Skip to content

Privacy Policy

Last updated 28 September 2026

This policy explains what BlogTend collects, why, who else sees it and how to get it back or deleted. The short version: we collect what the Service needs to write and publish your articles, your WordPress credentials are encrypted and never shared with an AI provider, and nothing here is sold to anyone.

1. Who is responsible for your data

Ravinaro LLC-FZ, Dubai, Meydan Grandstand is the controller of personal data processed through BlogTend.

For anything in this policy, including a request to see or delete your data, write to info@yodon.com or use the contact form.

2. What we collect

You give us

  • Account details — name, email address and a hashed password. If you sign in with Google we receive your name, email address, profile picture and Google's stable account identifier instead of a password.
  • Connected site credentials — the site URL and whatever lets BlogTend publish there: a WordPress username and Application Password or connector token, a Wix app instance or API key, or a Webflow app access token or site API token. Secrets are encrypted at rest with AES-256-GCM, are never shown back to you or sent to any AI provider, and are deleted when you disconnect the site (Wix and Webflow app access is also revoked with the platform).
  • Shopify installs — the shop domain, the store owner's email and name (used to create your BlogTend account when the app is first opened), an encrypted access token, plus the blog and article content BlogTend publishes to your store. We never receive your Shopify customer or order data. The access token is deleted when you uninstall the app. On Shopify's shop-redact request, the store's details are erased, and so is the account created for it unless you took it over by setting a password.
  • Content you write — prompts, topics, business context, saved article styles, and anything you type into a support ticket or the contact form.
  • Billing details — handled by Stripe. We store the Stripe customer and subscription identifiers and your plan. We never see or store card numbers.

We generate or collect automatically

  • Generated content — articles, images, research notes and the source URLs behind them.
  • Usage records — which model ran at which step, token counts and the cost of each run, so both of us can see what an article cost.
  • Operational logs — request and error logs, and a log of emails sent to you.
  • Analytics and advertising measurement — pages viewed, clicks on key buttons, sign-ups, check-outs and purchases, the device, browser and approximate location Google derives from your network address, and, if you arrived from one of our Google ads, the ad click identifier. See “Analytics and advertising measurement” below.
  • Bot-protection signals — Cloudflare Turnstile inspects the browser on sign-up, sign-in and the contact form. It is designed not to track people across sites.

3. Why we use it, and on what legal basis

  • To provide the Service — generating and publishing articles, running your automations, showing your usage. Basis: performance of our contract with you.
  • To bill you and keep the records tax law requires. Basis: contract and legal obligation.
  • To email you about verification, published articles, paused automations, low credits and support replies. Basis: contract. Optional notifications can be turned off.
  • To keep the Service secure and working — bot protection, abuse prevention, debugging. Basis: our legitimate interest in a service that is not overrun.
  • To understand how the site is used and whether our ads work — Google Analytics and Google Ads conversion measurement. Basis in the EEA, the UK and Switzerland: your consent, which you give or refuse in the cookie banner and can withdraw at any time. Elsewhere: our legitimate interest in measuring our own website and advertising, and you can switch it off at any time in Cookie settings.

4. What the AI providers receive

Producing an article means sending your prompt, the site context you supplied and the intermediate drafts to the AI provider handling that step, and sending the topic to a web-search provider. Providers used today: OpenAI, Google (Gemini), Anthropic and DeepSeek.

We use these providers through their paid APIs. OpenAI, Anthropic and Google state that API content is not used to train their models by default, and typically retain it for a limited period for abuse monitoring. DeepSeek processes and stores data in the People's Republic of China under its own policy, which is materially different — if that matters to you, tell us and we will confirm which providers are configured for your pipeline.

We never send your WordPress credentials to any AI provider. They receive the writing task, not the keys to your site.

5. Analytics and advertising measurement

We use Google Analytics 4 on our website and in the app to see which pages are visited, which buttons are clicked and where sign-ups and purchases come from. We advertise with Google Ads, and Google Ads counts sign-ups and purchases as conversions by importing them from Google Analytics. We do not use any other advertising network or tracking pixel.

