Privacy Policy
How AuthorityWriter collects, encrypts, and handles your account data, domain metrics, Google Search Console tokens, and CMS connection keys under strict zero-retention guarantees.
1. Overview and Core Philosophy
AuthorityWriter ("we", "us", "our", or the "Platform") operates an autonomous search engine optimization and publishing engine for digital publishers, content networks, e-commerce storefronts, and software companies. We design our entire software infrastructure around an immutable premise: your content strategy, competitive keyword research, domain analytics, internal link graphs, and private credentials belong exclusively to you.
Unlike legacy AI platforms that harvest customer data to train public foundation models, AuthorityWriter maintains a strict Zero-Training Data Architecture. We do not use your proprietary articles, customer prompts, domain metrics, sitemap topologies, or CMS media to train, fine-tune, or validate any public or shared machine learning models.
This Privacy Policy explains our practices regarding the collection, storage, encryption, processing, and transfer of personal information, credentials, and search telemetry when you access or use AuthorityWriter websites, APIs, webhooks, or browser extensions.
2. Categories of Information We Collect
We practice rigorous data minimization, collecting only the specific data points required to execute our autonomous research, drafting, CMS publishing, and search console indexing protocols:
A. User Account Information
When you create an account or administer team workspaces, we collect your full name, email address, company or agency name, IP address at registration, and salted password hashes encrypted using modern Argon2id or Bcrypt cryptographic hashing algorithms. We never store plaintext passwords.
B. Connected Website & Domain Telemetry
To calibrate content generation to your site's striking-distance authority, we process your verified domain URL, XML sitemap address, calculated Domain Rating (DR), backlink count benchmarks, existing published URL paths, and editorial publishing schedules. This topology data is used solely to construct your site's contextual internal link graph and eliminate topic cannibalization.
C. CMS Integration Credentials
To enable automated direct publishing, our system securely receives credentials you provide: WordPress REST API Application Passwords, Shopify Admin OAuth tokens, Webflow Collection IDs and API keys, Wix site tokens, or custom webhook endpoint signatures. All credentials are encrypted at rest using AES-256-GCM authenticated encryption and stored in isolated database records.
D. Operational Log Data & Web Analytics
When interacting with our web application, servers automatically record standard operational logs including browser user-agent strings, referring URLs, request timestamps, response codes, and session identifiers. These logs are maintained strictly for debugging, load balancing, and anti-abuse security monitoring.
3. Google Search Console & Google API Services User Data Policy
AuthorityWriter provides an optional, 1-click integration with Google Search Console via OAuth 2.0. This allows our system to prompt automated Googlebot crawling upon article publication and display search impression telemetry directly inside your dashboard.
Compliance with Google Limited Use Requirements
AuthorityWriter's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements:
-
✓
Restricted Scope Access: We request only the specific
webmasters.readonlyandindexingscopes necessary to dispatch URL inspection queries and retrieve performance impressions for connected domains. - ✓ No Artificial Intelligence Training: Data obtained via Google Search Console APIs is strictly prohibited from being used to train, develop, or improve generalized AI, machine learning models, or natural language processing heuristics.
- ✓ Zero Data Pooling or Reselling: Search performance metrics, click counts, search queries, and impressions retrieved from your Google account are never merged across different users, sold to third-party data brokers, or used for advertising targeting.
- ✓ Encrypted OAuth Tokens: Google OAuth refresh tokens and temporary access credentials are encrypted at rest using AES-256-GCM. You may revoke access immediately at any time via your account settings or directly through your Google Security permissions.
4. How We Use and Process Your Information
We utilize collected data strictly in fulfillment of our contractual commitment to provide autonomous SEO services:
- • Calibrating Keyword Harvester Algorithms: Computing mathematical keyword difficulty thresholds against your live backlink authority to prevent wasted publication credits on unwinnable search terms.
- • Autonomous Content Generation: Producing comprehensive, structured EEAT articles featuring uncapped word counts, comparison data tables, JSON-LD schema scripts, and contextual media.
- • Internal Linking Mesh Construction: Crawling your verified XML sitemaps to intelligently weave natural in-text links from newly generated content back to your existing pillar pages.
- • Direct CMS Auto-Publishing: Communicating with WordPress, Shopify, Webflow, or custom webhooks to publish articles or stage drafts according to your scheduled cadence.
- • Account Administration & Security: Sending transactional billing notifications, subscription receipts, critical security alerts, and technical support responses.
5. Enterprise AI Processing & Sub-Processors
To deliver humanized, domain-grounded prose at scale, AuthorityWriter routes content generation requests through dedicated, enterprise-tier language inference engines and cloud infrastructure:
All external AI inference partners are bound by strict contractual enterprise agreements containing explicit Zero Data Retention (ZDR) and Zero Model Training clauses. Your input queries, generation prompts, and resulting articles are discarded immediately following pipeline completion and are never stored or reviewed for training public models.
Key Sub-Processor Categories:
6. Payment Processing & Financial Safeguards
AuthorityWriter utilizes certified PCI-DSS Level 1 payment processing partners (including Stripe and Polar) to process subscription billing.
When purchasing a website subscription ($10/month per domain), your financial data (such as full 16-digit credit card numbers, CVV security codes, and expiration dates) is transmitted directly to our payment partners via encrypted tokenization. AuthorityWriter's servers never capture, view, process, or store raw cardholder data. We maintain only high-level billing records: billing address, card brand, last 4 digits, expiration month/year, and transaction receipts.
