ContentPlus.ai

Legal

Privacy Policy

Effective 30 August 2026

This explains what ContentPlus.ai collects, why, who else sees it, and what you can require of us.

The short version: we hold what the product needs to write your articles, we run no advertising or analytics trackers of any kind, and we do not sell anything about you. The long version is below, and it is specific about where the limits of that are.

01

Scope

This policy covers the ContentPlus.ai web application, the emails we send, and the free website analysis available before you have an account. It does not cover any third-party site you reach from ours, or the website we analyse on your behalf.

ContentPlus is the controller of the personal data described here. For the business data inside your workspace (your answers, your photographs, your drafts) we act on your instructions.

02

Account data

Your name, email address, profile picture if you upload one, and the role you hold in each workspace. Optionally, the author details you add for your byline: a short bio and your X and LinkedIn addresses. Those three are optional, and an article whose author has filled in none of them reads exactly as it did before.

Your password is never stored. We keep a scrypt hash of it with a per-account salt, and the original is discarded the moment it is hashed. Nobody at ContentPlus can read your password. If you sign in with Google or GitHub instead, we store the tokens those providers issue, encrypted at rest with AES-256-GCM.

03

Business and workspace data

  • The website address you give us, and what we read from its public pages: what the business does, who it serves, where it operates, and the services it lists.
  • The business context built from that: goals, audience, services, locations and tone, together with any corrections you make to it.
  • Topics and opportunities, their scores, and the ones you chose.
  • Your answers to the questions we ask, typed or dictated, which are the part of the product that is genuinely yours.
  • Article drafts, briefs, FAQs, calls to action and report cards, and the record of who was assigned what.
  • Workspace membership: who is in a workspace, at what role, who invited them, and the email address an invitation was sent to.
04

Photographs and uploads

The Service stores the job and project photographs you upload, your business logo, and your profile picture. Files are held in our storage bucket and served through an endpoint that checks, on every request, that the person asking is in the workspace the file belongs to. Access is decided by the record, never by knowing the URL.

Photographs are not sent to any AI model. They are stored, placed into your article, and exported with it. The caption written next to one comes from what you told us it shows, not from the picture itself.

Upload photographs of your work, not of people. Please do not upload identifiable individuals without their consent, identity or financial documents, or anything else that does not belong in a record of a job you have done. If such a photograph reaches us, tell us and we will delete it.

05

Website analysis, before you have an account

If you submit a website address on our home page, we fetch a small number of its public pages and keep what the analysis found, together with the draft workspace built from it, so that the questions you answer next are not lost when you create an account. If you never create one, that draft is an orphan record we delete on request and prune over time.

That fetch is limited by scheme and refuses private network addresses and untrusted redirects. We read pages; we do not sign in anywhere, and we do not fetch anything a visitor could not.

06

Payment data

Payments are processed by Stripe. We never receive or store your card number. What we hold is the Stripe customer identifier attached to your account and the state of your subscription: which plan, which billing cycle, whether it is active, and when the period ends. Your name, billing address and card details are held by Stripe under their own privacy policy.

07

Technical data

  • A session cookie set when you sign in. It holds a signed reference to your session and nothing else: no tracking identifier and no profile. It is http-only, same-site, marked secure over HTTPS, and expires after 30 days.
  • The IP address and browser user-agent recorded with a session, kept by our authentication layer so a sign-in can be told apart from another and a session can be revoked. They live as long as the session does.
  • An IP-derived key used to rate-limit the free analysis and sign-in attempts, so one visitor cannot exhaust the Service for everyone. Honest detail: this is written to a row in our database, not merely held in memory. Rows are counted against a one-minute window and pruned, typically within the hour, and never kept as a history of who looked at what.
  • Ordinary server and platform logs from our host, which include IP addresses and request paths and are retained on their standard schedule.

Dictation, where your browser offers it, uses the browser’s own speech recognition. The audio never reaches us. We receive the text it produces, the same as if you had typed it. Whether your browser sends that audio to its own vendor is a matter between you and your browser.

08

What we do not do

There is no advertising pixel, no analytics script and no third-party tracker anywhere on ContentPlus.ai. No Meta Pixel, no Google Analytics, no session recorder. The only cookie we set is the one that signs you in, which is why you are not asked to dismiss a cookie banner.

We do not sell your personal data or share it for cross-context behavioural advertising. We do not build advertising profiles, and we do not use your content to train models of our own. Our AI providers state that content submitted through their APIs is not used to train their models; their terms govern that, and we have linked them below so you can check rather than take our word for it.

If we ever add analytics, it will be described here before it runs, and the date at the top of this page will move.

