Privacy Policy
Last Updated: August 22, 2026
This Privacy Policy describes how YOTAKO S.A. ("we," "us," or "our") collects, uses, and protects your personal data when you use WPMaven ("the Service"). This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
YOTAKO S.A.
4 rue Samuel Beckett, Luxmill building
L-4371 Belvaux, Sanem
Grand-Duchy of Luxembourg
R.C.S. n°: B 205443
TVA n°: LU 29326106
Email: privacy@wpmaven.ai
Data Protection Officer: dpo@wpmaven.ai
2. Personal Data We Collect
2.1 Information You Provide Directly
Account Information
- Identity Data: Name, email address, username
- Contact Data: Email address, phone number (optional)
- Billing Data: Billing address, payment information (processed by third-party payment processors)
- Authentication Data: Password (hashed), authentication tokens
Usage Data
- Descriptions and Prompts: What you type to describe your business, and anything you later ask the AI assistant. We record this from the moment you type it, which includes descriptions written before you create an account. If you go on to sign up, we link what you wrote earlier to your account. If you never sign up, it stays unlinked to any name or email address
- Generated Content: Content created by the Service in response to your prompts
- WordPress Site Data: Site URL, WordPress version, theme and plugin information
- Settings and Preferences: Your configuration choices and customizations
2.2 Information Collected Automatically
Technical Data
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, pages viewed, actions taken
- Performance Data: Error logs, crash reports, performance metrics
- Cookies and Tracking: See Section 7 for details
Analytics Data
- Usage Statistics: Features used, frequency of use, session duration
- AI Interaction Data: Number of requests, credit consumption, response times
- Site Health Data: Performance metrics, security scan results (from your WordPress site)
2.3 Information from Third Parties
- Authentication Providers: If you sign in with Google, GitHub, or Microsoft, we receive basic profile information (name, email)
- Payment Processors: Transaction confirmations and payment status from Stripe, PayPal
- WordPress.org: Plugin and theme information from public repositories
2.4 Information from Social Accounts You Connect
WPMaven only ever connects social accounts you already own, and only after you authorise it yourself. We never create accounts, Pages or profiles on your behalf.
Facebook Pages. If you connect a Facebook Page, we receive from Meta: the list of Pages you manage with their names and IDs, an access token for the Page you select, that Page's published posts, the comments people leave on them, the Page's and posts' engagement statistics, and the Messenger conversations sent to that Page including message text and the sender's Meta-provided name and ID.
Instagram. If you connect an Instagram professional account, we receive: the account's ID and username, an access token, the account's own media and captions, the comments on that media, the account's and media's insights, and the direct messages sent to the account including message text and the sender's Meta-provided username and ID.
Pinterest. If you connect Pinterest, we receive your account name, your boards, the pins we create for you, and their analytics (impressions, pin clicks, outbound clicks and saves).
Google (YouTube and Business Profile). If you connect YouTube we receive your channel identity and can upload videos you approve. If you connect a Google Business Profile we receive the list of accounts and locations you manage and can create posts on the location you select. WPMaven's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
LinkedIn and X. If you connect these, we receive your account identity and publish only the posts you approve.
What we do with it. We show it to you inside WPMaven, we use it to draft posts and replies for your approval, and we summarise it in the weekly report we send you. We publish or reply only to what you have explicitly approved. We do not sell it, we do not use it for advertising, and we do not combine one customer's social data with another's.
How long we keep it, and how to delete it. Access and refresh tokens are encrypted at rest. Disconnecting a channel in WPMaven deletes the stored tokens for that account immediately and stops all further access. Posts, comments, messages and statistics we cached to display are deleted with your account, or on request at any time to privacy@wpmaven.ai. See Section 9 for your full rights, including erasure.
Revoking access. You can review and revoke WPMaven's access at any time from your Facebook settings under Business Integrations, your Instagram settings under Apps and Websites, or your Google Account under Third-party apps with account access. Data received from Meta is additionally handled in accordance with the Meta Platform Terms and Developer Policies.
