This Privacy Policy explains how AI Blog Autopilot (aiblogautopilot.com, the “Service”) collects and uses personal data. We collect only what we need to run the Service, we do not sell personal data, and your articles and project data are never used to train AI models.
1. Who we are (data controller)
The Service is operated by Internet Solutions, UAB, a company registered in the Republic of Lithuania (European Union):
- Company code: 302617697
- VAT code: LT100006088413
- Registered address: Tvenkinių g. 8A, Šakių k., Kauno r. sav., LT-47415, Lithuania
- Correspondence address: Vilniaus g. 72-310, LT-76298 Šiauliai, Lithuania
- E-mail for privacy requests: [email protected]
Internet Solutions, UAB is the controller of the personal data described in this policy. We also operate PostRSS, the social publishing service that AI Blog Autopilot uses to share your articles (see section 5).
The Service is used by people and businesses worldwide. We apply the EU General Data Protection Regulation (GDPR) to everyone, wherever you are. If the law of your country gives you additional rights, those rights apply as well.
2. What data we process
| Category | What it includes |
|---|---|
| Account data | E-mail address, name, password (stored only as a one-way hash), plan and plan validity, account creation and last login time, notification and newsletter preferences. |
| Sign-in with Google, Facebook, Apple or Yahoo | If you choose to sign in with one of these providers, we receive only your name and e-mail address from that provider. No password is shared with us. |
| Project data | Business or project name, website address, description of your business, audience, tone, topics, keywords, content language, publishing schedule and time zone, selected social networks and pages, and your choices in the setup wizard. |
| Website content we read | When you add a website, we read the publicly available text of its home page and “about” page to suggest topics and settings. We do not read password-protected areas. |
| Generated content | Article topics, outlines, texts, FAQ, meta titles and descriptions, tags, social post texts, cover images, quality scores, publication status and the links to published posts. |
| Connection credentials | If you connect WordPress, the user name and application password you provide (stored encrypted), or the connection data of our WordPress plugin; the link to your PostRSS account and the list of social destinations you choose. We never ask for your social network passwords. |
| Billing data | Orders, plan, amount, VAT, payment method, payment status, transaction or subscription identifiers from the payment processor, and the invoice details you enter (company name, address, country, VAT number). We do not receive or store full card numbers. |
| Communication | Messages you send us and our replies, and service e-mails we send you (for example password reset, publishing alerts, billing notices). |
| Technical data | IP address, browser and device information, and request logs created by our servers when you use the Service; cookies described in section 9. |
The Service is not intended for sensitive data (such as health data or data about children). Please do not put such data into your project description or topics.
When you sign in with Google, Facebook, Apple or Yahoo, we request only your basic profile (name) and e-mail address and use them only to create your account and sign you in. We do not post through these sign-in connections, do not access your contacts, files or other data from these providers, and do not sell or share this information. AI Blog Autopilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Why we process data and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account; planning, writing, publishing and sharing your content; customer support | Performance of our contract with you (Art. 6(1)(b)) |
| Payments, invoices, accounting and tax records | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Security, fraud and abuse prevention, enforcing plan limits, debugging, keeping logs | Our legitimate interest in a safe and reliable service (Art. 6(1)(f)) |
| Service e-mails about your account, publishing results and billing | Contract (Art. 6(1)(b)) |
| Newsletter and product news | Your consent (Art. 6(1)(a)); it is off by default and you can withdraw it at any time |
| Showing your published articles in the “Just published” block on our home page | Your consent (Art. 6(1)(a)); it is off by default and can be switched off in the project settings at any time |
| Handling legal claims and requests from authorities | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
We do not use your data for automated decisions that have legal or similarly significant effects on you. The automatic quality check that decides whether an article is published automatically or kept for your review concerns your content, not you.
4. How AI is used
To write your articles and social posts, the Service sends the information needed for the task — your project description, topics, keywords, tone, language, excerpts of your public website text and the article draft — to third-party AI model providers acting on our instructions. We do not send your e-mail address, password or payment details. Under our arrangements, the data we send is not used to train the providers’ models. We do not use your content to train any AI model ourselves.
AI-generated text can contain errors or outdated information. See our Умови використання for your responsibilities when publishing it.
