Privacy Policy
Last updated 2026-07-06. This explains what ContentWise collects, why, and what control you have over it.
1. Who we are
ContentWise ("we," "us") operates this service online. This policy covers the ContentWise web application, its API, and the ContentWise landing site.
Contact for privacy matters: privacy@content-wise.app.
2. What we collect
Account data. Name, email address, and authentication metadata, handled by our authentication provider, Clerk. We don't see or store your password.
Brand and business data you provide. Company name, industry, website, brand brief, target audience, content pillars, brand guidelines, tone, writing samples, footer/hashtag preferences, and any logo or brand assets you upload.
Content you generate. The calendars, captions, blog posts, emails, and designs ContentWise produces for you, and any edits you make to them.
Conversations. Messages you send to the in-product strategist chat, so it can maintain context across a session.
Billing data. Handled by Stripe. We store your plan tier and Stripe customer reference, not your card number.
Third-party connections you opt into. If you connect a CMS (Ghost, WordPress) or an email provider (Mailchimp) to publish content, we store the credentials needed to do that, encrypted at rest (AES-256-GCM). If you connect Canva, we store OAuth tokens, not your Canva password.
Usage data. Which features you use and how often, so we can enforce plan limits and improve the product.
Anonymous visitors. If you try the landing-page demo chat before signing up, we store a hashed (not raw) version of your IP address, solely to apply a fair-use limit — we can't reverse it back to your actual IP.
3. How your content is generated — the AI processing disclosure
ContentWise's core function is sending your brand data (brief, guidelines, tone, voice samples, topic) to Anthropic's Claude API to generate content. This is fundamental to how the product works, not an optional add-on — if that's not something you're comfortable with, ContentWise isn't the right tool. Anthropic processes this data to return generated text; we don't control how Anthropic itself retains or uses API inputs beyond what its own terms specify.
4. Who else processes your data
We use the following sub-processors to run the service. None of them see your data except as needed to provide their specific function:
- Anthropic — AI content generation (see §3)
- Clerk — authentication and account management
- Stripe — billing and payment processing
- Neon — database hosting (PostgreSQL)
- Vercel — application hosting
- Resend — transactional email (account and billing notifications)
- Calendarific, Google Trends — public holiday and trend data used to suggest content topics; no personal data is sent to these
If you choose to connect them, these become additional processors of your published content:
- Mailchimp — if you send email campaigns through it
- Ghost or WordPress — if you publish blog posts through them
- Canva — if you connect it for design
5. International data transfers
Our processors (listed above) operate in the United States and elsewhere. If you're in the EU, UK, or another jurisdiction with data-transfer restrictions, your data may be transferred outside your region. We rely on our processors' own compliance mechanisms for these transfers (each of the providers listed in §4 publishes its own data-transfer safeguards, typically Standard Contractual Clauses for EU-origin data). We haven't independently executed separate transfer agreements beyond relying on those providers' standard terms.
6. How long we keep data
We keep your account and content data for as long as your account is active. If you delete your account, we delete your brand data, generated content, and connection credentials within 30 days, except where we're required to keep billing records longer for tax or legal reasons.
7. Your rights
You can ask us to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Export your content (also available directly in-product via PDF/CSV export)
- Object to or restrict certain processing
To exercise any of these, contact us at the address in §12. We'll respond within a reasonable time, consistent with applicable law (e.g. GDPR's 30-day window where it applies).
8. Cookies
We use a small number of cookies, all functional — no third-party advertising trackers:
- A session cookie from Clerk, to keep you signed in
- A theme preference cookie, to remember light/dark mode
9. Security
Sensitive credentials (CMS and email-provider API keys) are encrypted at rest with AES-256-GCM. Access to your data is authenticated and scoped to your account — every request is checked against account ownership before it touches your data. No system is perfectly secure, and we can't guarantee absolute security, but this is the standard we hold the product to.
10. Children
ContentWise is a business tool. It isn't directed at, and we don't knowingly collect data from, anyone under 16.
11. Changes to this policy
If we make material changes, we'll update the date at the top of this page and, for significant changes, notify you by email.
12. Contact
ContentWise
privacy@content-wise.app
Questions about your data?
Reach out any time — we'd rather explain than have you guess.