Privacy Policy

Last updated: 2025-11-02

1. Scope

This policy covers the WordPress plugin, admin dashboard, and APIs that power content generation, billing, and site assessments.

2. Information We Collect

  • Account & License: name, email, credentials, site/domain, license keys, binding state, plan/quota.
  • Plugin & API Requests: topic/title, template settings (audience, country, CTA choice/manual snippet, image preferences), length/tone/language, keyword, image on/off flags, optional internal link URL, license + site identity, and a unique request ID to prevent duplicate processing.
  • Content & Logs: prompts, AI responses (text/image; image base64 is truncated), token usage, debug cURL, error events, site scan URLs/HTML snippets.
  • Usage & Device: IP address, browser/user agent, timestamps, performance metrics, and duplicate-request protection data.
  • Billing: plan code, voucher IDs, payment references, and callback tokens/IDs from payment providers.

3. How We Use Information

  • Operate the service (auth, license binding, quota enforcement, content generation, site assessments).
  • Debugging, quality, and analytics (request IDs, logs, token usage, prompt/response traces in admin).
  • Security (rate limiting, fraud/abuse detection, HMAC push to WordPress).
  • Billing and account administration.
  • Legal and compliance obligations.

4. Sharing

  • AI providers: OpenAI (text/images). Prompts and generation parameters may be sent; image b64 may be stored truncated.
  • Payments: Xendit (or equivalent) for invoices, callbacks, vouchers; payment references and webhook headers are shared as needed.
  • Infrastructure/analytics/email: vendors that support hosting, monitoring, notifications.
  • Legal/safety: when required by law or to protect rights and security.
  • Business transfers: in connection with mergers, acquisitions, or asset sales.

5. Cookies and Tracking

The admin dashboard may use cookies or similar technologies for sessions, security, and analytics. You can control cookies via browser settings; some features may not function without them.

6. Retention

Data is retained as long as needed to operate the service, enforce quotas, debug issues, meet legal obligations, and resolve disputes. Logs (including prompts/responses and site scan snippets) may be kept for a limited period for diagnostics.

7. Security

We use reasonable technical and organizational measures (request IDs, HMAC for WP push, rate limiting). No method is perfectly secure; notify us of suspected incidents.

8. Your Choices

  • Update account and site/license settings in the service.
  • Request deletion where applicable; some data may be retained as required by law or for audit/log integrity.
  • Control cookies in your browser; opt-out options may be available for non-essential communications.

9. International Transfers

Data may be processed in regions where we or our providers operate. We apply safeguards consistent with applicable law.

10. Children

The service is not directed to children under 16 (or the relevant age in your jurisdiction). Do not submit children’s data.

11. Changes

We may update this policy. Material changes will be communicated via the service or email where required. Continued use means you accept the updated policy.

12. Contact

For privacy questions or requests, contact us at articlesupport [at] drofu [dot] com.