Last updated: September 2026
When you buy: your email address and payment details, processed by Stripe. We never see your card number.
Purchase and recovery emails: Resend processes your checkout email address and transactional message contents, including your license and private purchase link, to deliver purchase confirmations and requested recovery emails. Our recovery lookup uses a keyed hash of your checkout address and encrypted receipt references. Pending email payloads are encrypted, removed when Resend accepts a message, and expire after 30 days without a successful retry. Delivery markers are retained to prevent duplicate messages. Purchase references remain available for license and billing recovery.
Support emails: messages sent to our receiving support address, including sender details and attachments, are processed by Resend and forwarded to our support inbox hosted by Google. We store encrypted provider references for forwarding retries, rather than copying inbound attachments into our application database. Support correspondence is retained while needed to respond and resolve issues, or until you request deletion subject to applicable retention requirements.
When you connect a site: your site URL, admin email, WordPress version, and PHP version — sent once, at connection time, to create your account record.
When you run an action: the content you submit for processing (e.g. a post’s title and body, existing meta values, and a list of published post titles/URLs for internal-link suggestions), plus your brand context. Nothing is sent until you run an action.
When you send plugin feedback: your message, selected reply email, plugin and software versions, and connected site identity are stored so we can investigate bugs, reply when requested, and plan improvements. Feedback remains in our review inbox until it is no longer useful for support or product planning, or you ask us to delete it.
When you connect Google Search Console: Google grants the gateway a read-only refresh token, which is stored encrypted. The selected property and its search queries, pages, clicks, impressions, click-through rates, and average positions are retrieved only to provide the WordPress search-performance dashboard. Search Console data is not sent to an AI model. Disconnecting removes the stored Google token.
Challenge interest: if you register interest in the Forgotten Post Challenge, we store your name, reply email, website origin, optional note, and contact consent in encrypted form for 90 days. Our private project inbox is used to organize participation and follow up about the challenge. This is not a newsletter subscription. Public recordings, analytics, and case studies require separate agreement. A keyed hash of your network address is retained for up to one hour to limit repeated form submissions; the raw address is not stored by that rate limiter.
Internal Link Matchmaker: when you request a scan, our server downloads the submitted public article URLs and their site’s robots.txt, including supported same-site redirects. Page text is processed in memory and is not sent to an AI provider. Submitted URLs, downloaded content, and reports are not saved by the tool. Results are returned to your browser; CSV files are created there when you choose to download one. The destination site can see our crawler’s request and server network address. Keyed hashes of the requesting network address and scanned site are kept for up to one hour to limit scans; those rate-limit records do not contain raw addresses or URLs. We record aggregate scan and installation-guide click counts without article URLs or text.
On this website: anonymous traffic measurement via Vercel Web Analytics. We also keep first-party daily counters for page views, plugin install and download clicks, connection progress, first completed plugin jobs, checkout clicks, and confirmed purchases, sample-demo interactions, kit download clicks, and saved challenge interest. Those counters contain the event type, day, page path, and, when available, a campaign name from a fixed list such as “wp-weekly” or “youtube”. A recognized campaign name from the utm_source parameter is kept in tab-scoped session storage to attribute subsequent actions. Arbitrary query values are not recorded. The name does not identify a visitor. Anonymous duplicate-prevention markers are used for first-job and purchase counts. Counters and markers expire after 180 days.
We do not add raw IP addresses, cookies, emails, payment details, license keys, submitted content, arbitrary URL query values, or advertising identifiers to these first-party counters. We do not use advertising trackers.
We never use your content to train AI models. We never sell your data. Your AI provider key (BYOK mode) is posted directly to the gateway and never written to your WordPress database.
Stripe (payments), Resend (transactional emails and support receiving/forwarding), Anthropic (inference, with training opted out), Google (support email hosting and optional read-only Search Console data), Vercel (hosting and analytics), and Upstash (durable gateway, OAuth token, feedback, and anonymous aggregate analytics storage).
Email support@founderpostai.com to access, correct, export, or delete your data. Deleting your account removes your site record and content history from the gateway.