You must redact that material before submitting notes, questions, Project facts, images, support requests, or other content to Permitext. Ordinary project information, including a property address, may be submitted when needed for a feature you request.
How information is used
Permitext uses this information to authenticate your account, synchronize your work, provide saved research features, verify paid access, generate requested Research responses, protect accounts and infrastructure, troubleshoot failures, and respond to support requests. If you opt in, Permitext may also use your account email to send occasional product updates, tips, and announcements. Account and session activity also support reports about sign-ups, sign-ins, active use, and returning users. Permitext does not sell personal information, show third-party advertising, or use your activity for cross-app advertising tracking.
Service providers
When you sign in, Clerk processes account- and device-linked session information, including device identifiers and technical metadata. Its session records can include approximate city and country derived from your IP address for account management and security. This is distinct from device GPS location and from Project addresses you enter. Clerk also uses account and session activity to provide sign-up, sign-in, active-user, and retention reports. These reports measure use of Permitext and do not add cross-app advertising tracking. Provider-managed logs and backups follow the applicable provider retention practices.
Permitext uses service providers only as needed to deliver the application. These currently
include Clerk for account authentication; Apple, Google, and Microsoft as sign-in providers;
Apple for in-app purchases; Stripe for web subscriptions; Vercel for application hosting,
private file storage, and privacy-focused web analytics; and Neon for hosted PostgreSQL storage.
Vercel Web Analytics does not use third-party cookies or persistent cross-site identifiers.
Permitext does not add analytics cookies, so it does not display an analytics-cookie banner.
When paid Research generation is enabled, Permitext also uses OpenAI for user-requested
Research responses. A Research request can send the question, recent conversation messages,
selected and Permitext-retrieved enacted evidence, current Project facts, established or
hypothetical conversation facts, structured evidence analysis, and any separately identified
supporting official-web context needed to generate and verify the answer. When selected official
evidence includes an image, that image is also sent to OpenAI for analysis. Private notes are not
included. Permitext uses the Responses API with store: false, so the generated
response is not stored for later API retrieval. OpenAI's default API policy states that API
data is not used to train its models unless the API account owner opts in, and that abuse-
monitoring logs may be retained for up to 30 days unless longer retention is legally required.
OpenAI's current policy also describes encrypted prompt-cache tensors that may remain in
GPU-local storage for up to 24 hours.
These controls and provider practices may change; see
OpenAI's current data-controls policy.
Each provider also processes information under its own terms and privacy practices.
Submitting a Research question sends the information described above to OpenAI to generate a response. You can review these details through the Research info icon before sending. You can use non-Research features without submitting a question. To stop future Research processing, stop submitting requests; you may also remove saved Research conversations or delete the Permitext account as described below.
For Research, Permitext grounds code conclusions in applicable enacted text and cites the sources used. Supporting sources are identified separately, and private notes are excluded from Research evidence sent for generation.
When Research requests an official-web search, Permitext attempts to remove obvious identifiers from the search query, including email addresses, phone numbers, explicitly labeled personal or client names, common-form street addresses and intersections, and BBL or block-and-lot identifiers, before limiting that search to configured official domains. This protection reduces identifying details but cannot guarantee that every possible identifier will be recognized. It is separate from the core Research generation described above, which may include current Project facts when you assign the conversation to a Project.
Local and hosted storage
Some reading preferences and offline material remain on your device or browser. When you sign in, eligible account and workspace information is stored in Permitext's hosted systems so it can synchronize across your devices. Private images, including legacy Workboard images, and generated files are accessed through authenticated Permitext endpoints rather than public file links.
Retention and deletion
Permitext retains account and workspace information while your account remains active or as needed to provide the service. You can delete your Permitext account from Settings in the iOS app or web application. Deletion removes the Permitext account and associated synchronized content and private files from active Permitext storage. Permitext may retain a minimal purchase-ownership record after deletion to prevent purchase replay or fraud and permit the same Apple account to restore a qualifying subscription purchase. Provider-managed logs or backups may persist temporarily according to provider retention schedules, and Apple or Stripe may retain transaction records independently where required for billing, fraud prevention, accounting, or legal obligations.
Permitext attempts to cancel an active Stripe subscription before deleting the account and stops deletion if Stripe cancellation cannot be confirmed. Permitext cannot cancel an Apple subscription; manage that subscription in App Store settings before deleting the account. When a Clerk-authenticated account is deleted from the web or iOS app, the client also asks Clerk to delete its Permitext sign-in identity.
| Information | Typical retention | Deletion behavior |
|---|---|---|
| Account and synchronized workspace content | While the Permitext account is active and as needed to provide the service | Removed from active Permitext storage through account deletion, subject to temporary backups and legal obligations |
| Research conversations and answers | Until you remove the conversation or delete the account | Removed from active Permitext storage with the selected conversation or account |
| OpenAI Research request data | Response storage is disabled; encrypted prompt-cache tensors may remain for up to 24 hours and default abuse-monitoring logs may remain for up to 30 days | Controlled by OpenAI's API retention policy; approved Zero Data Retention controls may differ |
| Purchase-ownership and fraud-prevention records | As needed to prevent replay or fraud and restore qualifying purchases | A minimal record may remain after account deletion |
Your choices
You can review or change available account and project information in Permitext, remove individual saved content, sign out, or delete your account. You can also ask for access, correction, or deletion assistance by contacting permitext@gmail.com. Applicable law may provide additional rights depending on where you live. You can turn optional product emails on or off from your Permitext account profile.
Security
Permitext uses HTTPS, server-side authorization checks, hashed hosted session credentials, and the iOS Keychain for native session storage. No internet service can guarantee absolute security, but Permitext limits access and data use to what is needed to provide and protect the application.
Children
Permitext Beta 1 is a professional code-research product for people who are at least 18 years old. It is not directed to children, and Permitext does not knowingly collect personal information from anyone under 18.
Changes and contact
This policy may be updated as Permitext changes. Material changes will be reflected by the effective date on this page. Questions can be sent to permitext@gmail.com.