Privacy policy

Last updated: 2 July 2026

copyright.io is built for people whose privacy is already under attack. This policy says what we collect, why, who processes it, and how to make us delete it. It is written to be read, not skimmed past. copyright.io, operated from the United Kingdom, is the data controller.

1. What we collect

  • Account data — your email address and sign-in records.
  • Identity data you give us — the creator usernames, aliases, and public URLs you ask us to patrol.
  • Scan and takedown records — the public pages we matched, the notices we filed, and their outcomes.
  • Billing data — handled by Stripe. We never see or store your card number; we keep the subscription status and invoice references Stripe gives us.
  • Usage analytics — page views and funnel events via PostHog, used to understand what converts and what confuses.
  • Messages — anything you send through the contact or demo forms.

We do not require you to upload your content, and we do not store copies of it. We work from the identifiers you give us and from what is already publicly visible.

2. What we use it for

Running your patrols, filing your takedowns, sending your reports, billing your subscription, answering your messages, and improving the funnel. Legal bases under UK GDPR: performance of contract (the service itself), legitimate interests (analytics, fraud prevention), and consent where required.

3. The privacy gate

Scan results are visible only to the verified owner of the scanned identity — enforced at the database level, not just in the interface. Before verification, a scan shows counts only: no URLs, no thumbnails, no site names. This exists so the service cannot be used by stalkers or harassers to locate a creator’s content.

4. Who processes data for us

We use a small set of processors, each under data-processing terms:

  • Vercel — hosting
  • Supabase — database and authentication
  • Stripe — payments
  • Firecrawl — public-web scanning
  • Resend — transactional email (reports, sign-in)
  • PostHog — product analytics

Some of these are US companies; transfers rely on the UK extension to the EU–US Data Privacy Framework or standard contractual clauses. We do not sell personal data to anyone, and we never share the fact that a particular person uses this service.

5. Retention

Account, identity, and takedown records are kept while your account is open — takedown history is evidence, and it is yours. Close your account and we delete personal data within 30 days, except invoice records we must keep for tax law (6 years) and takedown notices already filed with third parties, which we cannot recall. Contact-form messages are deleted after 12 months.

6. Cookies

Essential cookies keep you signed in and hold your funnel progress. Analytics (PostHog) measures pages and funnel steps. We do not run advertising cookies or cross-site trackers.

7. Your rights

Under UK GDPR you can ask for access, correction, deletion, portability, or restriction of your data, and object to processing based on legitimate interests. Contact us and we will respond within one month. You can also complain to the ICO (ico.org.uk), though we would rather fix it first.

8. Changes

If this policy changes materially we will email account holders before the change takes effect. The date at the top always reflects the current version.

TermsPrivacyDMCA policyContact