3. How We Use Your Personal Data
We process your personal data for the following purposes, based on the legal grounds indicated:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain the Service | Contract Performance (Art. 6(1)(b)) |
| Process AI requests and generate responses | Contract Performance (Art. 6(1)(b)) |
| Process payments and billing | Contract Performance (Art. 6(1)(b)) |
| Send service updates and notifications | Contract Performance (Art. 6(1)(b)) |
| Provide customer support | Contract Performance (Art. 6(1)(b)) |
| Improve and optimize the Service | Legitimate Interest (Art. 6(1)(f)) |
| Train and improve AI models | Legitimate Interest (Art. 6(1)(f))* |
| Detect and prevent fraud and abuse | Legitimate Interest (Art. 6(1)(f)) |
| Ensure security and prevent threats | Legitimate Interest (Art. 6(1)(f)) |
| Comply with legal obligations | Legal Obligation (Art. 6(1)(c)) |
| Send marketing communications | Consent (Art. 6(1)(a))** |
* We use aggregated data that does not identify you. To opt out, email privacy@wpmaven.ai.
** You can withdraw consent at any time by clicking "unsubscribe" in emails or updating preferences.
4. Data Sharing and Disclosure
4.1 Service Providers
We share data with trusted third-party service providers who process data on our behalf:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Google Cloud Platform | Cloud hosting, database, and the servers your site runs on | All service data | EU (Belgium, europe-west1) |
| Stripe | Payment processing | Payment information | Global (GDPR compliant) |
| Amazon SES | Email delivery | Email, name | EU (Ireland, eu-west-1) |
| OpenAI | AI model processing | Your description and prompts, as written | US (DPA in place) |
| Anthropic | AI model processing | Your description and prompts, as written | US (DPA in place) |
| Google (Gemini) | AI model processing | Your description and prompts, as written | US (DPA in place) |
All service providers are contractually bound to:
- Process data only as instructed by us
- Implement appropriate security measures
- Comply with GDPR and data protection laws
- Not use data for their own purposes
4.2 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your personal data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
4.3 Legal Requirements
We may disclose your data if required by law, court order, or governmental authority, or to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or abuse
- Respond to emergencies involving danger to persons
4.4 Aggregated and Anonymized Data
We may share aggregated, anonymized data that cannot identify you with:
- Research partners (for AI improvement)
- Business partners (for analytics)
- The public (in reports or blog posts)
5. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States.
5.1 Transfer Mechanisms
For transfers outside the EEA, we use:
- Standard Contractual Clauses (SCCs): EU Commission-approved contracts ensuring GDPR compliance
- Data Processing Agreements (DPAs): Contractual guarantees with all processors
- Adequacy Decisions: Transfers to countries recognized by the EU as having adequate protection
5.2 AI Model Processing
Important: Prompts sent to AI providers (OpenAI, Anthropic, Google Gemini) may be processed in the United States. We:
- Have Data Processing Agreements with all AI providers, under which none of them may use your text to train their models
- Rely on Standard Contractual Clauses for the transfer to the United States (Section 5.1)
- Send what you write as you wrote it. We do not remove names, addresses, or phone numbers first, so anything you put in the box goes to the provider
- Ask you not to include payment card details, passwords, or health information you would not want processed in the United States. We cannot filter these out for you
6. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 90 days after closure |
| Descriptions and prompts you write | Kept indefinitely (see 6.1). Erased on request |
| Billing records | 7 years (legal requirement) |
| Usage logs | 12 months |
| Support communications | 3 years |
| Marketing consent records | Duration of consent + 3 years |
| Anonymized analytics | Indefinitely (cannot identify individuals) |
6.1 Why We Keep What You Write
The one row above that says "indefinitely" deserves a plain explanation, because it is a deliberate choice rather than an oversight.
