Privacy Policy
Last updated: 2026-09-15 · Effective: 2026-08-25
Who we are
Mastheads is operated by Palash Jain, 477, Garha Phatak, Jabalpur, India. For anything about personal data, write to privacy@mastheads.app. General questions go to hello@mastheads.app and billing to billing@mastheads.app. You can also call +91 9171725555.
For the data described in this policy - your account, your use of this site and of the dashboard - we are the controller. Where we process personal data that sits inside your own articles, sources, or connected sites, we act as your processor and you are the controller; our Data Processing Agreement governs that, not this policy.
1. What we collect
When you sign up, we collect your email address and, if you use social sign-in, the provider's account identifier. If you connect a site, we collect the site URL, the publishing username or account name, and the publishing credential (API key or application password, encrypted at rest). Billing details are collected by our payment processor; we do not store your full card number on our servers.
If a teammate invites you to their organization, we hold your email address, and any name or note recorded with the invite, from the moment the invite is created - which may be before you have an account. If you enable two-factor authentication or a passkey, we store the TOTP secret or passkey credential needed to verify your sign-in. If you take part in the partner programme, we collect your legal name, country, and entity type before we make a payout to you.
We log aggregate operational metrics (volume published, quality decisions, response times) to run and improve the service.
2. What we do with it
Email is used for transactional and service notices - sign-in and account security (including two-factor and passkey changes), service and billing messages, and the notifications you configure in your dashboard.
We send marketing email only to people who ticked a box asking for it. On the free site scan that tick is part of asking for the report, so requesting a scan signs you up for Mastheads news and offers as well. You can tell us to stop at any time - reply to any email, or write to hello@mastheads.app - and stopping never affects your report or your account.
Publishing credentials are used solely to publish content to your site. They are encrypted at rest, never logged in plaintext, never shared, and never used for any purpose other than publishing on your behalf.
If you commission content from a brief or supply reference links, we retrieve the content at those links so we can use it as editorial source material. Only submit links you are entitled to use, and do not include sensitive personal data in briefs or source material.
Billing information is processed by our payment processor (merchant of record) under its own privacy policy.
The free site scan. If you run a free scan from our website, we keep the address you gave us, the website you asked us to read, and the report we produced, so that we can send you the report and so you can ask us for it again. We use that address to send you the report. We only send you anything else if you separately ask us to, by ticking the box for it, and you can stop that at any time without losing the report. Ask us at privacy@mastheads.app and we will delete the address and the report.
Reading a website you asked us to read. A scan reads the pages of the website you name, as a search engine would. It identifies itself as QuorlBot, it obeys robots.txt, and this page explains how to refuse it. We keep the findings, not a copy of the website.
Why we are allowed to do each of these. Under the GDPR and UK GDPR we rely on performance of a contract to run your account, publish your articles, and bill you; legitimate interests to keep the service secure, to stop abuse, to diagnose faults, and to answer you when you write to us; consent for the dashboard session recordings described in §8, for the analytics cookies on this site, and for any marketing email you asked for, each of which you can withdraw at any time; and legal obligation for tax, accounting, and the records we have to keep. Where consent is the basis, refusing it never costs you the service itself.
3. Categories of service providers
We share the minimum data necessary with vetted service providers who help us operate. By category:
- Payment processor (merchant of record) - billing, payment, and tax compliance.
- Email delivery provider - transactional email.
- Infrastructure, content delivery, and security providers - to operate, deliver, and protect the service.
- Sign-in providers - only if you choose social sign-in; we receive your account identifier and email.
- Content-processing providers - content inputs and outputs are processed by specialized providers (currently OpenAI) to produce your articles. We do not include personally identifying customer information in these payloads beyond what is required for editorial context.
- Image generation providers - a prompt derived from your article is sent to specialized providers (Cloudflare Workers AI, then OpenAI) to generate an illustration.
- Job queueing provider - carries your generation request to the engine and runs it once, then returns to zero.
- Web search provider - used to source your articles, plus a fallback provider used when the primary is rate-limited.
- Error monitoring provider - client error capture and a masked session replay of the dashboard, made only when an error happens (see §8).
