CCPA/CPRA Privacy Notice
Effective Date: 10 February 2026 Last Updated: 10 February 2026
This Privacy Notice is provided pursuant to the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), for California residents ("consumers"). This notice supplements our general Privacy Policy.
1. Your Rights Under CCPA/CPRA
As a California resident, you have the following rights:
| Right | Description |
|---|---|
| Right to Know | Request what personal information we collect, use, disclose, and sell |
| Right to Delete | Request deletion of your personal information |
| Right to Correct | Request correction of inaccurate personal information |
| Right to Opt-Out of Sale/Sharing | Opt out of the sale of personal information or sharing for cross-context behavioral advertising |
| Right to Limit Use of Sensitive PI | Limit the use and disclosure of sensitive personal information |
| Right to Non-Discrimination | Not be discriminated against for exercising your privacy rights |
2. Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
2.1. Identifiers
- Name, email address, account name/username
- IP address, device identifiers
- Organization name and website domain
Source: Directly from you, automatically collected Purpose: Account management, authentication, communications, service delivery
2.2. Commercial Information
- Subscription tier and status (Found/Known/Basic/Pro)
- Billing history, payment amounts
- Stripe customer ID, card last 4 digits, brand, expiry
Source: Directly from you, from Stripe Purpose: Billing, subscription management, payment processing
2.3. Internet or Network Activity
- Page views (path, title, referrer, UTM parameters)
- Browser type, operating system, device type
- Session information, hashed visitor IDs
Source: Automatically collected via self-hosted analytics Purpose: Usage analytics, product improvement, security
2.4. Professional or Employment Information
- Job title, company name, professional role
- Specialties, background, expertise
Source: Directly from you (team profiles, customer stories, referrals) Purpose: Content attribution, AI content generation, case studies
2.5. Geolocation Data
- Country and region (derived from IP address)
Source: Automatically collected Purpose: Regional pricing, analytics, compliance
2.6. Inferences
- AI-generated content (blog posts, social posts, case studies)
- Brand voice analysis results
- SEO scores and keyword rankings
- AI visibility/stand-out scores
Source: Generated by our AI systems from data you provide Purpose: Service delivery (core product functionality)
2.7. Sensitive Personal Information
- Account login credentials (email address + verification codes)
Source: Directly from you Purpose: Authentication only
3. How We Use Personal Information
We use personal information for the following business purposes:
- Providing our services — account management, AI content generation, blog publishing, analytics
- Processing payments — subscription billing via Stripe
- Communicating with you — account notifications, feature updates, story invitations
- Improving the service — usage analytics, performance monitoring
- Security and fraud prevention — rate limiting, abuse detection
- Legal compliance — tax records, responding to legal obligations
4. Sale and Sharing of Personal Information
4.1. We Do Not Sell Personal Information
DiscoverWorthy does not sell personal information as defined by the CCPA/CPRA. We have not sold personal information in the preceding 12 months.
4.2. We Do Not Share for Cross-Context Behavioral Advertising
We do not share personal information for cross-context behavioral advertising. We do not use Google Analytics, Facebook Pixel, or any third-party advertising trackers.
4.3. Do Not Sell or Share My Personal Information
Although we do not sell or share personal information, you may submit a request at support@discoverworthy.com and we will confirm our practices.
5. Categories of Third Parties
We disclose personal information to the following categories of service providers for business purposes:
| Category | Service Provider | Purpose |
|---|---|---|
| AI content generation | Azure OpenAI (Microsoft) | Generating blog posts, social posts, case studies |
| Image generation | Azure DALL-E 3 (Microsoft) | Generating cover photos |
| Payment processing | Stripe, Inc. | Subscription billing, freelancer payouts |
| Search integrations | Google LLC | Search Console, Business Profile data |
| SMS delivery | Twilio, Inc. | Team member phone verification |
| Web search | Brave Software, Inc. | SERP keyword tracking, AI lookup |
| Email delivery | Azure Communication Services (Microsoft) | Notifications, invitations, reminders |
| Data storage | Azure SQL Database (Microsoft) | Secure storage of all data |
All third parties are service providers under CCPA — they are contractually prohibited from using your data for any purpose other than performing services for us.
6. Sensitive Personal Information
We collect the following sensitive personal information:
- Account login credentials (email + verification code)
This information is used only for authentication. We do not use sensitive personal information for purposes beyond what is necessary to provide the Service. You have the right to limit the use of your sensitive personal information.
7. Data Retention
We retain personal information only as long as necessary for the purposes described in this notice. See our Privacy Policy for specific retention periods.
8. Financial Incentives
Our free tier (Found plan) provides limited access to the Platform. Paid plans (Known, Basic, Pro) provide additional features. The difference in service levels is based on the features provided, not on the personal information collected. We do not offer financial incentives in exchange for personal information.
9. How to Exercise Your Rights
9.1. Submitting a Request
You may submit a request to:
- Email: support@discoverworthy.com
9.2. Verification
To protect your privacy, we will verify your identity before processing your request. We may ask you to:
- Confirm your email address via a verification code
- Provide additional information to match our records
9.3. Authorized Agents
You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide:
- Written authorization signed by you, or
- Power of attorney
We may still require you to verify your identity directly.
9.4. Response Timeline
We will acknowledge your request within 10 business days and respond substantively within 45 calendar days. If additional time is needed, we will notify you of an extension (up to 90 days total).
10. Non-Discrimination
We will not discriminate against you for exercising your CCPA/CPRA rights. We will not:
- Deny you goods or services
- Charge you different prices
- Provide a different level of service quality
- Suggest you will receive different prices or quality
11. Annual Metrics
As required by CPRA regulations, we will publish annual metrics regarding consumer requests received, complied with, and denied. These metrics will be updated annually.
| Metric | Count |
|---|---|
| Requests to know | [To be updated annually] |
| Requests to delete | [To be updated annually] |
| Requests to correct | [To be updated annually] |
| Requests to opt-out | [To be updated annually] |
| Average response time | [To be updated annually] |
12. Changes to This Notice
We may update this notice periodically. Changes will be posted with an updated effective date. Material changes will be communicated via email.
13. Contact Us
For CCPA/CPRA questions or requests:
- Email: support@discoverworthy.com
- Address: 140 Keller Road, ESSENDON NORTH, VIC 3041
You also have the right to contact the California Attorney General at oag.ca.gov or the California Privacy Protection Agency at cppa.ca.gov.