When you describe your business to us, that sentence is what teaches us what people actually want to build. We read these descriptions to find the kinds of business we do not support yet, to fix the cases where we understood someone incorrectly, and to write our own website in the words people really use instead of the words we assume. A summary or a count cannot tell us any of that, so we keep the text itself.
We are telling you this rather than burying it because the descriptions people write are often personal. They frequently include a business name, an address, a phone number, and the founder's own name. Some of them, for example those written by clinics, therapists, and support groups, describe health matters, which European law treats as a special category needing extra care.
What this means in practice:
- Closing your account does not by itself erase the descriptions you wrote
- You can ask us to erase them at any time and we will, including anything you typed before you signed up (see Section 9.3)
- When we erase them, we keep only a count and the category we assigned, so our own totals stay accurate. The text itself is gone and cannot be recovered
- We do not sell them, and we do not use them to train AI models
6.2 Early Deletion
You can request early deletion of your data at any time (see Section 9).
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Authentication, security, core functionality | Session / 1 year |
| Functional Cookies | Remember preferences, settings | 1 year |
| Analytics Cookies | Usage statistics, performance monitoring | 2 years |
| Marketing Cookies | Track campaign effectiveness (with consent) | 1 year |
7.2 Managing Cookies
You can control cookies through:
- Cookie Preferences: Use the cookie banner on our website to accept or decline non-essential cookies
- Browser Settings: Most browsers allow you to refuse or delete cookies
- Do Not Track: If your browser sends a Do Not Track signal, we honor it and do not measure your visit, whatever you chose in the banner
Note: Disabling essential cookies may affect Service functionality.
7.3 Who Measures You, and Where That Data Goes
We do not use Google Analytics. We use Matomo, an open source analytics tool that we run ourselves on our own server at analytics.yotako.io, operated by Yotako S.A. That means the record of your visit is not shared with an advertising company, is not used to build a profile of you across other websites, and is not sold to anyone. It stays on infrastructure we control.
WPMaven has its own separate space inside that Matomo, so its data is not mixed with any other Yotako product.
What we measure, if you accept:
- Which pages you visited, in what order, and how long you stayed
- Which buttons and links you clicked, and how far down a page you read
- Where you arrived from, such as a search engine, an ad, or another website
- A rough idea of where you are, worked out from that shortened IP address, along with your browser and device type. Because we shorten the address first, this is approximate by design and gets the region right more often than the city
What we do about the obvious risk in that list:
- The last two bytes of your IP address are removed before it is stored, so what we keep looks like 203.0.xxx.xxx. That is coarse enough to point at a broad area rather than a household or a street
- Decline in the banner and we measure nothing at all, on any page, not a reduced version
- If your browser sends a Do Not Track signal we obey it, even if you accepted
- Once you have an account we link this to it, so that we can see how the product is actually used. Section 9 covers your rights over that
8. Data Security
We implement industry-standard security measures to protect your personal data:
8.1 Technical Measures
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Access Controls: Role-based access, multi-factor authentication
- Infrastructure Security: Firewalls, intrusion detection, regular security audits
- Secure Development: Code reviews, security testing, vulnerability scanning
- Data Isolation: Customer data is logically separated
8.2 Organizational Measures
- Employee Training: Regular security and privacy training
- Access Limitation: Data access on a need-to-know basis
- Confidentiality Agreements: All employees sign NDAs
- Incident Response: Documented procedures for data breaches
- Regular Audits: Annual third-party security assessments
8.3 Data Breach Notification
In the event of a data breach affecting your personal data, we will:
- Notify you within 72 hours of discovering the breach
- Notify relevant supervisory authorities as required by law
- Provide details of the breach, affected data, and remediation steps
- Offer assistance and guidance to mitigate potential harm
9. Your Rights Under GDPR
As a data subject in the European Economic Area, you have the following rights:
9.1 Right of Access (Art. 15 GDPR)
You can request:
- Confirmation of whether we process your personal data
- A copy of your personal data
- Information about how we use your data
How to exercise: Email privacy@wpmaven.ai and we will send you a copy
9.2 Right to Rectification (Art. 16 GDPR)
You can request correction of inaccurate or incomplete data.
