At Niubx, we believe privacy is foundational to autonomous publishing. We handle your account information, crawled domain content, and CMS credentials with industry-grade security and zero unauthorized data brokering.
This Privacy Policy explains the categories of data we collect, how we process it to generate and sync your SEO content, and the statutory privacy rights available to you under GDPR, CCPA, and global regulations.
01. Privacy Commitment
We never sell, rent, or trade your personal data, business analytics, or generated articles to data aggregators or third-party advertisers. Your website configurations and content parameters remain exclusively dedicated to powering your account's organic growth pipeline.
02. Information We Collect
To operate our autonomous platform, we collect:
- Account Details: Name, work email address, password hash, and company name.
- Domain & Content Configurations: Website URLs, target keywords, sitemap structures, industry vertical, and brand voice guidelines.
- CMS Credentials: Encrypted API keys, webhooks, or application passwords required to push articles directly to WordPress, Shopify, Webflow, or Notion.
- Billing Records: Transaction identifiers, subscription dates, and masked card details handled securely via PCI-DSS certified processors (Stripe, PayPal).
03. Methods of Data Collection
Information is gathered when you register an account, run the initial domain audit on our welcome page, connect integrations in project settings, or interact with customer support. Technical data (IP addresses, browser signatures, error logs) is logged during standard application requests.
04. How We Use Your Data
Your information is utilized solely for legitimate operational purposes:
05. AI Model Processing Safety
Niubx leverages modern large language models to construct articles. We maintain commercial enterprise agreements with our model providers ensuring that your proprietary website drafts, credentials, and company data are never used to train public foundation models.
06. CMS Tokens & Access Keys
When you connect WordPress, Shopify, Webflow, or Notion, tokens are encrypted at rest using AES-256 encryption. These tokens are accessed exclusively during active publication jobs and automated status health checks. You may revoke these tokens at any time via your project settings.
07. Cookies & Session Storage
We use strictly necessary session cookies to authenticate your login state and maintain security against cross-site request forgery (CSRF). Anonymous aggregated analytics help us detect performance anomalies and optimize website loading speeds.
08. Third-Party Integrations
We partner only with vetted, SOC-2 compliant infrastructure providers:
- Payment Gateways: Stripe, PayPal (PCI-DSS compliant for tokenized billing).
- Cloud Infrastructure: Google Cloud Platform & AWS (secure container hosting).
- Transactional Email: Enterprise SMTP services for trial notifications and analysis alerts.
09. Data Retention & Archival
We retain your project files, published drafts, and analytical history for the lifetime of your active membership. If you terminate your account, you can request immediate purging of all stored content and domain crawl data from our operational databases.
10. Global Cloud Infrastructure
Niubx servers and cloud clusters are distributed globally across secure tier-4 data facilities in North America and Western Europe. Cross-border transfers adhere to EU Standard Contractual Clauses (SCCs) to guarantee statutory data protection compliance.
11. Encryption & Protection Standards
All communications between your browser and Niubx are enforced over TLS 1.3 encryption. Backend database volumes and backups are protected with AES-256 bit encryption keys managed under hardware security modules.
12. GDPR Rights & Inquiries
If you reside in the European Economic Area (EEA) or United Kingdom, you possess specific legal rights under the General Data Protection Regulation (GDPR), including: the right to access, rectify, or erase your personal data; the right to data portability; and the right to object to or restrict specific processing activities.
13. California Privacy (CCPA / CPRA)
California residents have the right under the CCPA/CPRA to request disclosure of personal data categories collected, request erasure of personal information, and opt out of any sale or sharing. We do not sell personal information as defined by California statute.
14. Policy Updates & Notice
We may update this Privacy Policy periodically to reflect technological improvements or regulatory changes. We will notify active account holders via email or in-app announcement of any material modifications prior to their effective date.
15. Contact DPO & Compliance
For questions concerning privacy, data subject requests, or to contact our designated Data Protection Officer, reach out directly:
Privacy & Data Governance Office
Requests are processed within 30 days in accordance with statutory requirements: