Privacy Policy
Privacy Policy
Last updated: August 16, 2026
Contentcron is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights. We never sell your personal data.
Data we collect
Identity and access
When you sign up, we collect your email address, name, and team membership. We use this to sign you in, run your team, and send service communications such as pipeline failure notices and important product updates.
Billing information
Payment details are processed directly by our payment processor (Stripe) and never touch Contentcron servers. We retain transaction records and billing details for invoicing and fraud detection.
Crawled website content
When you create a project, Contentcron crawls the website and blog URLs you configure, your public marketing pages and posts, to build your brand profile: voice, company facts, and style examples. We crawl only sites you explicitly configure, and we store the resulting profile (which you can view, edit, or delete in the app), not a copy of your whole site.
GitHub data
The Contentcron GitHub App is scoped to repository contents (read/write), pull requests (read/write), and repository metadata (read). With that access we read existing posts to infer your format, create branches and commits, open PRs, and read PR comments on Contentcron’s own PRs to drive revisions. We do not clone your repository; access is per-file over GitHub’s API. Uninstalling the App from GitHub revokes all of this immediately.
Google Search Console data
If you connect Google Search Console, Contentcron requests the read-only scope https://www.googleapis.com/auth/webmasters.readonly and the email scope. You choose which single property the project uses. With that access we read Search Analytics data for that property only: per-page clicks, impressions, and average position, and the search queries the property already ranks for. We store the Google account email you connected with, the property you selected, an OAuth refresh token, and the per-article clicks, impressions, and average position shown in the app. The access is read-only: Contentcron cannot submit sitemaps, request indexing, or change anything in your Search Console account.
Generated content and pipeline records
We store the articles, topics, revisions, and pipeline run records (step, status, timestamps, token counts, errors) the Services produce for you, with access controlled per team by row-level security.
Cookies
We use first-party cookies for authentication and session management in the app. We do not use third-party tracking cookies or advertising cookies, and this marketing site sets no analytics cookies.
How we use your data
- To provide, maintain, and improve the Contentcron service
- To research, write, and revise articles for your projects
- To show how your published articles perform in Google Search, and to pick and refresh topics based on the queries your site already ranks for
- To authenticate you and manage your account and team
- To process payments and send invoices
- To send service-related communications, such as pipeline failures and security notices
- To detect and prevent fraud and abuse
- To comply with legal obligations
AI processing
Content generation runs on Anthropic’s API (Claude). Brand profiles, style examples, repository posts, research material, and PR comment threads are sent to Anthropic to research, write, and revise articles. If you have connected Search Console, the striking-distance queries for your property (the query text, the page it points at, its impressions, and its average position) are sent along with them so the topic engine can weight what you already rank for. Per Anthropic’s commercial API terms, none of this data is used to train their models.
Google user data and Limited Use
Contentcron’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Search Console data only to provide and improve the user-facing features you connected it for: article performance reporting, topic selection, and automatic refreshes of decaying articles.
- We do not sell it, and we never use it for advertising of any kind.
- We transfer it only as needed to run those features (our hosting and database providers, and Anthropic for topic selection as described above), to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use it to develop, improve, or train generalized or non-personalized AI or machine learning models, and our AI provider does not train on it either.
- No human at Contentcron reads it, except with your explicit consent (for example while handling a support request), for security purposes such as investigating abuse, or where required by law.
Disconnecting Google Search Console
You can disconnect at any time from Integrations in the app. That deletes the stored refresh token, the connected Google account email, the selected property, and stops all further syncing; the performance figures already attached to your articles are removed with the project or on account deletion. You can independently revoke Contentcron’s access from your Google Account at myaccount.google.com/permissions, which takes effect immediately.
Data access and disclosure
Contentcron personnel access your account data only with your permission (for example, when troubleshooting a support request) or as a last resort when investigating potential abuse. We may disclose data when legally required or to the third-party subprocessors listed on our Subprocessors page.
Your rights
Under the GDPR and other applicable data protection laws, you have the following rights:
- Right to know what personal data we collect and why
- Right of access: request a copy of your personal data
- Right to correction: correct inaccurate personal data
- Right to erasure: request deletion of your personal data (this may prevent continued service use)
- Right to restrict processing: limit how we use your data
- Right to object to our processing of your data
- Right to portability: receive your data in a machine-readable format
- Right to complain: lodge a complaint with your local supervisory authority
To exercise any of these rights, contact us at ben@contentcron.com.
Security
All data in transit is encrypted via TLS. Data at rest is encrypted by our hosting providers. Access to your data is scoped by team membership and enforced in the database with row-level security. GitHub access uses short-lived installation tokens, and webhook payloads are signature-verified. The Google OAuth refresh token is stored server-side in a column that is unreadable by the application’s user-facing database role, is never sent to the browser or exposed through our API, and is exchanged for a short-lived access token only when a sync runs.
Data retention
Account data is retained for the duration of your account. Delete a project and its brand profile, topics, articles, and pipeline records go with it. Upon account deletion, your data is permanently removed from active systems within 30 days and from backups within 60 days, excepting minimal records we need for security or legal reasons. Content already merged into your repository is yours and stays exactly where you put it.
If we crawled your site
If Contentcron crawled your site because one of our customers configured it as their own property and you believe that was wrong, contact us and we will stop crawling it and delete the derived profile.
Subprocessors
We use a small number of third-party services to operate Contentcron. See our Subprocessors page for the full list.
Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated to account holders. The “last updated” date at the top reflects the most recent revision.
Contact
Questions about this privacy policy? Contact us at ben@contentcron.com.