Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains what information PubSchedule ("PubSchedule," "we," "us") collects when you use our website, dashboard, API, and the PubSchedule Bridge WordPress plugin (together, the "Service"), how we use it, and the choices you have.
1. Information We Collect
Account information
When you register, we collect your email address, a hashed password (we never store your password in plain text), and optionally your full name, company name, and timezone.
Payment information
Payments are processed by third-party providers — Stripe, PayPal, Lemon Squeezy, Paddle, or NOWPayments (for cryptocurrency). We do not store your full card number or bank details. We store only the customer/subscription identifiers those providers give us, so we can manage your subscription and issue receipts.
Usage and quota data
We log how many articles you generate, when, in which language, and whether generation used our managed AI keys ("Platform AI") or your own connected API key ("BYOK"). This is required to enforce your plan's limits and to give you accurate usage figures on your dashboard.
Your own LLM API keys (BYOK)
If you connect your own Anthropic, OpenAI, OpenRouter, DeepSeek, or other compatible API key, it is transmitted directly and encrypted before storage — it is never stored in your WordPress database. We use envelope encryption (a unique encryption key per stored credential, itself encrypted with a master key) so that no single leaked record exposes any other customer's key. We use this key only to make the specific LLM calls you request.
Generated content
Articles generated through the Service are stored so you can review, approve, or reject them in your editorial queue, and so we can show your generation history. Draft and rejected articles are retained the same way as published ones unless you delete them.
Technical and device data
We log IP addresses associated with API requests. This is used exclusively for abuse detection (for example, identifying a token being shared across many unrelated sites) and rate limiting — not for advertising or tracking you across other services.
News source data
If you configure RSS/Atom news sources, our system fetches only public headlines and article URLs from those feeds to use as topic signals. We do not scrape or store the full text of third-party articles.
Cookies and session data
We use a session cookie/token to keep you signed in to your dashboard. We do not use third-party advertising or tracking cookies.
2. How We Use Information
- To create and maintain your account and subscription
- To operate the article-generation pipeline you configure (news fetching, AI generation, WordPress publishing)
- To enforce plan limits (monthly Platform AI quota, daily BYOK quota, language/source/keyword caps)
- To send transactional emails — verification, password reset, billing receipts, abuse alerts, and service notices
- To detect and prevent abuse of the Service (e.g. a single token used across an unreasonable number of sites)
- To provide customer support when you contact us
We do not sell your personal information, and we do not use your account data to train AI models.
3. Third Parties We Share Data With
We use the following categories of subprocessors to operate the Service. Each only receives the data it needs to perform its function:
- Payment processors — Stripe, PayPal, Lemon Squeezy, Paddle, NOWPayments (billing and subscription management)
- Email delivery — Resend (transactional emails only; no marketing lists without separate consent)
- AI providers — Anthropic, OpenAI, OpenRouter, DeepSeek, or a custom OpenAI-compatible endpoint you configure. When you use "Platform AI," your prompt data is sent to our managed provider account. When you use "BYOK," it is sent under your own API key and is subject to that provider's own terms and data-handling policies.
- Infrastructure — our hosting and database providers, who store the data described above on our behalf under standard hosting agreements.
4. Data Security
API keys and service tokens are encrypted at rest (AES-256-GCM for provider keys, with per-record envelope encryption; AES-256 for the WordPress-side connection token). All traffic between the plugin, our API, and your browser is encrypted in transit via TLS. Access to production systems is restricted to what's operationally necessary.
No method of transmission or storage is 100% secure. We work to protect your information but cannot guarantee absolute security.
5. Data Retention
We retain account and usage data for as long as your account is active, plus a reasonable period afterward for legal, billing, and abuse-prevention purposes. Database backups are retained on a rolling basis (30 days by default) and then deleted.
6. Your Rights
You can, at any time:
- Access and update your account information from your dashboard
- Delete your saved API keys and news sources yourself
- Request full account deletion — submit a request from your dashboard, which is reviewed and processed by our team
- Export or ask for a copy of your stored data by contacting us
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing. Contact us to exercise any of these rights.
7. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children.
8. International Data Transfers
Your information may be processed in countries other than your own, including the country where our hosting infrastructure and subprocessors operate. We take steps to ensure it receives an adequate level of protection wherever it is processed.
9. Changes to This Policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you by email.
10. Contact Us
Questions about this policy or your data can be sent to hello@pubschedule.com.