Política de Privacidad
Última actualización: July 14, 2026
Privacy Policy
This Privacy Policy describes how DailyBlogPost collects, uses, and protects your personal information when you use dailyblogpost.app. The data controller is Jsampedro, registered under number 939 617 866 00016, 119 rue Michel Teule, 34080 Montpellier, France.
Information We Collect
Account data — when you sign up (Google sign-in or email magic link): your email address, name, and profile picture. We never store passwords: authentication is passwordless.
Workspace content — the data you provide to generate content: your site details, brand profile, business information, keywords, and the articles generated for you.
Integration credentials — API keys and tokens you connect (WordPress, Shopify, Webflow, Google Search Console). These are stored encrypted (AES-256-GCM) and are never readable in plain text at rest.
Billing data — handled by our payment processors (Stripe). We never store your card details; we keep only subscription status, invoices and credit history.
Free-tools email — when you use our free tools (headline analyzer, topic generator, etc.), we ask for your email address to display your results, along with the tool used and, if the visit came from a campaign link, its parameters (utm tags, click identifiers). Receiving marketing emails requires a separate, explicit checkbox: if you leave it unchecked, your email is never used for commercial communication.
Campaign attribution — if you arrive on our site through a campaign link (utm parameters, advertising click identifiers), we store those parameters in a first-party cookie and attach them to your account when you sign up. This tells us which channel brought you; it involves no third-party tracking of your browsing.
Technical data — server logs required to operate and secure the service. We do not build advertising profiles.
How We Use Your Information
- Provide the service: generate, optimize and publish your content (legal basis: contract)
- Process payments and maintain billing records (contract, legal obligation)
- Send transactional emails — sign-in links, notifications, reports (contract)
- Send SEO tips and product news to free-tools users who explicitly opted in (consent — withdrawable at any time via the unsubscribe link)
- Measure which acquisition channel brought a signup, via first-party campaign parameters (legitimate interest — no third-party profiling)
- Secure the service and prevent abuse (legitimate interest)
- Measure aggregate site audience (legitimate interest — see Cookie Policy)
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Application & database hosting | European Union (Finland/Germany) |
| Cloudflare R2 | Image storage | EU jurisdiction available |
| Google (Sign-In, Gemini AI, Search Console API) | Authentication, content generation, SEO metrics | USA * |
| Stripe | Payments | USA/EU * |
| Resend | Transactional email delivery | USA * |
| Inngest | Background job orchestration | USA * |
| DataForSEO, Tavily | Keyword & web research | USA * |
| Meta (Pixel — only with your consent, when we run ad campaigns) | Advertising measurement | USA * |
| Pexels | Stock image search (queries derived from your content) | USA * |
| Logo.dev | Logo retrieval from your website domain | USA * |
| GitHub | Code hosting & build infrastructure | USA * |
* Transfers outside the EU are covered by the providers' Standard Contractual Clauses and/or EU-US Data Privacy Framework certifications.
Content you submit for generation (brand and business information) is processed by Google Gemini to produce your articles. It is not used to train models per Google Cloud's API terms.
Data Retention
- Account and workspace data: for the life of your account. You can delete your account yourself from the account page; deletion is effective immediately.
- Free-tools emails: at most 3 years after collection, or immediately upon unsubscribe/deletion request.
- Invoices and billing records: 10 years (legal obligation).
- Database backups: rolling retention (14 days), then destroyed.
Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to processing of, and port your personal data. Most of these are self-service: your profile and content are editable in the app, and account deletion is available on your account page. For anything else, contact us — we respond within 30 days. You may lodge a complaint with your supervisory authority (in France: the CNIL, cnil.fr).
Security
Data in transit is encrypted (TLS). Integration credentials are encrypted at rest (AES-256-GCM). Hosting and backups are located in the European Union. Administrative actions on user data are logged.
Changes to This Policy
We will post any changes on this page and update the date above. Material changes will be notified in the app or by email.
Contact
Privacy questions and rights requests: privacy@dailyblogpost.app