Legal
Privacy Policy
Last updated: 2026-05-24 · Effective: 2026-05-24
1. What we collect
When you sign up, we collect your email address. If you connect a WordPress site, we collect the site URL, username, and Application Password (encrypted at rest). We collect billing information via Stripe; we do not store your full card number on our servers.
We log aggregate usage metrics (articles generated, validator decisions, API response times) for service operation and improvement.
2. What we do with it
Email is used for transactional notices (welcome, password reset, trial expiration, billing). We do not send marketing email without opt-in.
WordPress credentials are used solely to publish articles to your site. They are never logged, never shared, and never used for any purpose other than publishing on your behalf.
Billing information is processed by Stripe under their privacy policy.
3. Third parties we share with
- Stripe — payment processing
- Resend — transactional email delivery
- Cloudflare — DNS, CDN, security headers
- OpenAI / Anthropic — large language model inference for article drafting and validation. Article inputs and outputs may be processed by these vendors as part of the pipeline. No personally identifying information is included in article payloads.
We do not sell your data to third parties. We do not use it for advertising.
4. Where it lives
Mastheads infrastructure is hosted in the European Union. Backups are encrypted at rest. Database access is restricted to a small number of authorized engineers.
5. Retention
Active accounts: data is retained as long as the account is active. Cancelled accounts: data is retained for 30 days, then permanently deleted. Aggregate usage metrics may be retained longer in anonymized form.
6. Your rights (GDPR)
If you are in the European Union, you have the right to access, correct, export, or delete your personal data. Email privacy@mastheads.app to exercise these rights. We respond within 30 days.
7. Cookies
We use strictly necessary cookies for authentication on the dashboard. We do not use third-party analytics, tracking pixels, or advertising cookies on this marketing site or the dashboard.
8. Contact
For privacy questions, email privacy@mastheads.app.