Privacy Policy
Your privacy is important to us. This Privacy Policy describes how Wordiva.ai collects, uses, stores, and protects your personal information when you use our AI content marketing platform. We are committed to handling your data responsibly and in compliance with applicable privacy laws, including GDPR.
1. Who We Are
Wordiva.ai ("we", "our", "us") operates the Wordiva.ai platform, an agentic AI content marketing service. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and platform at wordiva.ai.
2. Information We Collect
- •Account information: name, email address, and password (stored securely via Supabase Auth).
- •Brand profile data: website URL, business description, target audience, tone of voice, and publishing preferences you provide during onboarding.
- •Payment information: billing details processed and stored securely by Stripe. We never store your full card number.
- •Content data: article drafts, AI-generated images, WordPress publishing records, and idea records associated with your brands.
- •Usage data: log files, IP address, browser type, pages visited, features used, and session duration collected automatically.
- •Communications: emails and messages you send us for support purposes.
- •Cookies and tracking: see our Cookie Policy for details.
3. How We Use Your Information
- •To provide, operate, and improve the Wordiva.ai platform and its AI content generation features.
- •To manage your account, process subscription payments, and send billing communications.
- •To send transactional emails such as email verification, plan activation notices, and article-ready review notifications.
- •To personalise AI prompts and model selection based on your subscription plan and brand settings.
- •To analyse usage patterns and improve product features, UI/UX, and AI model performance.
- •To comply with legal obligations and enforce our Terms and Conditions.
- •To send marketing communications where you have provided consent (you may opt out at any time).
4. Legal Basis for Processing (GDPR)
- •Contract performance: processing necessary to provide the Service you have subscribed to.
- •Legitimate interests: product improvement, fraud prevention, and service security.
- •Legal obligation: compliance with applicable laws and regulations.
- •Consent: marketing communications and non-essential cookies (you can withdraw consent at any time).
5. How We Share Your Information
- •Supabase: authentication and database hosting for your account and content data.
- •Stripe: payment processing. Stripe is PCI-DSS certified and handles all card data.
- •OpenAI / OpenRouter / NVIDIA: AI model providers that process your prompts to generate article and image content.
- •Resend: transactional email delivery.
- •AWS S3 / Supabase Storage: storage of generated article HTML and images.
- •WordPress: content is published to your connected WordPress site on your instruction.
- •Unsplash / Pexels: stock photo and media search used to illustrate generated articles.
- •We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
6. Data Retention
We retain your account data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it by law (e.g., billing records for tax compliance, which are retained for up to 7 years). AI-generated content stored in our systems may be purged sooner in line with storage limits.
7. Data Security
- •WordPress OAuth access tokens are encrypted at rest using AES-256 encryption before storage.
- •All data in transit is protected by TLS/HTTPS.
- •Access to production databases is restricted and audited.
- •We use Supabase Row-Level Security (RLS) to ensure users can only access their own data.
- •Despite these measures, no system is completely secure. You should use a strong, unique password and notify us immediately if you suspect unauthorised access.
8. International Transfers
Our infrastructure and third-party service providers may be located outside your country of residence. When we transfer personal data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) under GDPR, to protect your information to the same standards as required in your jurisdiction.
9. Your Rights
- •Access: request a copy of the personal data we hold about you.
- •Correction: request correction of inaccurate or incomplete data.
- •Erasure: request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- •Portability: receive your personal data in a structured, machine-readable format.
- •Restriction: request that we restrict processing of your data in certain circumstances.
- •Objection: object to processing based on legitimate interests or for direct marketing.
- •Withdraw consent: where processing is based on consent, you may withdraw it at any time.
- •To exercise any of these rights, contact us at hello@wordiva.ai.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided personal information, we will take steps to delete it promptly.
11. Third-Party Links
The Service may contain links to third-party websites and services (such as our blog at wordiva.ai/blog). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date and, where appropriate, by sending an email to your registered address. Your continued use of the Service after any changes take effect constitutes acceptance of the updated policy.
13. Contact and Complaints
For privacy-related questions, data requests, or complaints, please contact us at hello@wordiva.ai. If you are located in the EEA and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.
If you have questions about this policy, please contact us at hello@wordiva.ai.