Privacy Policy
Effective: September 1, 2026 · Last updated: September 1, 2026
What changed in this version: we added Voice notes, an optional feature that transcribes audio you upload. It does not change how we handle data you have already given us — no audio is processed until you give separate consent inside the app, and you can withdraw that consent at any time in Settings.
This Privacy Policy explains how Autobyline ("we", "us", or "our") collects, uses, and protects personal data when you use our service at autobyline.io and app.autobyline.io (the "Service").
We are committed to handling personal data in compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.
1. Information We Collect
1.1 Information you provide
- Account information: email address, display name, OAuth identifier (Google).
- Tenant settings: company name, country (for trend localization), preferred article language.
- Content: prompts you submit, articles you generate, journalist configurations.
- Integration credentials: WordPress site URLs and Application Passwords you connect (stored encrypted).
- Voice recordings (Voice notes): audio files you upload for transcription, the transcript produced from them, and any names you provide to improve recognition. Recordings may contain the voices and personal details of other people; you confirm for each upload that you have the right to record and use the audio.
1.2 Information collected automatically
- Usage data: API requests, feature usage, error logs (30-day retention).
- Technical data: IP address, browser type, OS, request timestamps (for security and abuse prevention).
- Cookies: session cookies for authentication. No third-party advertising cookies.
1.3 Information from third parties
- Polar.sh (payments): billing email, payment status, invoice records. Card data is processed by Polar.sh and Stripe; we never see or store full card numbers.
- Google OAuth: email, name, profile picture URL (when you sign in with Google).
2. How We Use Your Information
- Provide the Service (authenticate you, generate articles, publish to your sites).
- Transcribe audio you upload to Voice notes, and let you review and correct the transcript before turning it into an article.
- Process payments via Polar.sh (Merchant of Record).
- Send transactional emails (welcome, receipts, account notifications).
- Send marketing emails only with your explicit opt-in consent (you can withdraw anytime).
- Monitor abuse, fraud, and security threats.
- Comply with legal obligations (tax records, law enforcement requests).
3. Legal Bases (GDPR)
- Contract: processing necessary to provide the Service you signed up for.
- Legitimate interest: security, abuse prevention, service improvement.
- Consent: marketing emails, optional cookies, and Voice notes — you give separate in-app consent before any audio is processed, and you can withdraw it at any time in Settings. Withdrawing stops new uploads and stops existing transcripts from being turned into articles; you can still play back and edit what you already have, and recordings you already made stay in your library until you delete them. Where a transcript was created by another member of your team, it is their withdrawal that applies to that transcript.
- Legal obligation: tax records, regulatory compliance.
4. Data Sharing
We share personal data only with the following categories of third parties:
- Polar.sh — payment processing (Merchant of Record). Privacy policy.
- Supabase — managed PostgreSQL hosting (data stored in us-east-1, N. Virginia). Privacy policy.
- Cloudflare — edge hosting, R2 storage, KV cache. Privacy policy.
- Resend — transactional and marketing email delivery. Privacy policy.
- ElevenLabs, Inc. (United States) — speech-to-text for Voice notes. Receives the audio file you upload and any names you enter. We have a Data Processing Agreement with them, and we have opted out of their AI model training in our account settings, so your audio is not used to train their models. Their terms still reserve use for security, abuse prevention, technical support and service analytics. They do not publish a retention period for what you send to and receive from their API, and their terms do not oblige them to delete it when you delete yours: for self-serve API use they reserve the right — but no obligation — to delete content after 180 days of inactivity. Separately, their privacy policy states that data they generate about a voice is kept no longer than 3 years after your last interaction with them, except where they are required by law to keep it longer. Copies they hold after you delete yours are governed by their policy. Privacy policy.
- Google (OAuth) / Anthropic / Perplexity / Runware — AI model providers and OAuth (limited to your prompts and content; not used to train models per their enterprise terms). Turning a transcript into an article sends the confirmed text (not the audio) to Google (Gemini).
