Portfolio Supported AIs Solutions Tasks Email Archive Integrations Pricing

Get Started

ChatGPT

ChatGPT

Start directly →

Ready
Claude

Claude

Directory Connector →

Ready
Mistral

Mistral

Directory Connector →

Ready

Dashboard Always available

1. Introduction

WebsitePublisher.ai ("we", "our", or "the Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-native website publishing platform.

By using WebsitePublisher.ai, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use the Service.

Data Controller: M25 — Brandemaat 78, 7943 EX Meppel, the Netherlands. Chamber of Commerce (KvK): 04072374. Contact: privacy@websitepublisher.ai

2. Information We Collect

Information You Provide

Data Type Purpose Required
Email address Account creation, authentication, notifications Yes
Google account profile (name, email address, profile picture) — only if you choose Sign in with Google Account creation and sign-in (see section 5) No
Google Sheets content you choose to sync — only if you connect the Google integration Syncing that content into your project, e.g. as leads (see section 5) No
Emails you send through the Gmail integration — only if you enable Gmail sending Delivering those emails from your own Gmail account; not stored (see section 5) No
Project names Organizing your websites Yes
Website content Publishing and hosting your websites Yes
Custom domain names Domain configuration (paid plans) No

Information Collected Automatically

Data Type Purpose
IP address Security, fraud prevention, rate limiting
Browser type and version Service optimization, troubleshooting
Device information Service optimization
Usage data (pages visited, features used) Service improvement, analytics
API request logs Debugging, security monitoring
Timestamps Audit trails, troubleshooting

Content You Publish

When you (or an AI assistant acting on your behalf) publish content through our Service, that content is stored on our servers and served publicly via your website URL. This includes HTML pages, images, and other assets.

Data Collected by Websites You Publish

Websites published through the Service can collect data from their own visitors — for example contact form submissions and lead capture, visitor login email addresses (visitor authentication), order and shipping details on webshops, and site analytics. For this data the site owner is the data controller and WebsitePublisher.ai acts as a data processor: we store and process it solely on the site owner's behalf and do not use it for our own purposes.

Site owners are responsible for informing their visitors and obtaining any consent required by law. Forms and data collection on published websites must not be used to collect restricted categories of data such as payment card numbers, government identification numbers, or health or biometric data. Payments on published webshops are handled entirely by the configured payment provider (such as Mollie or Stripe): card details are entered on the provider's hosted checkout page and never pass through or are stored on our servers.

Third-Party Credentials (Vault)

If you use our integrations feature (IAPI), you may store API credentials for third-party services such as Twilio, Stripe, Mailgun, or SendGrid. These credentials are stored in our Vault (VAPI) using AES-256 encryption and are only decrypted at the moment of an API call made on your behalf. We do not use these credentials for any purpose other than executing the integrations you configure.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide the Service - Host and serve your websites, manage your account
  • Authentication - Verify your identity via email OTP codes or Sign in with Google
  • Communication - Send transactional emails (OTP codes, security alerts, abuse notifications)
  • Security - Detect and prevent fraud, abuse, and unauthorized access
  • Content moderation - Scan published content for prohibited material
  • Service improvement - Analyze usage patterns to improve the Service
  • Legal compliance - Comply with legal obligations and respond to lawful requests

📧 We do not sell your email address or send marketing emails without your consent.

4. AI Assistants & Third Parties

How AI Assistants Access Your Data

WebsitePublisher.ai is designed to work with AI assistants like Claude, ChatGPT, and Grok. When you authorize an AI assistant to use the Service on your behalf:

  • The AI assistant receives an API token that grants access to your projects
  • The AI assistant can create, read, update, and delete content within authorized projects
  • Your interactions with the AI assistant are governed by that AI provider's privacy policy
  • We do not have access to your conversations with AI assistants

Third-Party Services

We use the following third-party services:

Service Purpose Data Shared
Google (Sign in with Google and Google integration) Optional sign-in with your Google account, and the optional Google integration (syncing or exporting Google Sheets, sending email from your Gmail account) Sign-in: Google shares your name, email address and profile picture with us after you approve it. Integration: we read only the spreadsheets you configure, create new spreadsheets for exports, and pass emails you send through Gmail to Google for delivery — always with the permissions you granted.
Google Analytics Website analytics Usage data, anonymized IP
PostHog (EU) Product analytics (EU-hosted) Usage events, account identifiers
DigitalOcean Spaces CDN & asset storage Public website assets (images, files)
Resend Transactional email (OTP codes, notifications) Email address, message content
Mollie Payment processing (subscriptions, domain purchases and webshop orders) Email address, billing information. Card details are entered directly on Mollie's secure hosted checkout and never pass through or are stored on our servers.
WebSumo Hosting infrastructure for published websites Published website content, subdomain

We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5. Google Sign-In and Integrations

Sign in with Google

You can sign in to the WebsitePublisher.ai dashboard with your Google account instead of a one-time email code. This is optional. Only after you approve it on Google's own sign-in screen, Google shares the following with WebsitePublisher.ai:

  • Your name
  • Your email address
  • Your profile picture

We use this information only to create your WebsitePublisher.ai account, to recognise you when you sign in, and to show you which account you are signed in with. We never see or store your Google password. Signing in with Google does not give us access to your Gmail, Google Drive, Google Sheets, contacts, calendar or any other data in your Google account.

