HowISay Home

Privacy policy

Effective 16 September 2026.

HowISay is a Chrome extension that drafts replies, posts and emails in your own writing voice. This policy explains what it collects, where that goes, and how to delete it. Operator: Aryan Tah. Contact: aryan.tah7@gmail.com.

What HowISay collects

Your account. When you sign in with Google, HowISay receives your Google account ID, email address, name and profile picture, and stores them. It never receives your Google password, and it asks for no access to your Gmail messages, Drive or contacts.

Your voice setup. The short scenario answers you write during setup, any style notes you add, and the field and role you select. These are encrypted before they are stored.

What you ask for. When you request a draft, HowISay sends the message you are replying to, or the topic you type for a new post or email, along with the site, who it is for, and any tone or formality you pick. If that post contains pictures, up to two of them are shrunk in your browser and sent with the request, so the draft can respond to what the picture actually shows. Video, audio and animated images are not read. None of this is stored, with one exception below.

Your edits. When you choose a draft and change it before sending, HowISay stores the draft it produced, your final version, and a short excerpt of what you were replying to. This is how it learns your voice. It is encrypted before it is stored, and you can delete it at any time.

Usage records. Counts of drafts, token counts, cost, model name, response time and whether a request succeeded. These records contain no message text.

Anti-abuse records. So free usage cannot be farmed with throwaway accounts, HowISay stores one-way keyed hashes of your Google account ID, a random ID for your browser installation, and your network. Your network means your IPv4 address or the /64 block of your IPv6 address. Raw IP addresses are never stored, and the hashes cannot be reversed to an address, an email or an install without the server key.

Stored in your browser. Your sign-in token and the random installation ID, in extension storage. HowISay does not collect your browsing history.

What it does not collect

HowISay does not read pages in the background. Its content script runs only on LinkedIn, X, GitHub and Gmail, and it reads the text box you are working in, the message you are replying to, and any pictures in that message, only when you ask it for a draft. It does not collect your browsing history, does not track you across sites, and shows no ads.

Who it shares data with

WhoWhat they receiveWhy
GoogleYour sign-in requestTo verify who you are
OpenRouter, routed to OpenAIThe text you asked to be drafted or checked, and your voice examplesTo write drafts and to check content against the usage rules
RailwayAll stored data, as the host of the service and its databaseHosting

OpenRouter does not log prompts by default. OpenAI may retain API data for up to 30 days for abuse monitoring and does not use it to train its models.

HowISay does not sell your data, does not share it with advertisers, and does not use your writing to train any model.

Content checks

Text you write is checked against the usage rules before it is stored or used, which blocks slurs, hate, harassment and threats. Ordinary swearing is allowed. When something is blocked, HowISay logs the category only, never the text.

How it is protected

Your scenario answers, notes and edit history are encrypted at rest with AES-256-GCM. All traffic runs over HTTPS. Sign-in tokens are stored only as hashes, and sessions expire after 60 days.

How long it is kept

Your account data and voice profile are kept until you delete them. Usage records are kept for about two months. Anti-abuse hashes are kept for up to about two months, including after an account is deleted, which is what stops an account being deleted and made again to reset free limits. Deleted data may remain in database backups for a short period before those expire.

Your choices

  • Delete your voice profile on the HowISay settings page. This removes your scenario answers, notes and edit history.
  • Delete your whole account on the same page. This removes your account, profile, edit history and usage records.
  • Stop all collection by signing out or removing the extension.
  • Request a copy of your data, or ask any question about this policy, at aryan.tah7@gmail.com.

Depending on where you live, you may have additional rights to access, correct, export or delete your data, and to complain to a data protection authority.

Children

HowISay is not intended for children under 13, and it is not knowingly used to collect their data.

Changes

If this policy changes in a way that matters, the effective date above changes and the extension will say so. Continuing to use HowISay after that means the new policy applies.

Questions: aryan.tah7@gmail.com.