Privacy Policy

Last updated: August 21, 2026

1. Data controller

The controller of personal data is eCopywriting.pl Karol Leszczyński, Papowo Biskupie 119/18, Poland, VAT ID (NIP): 9562203948, REGON: 340627879 (the "Controller"). Data protection contact: support@smart-copy.ai.

2. What data we process

  1. Account data — e-mail address, name (optional), password (stored only as a hash), country, Google account identifier for Google sign-in, registration and login IP addresses.
  2. Billing data — top-up and transaction history, balance, Stripe customer identifier and — with auto top-up enabled — the last digits and brand of the saved card. Full card data is processed solely by Stripe.
  3. Order content — topics, guidelines, SEO keywords and links, provided sources (URLs and uploaded files), generated texts, outlines, images and revision history.
  4. WordPress site data — site address, connection key or application-password credentials, connection status and the site profile sent by the plugin (title, tagline, categories, titles and excerpts of recent posts).
  5. API data — hashes of API keys and tokens, permission scopes, registered OAuth applications and granted consents, webhook endpoints and the API call log (method, path, response code, duration, cost).
  6. Technical data — server logs, device and browser data, cookies (sec. 10).

3. Purposes and legal bases

  1. Providing the services (account, content generation, publishing, Autoblog, API) — Art. 6(1)(b) GDPR (contract).
  2. Billing and tax/accounting obligations — Art. 6(1)(c) GDPR.
  3. Security, abuse prevention, claims, statistics and service development — Art. 6(1)(f) GDPR (legitimate interest).
  4. Marketing communication — only with consent (Art. 6(1)(a) GDPR), withdrawable at any time.

4. Recipients (processors)

We entrust data only to the extent necessary to provide the services:

  1. Anthropic (USA) — AI language models; receives order content (topics, guidelines, sources) necessary to generate the text. Anthropic does not use API customers' content to train models by default.
  2. Replicate (USA) — AI image generation; receives the image scene description (no User personal data).
  3. Serper.dev / Google Custom Search (USA) — source search; receive queries built from the order topic.
  4. Cytado — academic source search for academic/hybrid modes; receives the order topic.
  5. Amazon Web Services (EU servers: Frankfurt/Stockholm) — hosting, file storage (S3) and e-mail delivery (SES).
  6. Stripe — payment processing.
  7. Google — reCAPTCHA (form protection), Google sign-in, Google Analytics 4 (statistics) and Google Drive if you enable saving texts to Google Docs (sec. 7).

Transfers to third countries (USA) rely on an adequacy decision (EU-U.S. Data Privacy Framework) or Standard Contractual Clauses (SCC).

5. OAuth applications and webhooks

  1. Third-party applications access your account data only after you grant consent on the authorisation screen, within the scope shown there (e.g. reading texts, ordering, reading the balance). You may withdraw consent at any time in the dashboard ("Connected applications") — withdrawal invalidates all of the application's tokens.
  2. After data is shared, the third-party application's provider processes it as a separate controller.
  3. Webhooks are sent only to endpoints you configure; they contain order data (topic, status, the completed text) and are cryptographically signed.

6. Shop and product catalogue integrations

  1. The service lets you connect your Account to an external system holding your product catalogue — in particular Base (formerly BaseLinker), a WooCommerce shop, or a product feed at a URL you provide. The connection is made on your initiative alone, using credentials you supply yourself.
  2. Credentials (API tokens, shop keys) are stored encrypted with AES-256-GCM. Only the last four characters are ever shown in the interface. You can delete a saved connection at any time — and independently revoke the token in your own system, which cuts off our access immediately.
  3. The data we read covers what is needed to write a description: product name, identifier, attributes and any existing description. We do not read orders, your customers' data, or your shop's billing data.
  4. Write-back is limited to the product description field, matched by product identifier. We never change prices, stock levels, variants or marketplace links, and we never create or delete products.
  5. Product data is processed on your instruction and solely to deliver the service you ordered. The provider of the system you connect to is your supplier, not our sub-processor — your relationship with them is governed by the agreements you concluded.
  6. Product data is retained for as long as the batch exists in your dashboard; deleting the batch deletes it too. Credentials are deleted together with the connection or the Account.

7. Google Drive (Google Docs) integration

  1. The Service lets you save a finished text as a Google document on your Drive. The connection to your Google account is made solely on your initiative, after you grant consent on the Google sign-in screen.
  2. Access scope is limited to the drive.file permission — access only to files we create ourselves on your Drive. We cannot see your other files, folders or their names. We additionally read your Google account e-mail address to show you in the panel which account is connected.
  3. What we store: the refresh token issued by Google, kept encrypted with AES-256-GCM, the identifier of the folder we created and the links to the documents created. We do not store your Google account password.
  4. What we use it for: solely to create a document containing the text you ordered, on your instruction. We do not use data from your Google account for advertising, do not sell it, do not share it with third parties and do not use it to train artificial intelligence models.
  5. Withdrawing consent: you can remove the connection at any time in the panel (the "Integrations" section), which revokes the token on the Google side. Independently of that, you can revoke access yourself at myaccount.google.com/permissions. Documents created earlier remain yours and stay on your Drive — you alone decide whether to delete them.
  6. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Retention

  1. Account data and order content — for the lifetime of the Account and up to 30 days after deletion (backups), except billing data.
  2. Billing data — for the period required by law (as a rule 5 tax years).
  3. API call log and technical logs — up to 24 months.
  4. WordPress site data and site profile — until the site is disconnected or the Account deleted.

9. Your rights

You have the right to access, rectify, erase and port your data, to restrict processing, to object to processing based on legitimate interest, and to withdraw consent at any time (without affecting prior processing). Requests: support@smart-copy.ai. You may also lodge a complaint with your supervisory authority (in Poland: the President of the Personal Data Protection Office, uodo.gov.pl).

10. Cookies

  1. Essential — login session, language and theme preferences, security (reCAPTCHA). Always active.
  2. Analytics — Google Analytics 4 (anonymised traffic statistics).
  3. Details and management are described in the Cookie Policy . You can also restrict cookies in your browser settings.

11. Security

We use, among others: encrypted transmission (TLS), storage of passwords and API keys exclusively as cryptographic hashes, one-time display of secrets, least-privilege access and automatic backups. Data breaches are reported in accordance with the GDPR.

12. Changes to this policy

We will announce material changes in the Service or by e-mail. The current version is effective as of August 21, 2026.