Privacy Policy

Effective August 4, 2026

PacePen paces writing into Google Docs, rewrites drafts so they read naturally, and turns uploads into study material. This page explains what we collect to do that, why, how it's stored, who we share it with, and the rights you have over it — including under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. Who operates PacePen

PacePen is operated by Byeongmin Choi, an individual developer (not a registered company). For any privacy question or request, contact byeongminchoi12@gmail.com. PacePen does not have a dedicated Data Protection Officer or EU/UK representative — as a solo, free-to-use project, requests are handled personally at that address, and we'll engage formal representation if our EU/UK usage ever requires it.

2. Information we collect

What we don't collect

  • No passwords — sign-in is handled entirely by Firebase Authentication and Google.
  • No payment information — PacePen is free, with no billing of any kind.
  • No advertising or cross-site tracking cookies, and no ad networks.
  • No precise location data.

Google account information

When you sign in with Google, we collect your email address to identify your account. Sign-in itself is handled by Firebase Authentication — we never see or store your Google password.

Google Drive & Docs content you select

To use Pace, you connect your Google account and pick a document through the Google file picker (or let PacePen create one for you). We request Google's drive.file scope, which means PacePen can only ever see the specific file(s) you selected or created through it — never the rest of your Drive. For that file, we access its ID, name, and content, and write to it on the schedule you set.

Content you provide directly

Text you paste into Pace or Polish, and files, notes, or voice recordings you upload to Study, are sent to our backend so we can generate the output you asked for (a paced document, rewrite suggestions and AI-detection scores, or study material and chat answers). Voice recordings are transcribed to text and are not used to identify you biometrically.

Technical & log data

Like virtually every web service, our hosting and infrastructure providers automatically log technical details of each request — IP address, browser/device type, and timestamp — for security, abuse prevention, and debugging. We don't combine this with advertising profiles, and we don't use it to track you across other sites.

3. How we use your information

  • Your email identifies your account and connects your work across sessions.
  • Drive/Docs access lets Pace write your paced content into the document you chose.
  • Pasted, uploaded, or recorded content is what Polish rewrites and scores, and what Study turns into notes, flashcards, quizzes, and chat answers.
  • Log data is used only for security, abuse prevention, and keeping the service running.

We don't collect anything beyond what each feature needs to run, and we don't use your content for advertising or sell it to data brokers.

AI model training: we use OpenAI's API and self-hosted/Hugging Face–backed models to power Polish and Study. Content sent to OpenAI's API is not used by OpenAI to train its models, per OpenAI's API data usage policy. We do not use your content to train our own models either.

4. Cookies & local storage

PacePen doesn't run analytics or advertising cookies. Firebase Authentication stores your sign-in state in your browser (local storage/IndexedDB, not a tracking cookie) so you stay signed in between visits — clearing your browser data or signing out removes it. We don't currently respond to browser "Do Not Track" signals, since no uniform standard exists for interpreting them, but this has no effect on you because we don't run tracking cookies in the first place.

5. Who we share data with

PacePen does not sell or rent your personal information, and does not share it for advertising. Data is shared only with the service providers needed to run the product, each acting as a data processor on our behalf:

ProviderPurposePrivacy policy
Google (Firebase Auth & Drive/Docs API)Sign-in, and reading/writing the document(s) you selectpolicies.google.com/privacy
OpenAIProcesses text/audio you submit for Polish's rewriting and Study's generation, transcription, and chatopenai.com/privacy
Hugging FaceRuns additional model inference for Polish's rewritinghuggingface.co/privacy
SupabaseDatabase (Postgres) that stores your account and document metadatasupabase.com/privacy
Trigger.devRuns Pace's scheduled background jobs (e.g. drip-writing to your Doc)trigger.dev/legal/privacy
VercelHosts PacePen's website and APIvercel.com/legal/privacy-policy

We may also disclose information if required by law, subpoena, or to protect the rights, safety, or property of PacePen or others. Otherwise, your data isn't shared with anyone else.

6. Data retention

  • Account data (email, connected Doc references, encrypted OAuth tokens): kept while your account is active, deleted within 30 days of a deletion request.
  • Content you submit to Polish/Study (text, uploads, recordings) and their generated output: stored so you can revisit your history in the app, deleted with your account or on request.
  • Server access/security logs: retained for roughly 30 days, then purged.

7. Your privacy rights

If you're in the EEA, UK, or Switzerland (GDPR)

We process your data under these legal bases: performance of a contract (running the features you use), legitimate interests (security and keeping the service reliable), and consent (where you grant Google Drive/Docs access via the OAuth screen). You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Lodge a complaint with your local data protection supervisory authority.

We respond to verified requests within 30 days. Contact us below to exercise any of these.

If you're a California resident (CCPA/CPRA)

PacePen does not sell or share your personal information, as those terms are defined by the CCPA — including for cross-context behavioral advertising. In the past 12 months we've collected the following categories of personal information, used only to provide the service:

CategoryExamplesCollected?
IdentifiersEmail address, IP addressYes
Customer records (Cal. Civ. Code § 1798.80(e))Email addressYes
Internet/network activityRequest logs, timestampsYes
Audio/visual informationVoice recordings you submit to Study for transcriptionOnly if you use that feature
InferencesAI-detection likelihood score generated for text you submit to PolishOnly if you use that feature
Protected classifications, biometric identifiers, commercial info, geolocation, professional/employment infoNo

As a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete personal information we've collected from you.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — moot here, since we don't do either.
  • Non-discrimination for exercising any of these rights.
  • Designate an authorized agent to make a request on your behalf.

To exercise these rights, email us below from the address on your account (so we can verify it's you). We'll respond within 45 days, with a one-time 45-day extension if needed for complex requests.

8. International data transfers

Our infrastructure providers (listed in §5) operate globally, so your data may be processed in the United States or other countries outside your own as part of normal internet routing and cloud hosting. Where required, we rely on those providers' standard contractual clauses or equivalent safeguards for cross-border transfers.

9. Children's privacy

PacePen is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. Before an account can be created — by email/password or by "Continue with Google" — you must affirmatively check a box confirming you're at least 13 years old and agreeing to this Privacy Policy and our Terms of Service; account creation is blocked until you do. If we ever learn that someone under 13 has given us personal information despite this, we will delete it and the associated account promptly — contact us below if you believe this has happened.

10. Security

  • All traffic to PacePen is encrypted in transit (HTTPS/TLS).
  • Your Google OAuth tokens are encrypted before they're stored, so they aren't held as plain text in our database.
  • Sign-in credentials are managed entirely by Firebase Authentication and Google — PacePen never collects or stores your Google password.
  • We use reasonable administrative and technical measures to protect your information, but no method of electronic storage or transmission is completely secure. If we experience a data breach affecting your information, we'll notify you as required by applicable law.

11. Changes to this policy

If this policy changes, we'll update the effective date above; for material changes, we'll make reasonable efforts to notify you (e.g. by email or an in-app notice). Continued use of PacePen after a change means you accept the updated policy.

12. Contact us / exercise your rights

For any privacy question, or to access, correct, delete, or export your data (GDPR), or to exercise your CCPA rights, email byeongminchoi12@gmail.com. You can also revoke PacePen's Google Drive access at any time from your Google Account permissions.

This policy is provided as general information about our data practices and is not a substitute for independent legal advice about your specific situation.

← Back to PacePenTerms of Service