Who this policy applies to
This policy applies to visitors, account holders, and users of FullAutoBlog.
Where this page refers to "we", "us", or "our", it means the operator of FullAutoBlog, currently identified as [Add legal owner or company name before publication] until final legal entity details are published.
Data we process
FullAutoBlog currently processes the categories of data needed to authenticate users, manage automations, generate content drafts, and publish to connected WordPress websites.
- Account and identity data from supported OAuth providers, such as email address, provider account identifier, and basic profile information made available during sign-in.
- Profile and access-control data, such as plan, role, internal profile identifiers, and administrative overrides needed to enforce plan and access rules.
- Automation settings, including source URLs, RSS feed URLs, publishing intervals, language selection, content-generation settings, and connected WordPress site labels.
- Encrypted WordPress credentials and related connection details needed to publish content to user-selected WordPress sites.
- Generated content, article drafts, publishing metadata, processed-item records, and automation statistics.
- Operational logs, error messages, and service health or scheduling data needed to secure, troubleshoot, and improve the service.
- Essential authentication cookies and related session information.
How we use data
We use personal data only to the extent reasonably necessary to provide, secure, maintain, and improve the service.
- To create and manage user accounts and authenticate sign-in sessions.
- To store automation settings and execute scheduled publishing workflows.
- To generate or rewrite content at the user's request.
- To connect to user-designated WordPress websites and submit posts on the user's behalf.
- To prevent abuse, enforce plan limits, protect infrastructure, and investigate misuse.
- To respond to support requests, privacy requests, and account-deletion requests.
- To comply with legal obligations, resolve disputes, and protect legal claims.
Legal bases and user responsibilities
Where EU or UK data-protection rules apply, our processing typically relies on the performance of a contract, legitimate interests in operating a secure service, compliance with legal obligations, and, where applicable, user consent.
Users are responsible for ensuring they have a lawful basis to upload, import, rewrite, or publish third-party content and for making sure the content they publish complies with applicable law.
Cookies and session storage
Based on the current implementation in this repository, FullAutoBlog uses cookies that are necessary for authentication and session continuity.
No non-essential analytics, advertising, or behavior-tracking cookies were identified in the current application code reviewed for this release.
If non-essential cookies or trackers are added later, this policy and the Cookie Policy should be updated and any legally required consent tools should be implemented before those technologies go live.
Service providers and third parties
To run the service, FullAutoBlog may rely on infrastructure and integration providers selected by the operator and configured in the application.
- Authentication and application data providers, such as Supabase.
- Queueing, scheduling, rate-limiting, or caching providers, such as Upstash services.
- OAuth identity providers chosen by the user, currently Google and GitHub.
- WordPress websites, hosting providers, and endpoints designated by the user for publishing.
Retention
We keep data only for as long as it is needed to operate the service, secure the platform, maintain backups, meet legal obligations, or resolve disputes.
Account data, automations, WordPress connection settings, generated articles, and logs may remain stored until the user deletes them, closes the account, or asks us to delete them, subject to any retention period needed for legal, security, fraud-prevention, or backup purposes.
Security
FullAutoBlog stores WordPress publishing credentials in encrypted form rather than keeping a user's main WordPress admin password in plain text.
No online service is perfectly secure, so users should use strong credentials, revoke no-longer-needed WordPress application passwords, and review their publishing output before publication.
User rights and contact
Users can contact hello@fullautoblog.com to request access, correction, deletion, restriction, objection review, or other privacy help, subject to verification and applicable law.
Privacy and deletion requests should be sent from the account email where possible and should include enough information to identify the relevant account.
International transfers and updates
Depending on the providers chosen to operate the service, data may be processed in countries outside the user's home jurisdiction. Additional provider-specific safeguards may apply.
This policy should be updated whenever the operator finalizes legal-entity details, introduces new subprocessors, adds analytics or advertising tools, or materially changes how data is processed.
