Privacy Policy
Last updated: August 17, 2025
1. Introduction
BlogYak ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered blog writing service ("Service"). This policy applies to all users worldwide and complies with international privacy laws including GDPR, CCPA, and other applicable regulations.
2. Information We Collect
2.1 Personal Information You Provide
- Account Information: Email address, name (if provided), and authentication credentials
- Profile Information: Any additional profile information you choose to provide
- Communication Data: Messages you send to us through support channels, Discord, or email
- Payment Information: Billing details processed securely through third-party payment processors
2.2 Content and Usage Data
- Project Data: Project names, descriptions, and metadata you create
- Blog Content: Blog posts, titles, prompts, and content you generate or input
- AI Interactions: Prompts sent to AI services and generated responses
- Blog Suggestions: AI-generated topic suggestions and your responses (accepted/rejected)
- SEO Keywords: Keywords associated with your content
2.3 Automatically Collected Information
- Usage Analytics: How you interact with our Service, features used, and session duration
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, pages viewed, and referrer information
- Cookies and Tracking: Session management, preferences
3. How We Use Your Information
3.1 Service Provision
- Create and manage your user account
- Process your projects and generate AI-powered content
- Store and organize your blog posts and projects
- Provide personalized content suggestions based on your projects
- Enable content export in various formats
3.2 Service Improvement
- Analyze usage patterns to improve our AI models and features
- Understand user preferences to enhance user experience
- Develop new features and capabilities
- Monitor and maintain service performance and security
3.3 Communication
- Send service-related notifications and updates
- Respond to your inquiries and provide customer support
- Send important security and legal notices
- Provide optional marketing communications (with your consent)
3.4 Legal and Safety
- Comply with legal obligations and court orders
- Detect and prevent fraud, abuse, and security threats
- Enforce our Terms of Service and protect our rights
- Investigate and respond to user reports and violations
4. Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data based on:
- Contract Performance: To provide the Service you've subscribed to
- Legitimate Interest: To improve our Service, ensure security, and analyze usage
- Consent: For marketing communications and optional features (where applicable)
- Legal Obligation: To comply with applicable laws and regulations
5. Information Sharing and Disclosure
5.1 Third-Party Service Providers
We share information with trusted service providers who assist us in operating our Service:
- Clerk: User authentication and account management
- Convex: Database hosting and data storage
- AI Providers: Content generation services (OpenAI, Anthropic, or similar)
- Posthog: Usage analytics and performance monitoring
- Cloudflare: DDoS protection and security services
- Vercel: Web Hosting
5.2 Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal process, court orders, or government requests
- Protect our rights, property, or safety, or that of our users
- Investigate fraud, security issues, or Terms of Service violations
- Respond to emergencies involving immediate danger to persons
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
5.4 Aggregated Data
We may share aggregated, anonymized data that cannot identify individual users for research, analytics, or business purposes.
6. Data Storage and Security
6.1 Data Storage
- Your data is stored securely using industry-standard cloud infrastructure
- Data may be processed and stored in multiple jurisdictions to ensure service reliability
- We implement appropriate safeguards for international data transfers
6.2 Security Measures
- Encryption of data in transit
- Regular security audits and vulnerability assessments
- Access controls and authentication mechanisms
- Monitoring for unauthorized access and security threats
- Regular security updates and patches
6.3 Data Retention
- Account data: Retained while your account is active and for a reasonable period after deletion
- Content data: Retained according to your account settings and legal requirements
- Usage logs: Typically retained for 12-24 months for security and analytics purposes
- Legal compliance: Some data may be retained longer to comply with legal obligations
7. Your Privacy Rights
7.1 Access and Control
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete information
- Deletion: Request deletion of your personal data (subject to legal requirements)
- Portability: Export your data in a machine-readable format
- Restriction: Request limitation of processing under certain circumstances
7.2 Communication Preferences
- Opt out of marketing communications at any time
- Manage notification preferences in your account settings
- Note: You cannot opt out of essential service communications
7.3 California Residents (CCPA)
California residents have additional rights including:
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
7.4 How to Exercise Your Rights
To exercise your privacy rights, contact us at:
- Email: support@blogyak.com
- Subject line: "Privacy Request"
- Include: Your account email and specific request details
8. Cookies and Tracking Technologies
8.1 Types of Cookies
- Essential Cookies: Required for basic site functionality and security
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how you use our Service
- Authentication Cookies: Manage your login sessions securely
8.2 Cookie Management
You can control cookies through your browser settings. Note that disabling certain cookies may affect Service functionality.
9. International Data Transfers
Your information may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses approved by relevant authorities
- Adequacy decisions by the European Commission (where applicable)
- Other approved transfer mechanisms under applicable laws
10. Children's Privacy
Our Service is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. AI and Automated Processing
11.1 AI Content Generation
We use AI services to generate blog content and suggestions. Your prompts and content may be processed by third-party AI providers subject to their own privacy policies.
11.2 Automated Decision Making
We may use automated systems for content suggestions and spam detection. You have the right to request human review of automated decisions that significantly affect you.
12. Changes to Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or by updating this page. Your continued use after such modifications constitutes acceptance of the updated policy.
13. Supervisory Authority
If you are in the EU and have concerns about our data processing practices, you have the right to lodge a complaint with your local data protection authority.
14. Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us: