Privacy Policy
This policy explains what AffSERP collects, why, who we share it with, and what you can do about it. We have tried to write it in plain language. If anything is unclear, email support@affserp.com and a person will answer.
The short version
- We collect what we need to run your account and generate your content, and not much else.
- Your Amazon, WordPress, Blogger and Shopify credentials are encrypted before they are stored, and we never display them back to you.
- The keywords and content you generate are sent to AI providers to be written. They are not used to train those providers' models.
- We do not sell your data, and we do not show ads.
- You can delete your account at any time from Settings, and deletion is permanent. Email us for a copy of your data.
Who we are
AffSERP is operated by the owner of affserp.com ("we", "us"). We are the data controller for the personal information described here. You can reach us at support@affserp.com.
What we collect
We keep this to what the service actually needs.
Account information
- Email address, and a password if you sign up with one. Passwords are stored as a one-way hash; we cannot read them.
- Name and optional profile details (username, first and last name, phone) if you choose to add them.
- Google sign-in details, if you sign in with Google: your Google account ID and email. We do not receive your Google password.
Credentials you connect
To publish on your behalf, you may connect your own accounts. We store the credentials you provide, encrypted at rest:
- Amazon Creators API credential ID, secret, tracking ID, marketplace and version.
- WordPress site URL, username and application password.
- Blogger and Shopify access tokens, and any webhook secret you set.
Once saved, these are never shown back to you in the app. If you use our shared Amazon access instead of your own keys, we store only your tracking ID so that commissions are credited to you.
Content you create
- The keywords, product selections, brand voice and settings you enter.
- The articles, images and metadata that are generated for you, and a record of where they were published.
- Your credit balance and a ledger of how credits were used, so you can see exactly what each article cost.
Technical and usage information
- Standard server logs: IP address, browser type, the pages and API endpoints requested, and timestamps. We use these to keep the service running and to detect abuse.
- Cookies, used only to keep you signed in and to complete Google sign-in securely. They are marked HttpOnly and Secure. We do not use advertising or cross-site tracking cookies.
Payment information
Payments are handled by our payment processor. We receive your name, email, the plan or pack you bought and a transaction reference. We never see or store your card number.
How we use it
- To create and secure your account, and to sign you in.
- To generate the content you request and, if you ask us to, publish it to the sites you connected.
- To meter your credits and, where applicable, bill you.
- To send you transactional email: verification, password resets, receipts, and notices about your account. We do not send marketing email unless you opt in.
- To answer your support requests.
- To prevent abuse, such as disposable-email signups, brute-force login attempts and misuse of the shared Amazon access.
- To keep the service reliable, by monitoring errors and performance.
We do not sell personal information, and we do not use it for advertising.
AI processing, in detail
Generating content means sending your inputs to AI providers. Here is exactly what leaves our servers and where:
- Text generation (OpenAI and/or Anthropic): the keyword, product data fetched from Amazon, and any brand voice, keywords or instructions you entered. Under our agreements with these providers, API data is not used to train their models.
- AI images (OpenAI): a short prompt derived from your article's title and keyword.
- Product data (Amazon Creators API): the search term or product identifiers, sent with either your credentials or ours.
- Stock and web images (Pexels, Unsplash, Pixabay, or serper.dev for web search): the keyword, when you choose those image sources.
- YouTube-to-article: the video URL you paste, used to fetch its public transcript.
We do not send your account details, credentials or payment information to any AI or image provider.
Who we share it with
We share data only with services we need to operate, and only what each one needs:
- Hosting and infrastructure (Render): runs our application and database.
- AI and image providers, as described above.
- Amazon, for product data and affiliate links.
- Your connected sites (WordPress, Blogger, Shopify or a webhook you set), when you publish.
- Email delivery (Resend): to send transactional email.
- Google: for sign-in, and for keyword suggestions in the SEO tools.
- Our payment processor: to take payment and manage subscriptions.
We may also disclose information if the law requires it, or to protect the rights and safety of users or the service. If AffSERP is ever sold or merged, your data would transfer with it, and we would tell you first.
How long we keep it
- Your account and content: for as long as your account exists. Delete your account and it is removed, along with your credentials, sites, generated articles and history.
- Credentials you disconnect: deleted immediately.
- Server logs: kept for a limited period for security and debugging, then discarded.
- Billing records: kept for as long as tax and accounting rules require, even after account deletion.
How we protect it
- All traffic to AffSERP is encrypted with HTTPS.
- Connected-account credentials are encrypted at rest with a key that is not stored alongside the database.
- Passwords are hashed with bcrypt and cannot be recovered.
- Login, signup and password-reset endpoints are rate-limited to resist brute-force attacks.
- Access to production systems is restricted to the people who operate the service.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay and tell you what happened and what we are doing about it.
Your rights and choices
Wherever you live, you can:
- Access and update your details in Settings.
- Disconnect any Amazon, WordPress, Blogger, Shopify or webhook connection at any time, which deletes the stored credential.
- Delete your account from Settings. This is immediate and permanent.
- Ask us for a copy of the personal data we hold about you, or ask us to correct or delete it, by emailing support.
If you are in the UK, EU or EEA, you also have the rights under the GDPR to restrict or object to processing and to complain to your local data protection authority. If you are a California resident, you have the rights under the CCPA to know, delete, and opt out of sale; as noted above, we do not sell personal information. We will not treat you differently for exercising any of these rights.
International transfers
Our servers and the providers listed above are primarily in the United States. If you use AffSERP from elsewhere, your data will be transferred there. Where the law requires safeguards for such transfers, we rely on our providers' standard contractual clauses and equivalent protections.
Children
AffSERP is for adults running affiliate and content businesses. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.
Changes to this policy
If we make a material change, we will update the date at the top and, for significant changes, notify you by email before it takes effect. Continued use after that date means you accept the updated policy.
Contact
Questions, requests or concerns about your data: support@affserp.com.