What Google receives

  • The address of the page, the page before it, the event (for example a page view, a sign-up or a started check-out) and details such as the sign-in method or the plan you chose — never your name, your email address, your article content or your site credentials.
  • Your network address, device and browser. Google Analytics uses the network address to derive an approximate location and does not log or store the address itself. A random identifier kept in the _ga cookie tells one browser apart from another.
  • If you arrived from a Google ad: the ad click identifier (gclid) that Google adds to the link. It is kept in the _gcl_aw cookie, only when advertising is allowed, so a later sign-up or purchase can be credited to that ad.
  • When you pay: we store the Google Analytics identifiers of your browser (client and session identifiers, the ad click identifier if you allowed advertising, and your advertising choice) with the Stripe checkout. When Stripe confirms the payment, our server sends Google Analytics a purchase event with those identifiers, the transaction number, the plan or pack bought, the amount and the currency. Renewals are sent the same way, as a separate renewal event. Your name, email address and card details are never sent. If analytics was not allowed when you checked out, nothing is stored with the checkout and nothing is sent.

Your choice

  • In the EEA, the UK and Switzerland (and when we cannot tell where you are) analytics and advertising are off until you choose in the cookie banner, which offers Analytics and Advertising separately. Until then the Google tag stores no cookies; Google receives only cookieless signals (that a page was viewed, whether consent was given, and the page address, which may include an ad click identifier), which Google says it uses for aggregate modelling and not to identify you.
  • Everywhere else both are on by default and you can switch either off.
  • You can change or withdraw your choice at any time from Cookie settings at the foot of every page, or with this button:
  • Withdrawing does not affect measurement that already happened. You can also block these cookies in your browser, or install Google's opt-out add-on: tools.google.com/dlpage/gaoptout

Google's role

For Google Analytics, Google processes this data on our behalf under its data-processing terms. For advertising measurement, and for any use of the data to personalise ads, Google also acts as an independent controller under its own privacy policy. With advertising allowed, Google may use it to show our ads to people who have visited our site.

What we do not do

  • Google's enhanced conversions and user-provided data collection are switched off in our Google Analytics and Google Ads accounts, so Google does not collect your email address or any other contact detail from our site. If we ever turn them on, we will update this policy first.
  • We do not use session recording or heatmap tools. Our code can load Microsoft Clarity, but it is switched off; we will update this policy before turning it on.
  • Google signals is switched off, so Google Analytics does not link your visits to your Google account for cross-device reports.

6. Who else processes your data

These are the companies we rely on to run the Service:

ProviderWhat it doesWhere
CloudflareHosting, the database, image storage and bot protection (Turnstile)Global edge network
StripeSubscription and one-off payments. Card details go to Stripe, never to usUnited States / Ireland
ResendSending transactional emailUnited States
OpenAIArticle research, writing and imagesUnited States
Google (Gemini)Article research and writingUnited States
Google (Sign-in)Optional Google sign-inUnited States
Google (Analytics and Ads)Website analytics and advertising measurement, as your cookie choice allowsUnited States
AnthropicArticle research and writingUnited States
DeepSeekArticle writing, when selected as the model for a stepPeople's Republic of China

We do not sell personal data. The only advertising company that receives data from us is Google, for the measurement described under “Analytics and advertising measurement”. We may disclose data where the law requires it, or to establish or defend legal claims.

7. How your site credentials are protected

  • Secrets are encrypted at rest and decrypted only to make a request to your site.
  • They are never returned to the browser, logged, or included in an error message.
  • You can revoke an Application Password from your own WordPress admin at any time, which cuts our access immediately.
  • Disconnecting a site in BlogTend deletes the stored credential.

8. How long we keep things

  • Account and content — for as long as the account exists, then deleted or anonymised within 30 days of closure.
  • Site credentials — until you disconnect the site or close the account.
  • Billing records — as long as tax and accounting law requires, which is generally several years, regardless of account closure.
  • Operational and email logs — short-lived, kept only as long as they are useful for debugging and abuse prevention.
  • Google Analytics data — event-level data is kept for 14 months, then deleted by Google; aggregated reports that identify nobody are kept longer. The _ga cookies last up to 2 years and the _gcl cookies up to 90 days in your browser unless you delete them.
  • Google Ads conversion records — kept by Google under its own retention policies.