09

Why we process it, and on what basis

PurposeDataLawful basis
Providing the ServiceAccount, workspace, business context, answers, photographs, draftsPerformance of a contract
Writing your articlesBusiness context, your answers and the text read from your website, sent to our AI sub-processorsPerformance of a contract
Website analysis before signupThe address you submit and its public page contentLegitimate interests
Billing and renewalsEmail, Stripe customer id, subscription statePerformance of a contract, legal obligation
Invitations and service emailNames and email addresses of the inviter and the invitedPerformance of a contract, legitimate interests
Rate limiting and abuse preventionIP-derived key, request countsLegitimate interests
Account securityPassword hash, session cookie, session IP and user-agentLegitimate interests, legal obligation
SupportWhatever you include in an email to usLegitimate interests

We do not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 UK/EU GDPR. Scoring a content topic is a judgement about a topic, not about a person.

10

What the AI models see

Producing an article means sending text to a model. What goes is the business context, the topic, and your answers: the material you gave us for exactly this purpose. What does not go is your photographs, your password, your payment details, or the email addresses and names of your team.

ProviderWhat it receivesWhen
Anthropic (Claude)Website text, business context, topics, your answers, draft textAnalysis, planning and writing, on every article
OpenAIThe finished draft text, for an independent grade of itOnly where the report card is enabled; a model grading its own writing marks its own homework

Both act as our processors for this purpose and are bound by their API terms, under which submitted content is not used to train their models.

11

Who else handles it

Sub-processorWhat for
SupabaseThe database, and the bucket your photographs live in
CloudflareHosting and delivery of the application
StripePayments, card details, invoices and renewals
PostmarkInvitation and welcome emails
Anthropic, OpenAIGenerating and grading your drafts

Each is engaged under terms that hold them to processing the data only to provide their service to us. We will update this list before adding another.

12

International transfers

Our sub-processors operate infrastructure outside the United Kingdom and the European Economic Area, including in the United States. Where personal data is transferred outside the UK/EEA, we rely on the transfer mechanisms those providers offer, including the standard contractual clauses and the UK international data transfer addendum.

13

How long we keep it

  • Account, workspace, draft and article data: for as long as your account exists, and until you ask us to delete it.
  • Photographs and uploads: until you delete them, or until the workspace they belong to is deleted.
  • Sessions: 30 days, or until you sign out.
  • Rate-limit rows: minutes to about an hour.
  • Website analyses that never became an account: deleted on request, and pruned as housekeeping.
  • Billing records: kept for as long as tax and accounting law requires, which is longer than the account itself.
14

Security, and an honest note about where we are

Passwords are hashed with scrypt and per-account salts. Session cookies are signed, http-only and same-site, and secure in production. OAuth tokens are encrypted at rest. Traffic is served over TLS. Sensitive routes are rate-limited. Every request for a file or a workspace record is authorised against the record itself, so knowing an identifier is never enough to read someone else’s work.

Because it matters at this stage: ContentPlus is a young product. Your data sits in a managed Postgres database and a managed storage bucket, which is a real foundation, but we hold no security certification, we have no formal third-party audit to point you at, and we would rather say so than imply one. Keep your own copies of work you have published.

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.

15

Your rights

Subject to the conditions in the data protection law that applies to you, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw any consent you have given. If you are in the UK or the EEA those rights come from the UK/EU GDPR. If you are in a US state with a consumer privacy law (Utah and California among them) you have comparable rights of access, deletion and appeal, and we do not sell or share your data in the sense those laws use.

Some of this you can do yourself: your profile, business context, topics, drafts and photographs are editable and deletable in the app, and articles can be exported. For anything else, such as a full export, an account deletion, or a question about what we hold, emailcontentplussupport@gmail.com and we will do it. We will respond within one month.

There is no self-service form for this yet. It is a person reading a message, and we would rather say that than pretend otherwise. We do not charge for these requests.

If you are unhappy with how we have handled your data you may complain to your supervisory authority. In the UK that is the Information Commissioner’s Office at ico.org.uk, and in the US it is your state attorney general. We would prefer you told us first.

16

Children

The Service is not directed at anyone under 18 and we do not knowingly collect their personal data. If you believe a child’s data has reached us, tell us and we will delete it.

17

Changes

If what the product does changes, this policy changes with it and the date at the top moves. Where a change materially affects your rights, we will give you notice before it takes effect.

18

Contact

You can reach ContentPlus at contentplussupport@gmail.com. Data protection enquiries go to the same address. We have no separate data protection officer, and we are not required to appoint one.