Legal · Privacy
Privacy Policy
This notice explains how we process personal data through the public Website and the managed BlogFactory Cloud service.
Effective September 20, 202601 · Scope
Scope and data controller
The data controller for blogfactory.io is GRİD SOLUTİON BİLİŞİM VE YAZILIM TİCARET LİMİTED ŞİRKETİ ("Grid Solution", "we", "us", or "our").
Huzur, Maslak Ayazağa Cd. No:4/B34485 Sarıyer/İstanbul, Türkiye
This policy covers the public marketing website, documentation, Help Center, Cloud accounts, billing, and hosted content operations. It does not replace a self-hosted operator's data practices or privacy notice.
02 · Collection
Data we collect
- Product updates
- Your normalized email address, consent version, and consent timestamps if you previously submitted the Cloud launch form or later request product communications.
- Security and delivery data
- Cloudflare may process IP address, browser, device, request, and anti-abuse signals required to deliver and protect the website and operate Turnstile.
- Privacy correspondence
- Your email address and the information you include when you contact us about a privacy request.
- Cloud account and billing
- Account identity, verified email, subscription and entitlement state, usage counters, and Polar customer, order, and subscription identifiers. We do not store card numbers or raw billing addresses from Polar webhooks.
- Hosted operations
- Sites, sources, settings, prompts, drafts, images, review state, sanitized operation events, and encrypted provider credentials needed to deliver the service.
The marketing site does not collect payment details or product content. Cloud data is processed by the separately hosted application after signup. The site code does not add an advertising tracker or separate marketing analytics service.
03 · Purpose
How we use personal data
- To create and secure Cloud accounts, authenticate sessions, and provide requested product functions.
- To process subscriptions, enforce plan limits, reconcile billing state, and answer support requests.
- To store and process content, settings, integrations, and credentials needed for your requested workflows.
- To protect the Website and Cloud Service, prevent abuse, diagnose failures, and maintain backups and operation records.
- To record and honour product-update consent where you provide it.
- To answer privacy requests and comply with applicable legal obligations.
We process Cloud account and service data to perform our contract with you; billing, tax, fraud, and compliance records where required by law; security and reliability data for our legitimate interests; and optional product communications based on consent. You may withdraw communication consent without affecting the service.
04 · Processors
Providers and international transfers
We use service providers only for the functions described below:
- Cloudflare
- Website delivery, proxy and security services, Turnstile abuse prevention, EU-jurisdiction R2 object storage and encrypted backups, and D1 records from the former Cloud launch form.
- Hetzner
- Application and worker compute in Nuremberg, Germany.
- Neon
- Managed PostgreSQL infrastructure in Frankfurt, Germany.
- WorkOS
- Authentication, sessions, MFA, account lifecycle, and essential authentication email.
- Polar
- Merchant-of-record checkout, subscriptions, invoices, taxes, payment status, cancellations, and refunds.
- OpenRouter and selected AI providers
- AI inputs and outputs only when you connect a provider and request generation. Their terms and retention practices also apply.
- Search Console data only when you connect and authorize that integration.
- Sanity
- Published marketing and blog content supplied at build time; Cloud account content is not submitted to Sanity.
Some providers may process data outside Türkiye. We use applicable contractual and provider safeguards for international transfers. Platform secrets are not included in browser bundles, MCP output, or sanitized operation records.
We do not sell or rent personal data. We disclose data only to providers needed for the purposes above, when required by law, or as part of a lawful corporate transaction with appropriate protections.
06 · Retention
How long we keep data
Former Cloud launch-update records are deleted within 90 days after the launch notification is sent unless you request earlier deletion. Privacy correspondence is kept only as long as needed to answer the request, establish that it was handled, or meet a legal obligation.
Sanitized operation records are retained for 30 days. Cloud account and content data remain while the account is active and afterwards only as needed to provide a requested recovery period, handle a privacy request, resolve a dispute, prevent fraud, or meet legal and accounting duties. Encrypted backups rotate on a limited operational schedule, so deleted records may remain inaccessible in backups until that schedule expires. Polar retains invoices and transaction records under its merchant-of-record obligations.
07 · Deployment boundary
Self-hosted BlogFactory instances
A Community instance runs on infrastructure selected and controlled by its operator. Content, credentials, MCP tokens, and operation records in that instance do not route through this marketing website.
The operator is responsible for its own privacy notice, legal basis, access controls, retention, backups, and the practices of its chosen hosting, AI, CMS, Google, storage, and email providers. This policy does not make Grid Solution the controller for an independently operated installation.
08 · Your choices
Your privacy rights
Under Article 11 of Türkiye's Personal Data Protection Law No. 6698 and other laws that may apply to you, you may have rights to:
- Learn whether we process your personal data and request information about that processing.
- Learn the purpose of processing and the recipients inside or outside Türkiye.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction when the legal conditions are met and notification of that action to relevant recipients.
- Object to a result produced against you solely through automated analysis.
- Request compensation for damage caused by unlawful processing.
Send a request to [email protected]. We may ask for information reasonably necessary to verify your identity and locate the relevant record. You can read the official English translation of Law No. 6698.
Until self-service export and deletion controls are available, verified access, portability, correction, and deletion requests are handled manually through that address.
09 · Protection
Security and children
We use site-scoped authorization, access controls, encrypted provider credentials, private object storage, sanitized operation records, and operational backups. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
The Website and Cloud Service are not directed to children. If you believe a child submitted personal data, contact us so we can investigate and remove it where required.
10 · Updates
Changes and contact
We may update this policy when the Website, Cloud Service, providers, or law changes. The revised page will show a new effective date, and we will provide additional notice of material changes when required.
Privacy questions and requests: [email protected]
GRİD SOLUTİON BİLİŞİM VE YAZILIM TİCARET LİMİTED ŞİRKETİHuzur, Maslak Ayazağa Cd. No:4/B
34485 Sarıyer/İstanbul, Türkiye