Privacy Policy
How DraftLynx collects, uses and stores information.
The headings below outline what this page needs to cover, based on how DraftLynx actually works. The content must be written or reviewed by someone qualified before launch — do not rely on this page as it stands.
1. What we collect
Account details (name, email, password hash via Better Auth), the websites you connect and their settings, and the content DraftLynx generates for you. Cover what a user provides versus what is captured automatically.
2. Website crawling
DraftLynx fetches pages from the websites you add in order to score them and ground content generation. Explain that only publicly reachable pages are fetched, that robots.txt is respected, and how long crawled page data is retained.
3. Third-party processors
Name every service that receives data and why: Anthropic (article generation and site analysis), the image provider, Stripe (payments — card details go directly to Stripe and are never stored by DraftLynx), the database host, and email delivery. Link each provider's own privacy policy.
4. Integration credentials
WordPress application passwords are encrypted at rest with AES-256-GCM and are only decrypted to publish on your behalf. State that they are never returned to the browser and can be revoked at any time from WordPress.
5. Cookies and sessions
DraftLynx sets a session cookie to keep you signed in. Note whether any analytics or marketing cookies are used, and how consent is handled where required.
6. Data retention and deletion
How long data is kept after an account is closed, what a deletion request removes, and how someone requests it.
7. Your rights
Access, correction, export, deletion and objection rights, and how to exercise them. If you serve UK/EU users, this must reflect UK GDPR / GDPR obligations, including your lawful basis for processing.
8. Contact
The business name, registered address and a contact email for privacy enquiries. Add a data protection contact if you are required to have one.