5. Who receives your data
We share personal data only with recipients that help us provide the Service, and only to the extent needed:
- Hosting and infrastructure providers — servers, storage, backups, network and security services.
- AI model providers — generating texts, as described in section 4.
- Payment processors — processing card, e-wallet, crypto and similar payments. They process your payment data as independent controllers under their own privacy policies.
- E-mail delivery providers — sending service e-mails.
- PostRSS — our own social publishing service, operated by Internet Solutions, UAB. When you connect social networks, your PostRSS account is linked in the background and receives the post texts, images, links and destinations needed to publish.
- Platforms you connect — your WordPress site, webhook endpoint and the social networks you choose receive the content you publish there. Once published, the content is governed by those platforms’ own terms and privacy policies.
- Professional advisers and authorities — accountants, lawyers, auditors, courts and authorities when required by law or to protect our rights.
Our service providers act as processors under data processing agreements and may use the data only on our instructions. We do not sell or rent personal data and do not share it for advertising.
6. International transfers
We store the Service’s data on servers located in the European Union. Some service providers (for example AI model providers or payment processors) may process data outside the European Economic Area. In that case we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses approved by the European Commission, together with additional safeguards where needed. You can ask us for more information about these safeguards.
7. How long we keep data
- Account, project and generated content — while your account is active. After the account is deleted, it is removed from our live systems within 30 days and from backups when they are overwritten in the normal backup cycle.
- Invoices, orders and payment records — for the period required by Lithuanian accounting and tax law (currently up to 10 years), even after account deletion.
- Server and security logs — for a limited period, normally not longer than 12 months, unless needed longer to investigate an incident.
- Support correspondence — for as long as needed to handle your request and for up to 3 years afterwards for follow-up questions and legal claims.
- Newsletter consent — until you unsubscribe.
Content you have already published on your website or social networks stays there after your account is deleted. We cannot remove it from those platforms; you can do this yourself.
8. Your rights
You have the right to:
- access your personal data and receive a copy of it;
- correct inaccurate data;
- ask us to delete your data;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable, machine-readable format;
- withdraw your consent at any time (this does not affect processing carried out before the withdrawal);
- lodge a complaint with a data protection authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). You can also contact the authority in the country where you live or work.
To use any of these rights, write to [email protected] from the e-mail address registered in your account. We reply within one month. We may ask you to confirm your identity.
Account deletion
You can ask us to delete your account at any time by writing to [email protected] from your registered e-mail address. Your account is not suspended because of the request; we delete it and its data as described in section 7.
If your account has an unpaid balance, the deletion request is registered, and the account is closed and deleted after the balance is settled. Until then we keep the data needed to establish and collect the claim, as allowed by GDPR Article 17(3)(e). Invoices and payment records are kept for the period required by law.
Deleting your AI Blog Autopilot account removes the link to PostRSS. If you also want your PostRSS account deleted, tell us in the same request.
9. Cookies
We use only cookies that are necessary for the Service to work or that remember your own choice:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in during a visit and protects forms against forgery | Until the browser is closed |
| Remember-me cookie | Keeps you signed in on your device | 30 days |
| theme | Remembers light or dark display mode (also stored in your browser’s local storage) | Until you change it or clear it |
We do not use advertising or third-party tracking cookies. Payment pages of payment processors may set their own cookies under their own policies. You can delete cookies in your browser settings; without the session cookie you cannot sign in.
10. Security
We use encrypted connections (HTTPS), store passwords as one-way hashes, encrypt stored connection credentials such as WordPress application passwords, and limit access to personal data to people who need it for their work. No system is completely secure; if a personal data breach is likely to put your rights at risk, we will inform you and the supervisory authority as required by law.
11. Children
The Service is intended for businesses and adults. It is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
12. Personal data in your content
If your project description, topics or published articles contain personal data of other people, you are responsible for having a lawful basis to use and publish it. For such data we act on your instructions.
13. Changes to this policy
We may update this policy when the Service or the law changes. We will post the new version on this page with a new date and, for important changes, inform registered users by e-mail before the changes take effect.
14. Contact
Internet Solutions, UAB, Vilniaus g. 72-310, LT-76298 Šiauliai, Lithuania — [email protected]