9. International transfers

We operate from Dubai, United Arab Emirates. and our providers are located in several countries, including the United States (among them Google, for analytics and advertising measurement) and, for one AI provider, the People's Republic of China. Where data leaves a jurisdiction that restricts transfers, we rely on the appropriate safeguards for that route — for transfers out of the EEA or the UK, the standard contractual clauses in our providers' data-processing terms, or the provider's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions where it holds one.

10. Your rights

Depending on where you live you may have the right to:

  • ask what we hold about you and get a copy;
  • have inaccurate details corrected;
  • have your data deleted;
  • receive it in a portable format;
  • object to, or ask us to restrict, processing based on legitimate interests;
  • withdraw consent where we relied on it;
  • complain to your data-protection authority.

These rights come from the UAE Personal Data Protection Law, the GDPR and UK GDPR, and the CCPA/CPRA in California, among others. Write to info@yodon.com and we will answer within 30 days. We do not discriminate against anyone for exercising a right.

Your privacy choices (California and other US states)

We do not sell personal information for money. Letting Google Ads cookies measure and personalise our advertising may count as “sharing” personal information for cross-context behavioural advertising, or as “targeted advertising”, under California and other US state laws. You can opt out at any time: open and turn off Advertising (or Analytics too). The choice is stored in that browser, so repeat it on each browser you use; clearing your cookies resets it. You can also email info@yodon.com, and an authorised agent may make a request for you. We do not knowingly sell or share the personal information of anyone under 16.

11. Cookies and similar technologies

Necessary cookies and your saved preferences are always on. Analytics and advertising cookies follow your choice in the cookie banner: in the EEA, the UK and Switzerland they are off until you accept them; elsewhere they are on until you turn them off. Change your choice at any time in .

NameProviderPurposeDurationCategory
authjs.session-tokenBlogTendKeeps you signed in (prefixed __Secure- on https)30 days, or until you sign outNecessary
authjs.csrf-token, authjs.callback-urlBlogTendProtects the sign-in form and returns you to the right page after signing inUntil you close the browserNecessary
authjs.state, authjs.pkce.code_verifierBlogTendSecures a Google sign-in while it is in progress15 minutesNecessary
yodon_webflow_oauth_state, yodon_webflow_pendingBlogTendCompletes a Webflow connection you started30 minutesNecessary
voucherBlogTendRemembers a voucher code you claimed until you sign up and check out30 daysNecessary
rv_consentBlogTendRemembers your analytics and advertising choice12 monthsNecessary
yodon_locale, yodon_currencyBlogTendThe language and currency you chose12 monthsPreference
yd_new_signupBlogTendMarks a new Google sign-up so the sign-up can be counted once; holds no identifier, and the event it triggers follows your analytics choice10 minutesAnalytics (optional)
_gaGoogleGoogle Analytics: tells one browser apart from another2 yearsAnalytics (optional)
_ga_<ID>GoogleGoogle Analytics: keeps track of the current visit2 yearsAnalytics (optional)
_gcl_awGoogleGoogle Ads: stores the ad click identifier when you arrive from one of our Google ads, so a later sign-up or purchase can be credited to it90 daysAdvertising (optional)
_gcl_auGoogleGoogle Ads: conversion measurement, when the Google tag sets it90 daysAdvertising (optional)

Your light/dark theme choice is kept in your browser's local storage, not in a cookie, and is never sent to us.

Cloudflare Turnstile may set its own cookies while it runs the bot check, and Stripe sets its own cookies on its checkout and billing-portal pages, under their own policies.

12. Children

The Service is for business use by adults. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we will remove it.

13. If something goes wrong

If a security incident affects your personal data we will investigate, contain it, notify the relevant authority where the law requires, and tell affected customers by email without undue delay.

14. Changes to this policy

We will update this page when our practices change and move the "last updated" date. For material changes — a new category of data, or a new kind of processor — we will also email account holders.