Your account details are stored on our servers in the European Union and kept for as long as your account exists. When you delete your account, they are deleted within 30 days.

Google integration (optional, paid plans)

Separately from signing in, an account holder can connect a Google account to a project with the Google integration. This always starts with your explicit approval on Google's own consent screen, where you see and choose the permissions you grant. Each permission is only requested when a feature needs it:

  • Google Sheets (read-only): we read the content of the spreadsheets and tabs that you, or an AI assistant acting on your behalf, configure for syncing — for example to keep leads in your project in sync with a Google Sheet. This permission cannot change or delete anything.
  • Google Drive (only files created by WebsitePublisher.ai): we create new spreadsheets in your Google Drive for exports and write the exported data into them. This permission gives no access to any other file in your Drive.
  • Gmail (send only): we send the emails that you, or an AI assistant acting on your behalf, ask the integration to send, from the connected Gmail account. This permission cannot read, search, change or delete any email in your mailbox.

We also receive the email address of the connected Google account, to show which account is connected.

  • How we use it: only to provide the sync, export or email sending you set up. Data synced into a project is handled like other data collected by that project: the site owner is the data controller and WebsitePublisher.ai acts as processor (see section 2).
  • Storage: access tokens are stored encrypted in our Vault and are never shown or logged. For each sync we keep technical state (row identifiers, fingerprints and run logs) to prevent duplicates. Emails sent through Gmail are passed to Google for delivery and are not stored by us; we only keep a count of emails sent per project per day to enforce sending limits.
  • Removal: you can disconnect at any time. This revokes our access at Google and deletes the stored tokens immediately. Deleting a sync deletes its technical state. Data already synced into your project stays until you delete it, or until the project or account is deleted. Spreadsheets created for exports are files in your own Google Drive; you keep or delete them yourself.

How we treat Google user data

We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties, except where needed to provide the Service or to comply with the law. We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models. Our staff do not read Google user data, except with your explicit permission (for example for a support request), when needed for security purposes such as investigating abuse, or to comply with applicable law.

You can request deletion at any time via privacy@websitepublisher.ai, and you can remove WebsitePublisher.ai's access to your Google account at any time at myaccount.google.com/permissions.

WebsitePublisher.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Cookies & Tracking

Cookies We Use

Cookie Purpose Duration
Session cookie Maintain login state Session / 30 days
_ga, _gid (Google Analytics) Analytics and usage tracking 2 years / 24 hours

Managing Cookies

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service, particularly login and session management.

Do Not Track

We currently do not respond to "Do Not Track" browser signals. However, you can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

7. Data Storage & Security

Where We Store Data

Your data is stored on servers located in the Netherlands (EU). Website content is distributed globally via CDN for performance.

Security Measures

We implement industry-standard security measures to protect your data:

  • All data transmitted over HTTPS/TLS encryption
  • API tokens are hashed before storage
  • Rate limiting to prevent brute force attacks
  • Regular security audits and monitoring
  • Access controls and authentication for all systems

While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your data for as long as necessary to provide the Service and fulfill the purposes described in this policy:

Data Type Retention Period
Account information Until account deletion + 30 days
Google account profile (Sign in with Google) Until account deletion + 30 days
Google integration access tokens Until you disconnect the integration (then deleted immediately)
Google sync state (row identifiers, fingerprints, run logs) Until the sync is deleted; run logs are limited to the most recent runs per sync
Emails sent through the Gmail integration Not stored by us; only a daily count of sent emails per project, kept for one day
Published website content Until deletion or account termination
Data collected by published websites (form submissions, visitor accounts, orders, synced leads) Managed by the site owner; removed when the site owner deletes it or when the project or account is deleted
API logs 90 days
Security/abuse logs 1 year
Expired OTP codes 24 hours
Revoked API tokens 30 days (for audit), then deleted

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

For All Users

  • Access - Request a copy of the personal data we hold about you
  • Correction - Request correction of inaccurate data
  • Deletion - Request deletion of your account and associated data
  • Data portability - Export your website content

For EU/EEA Residents (GDPR)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to object - Object to processing of your data
  • Right to restrict processing - Request limitation of processing
  • Right to lodge a complaint - File a complaint with your local data protection authority

For California Residents (CCPA)

California residents have the right to:

  • Know what personal information is collected
  • Know whether personal information is sold or disclosed and to whom
  • Opt out of the sale of personal information (we do not sell your data)
  • Access your personal information
  • Request deletion of your personal information
  • Not be discriminated against for exercising your rights

How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@websitepublisher.ai. We will respond within 30 days.

10. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@websitepublisher.ai.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • EU Standard Contractual Clauses for transfers outside the EEA
  • Data processing agreements with all third-party processors
  • Compliance with applicable data protection laws

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you by email for material changes
  • Post a notice on the Service

We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

For data protection inquiries in the EU, you may also contact your local data protection authority.