1. Data collection and processing#
We collect only the data necessary to run the service:
- Email (for authentication and contact)
- IP address (for abuse protection)
- Generation statistics (to improve the service)
Legal basis for processing: performance of our contract with you (providing the service and handling payment), our legitimate interest (protection against abuse, spam and fraud), and compliance with legal obligations (tax and accounting records — held by Creem as the seller of record).
How long we keep data: account data and the texts you save remain for as long as the account exists; once you delete the account they are permanently removed. Technical anti-abuse records (registration IP addresses) are pruned automatically once they are no longer useful. Payment records are retained by Creem for as long as tax law requires.
2. Third parties we share data with#
We do not sell your data or share it for third-party advertising or marketing. To run the service itself, we use the following providers — each receives only what its function needs:
- Armitage Labs OÜ (Creem) — payment processing (Merchant of Record); receives your email at checkout.
- Google (Gemini API) — text generation; receives the text of your generation requests. We use the paid tier of the Gemini API: under Google's terms for Paid Services, Google does not use your prompts or responses to improve its products, and does not train its models on them. The data is processed under Google's Data Processing Addendum, with Google acting as a data processor.
- Google (Sign in with Google) — if you use the "Continue with Google" button, Google verifies your identity and passes us your email address. This is separate from generation; you can register with an ordinary email and password instead.
- Brevo — transactional email (signup confirmation, password reset); receives your email.
- DataForSEO — Google ranking checks (SEO-monitoring feature); receives the URLs you provide.
- Unsplash / Openverse — photo search for inserting into content; receives your search queries.
- Railway — application and database hosting; technically stores all service data, including your account and saved texts.
- Cloudflare — anonymous site-traffic analytics; sets no cookies and receives no personal data, always on.
- Google Analytics — traffic-source analytics; only enabled if you click "Accept" on the cookie banner, and receives de-identified data about your visit (pages viewed, referring source).
Transfers outside the EEA. The service operator is based in Ukraine, and the providers listed above are in the EU and the US. Payments are processed by Armitage Labs OÜ (Creem), registered in Estonia — that is, within the European Economic Area, so payment data is not transferred outside it. For providers located outside the EEA (notably in the US), we rely on the European Commission's Standard Contractual Clauses (SCCs) within the data processing agreements (DPAs) we hold with them. You can request a copy of the applicable safeguards at the contact address in section 6.
All data is stored on secure servers. Your rights over that data are set out in section 5.
WordPress credentials. If you use direct publishing, your site address and username are kept in your browser and the application password only for the session. They pass through our server solely at the moment of publishing, in order to reach your site, and are never written to our database. Logging out clears them from your browser.
3. Cookies#
We use only strictly necessary (functional) cookies — to maintain your login session and to protect the free plan from abuse (multiple accounts from one device). No analytics or advertising cookies are used — we do not track your activity on other sites.
4. AI and your content#
Content you paste only for a one-off analysis (the SEO analyzer) is not stored beyond that request. Text you explicitly save to your History remains on our servers until you delete it yourself. We never use your content to train our own models. Generation requests are processed by Google's Gemini API on the paid tier — Google does not use them to train its models (see section 2 above).
5. Your rights over your data#
If you are in the EU, the UK or Switzerland, the GDPR (and equivalent laws) give you the following rights:
- Access — obtain a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — you can delete your account and all associated data yourself, instantly: Settings → Delete account. This cannot be undone.
- Portability — receive your data in a structured, machine-readable format.
- Restriction and objection — restrict or object to processing, including processing based on our legitimate interest.
- Withdrawal of consent — where processing is based on consent, withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.
Deleting your account is self-serve in Settings. To exercise any other right, contact us (see section 6) — we respond within 30 days.
You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
The data controller is the service operator named at the bottom of this document.
6. Contacts#
For privacy matters, email [email protected] or use the "Need help?" button.
Updated: August 2026
Service operator: Oleg Ivachevskyi (Ukraine). Contact: [email protected].