Legal
Privacy Policy
This Privacy Policy explains how Site Fuel collects, uses, stores, and shares personal data when you use our service. It is written to satisfy the EU General Data Protection Regulation (GDPR) for our primarily EU-based customer base, and applies alongside the Terms of Service and, for business customers acting as data controllers, the Data Processing Agreement.
1. Controller
The data controller for personal data processed through Site Fuel's own operation of the service (account administration, billing, support) is:
Kay Joosten, sole proprietor (eenmanszaak) under Dutch law
[ADDRESS]
Where a Customer uses Site Fuel to process personal data belonging to its own end users or website visitors (for example, content that references identifiable individuals), the Customer is the data controller for that data and Site Fuel acts as a processor under the DPA.
2. What We Collect
We collect and process the following categories of personal data:
- Account and user data: names, work email addresses, and bcrypt-hashed password hashes for users who log in to the admin interface or hold API credentials. We never store passwords in plain text.
- Customer site content: the pages, text, and metadata crawled from a Customer's website in order to understand the business and generate content, along with the AI-generated blog posts, briefs, and related artifacts produced on the Customer's behalf.
- Search performance metrics: where a Customer connects Google Search Console for a site, aggregated search performance data (impressions, clicks, queries, positions) for that site.
- Billing metadata: subscription tier, usage/overage counts, invoice and payment status information. Card numbers and full payment details are handled directly by our payment processor, Stripe, and are not stored by us.
- Operational data: IP addresses and timestamps associated with signup, login, and API requests, used for rate limiting, abuse prevention, and security logging.
3. Legal Bases for Processing
- Contract (Art. 6(1)(b) GDPR): processing account data, site content, and generated content is necessary to perform the service Customers sign up for.
- Legitimate interest (Art. 6(1)(f) GDPR): security logging, abuse prevention, rate limiting, and product improvement, balanced against data subject rights.
- Legal obligation (Art. 6(1)(c) GDPR): retention of billing and financial records to meet Dutch tax and accounting law.
- Consent (Art. 6(1)(a) GDPR): where an account explicitly opts in to a non-default processor (DeepSeek) for content generation, as described in Section 5.
4. Retention
We keep personal data only as long as necessary for the purposes above:
- Pending (unverified) signups: purged 48 hours after creation if not verified.
- Expired login tokens: deleted 30 days after expiry. Revoked tokens (e.g. on logout) are deleted immediately, not held for the 30-day window.
- Soft-deleted content briefs: permanently deleted 90 days after deletion.
- Billing events: retained 365 days after processing, then purged from our systems.
- Financial records: retained 7 years via Stripe, as required by Dutch fiscal law (NL bewaarplicht), independent of our own systems' retention windows above.
- Erasure audit records: a hashed-email tombstone (see Section 7) is retained indefinitely as minimal evidence that an erasure was performed.
These windows are enforced by an automated nightly retention sweep and are also documented in our engineering configuration so they stay consistent with this policy.
5. Processors and International Transfers
We share personal data with the following processors, each engaged under a data processing agreement and, where data leaves the EU/EEA, Standard Contractual Clauses (SCCs):
| Processor | Region | Role |
|---|---|---|
| Stripe | US | Payment processing and billing |
| Hetzner | DE | Hosting infrastructure |
| Google Search Console | US | Search performance metrics (only for sites a Customer explicitly connects) |
| Anthropic | US | AI content generation (default provider) |
| DeepSeek | CN | AI content generation — only for accounts that explicitly opt in per account setting |
| [SMTP_PROVIDER] | env-dependent | Transactional email (verification, notifications) |
DeepSeek transfer notice: DeepSeek is based in the People's Republic of China, a country for which the European Commission has not issued an adequacy decision. If your account opts in to DeepSeek as a content generation provider, your website content submitted for generation will be transferred to and processed in China under contractual safeguards (SCCs) we put in place with DeepSeek. This transfer only occurs for accounts that have affirmatively enabled this option; it is never the default. You may opt out at any time by switching your account's generation provider back to the default.
For all other cross-border transfers (Stripe, Google, Anthropic — all US-based), we rely on the processors' Standard Contractual Clauses and, where applicable, supplementary measures, as the transfer mechanism under Chapter V GDPR.
6. Cookies
Our public website (landing, signup, and legal pages) sets no cookies and uses no trackers, analytics, or third-party assets.
The customer dashboard sets a single session cookie after you log in. It is cryptographically signed and used solely to keep you authenticated (login state, your role, and the Terms version you accepted). It is strictly necessary for the service you requested, so no consent banner is required for it under the ePrivacy rules (Article 5(3) ePrivacy Directive); it contains no tracking or advertising identifiers and is invalidated when you log out.
When you pay, checkout happens on Stripe's own website, which sets its own cookies under Stripe's cookie policy.
We use no analytics or advertising cookies anywhere.
7. Data Subject Rights
Subject to applicable law, you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data; restrict or object to processing; receive your data in a portable format; and lodge a complaint with a supervisory authority. Individual end users whose personal data appears within Customer-generated content should direct requests to the relevant Customer, who is the data controller for that content; we will assist Customers in fulfilling such requests as their processor.
Exercising your rights
- Export (access/portability): an account owner or admin can export the
full account data bundle at any time via
GET /accounts/me/export, authenticated with the account's own API key (or a bearer token for admin/super-admin users). The export is a synchronous JSON download and is not separately retained by us afterward. - Deletion (erasure): send a deletion request by email to the operator contact in Section 9. On a verified request, we perform a full erasure — a hard delete of the account and all its owned data (users, sites, strategies, briefs, posts, feed entries, token usage, subscription) — and retain only a hashed-email, timestamped audit tombstone as evidence the erasure occurred (see Section 4 and the DPA, Section 6).
To exercise a right not covered above, contact us as described in Section 9.
8. Supervisory Authority
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP), or with the supervisory authority in your own EU member state of residence.
9. Contact
For privacy questions or to exercise your rights, contact Kay Joosten, sole proprietor (eenmanszaak) under Dutch law at [ADDRESS] or via the contact details published on the Site Fuel website.
10. Changes to This Policy
We may update this policy as the service or our processors change. Material changes will be communicated by email to account administrators, and, where required, will trigger renewed acceptance in the product. The version and date at the top of this document reflect the currently effective text.