Privacy Policy
Version 2026-08-03 · Draft — under review. The short version: we hold the minimum we need, you can download all of it, and you can delete all of it yourself.
1. Who we are
Content Mapped (“we”) is the data controller for the personal data described here. Contact: hello@contentmapped.com.
2. What we hold, and why
- Your account: your email address and a password (the password is hashed by our authentication provider, Supabase — we never see or store it in readable form). Used to sign you in and, occasionally, to send you service email.
- Your sites' published content:the addresses of sites you add and what our crawler reads from their public pages — titles, text, links, categories. This is the product: it's how the reports are made. We only read what your site already publishes.
- Credentials you choose to add: WordPress application passwords (for restricted-content reading or the opt-in taxonomy feature) and AI API keys. Both are encrypted (AES-256-GCM) before storage, decrypted only server-side at the moment of use, and are never displayed, logged, or included in exports — not even your own.
- Usage events: a small activity log (signed up, added a site, crawl finished, viewed report, and similar) so we can tell whether the product is working for people. It records what you did, not keystrokes or page-by-page tracking.
- Early-access requests: if you left your email on our marketing site, we hold that address only to contact you about access. Email hello@contentmapped.com to have it removed at any time.
We use no analytics cookies — the only cookies are the ones that keep you signed in.
3. Where it lives
Your data is stored in a Supabase-hosted Postgres database, processed on our own server (Hostinger), and the marketing site is served by Cloudflare. Server logs contain internal account identifiers (random UUIDs) but are scrubbed of emails, passwords, and keys by design, and are rotated after roughly 30 days.
4. Who else sees it
Nobody, by default. If you add your own AI keys, the content of your posts is sent to the provider those keys belong to (OpenRouter, OpenAI, or Google) to power the AI features — that's your choice, under your account with them, and switching it off is as simple as removing the key. We don't sell data, share it with advertisers, or use your content to train anything.
5. How long we keep it, and how you delete it
Everything is kept while your account exists, because the product's memory (crawl history, change tracking) is the point. When you want out:
- Download my data (My Account) gives you everything in one JSON file — sites, pages, links, settings, activity. Keys and passwords excluded, as above.
- Delete my account(My Account) erases your sign-in, sites, indexed content, links, entities, settings, encrypted credentials, and activity log — hard deletion, not archiving. By default there's a 7-day cooling-off period you can cancel; “delete immediately” skips it. An early-access request under the same email is removed too.
- What survives deletion: one anonymous row of counts — how many sites and pages the account had, how long it existed, which plan it was on. It contains no email, no site addresses, and no identifier that can be linked back to you. We keep it so we can understand usage honestly without keeping you.
6. Your rights
Under UK GDPR you can ask for access, correction, deletion, portability, or restriction of your personal data. The export and deletion tools above are those rights, self-serve; anything else, email hello@contentmapped.comand we'll respond within a month. If you're unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk).
7. Changes
Material changes to this policy are announced in the app and versioned at the top of this page.