Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains how DisputeX AI collects, uses, processes, and protects your personal information in compliance with GDPR and CCPA guidelines.
1Information We Collect
We collect the following categories of information to provide and improve our service:
- Account Info: Full name, email address, and account status credentials when you sign up.
- Dispute Content: Recipient names, addresses, dispute types, state of residence, and the description of the situation you input to generate letters.
- Payment Info via Paddle: All transactions are processed securely via Paddle, our Merchant of Record. We do not store or process credit card numbers directly.
- Usage Data: Pages visited, interaction timestamps, referral sources, and device specifications.
- Cookies: Session identification cookies to keep you securely logged into your dashboard.
2How We Use It
We process your personal data for the following legitimate purposes:
- Generating legally-structured dispute letters using our AI templates.
- Processing paid subscriptions and handling billing transactions via Paddle.
- Sending automated email reminders about upcoming dispute tracking deadlines.
- Providing technical customer support.
3AI Processing
To generate personalized, legally-sound dispute letters, your input details (the dispute type and situation description) are processed by OpenAI APIs. OpenAI does not use data submitted via API endpoints to train their language models, ensuring that your private dispute details remain confidential and secure.
4Data Storage
All information collected by DisputeX AI is hosted securely in Supabase databases. We use robust industry-standard AES-256 encryption for data at rest and TLS for data in transit. Supabase Row Level Security (RLS) policies are active on all tables, ensuring only verified account holders can ever query or modify their own letters and dispute history.
5Third-Party Services
To provide high-quality services, we share necessary data fragments with the following compliant providers:
| Service | Purpose | Privacy Link |
|---|---|---|
| Supabase | Database hosting & secure storage with Row Level Security | View Policy → |
| OpenAI | AI processing to generate legally-grounded dispute letters | View Policy → |
| Paddle | Merchant of Record for secure billing and subscription management | View Policy → |
| Vercel | Application hosting and CDN performance optimization | View Policy → |
| Resend | Transactional email delivery for reminders and signup verification | View Policy → |
6Your Rights (GDPR/CCPA)
Regardless of your geographical location, DisputeX AI grants all users standard rights over their personal data:
- Access: You can request a copy of all personal details and letters stored in your account.
- Delete: You can request immediate, permanent deletion of your profile, billing history, and letters.
- Export: You can export your generated letters in PDF and plain-text formats at any time.
7Contact Information
For any data protection requests, security queries, or to exercise your GDPR/CCPA rights, please contact us:
Email: privacy@disputeletterai.com