7. Cookies, Session Tokens & Local Storage
We believe in a tracker-free web experience. We use only strictly necessary first-party cookies and session storage mechanisms essential to application security and authentication:
- • Authentication Sessions: Secure, HTTP-only, SameSite-restricted cookies that maintain your authenticated dashboard session across page transitions.
- • Cross-Site Request Forgery (CSRF) Tokens: Cryptographic tokens preventing unauthorized external web requests from executing actions on your account.
- • UI Preferences: Local storage flags for dashboard view toggles, sidebar state, and theme settings.
We do not use intrusive third-party cross-site advertising trackers, behavioral fingerprinting scripts, or third-party pixel beacons.
8. Cryptographic Security & Storage Architecture
We implement multi-layered administrative, operational, and technical safeguards engineered to protect your domain credentials and generated content:
- ✓ Encryption in Transit: All network communication is mandated over Transport Layer Security (TLS 1.3) with modern cipher suites and Strict-Transport-Security (HSTS) headers.
- ✓ Encryption at Rest: Database backups, sensitive credential columns (CMS keys, Google OAuth tokens, webhooks), and article drafts are encrypted using hardware-backed AES-256-GCM encryption keys.
- ✓ Strict Least-Privilege Access: Platform engineers and operational staff access internal infrastructure strictly through hardware 2FA keys, role-based access control (RBAC), and audited bastion jump hosts.
- ✓ Vulnerability Management: Automated daily dependency vulnerability scans, periodic dynamic application security testing (DAST), and real-time WAF rate-limiting against automated scraping bots.
9. Data Retention, Portability & Account Deletion
You retain absolute sovereignty over your account data. We enforce explicit lifecycle retention policies:
- ✓ Immediate Export: You can download all generated articles, metadata outlines, and schema blocks in raw Markdown, JSON, or clean HTML at any time directly from the dashboard.
- ✓ Immediate Integration Revocation: Disconnecting a website or deleting a CMS connection instantly purges all stored API tokens and OAuth credentials from our active database.
- ✓ Graceful Account Purging: Upon subscription cancellation or account deletion request, your historical data is held in inactive status for 30 days to facilitate accidental cancellation recovery, after which all databases, backups, and site caches are permanently purged.
10. Global Privacy Rights (GDPR, CCPA/CPRA, UK DPA)
Regardless of your physical location, AuthorityWriter extends core privacy protections aligned with global privacy standards, including the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act, and the California Consumer Privacy Act as amended by the CPRA:
Right to Access & Portability
You have the right to request a complete, machine-readable export of all personal data and content records we hold concerning your account.
Right to Rectification & Erasure
You may update inaccurate information directly in your profile or submit a request for full erasure ("Right to be Forgotten").
Right to Object & Restrict
You may object to or restrict specific processing operations, including automated pipeline schedules and analytical monitoring.
Zero Sale of Personal Data
AuthorityWriter does not sell, rent, or share personal data with third parties for cross-context behavioral advertising.
To exercise any of these statutory rights, submit a written verification request to our compliance team at [email protected]. We respond to all verified inquiries within 30 days without surcharge.
11. International Data Transfers
AuthorityWriter operates globally with primary cloud server infrastructure located in the United States and the European Union. If you access our Service from outside these jurisdictions, please be aware that information we collect will be transferred to, processed, and stored in our secure data centers.
When transferring personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure adequate protection through standard contractual safeguards, including European Commission Standard Contractual Clauses (SCCs) and adherence to recognized international cross-border transfer frameworks.
12. Children's Privacy Protection
AuthorityWriter is an enterprise and business-oriented SaaS platform engineered exclusively for commercial publishers, marketing professionals, and website owners aged 18 and older. We do not knowingly solicit, collect, or process information from individuals under the age of 18. If we become aware that personal data of a minor has been collected without verified parental consent, we take immediate corrective steps to delete such records permanently.
13. Policy Modifications and Notification Protocol
As search engine technologies, algorithmic indexing frameworks, and international privacy laws evolve, we may update this Privacy Policy periodically.
When material changes are made, we will notify registered workspace owners via email to the primary administrative address on file and post an announcement in the dashboard at least 14 calendar days prior to the modifications taking effect. The "Last Updated" timestamp at the top of this page will reflect the latest version date.
14. Contact Our Data Protection Officer
If you have inquiries, questions, or compliance concerns regarding this Privacy Policy or our security practices, our dedicated Data Protection Officer can be reached directly:
Quick Navigation
- 1. Core Philosophy
- 2. Information Collected
- 3. Google API Compliance
- 4. How We Process Data
- 5. AI Sub-Processors
- 6. Payment Processing
- 7. Cookies & Storage
- 8. Security & Encryption
- 9. Retention & Portability
- 10. Global Rights (GDPR)
- 11. International Transfers
- 12. Children's Privacy
- 13. Policy Modifications
- 14. Contact Privacy Team
Security Commitments
- Google Search Console API Verified
- Zero Training Retention Policy
- AES-256-GCM Encrypted Credentials
- TLS 1.3 End-to-End Encryption
- PCI-DSS Level 1 Payment Security
Compliance Inquiries?
Our security, engineering, and legal officers are here to assist with audits.
Contact Security Team