Scope
1. Information we collect
We may collect the following categories of information:
- Account and profile information, such as name, email address, organization, authentication details, and role assignments.
- Billing and transaction information, such as subscription details, credit balances, credit grants, invoices, payment status, tax-related metadata, and order records processed through connected billing providers.
- Workspace and product-use information, such as prompts, articles, uploads, workflow definitions, comments, settings, sites, newsletters, campaigns, ContentVault records, and other content submitted to the service.
- Technical and device information, such as IP address, browser type, operating system, session identifiers, access timestamps, log records, and diagnostic metadata.
- Support, communication, and feedback information, such as messages submitted through contact forms, support requests, demos, surveys, and product feedback.
- Cookie, consent, and analytics information as described in the Cookie Policy.
We use application databases and storage systems, including Supabase/Postgres-backed infrastructure, to operate the product. Payment card details are handled by payment processors such as Stripe; we do not intentionally store full card numbers in the application.
2. How we use information
- Provide, maintain, secure, and support the service and its features.
- Authenticate users, manage workspaces, enforce permissions, and prevent fraud, abuse, or misuse.
- Process subscriptions, billing, procurement, and account administration.
- Operate AI, search, workflow, publishing, notification, commerce, and customer-facing features requested by users.
- Monitor reliability, troubleshoot incidents, measure performance, and improve product quality.
- Communicate service updates, transactional notices, support responses, and, where permitted, product or marketing messages.
- Comply with applicable law, legal process, and contractual obligations, and protect our rights, users, customers, and systems.
3. AI features, model providers, and tenant data
When you use AI-assisted features, selected prompts, content, files, metadata, and related context may be processed by model or search providers that you enable, that your workspace configures, or that we route to in order to provide the requested feature.
We may retain prompts, outputs, workflow activity, logs, and diagnostic metadata for the periods described in this policy so we can provide the service, troubleshoot incidents, investigate abuse, preserve account history, and improve product reliability.
We do not use Customer Content to train foundation models unless you expressly enable that feature or agree to it in writing. Model, search, and infrastructure providers may process Customer Content and AI requests as necessary to provide the features you request, subject to their applicable service terms and data processing commitments.
Ownership and permitted use of AI outputs are addressed in the Terms of Service. You remain responsible for reviewing AI outputs before publishing or relying on them, including for accuracy, rights, compliance, and suitability for your audience.
If you operate a tenant site or customer-facing experience through the service, you are responsible for the notices and lawful basis applicable to the information you collect from your own readers, customers, or end users. Depending on the feature and relationship, we may act as a service provider or processor on your behalf.
Published tenant content, public pages, public articles, custom domains, newsletters, and other customer-facing experiences may be visible to the public or to the audiences configured by the workspace operator.
4. How we share information
We may share information with:
- Service providers and subprocessors that help us deliver hosting, databases, authentication, billing, communications, observability, analytics, search, AI, storage, content delivery, and security functions.
- Workspace administrators or account owners, to the extent necessary to provide team administration, billing, security, moderation, and audit functionality.
- Connected integrations and third-party services when you choose to enable them or direct us to transmit data to them.
- Authorities, regulators, counterparties, and professional advisers when we believe disclosure is necessary to comply with law, legal process, enforce our agreements, or protect rights, safety, and security.
- A purchaser, successor, or transaction counterparty in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal conditions.
We may also use and disclose aggregated or de-identified information that does not reasonably identify an individual.
A current overview of subprocessor and provider categories is available on our Subprocessors page. Data processing terms, including any DPA, Standard Contractual Clauses, data residency commitments, or custom retention terms, are available by written agreement or request to the privacy contact below.
5. Cookies, analytics, and similar technologies
We use cookies and similar technologies to keep the service working, remember settings, maintain sessions, prevent abuse, understand product usage, and improve the experience. Some features may rely on third-party analytics or embedded services.
See the Cookie Policy for more detail about the types of cookies we use and your choices.
6. Retention
We retain information for as long as reasonably necessary to provide the service, maintain security and records, resolve disputes, comply with law, and enforce agreements. Retention periods vary depending on the data category, feature configuration, workspace settings, and legal obligations.
7. Security
We use administrative, technical, and organizational measures intended to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No internet-based service or storage system is guaranteed to be perfectly secure, and you should also protect your credentials, devices, and workspace access.
8. Your choices and privacy rights
Depending on your location and role, you may have rights to request access to, correction of, deletion of, restriction of, portability of, or objection to certain processing of personal information, subject to applicable law and verification requirements.
- You may update some account information directly in the service.
- You may opt out of non-essential marketing messages using the unsubscribe instructions in those messages.
- You may manage non-essential cookies using available consent tools or your browser settings.
- You may submit privacy requests by contacting us at the email below or by using the data deletion page where available. We may need to verify your identity or authority before completing a request.
California residents and other users with applicable privacy rights may have additional rights under local law. We do not treat privacy request rights as absolute and may deny or limit requests where the law permits or requires us to do so.
9. International data handling
The service may be hosted, supported, or processed in multiple countries. By using the service, you understand that information may be transferred to and processed in locations that may have different data-protection laws than the place where you reside.
10. Children
The service is intended for business, editorial, and professional use and is not directed to children. If you believe a child has provided personal information to us without appropriate consent, contact us and we will investigate and take appropriate action.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date on this page and may provide additional notice where required by law or where we determine that a material change warrants it.
12. Contact
Privacy questions and requests may be sent to [email protected].