Privacy Policy

Privacy Policy

Last updated: 18 April 2026

Your privacy matters. This Policy explains what personal data Tesify collects, for what purposes, how we protect it, and what your rights are when you use Tesify. Questions? Contact us at privacy@tesify.app.

1. Controller

jecrs687, a company registered in Malta, is the data controller for all personal data processed through Tesify. Contact: privacy@tesify.app.

2. Data We Collect

  • Account data: name, email address, password (hashed), university and field of study (optional)
  • User content: text, chapters, bibliography entries, and documents you create or upload within Tesify
  • Usage data: pages visited, features used, access timestamps, device type, and browser
  • Payment data: processed by Stripe (PCI-DSS compliant); we do not store card details
  • Cookies and identifiers: strictly necessary session cookies only; no advertising or tracking cookies

3. Purposes and Legal Bases

  • Performance of contract — providing the service, authentication, and payment processing
  • Legitimate interest — security, fraud prevention, and aggregate analytics to improve the service
  • Consent — marketing communications (you can withdraw at any time)
  • Legal obligation — tax compliance and responding to lawful authority requests

4. Your Content Belongs to You

All text and documents you create in Tesify remain your intellectual property. Your content is not used to train AI models and is not shared with third parties. You can export or delete your content at any time from your account settings.

5. Sub-processors

We use the following categories of sub-processors, all operating under GDPR-compliant Data Processing Agreements:

  • Cloud infrastructure: AWS / Cloudflare (hosting and delivery)
  • Payments: Stripe (payment processing)
  • Transactional email: sending account notifications
  • AI models: used to generate phrasing suggestions and integrity analysis

6. International Transfers

Sub-processors based outside the EEA use Standard Contractual Clauses approved by the European Commission, or an equivalent transfer mechanism, to ensure your data is protected to EU standards.

7. Retention

We retain your data for as long as your account is active. After account cancellation, your content is deleted within 30 days. Tax and billing records are retained for the period required by Maltese and applicable EU law.

8. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data (right to be forgotten)
  • Restrict processing in certain circumstances
  • Port your data to another service
  • Object to processing based on legitimate interest

To exercise any of these rights, contact privacy@tesify.app. The lead supervisory authority for jecrs687 is the Information and Data Protection Commissioner (IDPC) in Malta. UK-based users may also contact the Information Commissioner’s Office (ICO).

9. Security

Data in transit is protected by TLS 1.3 encryption. Data at rest is encrypted with AES-256. We apply multi-factor authentication, role-based access controls, and continuous security monitoring.

10. Policy Changes

We may update this Policy from time to time. Material changes will be communicated at least 14 days before taking effect.


See also: Terms and Conditions | Academic Integrity Policy

Contact: privacy@tesify.app