# Privacy

What Writavo holds, why it holds it, who else processes it, how long it is kept, and how to have it erased. This marketing site sets no cookies and runs no tracking script.

Effective 25 August 2026.

## The short version

Writavo holds the account details you give us, the content and configuration of the Sites you
create, and the usage records we need in order to bill you and to stop an autonomous pipeline
from spending without limit. We do not sell any of it, we do not build advertising profiles, and
we do not use one customer's content to train anything for another customer.

## What this site collects

This marketing site, `writavo.com`, sets **no cookies**, runs **no advertising or analytics
tags**, and requires no account to read. Pages are server-rendered and ship no tracking script.

Two things are recorded when you use it:

- **Request logs.** Method, path, referring host, a shortened user agent, the client IP and the
  country, written to our application log. Query strings, request bodies and any header that can
  carry a token are deliberately never logged.
- **Error reports.** If a page throws, an error report goes to Sentry with the user's email, IP
  address and username stripped before it leaves the browser.

If you join the waitlist we store the email address you give us, the referral parameters that
brought you here, and a **SHA-256 hash of your IP address**. The raw address is never stored. You
can have the row deleted by emailing [support@writavo.com](mailto:support@writavo.com).

## What the product collects

| Category | What it is | Why we hold it |
|---|---|---|
| Account | Email address, name, password hash, the organisations and Sites you belong to | To sign you in and to decide what you may do |
| Site configuration | Domain, niche, prompts, schedule, authors, delivery settings | It is the product |
| Content | Articles, media, taxonomy, revisions | It is your content, held for you |
| Usage | Per-Site counts of API requests, generated articles, storage and bandwidth | Billing, and the spend caps that stop a runaway pipeline |
| Audit | Who did what, when, in an append-only log | Security, and answering "who changed this" |
| Integrations | Search Console OAuth tokens, CMS push credentials, connected mailbox credentials | Only the connections you explicitly authorise |

Visitors to a blog you publish through Writavo are counted in aggregate for your analytics. We do
not set a cross-site identifier on them, and engagement writes are attributed by a hash rather
than by a stored visitor identity.

## Who else processes it

Writavo runs on third-party infrastructure. These are the processors that can hold customer data,
and what each one is for.

| Processor | Purpose |
|---|---|
| Supabase | The application database, authentication and file storage |
| Vercel | Hosting for the dashboard, the marketing site and the public blog gateway |
| Cloudflare | The API gateway, DNS, and SSL for customer custom domains |
| Stripe | Subscriptions and payment. Card details go to Stripe and never touch our systems |
| Sentry | Error reporting, with personal fields scrubbed before send |
| DeepSeek | The language model behind article generation |
| DataForSEO | Keyword, competitor and backlink data |
| Image generation providers | Article illustrations |

We hold the account with every one of these. There is no step where you hand us a vendor key, and
no step where a vendor bills you directly.

## What we do not do

- We do not sell personal data, and we never have.
- We do not use your content to train a model for anyone else.
- We do not send marketing email to addresses we obtained anywhere other than from you.
- We do not run advertising trackers on this site or on a blog we publish for you.

## Retention

Content and configuration are kept for as long as your organisation exists. Append-only ledgers,
the audit log and the API call record, are kept on a fixed retention window and then removed by a
scheduled job rather than accumulating forever.

Deleting your organisation deletes its Sites, its content and its memberships. Some records are
kept afterwards where we are required to keep them, principally billing records.

## Your rights

Email [support@writavo.com](mailto:support@writavo.com) to ask for a copy of what we hold about you, to
correct it, or to have it erased. We will respond within 30 days.

Erasure of an outreach contact is a first-class operation in the product rather than a support
ticket: a Site owner can erase a contact and every message record attached to it directly.

## Children

Writavo is a business product and is not directed at anyone under 16. We do not knowingly hold
data about children. If you believe we have, tell us and we will remove it.

## Changes

If this statement changes materially we will update the effective date above and tell account
holders by email before the change takes effect. This page is the current version.

## Contact

Privacy questions: [support@writavo.com](mailto:support@writavo.com). Security reports:
[security@writavo.com](mailto:security@writavo.com).
