Privacy Policy
Last updated 24 August 2026
This policy explains what SupaTraffic collects, why we collect it, who we share it with, and what you can do about it. It covers both the website and the product.
1. What we collect
Your account. Your name, email address and profile picture, from Google when you sign in with it, or just your email address if you use a sign-in link. We never see or store a password.
The websites you connect. The address you give us, and the readable text of a handful of its public pages, which our server fetches the same way any visitor’s browser would. We only ever read pages that are publicly reachable — we do not accept credentials for your site and could not use them if you offered.
What the product produces. The brand profile written from your site, your keyword library, your calendar, and the articles themselves, including any edits you make.
Billing. Your subscription status and credit balance. Card details go directly to Stripe and never touch our servers.
Basic technical logs. IP address, browser and timestamps, kept for security and debugging.
2. Why we collect it
- To run the product you signed up for, which is the bulk of it.
- To bill you correctly and stop credits being spent twice.
- To keep the service up and to investigate abuse — someone pointing our fetcher at addresses that are not their own website, for instance.
- To send you service email. We do not sell your data to anyone, ever.
3. Who else sees it
We use a small number of processors, and only where the work genuinely requires it:
- Our model provider — the text of your connected website and your brand profile are sent to a language model to produce keywords and articles. This is the core of the product and cannot be opted out of while using it.
- Stripe — payments and subscriptions.
- Google — only if you choose to sign in with a Google account.
- Our email provider — sign-in links and service notices.
- Our hosting and database provider — where the application runs and your data is stored.
We also disclose data where the law requires it, and we will tell you when we are permitted to.
4. How long we keep it
Your account and its content stay until you delete them. Deleting a project deletes its brand profile, keywords and articles. Deleting your account removes your personal data; we keep the minimum billing records that tax law requires, and anonymised aggregates that cannot be traced back to you.
5. Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we are using it. Email us and we will action it — normally within a few days, and always within a month. If you are in the UK or EU you also have the right to complain to your data protection authority.
6. Cookies
We set a cookie to keep you signed in, and Stripe sets its own on the checkout flow to prevent fraud. Both are strictly necessary to operate the service. We do not run advertising or cross-site tracking cookies.
7. Security
Data is encrypted in transit and at rest, access is limited to the people who need it, and each customer’s content is isolated at the database level. No system is perfect; if a breach affects you we will tell you promptly.
8. Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
9. Contact
Questions about any of this: [email protected].