- Product analytics provider - masked session recordings of the dashboard, made only if you accept them, used to see where the product is hard to use (see §8).
- Bot and abuse protection- a background check from Cloudflare Turnstile tells people from bots when you sign in with a password or passkey, create an account, reset a password, use our contact form, or run the public site scan. See Cloudflare's Turnstile Privacy Addendum.
We do not sell your data. We do not use it for advertising. A current list of sub-processors is available on request to the contact below.
4. Where it lives
Application data is stored with managed cloud providers - a managed Postgres database, object storage for generated images, and managed compute - under data-processing terms with each of them. Backups are encrypted. Access is restricted to authorized personnel under confidentiality obligations. Some processing is performed by the service providers described in §3, which operate globally.
5. International data transfers
Because the service operates globally, personal data may be processed across multiple jurisdictions, which may be outside your country of residence and may not offer the same level of data protection. Where data originates in the European Union or United Kingdom, we rely on appropriate transfer mechanisms (Standard Contractual Clauses or equivalent) with our processors.
6. Retention
Active accounts: data is retained as long as the account is active. Closed accounts: we send a reminder before deletion, and data is deleted or irreversibly anonymized 30 days after the account is closed - whether you close it or we do - except records we must keep for legal compliance (such as proof of agreement to our terms and billing/tax records), which are retained for the period required by law and then deleted. Aggregate metrics may be retained longer in anonymized form for service-quality analysis.
7. Your rights (GDPR / UK GDPR / CCPA)
You have the right to access, correct, export, restrict processing of, or delete your personal data, and to lodge a complaint with your data-protection authority. Export and account deletion are self-serve from your dashboard’s Account settings. Where we rely on your consent, you can withdraw it at any time - §8 says where. For anything else, email privacy@mastheads.app and we will respond within 30 days.
8. Cookies, analytics & diagnostics
We use strictly necessary cookies for authentication on the dashboard. On this marketing site we use Google Analytics 4 to measure aggregate traffic. It runs under Google Consent Mode v2 with analytics and advertising storage denied by default - no analytics cookies are set unless you accept them in the cookie banner. We do not use advertising cookies, and we do not sell personal data.
We also use Sentry, a third-party error-monitoring service, to detect and diagnose technical faults in the dashboard and web app. When an error happens, Sentry records a masked session replay of the moments around it, together with the details of the error itself. It does not record ordinary sessions, only faults. All text, form inputs, and media are masked in your browser before anything is sent, so the recording contains no readable content, article text, or credentials. Replays are kept for about 90 days. We use this data solely to diagnose and fix faults. It is never used for advertising and never sold.
We use Microsoft Clarity to understand how the dashboard is used - which screens people reach, and where they get stuck. Nothing is recorded until you accept it. The dashboard asks the first time you arrive, and if you decline, or never answer, Clarity is never loaded. If you accept, it records a masked session replay: text, form inputs, and media are hidden in your browser before anything is sent, so a recording shows navigation and layout rather than readable content. This covers the dashboard including the sign-in screen, and Clarity sets its own cookies to recognise a returning visit. You can turn it off at any time in Settings, under Data and privacy, and recording stops there and then. Your choice is kept in the browser you made it in, so a different browser or device asks again. Once someone is signed in we can tell our own staff apart, and we do not record them; on the sign-in screen nobody is identified yet, so what covers that screen is your own answer to the banner. We use this data solely to improve the product. It is never used for advertising and never sold.
Links in our emails. When we send you an email about your account, links back to your dashboard pass through a counter on our own servers before forwarding you on. It records that a link of that type was followed and when. There is no third party involved, no tracking pixel, and no image loaded to detect that a message was opened.
9. Children
Mastheads is a business tool for publishers, agencies, and the people who write for them. It is not directed at children, we do not market it to them, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, write to privacy@mastheads.app and we will delete it.
10. Changes to this policy
We may update this policy as the service evolves. Material changes will be communicated to active customers by email at least 30 days before they take effect.
11. Contact
For privacy questions, email privacy@mastheads.app.