Privacy Policy
DRAFT — pending review by counsel and an effective date. Bracketed [COUNSEL] notes mark items a lawyer or operator must confirm.
This Privacy Policy explains how Wordhelm ("we", "us"), operated by [COUNSEL: legal entity name], collects, uses, and protects information when you use our website and service (the "Service"). We handle your data responsibly and never sell personal data.
Information we collect
- Account information — your name, email, password (stored hashed), and organization details.
- Your website content — we read your public pages to learn your brand voice and topics.
- Connected-platform credentials — credentials or tokens for the CMS/publishing endpoints you connect, stored encrypted at rest and used only to publish on your behalf.
- Google Search Console data — when you connect it, read-only search-performance data and an OAuth refresh token (encrypted at rest). See "Google user data" below.
- Usage and log data — actions in the app, device/browser information, and diagnostic logs used to operate and secure the Service.
- Payment information — handled by our payment processor; we do not store full card numbers.
- Waitlist email — if you join the waitlist, your email and where the signup came from.
How we use information
To provide and operate the Service (research keywords, generate drafts, publish to your connected platforms, and show your performance dashboard); to secure, maintain, and improve the Service; to communicate with you (transactional and account emails); to process payments; and to comply with legal obligations. [COUNSEL: confirm wording — current practice does not use customer content or Google data to train generalized AI models.]
Legal bases (where GDPR applies)
We process personal data to perform our contract with you, for our legitimate interests in operating and securing the Service, to comply with legal obligations, and with your consent where required. [COUNSEL: confirm bases; add an EU/UK representative if required.]
Google user data & Limited Use
When you connect Google Search Console, Wordhelm requests the read-only scope
webmasters.readonly. We use it solely to read the search-performance data
(clicks, impressions, average position, and queries) for the properties you explicitly
authorize, in order to display your own performance dashboard. We never request a write
scope and never modify your Search Console data. We also use the basic
openid, email, and profile scopes to sign you in.
Wordhelm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data is:
- used only to provide and improve the user-facing features (your performance dashboard) that are prominent in the Wordhelm interface;
- never sold, and never used for advertising of any kind (including personalized or retargeted ads);
- never used to train generalized or large-scale AI/ML models;
- not transferred to others except as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with your consent;
- not read by humans unless you give explicit consent, it is necessary for security or to comply with the law, or the data has been aggregated and anonymized.
Search Console refresh tokens are encrypted at rest, used only to refresh the read-only metrics shown to you, and deleted when you disconnect the integration or delete your account.
How we share information
We do not sell personal data. We share data with service providers ("subprocessors") only as needed to run the Service, under contracts that limit their use of it. Categories include: cloud hosting and database, AI/LLM providers (for content generation), keyword/SEO data providers, transactional email, payment processing, and error/diagnostic monitoring. We may also disclose data to comply with law, enforce our terms, or in connection with a merger or acquisition. [COUNSEL: maintain a current, named subprocessor list.]
Data retention
We keep personal data while your account is active or as needed to provide the Service, then delete or anonymize it within a reasonable period, except where longer retention is required by law. You can delete your account and connected data at any time.
Security
Credentials and tokens are encrypted at rest, access is restricted, and we use industry-standard safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your rights & choices
Depending on where you live (for example under the GDPR or California's CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object or withdraw consent. You can disconnect any integration and delete your account in-app, or contact us to exercise these rights; we will not discriminate against you for doing so. [COUNSEL: confirm rights, response timelines, and identity-verification process.]
International transfers
We may process and store data in countries other than your own. Where required, we use appropriate safeguards for such transfers. [COUNSEL: confirm transfer mechanism, e.g., Standard Contractual Clauses.]
Children
The Service is intended for users 18 and older and is not directed to children. We do not knowingly collect data from children.
Changes
We may update this Policy and will post the revised version with a new effective date.
Contact
Privacy questions or requests: privacy@wordhelm.com. [COUNSEL/setup: ensure this inbox is monitored; add a postal address if required.]