Privacy Policy

Version 2026-08-03 · Draft — under review. The short version: we hold the minimum we need, you can download all of it, and you can delete all of it yourself.

1. Who we are

Content Mapped (“we”) is the data controller for the personal data described here. Contact: hello@contentmapped.com.

2. What we hold, and why

We use no analytics cookies — the only cookies are the ones that keep you signed in.

3. Where it lives

Your data is stored in a Supabase-hosted Postgres database, processed on our own server (Hostinger), and the marketing site is served by Cloudflare. Server logs contain internal account identifiers (random UUIDs) but are scrubbed of emails, passwords, and keys by design, and are rotated after roughly 30 days.

4. Who else sees it

Nobody, by default. If you add your own AI keys, the content of your posts is sent to the provider those keys belong to (OpenRouter, OpenAI, or Google) to power the AI features — that's your choice, under your account with them, and switching it off is as simple as removing the key. We don't sell data, share it with advertisers, or use your content to train anything.

5. How long we keep it, and how you delete it

Everything is kept while your account exists, because the product's memory (crawl history, change tracking) is the point. When you want out:

6. Your rights

Under UK GDPR you can ask for access, correction, deletion, portability, or restriction of your personal data. The export and deletion tools above are those rights, self-serve; anything else, email hello@contentmapped.comand we'll respond within a month. If you're unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk).

7. Changes

Material changes to this policy are announced in the app and versioned at the top of this page.