Privacy Policy

Public draft v1 · Last updated
Effective date: none — not yet in effect.

1. Document status

This is a public draft, not an effective Privacy Policy. It describes the product implementation reviewed on 24 September 2026 and includes unresolved information. Reading this page or using the service does not constitute acceptance of this draft. Publishing it does not establish legal compliance or limit any rights you have under applicable law.

2. Who we are and scope

SEO Article Studio is the public brand of a site-aware article production service. The verified legal operator, registered country and address, and privacy and legal contact details have not yet been supplied for this document. No legal entity is identified by this draft.

This draft concerns the marketing website and application. Third-party websites and services you use directly have their own policies.

3. Information processed

Account and profile

The service processes email addresses, account identifiers, authentication providers, profile information, registration and sign-in metadata, and display names or profile pictures supplied by users. Google sign-in may provide associated profile information. Authentication is handled through Supabase Auth.

Custom avatars use publicly accessible image URLs: someone with the URL may be able to retrieve the picture. Do not use a confidential image as an avatar. Article image files use a separate authenticated access route.

Workspace and website

Information includes workspace names, website addresses, domain and brand information, selected markets and languages, and setup details. At your request, the service retrieves public website pages for site context and internal-link targets. Retrieved data can include URLs, titles, summaries, verification results and scan status. This is distinct from information you submit directly.

Content and production

The service processes keywords, selected spreadsheet-import fields, instructions and conversations, Content Plans, drafts and edits, generated or uploaded images and metadata, research sources and excerpts, links, review issues, QA results, workflow status, errors and usage records. Keyword imports parse CSV/XLSX files into selected fields rather than saving the original upload as a stored document.

Billing and technical records

Billing records include plan information, Stripe customer and subscription references, subscription status and periods, cancellation flags, allowances, usage and payment-provider event references. The reviewed hosted-payment flow does not collect full card numbers or card security codes in the application.

Web-server logs record request metadata such as IP address, time, requested resource, response status, referrer and browser user-agent. Authentication and workflow systems also maintain events, errors and usage records.

5. Website content and AI processing

Submit only material you are entitled to use and have processed. Public availability does not remove personal-data or intellectual-property rights. Website context, research and instructions may be combined to generate and review articles.

Relevant instructions, website context, evidence and draft content may be sent to OpenAI’s API for text production, editing and review. Image generation sends an image brief and relevant context. DataForSEO receives keywords, search queries and settings, including queries derived from claims being researched; the reviewed transport does not send an entire article as a document.

OpenAI states that API data is not used for model training by default unless the customer opts in. This is not a zero-retention promise. The reviewed text requests disable response storage, but provider security and abuse-monitoring processing may still apply. This account’s data-sharing, regional and contractual settings are not confirmed here. See OpenAI’s API data controls.

Review generated content for accuracy, legality, rights and suitability before publication. QA indicators do not replace human judgment.

6. Payments

The reviewed integration uses Stripe-hosted Checkout and the billing portal. The application receives identifiers and subscription-state information rather than full payment-card details through that workflow. See Stripe’s Privacy Policy.

At the review date, the payment integration was restricted to test mode. This document does not announce live payment availability, and publishing it does not activate real charges.

7. Service providers

The reviewed integrations include:

  • Supabase — authentication, database services and avatar storage.
  • OpenAI — AI text and image processing.
  • DataForSEO — search and keyword research.
  • Stripe — hosted billing integration.
  • Google — optional Google sign-in. The marketing homepage also requests Google Fonts.

Hosting infrastructure operates the application, website, article-image files and logs. The contracting hosting provider, email delivery chain, provider regions and applicable agreements have not been fully verified for this draft.

8. International transfers

Provider processing may involve locations outside your country. Exact processing locations and applicable transfer safeguards have not been confirmed for this document. This draft does not assert EU-only hosting, an executed transfer agreement, or any particular international-transfer mechanism.

9. Retention and deletion

The reviewed implementation retains account, site, content, research, workflow and billing records without a comprehensive automatic age-based deletion schedule. Replacing a site archives its records; it does not erase them. Replacing an article image does not automatically erase the previous file. Clearing a browser draft does not remove server-side records.

A complete retention schedule, backup handling and manual deletion procedure have not been finalized. This draft makes no fixed-duration deletion promise.

10. Security and internal support

The reviewed code includes authenticated access, user/workspace/site-scoped queries, database access controls, protected article-media routes and role-limited administration. This is a description of the reviewed implementation, not a certification or guarantee of security. No storage or transmission method is completely secure.

Authorized administrators can view account, workspace, site, usage and article-status information for support and troubleshooting. Article bodies are not loaded by default. The implemented explicit article-body view is restricted to the owner role and records that access in an audit log. The support role has narrower access. Metadata and issue descriptions may still contain information about your work.

11. Privacy rights and contact

Depending on your location and applicable law, you may have rights to access, correct, erase or obtain a portable copy of information, restrict or object to processing, withdraw consent where processing relies on consent, and complain to a relevant supervisory authority. Applicable limitations and identity verification may apply.

Display names and avatars can be edited in account settings. The reviewed product does not offer full self-service account deletion or a full personal-data export.

A verified monitored privacy, legal or support contact has not yet been provided for this document. Consequently, this draft does not provide a functioning rights-request channel. This missing information is one reason it is not an effective final policy; it does not remove any statutory rights.

12. Cookies and similar technologies

The application uses authentication/session storage and cookies for authentication intent and active-site selection. Browser local storage also holds a theme preference, a conversation identifier and an unsent writing draft. Hosted payment and Google sign-in pages may use their own technologies.

No advertising or analytics integration was found in the inspected source and public HTML. This is not an exhaustive authenticated-runtime audit or a business-wide promise about every disclosure. Functional storage and external font requests still require applicable privacy and consent review. No new trackers or cookie banner are introduced by these draft pages.

13. Children

The service is intended for business and professional users, not children. The proposed Terms require users to be at least 18 and of legal majority. That proposal is not activated by publication of this draft.

14. Future versions

This document has no effective date. A finalized policy would need verified operator and contact information, completed operational and legal review, and its own effective and last-updated dates. The last-updated date shown above is a draft revision date only.