We do not sell personal data. We do not share data for cross-context behavioral advertising.
5. International Data Transfers
Our primary infrastructure is in the United States (us-east-1). For EU residents, transfers rely on Standard Contractual Clauses (SCCs) and the Polar.sh Merchant of Record framework for payment data. Voice recordings are stored in the United States (Cloudflare R2) and sent to ElevenLabs, Inc. in the United States for transcription — their processing may transit the Netherlands or Singapore. For residents of the EEA, the UK and Switzerland those transfers rely on Standard Contractual Clauses and the EU–US Data Privacy Framework, and ElevenLabs gives us 30 days' notice before adding a sub-processor. You can request more information on our transfer safeguards at any time.
6. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account closure.
- Generated articles: retained while your account is active. Deleted on account closure or on your request.
- Payment records: retained 7 years for tax compliance (legal obligation).
- Voice recordings and transcripts: retained until you delete them. Open a transcript in your library to delete it — the audio file is deleted with it. Both are destroyed when you close your account, within the same 30 days as your other account data. If a transcription fails, the recording is kept for up to 7 days so we can investigate the cause, then deleted automatically.
- Error logs: 30 days.
- Marketing email subscribers: until you unsubscribe.
7. Your Rights
7.1 GDPR (EU/UK residents)
- Article 15 — Access: request a copy of personal data we hold about you.
- Article 16 — Rectification: correct inaccurate data.
- Article 17 — Erasure: request deletion ("right to be forgotten").
- Article 18 — Restriction: limit how we process your data.
- Article 20 — Portability: export your data in a machine-readable format.
- Article 21 — Object: object to processing based on legitimate interest.
- Article 7(3) — Withdraw consent: for marketing, optional cookies, and Voice notes, anytime.
- Right to lodge a complaint with your national supervisory authority (e.g. CNIL for France, ICO for the UK, BfDI for Germany).
7.2 CCPA / CPRA (California residents)
- Right to know what personal information we collect.
- Right to delete personal information.
- Right to correct inaccurate information.
- Right to opt-out of "sale" / "sharing" — we do not sell or share for cross-context behavioral advertising.
- Right to non-discrimination for exercising your rights.
- Right to limit the use of sensitive personal information. Voice recordings are transcribed and separated by speaker only within the recording you upload — we do not use them to identify anyone, do not build voice profiles, and do not match voices across recordings or against any database. We do not use or disclose them for any purpose beyond providing the Service and the processor purposes disclosed in section 4, and you can delete voice data at any time.
7.3 How to exercise your rights
Email [email protected] from the email address associated with your account, or use the self-service data export and deletion tools in Settings → Privacy & data. The self-service export does not include audio files or full transcript text — you can view, edit and delete those by opening a transcript in your library, or request a copy by email. We respond within 30 days (60 days for complex requests, with notice).
8. Security
- HTTPS everywhere. TLS 1.2+ for all connections.
- API keys are hashed; OAuth tokens are scoped to least privilege.
- WordPress Application Passwords are encrypted at rest in our database.
- Row-Level Security on all tenant data — no cross-tenant access.
- Regular dependency audits and security patches.
No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify you and the appropriate supervisory authorities within 72 hours as required by GDPR.
9. Children's Privacy (COPPA)
Autobyline is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete the data.
10. Cookies
We use only essential cookies required for authentication and security. We do not use third-party advertising or tracking cookies. A cookie banner will be added in v1.1 to allow you to manage optional cookies (currently none in use).
11. Changes to This Policy
We will notify you of material changes by email (if you have an account) at least 30 days before they take effect, except for minor clarifications and for new optional features that require your separate consent before any of your data is processed — those take effect when you consent, and until you consent nothing changes for you. The current version is always available at autobyline.io/privacy.
12. Contact
For privacy questions, data requests, or complaints:
Email: [email protected]
General support: [email protected]
This Privacy Policy is provided for transparency and to demonstrate our commitment to responsible data handling. It does not create a contract between you and Autobyline; contractual terms are in the Terms of Service.