Legal · Privacy

Privacy Policy

This notice explains how we process personal data through the public Website and the managed BlogFactory Cloud service.

Effective September 20, 2026

01 · Scope

Scope and data controller

The data controller for blogfactory.io is GRİD SOLUTİON BİLİŞİM VE YAZILIM TİCARET LİMİTED ŞİRKETİ ("Grid Solution", "we", "us", or "our").

Huzur, Maslak Ayazağa Cd. No:4/B
34485 Sarıyer/İstanbul, Türkiye

This policy covers the public marketing website, documentation, Help Center, Cloud accounts, billing, and hosted content operations. It does not replace a self-hosted operator's data practices or privacy notice.

02 · Collection

Data we collect

Product updates
Your normalized email address, consent version, and consent timestamps if you previously submitted the Cloud launch form or later request product communications.
Security and delivery data
Cloudflare may process IP address, browser, device, request, and anti-abuse signals required to deliver and protect the website and operate Turnstile.
Privacy correspondence
Your email address and the information you include when you contact us about a privacy request.
Cloud account and billing
Account identity, verified email, subscription and entitlement state, usage counters, and Polar customer, order, and subscription identifiers. We do not store card numbers or raw billing addresses from Polar webhooks.
Hosted operations
Sites, sources, settings, prompts, drafts, images, review state, sanitized operation events, and encrypted provider credentials needed to deliver the service.

The marketing site does not collect payment details or product content. Cloud data is processed by the separately hosted application after signup. The site code does not add an advertising tracker or separate marketing analytics service.

03 · Purpose

How we use personal data

  • To create and secure Cloud accounts, authenticate sessions, and provide requested product functions.
  • To process subscriptions, enforce plan limits, reconcile billing state, and answer support requests.
  • To store and process content, settings, integrations, and credentials needed for your requested workflows.
  • To protect the Website and Cloud Service, prevent abuse, diagnose failures, and maintain backups and operation records.
  • To record and honour product-update consent where you provide it.
  • To answer privacy requests and comply with applicable legal obligations.

We process Cloud account and service data to perform our contract with you; billing, tax, fraud, and compliance records where required by law; security and reliability data for our legitimate interests; and optional product communications based on consent. You may withdraw communication consent without affecting the service.

04 · Processors

Providers and international transfers

We use service providers only for the functions described below:

Cloudflare
Website delivery, proxy and security services, Turnstile abuse prevention, EU-jurisdiction R2 object storage and encrypted backups, and D1 records from the former Cloud launch form.
Hetzner
Application and worker compute in Nuremberg, Germany.
Neon
Managed PostgreSQL infrastructure in Frankfurt, Germany.
WorkOS
Authentication, sessions, MFA, account lifecycle, and essential authentication email.
Polar
Merchant-of-record checkout, subscriptions, invoices, taxes, payment status, cancellations, and refunds.
OpenRouter and selected AI providers
AI inputs and outputs only when you connect a provider and request generation. Their terms and retention practices also apply.
Google
Search Console data only when you connect and authorize that integration.
Sanity
Published marketing and blog content supplied at build time; Cloud account content is not submitted to Sanity.

Some providers may process data outside Türkiye. We use applicable contractual and provider safeguards for international transfers. Platform secrets are not included in browser bundles, MCP output, or sanitized operation records.

We do not sell or rent personal data. We disclose data only to providers needed for the purposes above, when required by law, or as part of a lawful corporate transaction with appropriate protections.

05 · Browser data

Cookies and tracking

The public Website does not currently add advertising or analytics cookies. Cloudflare and Turnstile may use signals necessary for security and bot detection. The Cloud Service uses an essential sealed HttpOnly session cookie through WorkOS authentication; blocking essential cookies prevents sign-in.

06 · Retention

How long we keep data

Former Cloud launch-update records are deleted within 90 days after the launch notification is sent unless you request earlier deletion. Privacy correspondence is kept only as long as needed to answer the request, establish that it was handled, or meet a legal obligation.

Sanitized operation records are retained for 30 days. Cloud account and content data remain while the account is active and afterwards only as needed to provide a requested recovery period, handle a privacy request, resolve a dispute, prevent fraud, or meet legal and accounting duties. Encrypted backups rotate on a limited operational schedule, so deleted records may remain inaccessible in backups until that schedule expires. Polar retains invoices and transaction records under its merchant-of-record obligations.

07 · Deployment boundary

Self-hosted BlogFactory instances

A Community instance runs on infrastructure selected and controlled by its operator. Content, credentials, MCP tokens, and operation records in that instance do not route through this marketing website.

The operator is responsible for its own privacy notice, legal basis, access controls, retention, backups, and the practices of its chosen hosting, AI, CMS, Google, storage, and email providers. This policy does not make Grid Solution the controller for an independently operated installation.

08 · Your choices

Your privacy rights

Under Article 11 of Türkiye's Personal Data Protection Law No. 6698 and other laws that may apply to you, you may have rights to:

  • Learn whether we process your personal data and request information about that processing.
  • Learn the purpose of processing and the recipients inside or outside Türkiye.
  • Request correction of incomplete or inaccurate data.
  • Request deletion or destruction when the legal conditions are met and notification of that action to relevant recipients.
  • Object to a result produced against you solely through automated analysis.
  • Request compensation for damage caused by unlawful processing.

Send a request to [email protected]. We may ask for information reasonably necessary to verify your identity and locate the relevant record. You can read the official English translation of Law No. 6698.

Until self-service export and deletion controls are available, verified access, portability, correction, and deletion requests are handled manually through that address.

09 · Protection

Security and children

We use site-scoped authorization, access controls, encrypted provider credentials, private object storage, sanitized operation records, and operational backups. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.

The Website and Cloud Service are not directed to children. If you believe a child submitted personal data, contact us so we can investigate and remove it where required.

10 · Updates

Changes and contact

We may update this policy when the Website, Cloud Service, providers, or law changes. The revised page will show a new effective date, and we will provide additional notice of material changes when required.

Privacy questions and requests: [email protected]

GRİD SOLUTİON BİLİŞİM VE YAZILIM TİCARET LİMİTED ŞİRKETİ
Huzur, Maslak Ayazağa Cd. No:4/B
34485 Sarıyer/İstanbul, Türkiye