Sembalia
Back to home

Privacy Policy

Last updated: [DATE]

This policy explains how [LEGAL_NAME] processes personal data when you use Sembalia. We are the data controller. For privacy questions contact [PRIVACY_EMAIL].

1. Data we process

Account: your name, email and a hashed password (or your Google account identifier if you sign in with Google).

Project configuration: the URL and settings of your sites, and the credentials or tokens needed to publish — WordPress application passwords, webhook secrets and OAuth refresh tokens for Google Search Console and connected social accounts. These are encrypted at rest (AES-256-GCM).

Content and analytics: the content we generate, embeddings for internal linking and deduplication, and Search Console metrics for your sites.

Technical: logs and basic usage data needed to run and secure the service. Authorization headers and cookies are redacted from logs.

2. How we use it and legal bases

To provide the service and perform our contract with you (account, generation, publishing, billing); on the basis of our legitimate interest to secure, debug and improve the service; and on your consent where required (e.g. newsletter opt-in). We do not sell your personal data.

3. Subprocessors and third parties

We rely on trusted providers who process data on our behalf: Google (Gemini, and Search Console/OAuth), OpenAI (text generation and embeddings), Cloudflare R2 (image and asset storage), Polar (payments), your chosen email provider (Resend, Brevo, SendGrid, Mailgun or Postmark) for the newsletter, DataForSEO (keyword and SERP data), and Meta (when you connect Instagram/Facebook). We only share what each function requires.

AI processing: to generate content we send the relevant inputs (your topics, site signals, strategy and source titles) to the AI providers above. The newsletter add-on writes the issue and hands you the HTML: we do not store your subscribers or send anything on your behalf.

4. International transfers

Some providers are located outside your country (e.g. the United States). Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses. Details on request at [PRIVACY_EMAIL].

5. Retention

We keep account and project data while your account is active. When you delete a project or your account, the associated data — content, keywords, tokens and stored files — is deleted. Minimal billing records may be retained where legally required.

6. Your rights

Under the GDPR and similar laws you can access, rectify, erase, restrict or object to the processing of your data, and request portability. You can delete your projects or your entire account (right to erasure) directly from your account settings. You may withdraw consent at any time and lodge a complaint with your data protection authority.

Newsletter recipients can unsubscribe from any email (one-click) and request erasure of their address.

7. Security

Data is transmitted over TLS and secrets are encrypted at rest. Access is restricted and authentication is required for all account operations. No system is perfectly secure, but we apply industry-standard measures.

8. Cookies

We use only essential cookies: a session token to keep you signed in and a small preference cookie to remember your interface language. We do not use advertising or third-party tracking cookies on the app.

9. Children

Sembalia is not directed to children and is not intended for anyone under the age required to consent to data processing in their country.

10. Changes and contact

We may update this policy; material changes will be notified. Controller: [LEGAL_NAME], [ADDRESS]. Privacy contact: [PRIVACY_EMAIL].