Legal

Privacy Policy

Last updated: February 6, 2026

Data we collect

Account info (name, email, hashed password or Google OAuth identifier), business data you input (URL, industry, goals), payment metadata (Stripe — we never store full card numbers), generated content + AI usage logs, and analytics events.

How we use data

To provide the Service, generate AI content, run integrations (WordPress publishing, Stripe billing, ad CSV exports), improve product quality, and comply with legal obligations.

Sub-processors

Claude (Anthropic), Gemini (Google) and Sora (OpenAI) for AI; Stripe for payments; MongoDB Atlas for storage. They are bound by their own privacy commitments.

Sharing

We do not sell personal data. We share data only as needed with sub-processors above or to comply with law.

Retention

We keep your data while your account is active and up to 90 days after deletion (for backups and legal). Payment records are retained per applicable tax law.

Your rights

Access, correct, export and delete your data anytime by contacting us. EU/UK residents have GDPR rights; California residents have CCPA rights.

Security

Passwords are hashed with bcrypt. All data in transit uses TLS. Production data lives in encrypted MongoDB clusters. Application Passwords (WordPress) are stored as-is in your account; rotate them anytime.

Cookies

We use httpOnly cookies for auth (`access_token`, `session_token`). Optional analytics cookies are off by default.

Children

The Service is not directed to children under 16.

Contact

Data requests: contact us.

Made with Emergent