Skip to content
Blogotter
Sign inStart a free trial

Legal

Privacy policy

Last updated: 28 July 2026

This notice explains how Blogotter handles personal data, as required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). It covers this website (blogotter.com) and the application (app.blogotter.com).

1. Who is responsible for your data

The data controller is Iacopo Bonandi, sole proprietorship “BONANDI IACOPO”, Lugo (RA), Italy — VAT no. IT02776330397.

For anything in this notice, including exercising your rights, write to privacy@blogotter.com.

2. What data we collect, why, and on what legal basis

  • Account data — your name, email address and password. The password is stored only as a cryptographic hash; we cannot read it. Used to create and operate your account, verify your email and let you sign in. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Workspace content — the sites you connect, editorial briefs, keywords, generated articles and images, and the publishing credentials you store (kept encrypted at rest). Used to provide the service you signed up for. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Billing data — handled by Stripe. We never see or store your card number; we keep your subscription status and the invoice records the law requires us to retain. Legal bases: performance of a contract (Art. 6(1)(b)) and legal obligation for tax records (Art. 6(1)(c) GDPR).
  • Technical and security logs — when you sign in we record a one-way hash of your IP address and a truncated browser identifier against your session, and we count failed login attempts per hashed IP to lock out brute-force attacks. Security-relevant actions are written to an audit log. Legal basis: our legitimate interest in keeping accounts and the platform secure (Art. 6(1)(f) GDPR).
  • Cookies — a single session cookie in the application, described in section 7 below.

We do not use your data for advertising, we do not build advertising profiles, and we do not sell personal data to anyone.

3. Who we share data with

We use a small number of service providers (processors under Art. 28 GDPR) to runBlogotter. Each one receives only what its job requires:

  • Anthropic, PBC (United States)

    Role: Generates article text from the briefs, keywords and drafts in your workspace.

    Data involved: Workspace content sent for generation: site briefs, keywords, article drafts and related instructions. No account credentials are shared.

    Transfer safeguard: EU Standard Contractual Clauses, as set out in Anthropic's data transfer terms.

  • Stripe, Inc. (United States)

    Role: Processes subscription payments. Card details are entered on Stripe's own pages and never reach our servers.

    Data involved: Your email address, a workspace reference, and the payment and invoice data Stripe needs to bill you.

    Transfer safeguard: Certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses as a fallback.

  • Cloudflare, Inc. (United States (global network))

    Role: Serves this website and the application (DNS, CDN, secure tunnel), runs the Turnstile bot check on signup, and runs the Worker that relays our transactional email.

    Data involved: IP address and browser metadata of every request; the Turnstile challenge on the signup form; transactional email content in transit through the relay.

    Transfer safeguard: Certified under the EU-U.S. Data Privacy Framework.

  • Resend, Inc. (United States)

    Role: Delivers our transactional email: verification links, password resets, invitations, billing and deletion notices.

    Data involved: Recipient email address, message subject and body.

    Transfer safeguard: Certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses in its data processing addendum.

  • Features and Labels, Inc. (fal.ai) (United States)

    Role: Generates the images that accompany articles.

    Data involved: Image prompts derived from your article content. No account data is shared.

    Transfer safeguard: Standard Contractual Clauses, as provided for in fal's terms.

  • DataForSEO OÜ (Estonia (European Union))

    Role: Provides keyword search volume and ranking data for planning.

    Data involved: The keywords and website domains configured in your workspace. No account data is shared.

    Transfer safeguard: Established in the EU; its own onward transfers rely on adequacy decisions or Standard Contractual Clauses.

  • Google LLC (Search Console) (United States)

    Role: Supplies search performance data for your own sites — only if you connect a Search Console service account.

    Data involved: The service account credentials you provide and the search performance data of your connected sites.

    Transfer safeguard: Certified under the EU-U.S. Data Privacy Framework.

Beyond these providers, we disclose personal data only if the law requires it.

4. Transfers outside the European Union

Several of the providers above are established in the United States. Where a provider is certified under the EU-U.S. Data Privacy Framework, the transfer relies on the European Commission's adequacy decision for that framework. Where it is not, the transfer is covered by the European Commission's Standard Contractual Clauses, incorporated into our agreement with the provider. The safeguard used for each provider is listed in section 3.

5. How long we keep data

  • Sessions — a sign-in session expires after 12 hours; the hashed IP and browser identifier are stored with it. Failed-login counters reset on a rolling 15-minute window.
  • Account and workspace data — kept while your account is active. When a subscription is cancelled, the workspace enters a 90-day retention period during which it is read-only and can be reactivated. Stored publishing and Search Console credentials are destroyed at the start of that period. We email the workspace owner 30 days, 7 days and 1 day before the deadline.
  • Deletion — at the end of the retention period, workspace media, database records and the Stripe customer link are permanently purged. What remains is a tombstone record — the workspace identifier and deletion timestamps, with no content and no credentials — kept as proof that the deletion happened.
  • Billing and tax records — invoicing data is kept for 10 years, as required by Article 2220 of the Italian Civil Code and tax law. This is the one category that survives workspace deletion.

6. Your rights

Under Articles 15 to 21 GDPR you can ask us, at any time, to:

  • access the personal data we hold about you;
  • rectify data that is inaccurate or incomplete;
  • erase your data (“right to be forgotten”);
  • receive your data in a portable, machine-readable format;
  • restrict processing while a dispute is resolved;
  • object to processing based on legitimate interest.

Write to privacy@blogotter.com and we will respond within one month. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the supervisory authority of your own EU member state.

7. Cookies

This website (blogotter.com) sets no cookies at all. It is a static page that runs no JavaScript and loads nothing from third parties — its security policy forbids scripts outright.

The application (app.blogotter.com) uses one cookie: a session cookie that keeps you signed in and expires after 12 hours. It is strictly necessary to provide the service you requested, which under the ePrivacy rules and the Italian Garante's cookie guidelines means it requires no consent — which is why you see no cookie banner. There are no analytics, advertising or third-party tracking cookies anywhere on either site.

8. How we protect data

All traffic is encrypted in transit (TLS). Passwords are stored as cryptographic hashes; stored third-party credentials are encrypted at rest; IP addresses in security logs are stored as one-way hashes. Access to production systems is restricted to the controller.

9. Changes to this notice

If this notice changes in a way that affects you, we will update the date at the top and, for significant changes, tell account holders by email. The current version is always at blogotter.com/privacy.

Blogotter — SEO articles, planned and published.
© 2026 Blogotter. All rights reserved.

Open the appSign inStart a free trialPrivacyTerms

Iacopo Bonandi — sole proprietorship “BONANDI IACOPO”, Lugo (RA), Italy — VAT no. IT02776330397