Privacy Policy
Last updated: January 21, 2026
Introduction
At HrefStack ("we", "our", or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our AI-powered SEO content generation platform ("Service").
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, password, and profile details
- Payment Information: Billing details processed securely through Stripe (we do not store full credit card numbers)
- Content Data: Articles, keywords, prompts, and other content you create or input
- Communications: Messages, feedback, and support requests you send us
1.2 Information We Collect Automatically
- Usage Data: Features used, pages visited, time spent, and interaction patterns
- Device Information: Browser type, operating system, IP address, device identifiers
- Analytics Data: Performance metrics, error logs, and service usage statistics
- Cookies and Tracking: Session data, preferences, and authentication tokens
1.3 Information from Third Parties
- Authentication Providers: Data from Google, GitHub, or other OAuth providers you use to sign in
- CMS Integrations: Connection details and credentials for platforms you integrate (Sanity, WordPress, etc.)
- Payment Processors: Transaction data from Stripe
2. How We Use Your Information
We use your information to:
- Provide the Service: Generate content, process requests, and deliver features
- Process Payments: Handle subscriptions, billing, and invoicing
- Improve Our Service: Analyze usage patterns, fix bugs, and develop new features
- Communicate: Send service updates, newsletters, and respond to inquiries
- Ensure Security: Detect fraud, prevent abuse, and maintain system integrity
- Comply with Laws: Meet legal obligations and enforce our Terms of Service
- Personalize Experience: Customize content recommendations and interface preferences
3. AI and Data Processing
3.1 AI Content Generation
When you use our AI features, your inputs (keywords, prompts, content briefs) are processed by third-party AI providers including OpenAI, Anthropic, and Google. These providers may use your inputs to:
- Generate content based on your requests
- Improve their AI models (unless you opt out where available)
- Comply with their respective privacy policies
3.2 Data Retention for AI
We store your AI-generated content on our servers for as long as you maintain an active account. You can delete your content at any time through your account settings.
4. Data Sharing and Disclosure
4.1 Third-Party Service Providers
We share your data with:
- AI Providers: OpenAI, Anthropic, Google (for content generation)
- Payment Processors: Stripe (for billing and payments)
- Hosting Services: Cloud providers for data storage and computing
- Analytics Tools: Services that help us understand usage patterns
- CMS Platforms: Platforms you choose to publish content to
4.2 Legal Requirements
We may disclose your information if required by law, legal process, or to:
- Comply with legal obligations or valid government requests
- Enforce our Terms of Service or protect our rights
- Prevent fraud, security threats, or illegal activities
- Protect the safety of our users or the public
4.3 Business Transfers
If HrefStack is involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Access Controls: Limited employee access on a need-to-know basis
- Authentication: Secure password hashing and optional two-factor authentication
- Monitoring: Regular security audits and intrusion detection
- Compliance: Adherence to security best practices and standards
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you of any data breaches as required by law.
6. Your Rights and Choices
6.1 Access and Control
You have the right to:
- Access: Request a copy of your personal data
- Update: Correct inaccurate or incomplete information
- Delete: Request deletion of your account and data
- Export: Download your content in a portable format
- Opt-Out: Unsubscribe from marketing communications
- Restrict: Limit how we use certain data
6.2 Exercising Your Rights
To exercise these rights, contact us at hello@hrefstack.com. We will respond to your request within 30 days.
6.3 Cookie Management
You can control cookies through your browser settings. Note that disabling certain cookies may limit Service functionality.
7. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy. Specifically:
- Account Data: Retained while your account is active
- Content: Stored until you delete it or close your account
- Payment Records: Kept for 7 years for tax and accounting purposes
- Usage Logs: Typically retained for 90 days
- Legal Requirements: Data may be retained longer if required by law
After account deletion, we anonymize or delete your data within 30 days, except where retention is required by law.
8. International Data Transfers
HrefStack operates globally, and your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses approved by regulatory authorities
- Adequate data protection frameworks
- Compliance with applicable data protection laws
9. Children's Privacy
Our Service is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
11. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation:
- Right to access, rectify, and erase your personal data
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page
- Updating the "Last updated" date
- Sending you an email notification (for significant changes)
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: hello@hrefstack.com
Data Protection Officer: privacy@hrefstack.com
By using HrefStack, you acknowledge that you have read, understood, and agree to this Privacy Policy.