How to exercise: Update your details under Settings → Profile, or email privacy@wpmaven.ai
9.3 Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
You can request deletion of your personal data in certain circumstances.
How to exercise: Email privacy@wpmaven.ai. This covers the descriptions and prompts you wrote, including anything you typed before creating an account
Note: We may retain some data if required by law (e.g., billing records).
9.4 Right to Restriction of Processing (Art. 18 GDPR)
You can request that we limit how we use your data.
How to exercise: Email privacy@wpmaven.ai
9.5 Right to Data Portability (Art. 20 GDPR)
You can receive your data in a structured, machine-readable format and transfer it to another service.
How to exercise: Email privacy@wpmaven.ai and we will send your data in a machine-readable format
9.6 Right to Object (Art. 21 GDPR)
You can object to processing based on legitimate interests or for direct marketing.
How to exercise: Settings → Notifications, or email privacy@wpmaven.ai
9.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on consent, you can withdraw it at any time.
How to exercise: Settings → Notifications, or click "unsubscribe" in any email we send
9.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority:
- Luxembourg: Commission Nationale pour la Protection des Données (CNPD) - cnpd.public.lu
- Your country: Contact your local data protection authority
9.9 Response Time
We will respond to requests within 30 days. If we need more time, we'll notify you of the extension and reason.
10. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@wpmaven.ai.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
11.1 Right to Know
You can request information about the personal data we've collected, used, disclosed, or sold in the past 12 months.
11.2 Right to Delete
You can request deletion of your personal data, subject to certain exceptions.
11.3 Right to Opt-Out of Sale
We do not sell your personal data.
11.4 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
How to exercise: Email privacy@wpmaven.ai with "CCPA Request" in the subject line.
12. AI-Specific Privacy Considerations
12.1 Prompt Processing
- What you write is sent to our AI providers as you wrote it. We do not strip out names, addresses, or phone numbers first, so please treat the description box the way you would treat an email to a supplier
- Our providers are listed in Section 4.1. Each is under a data processing agreement and none of them may use what you write to train their models
- We keep what you write. Section 6.1 explains why, and Section 9.3 explains how to have it erased
- We do not sell it and we do not use it to train AI models
12.2 Generated Content
- You own content generated by the Service
- Generated content is stored for as long as we run your site, because it is your site
- We do not claim ownership or copyright over your generated content
- Similar content may be generated for other users (AI is not deterministic)
12.3 How We Improve the Service
- We do not train AI models on your prompts or your content, and we do not allow our providers to
- Our own people do read the descriptions people write, in order to improve how the Service understands them. Section 6.1 explains this in full
- There is currently no self-serve switch to opt out of this. If you would rather we did not keep what you wrote, email privacy@wpmaven.ai and we will erase it
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will notify you via email and/or in-app notification
- We will update the "Last Updated" date at the top
- Changes take effect 30 days after notification
- Continued use after changes constitutes acceptance
We encourage you to review this Privacy Policy periodically.
14. Contact Us
For questions, concerns, or to exercise your privacy rights, contact us:
Privacy Inquiries: privacy@wpmaven.ai
Data Protection Officer: dpo@wpmaven.ai
General Support: support@wpmaven.ai
Postal Address:
YOTAKO S.A. - Privacy Department
4 rue Samuel Beckett, Luxmill building
L-4371 Belvaux, Sanem
Grand-Duchy of Luxembourg
15. Data Processing Agreement (DPA)
For White label customers requiring a Data Processing Agreement, please contact legal@wpmaven.ai. We provide standard DPAs that include:
- Processing terms compliant with GDPR Article 28
- Standard Contractual Clauses for international transfers
- Security measures and audit rights
- Sub-processor lists and notification procedures