Privacy

What happens to what you type.

Last updated 3 October 2026

The short version

  • No accounts, no sign-up, and no cookies on the public pages.
  • What you type goes to our server and on to Anthropic's Claude API, which writes the result. We don't save it and we don't log it.
  • Anthropic's published policy is to delete API inputs and outputs within 30 days (longer only for content flagged under its Usage Policy, or where the law requires it) and not to train on them by default.
  • We count visits and translations, never what you wrote. Your IP address sits in our rate limiter for up to about 2 days; the visitor count keeps only a hash of it, for 9 days.
  • Vercel Web Analytics and Speed Insights measure page views and page speed, without cookies.
  • Questions: privacy@genslator.com

What you type, and where it goes

  • Genslate It (the home page): your browser sends a POST request to /api/genslate with your message (up to 1,000 characters), who it's for (the age, birth year, date of birth or generation you entered), the relationship if you picked one, the intensity, Today or Back in My Day, and any follow-up adjustment.
  • Decode This: your browser sends a POST request to /api/decode with the text you pasted and, if you filled them in, the “who said it” and “explain it for” fields.
  • Your text travels in the body of the request, never in the page address.
  • Our server checks the request, then sends your text, with our instructions, to Anthropic's Claude API, which writes the rewrite or the explanation. The result comes straight back to your browser.
  • A birth year or date of birth is turned into an age on our server. Only that age goes to Anthropic; the date itself is not passed on or kept.

The AI provider: Anthropic

Anthropic, PBC runs the model that reads your text and writes the result. Its published policy for API customers is to delete inputs and outputs within 30 days, except content its automated safety systems flag under its Usage Policy (kept for up to 2 years) or where the law requires longer. By default it does not use API inputs or outputs to train its models.

Anthropic's own pages: how long it keeps API data and whether it trains on it.

What we keep, and for how long

Nothing you type. Our code doesn't write your message or its result to a database, a file or a log. What it does keep, in an Upstash Redis database:

  • Usage totals. For each day, the number of requests and AI tokens used, per tool and model. Totals only: no text, no IP address. Kept for 400 days.
  • Spend totals. The running cost of the current hour and day, which enforce our daily spending ceiling. Deleted after 3 hours and 3 days.
  • Rate limits. So no single address can overuse the service (15 requests a minute and 200 a day for each tool), your IP address is part of a short-lived counter. The counters delete themselves: after about 2 minutes for the per-minute limit, and about 2 days for the daily one.
  • Visitor count. Each full page load makes one request to /api/beacon. We store a salted SHA-256 hash of your IP address, not the address itself, in that day's list, and add one to that day's page-view count. Both are deleted after 9 days. They give us one figure: unique visitors per day.

Genslator runs on Vercel. As with any web host, Vercel receives your IP address with each request, and it keeps a log of requests to our server (time, path, status code, browser) for 1 hour on our plan. The log records the request, not its body, and our code never writes your message to it. See Vercel's privacy notice.

Analytics

Vercel Web Analytics counts page views. According to Vercel, each one records the page address, the referring site, filtered query parameters, approximate location (country, region, city), operating system, browser, device type and time. It uses no cookies: visitors are told apart by a hash of the request, which Vercel discards after 24 hours.

We also send it a few events about how the tools are used: the settings you chose (how you picked the person, intensity, mode, relationship, adjustment), the age profile of a result (for example “Age 14 · Teen”), whether a warning was shown, a speed bucket (fast, normal or slow), error codes, whether you filled in “who said it” and how many phrases a decode explained, and when you copy, share (and where to), regenerate, open or export a share card, or use “Reply in their language”. These never include your message, the result or a date of birth.

Vercel Speed Insights measures how fast pages load. According to Vercel, each measurement records the page, network speed, browser, device type, operating system, country and the timings, and is not tied to any individual visitor or IP address.

Both load from genslator.com itself. The site has no ads and no third-party trackers. If you block analytics, every feature still works.

Cookies and browser storage

  • The public pages set no cookies.
  • The admin area (/admin) is for the site owner. Signing in there sets sign-in cookies; nothing else on the site does.
  • “Reply in their language” on Decode passes the decoded meaning (and “who said it”, if you filled it in) to the home page through your browser's sessionStorage. The home page reads it once and deletes it.

Sharing

  • Share cards are drawn in your browser. The image is not uploaded to us.
  • The WhatsApp, X, Facebook and text-message buttons open that service with your result in the link. Nothing reaches them until you click; after that, their privacy policies apply.
  • Copy and your device's share sheet hand the text to your device, not to us.

Your choices

Nothing we keep is tied to a name, an email address or an account, so there is no profile of you to look up, export or delete. The only records that involve your IP address delete themselves within 9 days. To ask anything, or to have something removed sooner, email privacy@genslator.com.

Contact

privacy@genslator.com for privacy questions, and for anything else about Genslator.

Changes

If what the site collects changes, this page changes with it and the date at the top moves.