Privacy Policy

UniversalVersion 2Last updated 20 February 2026

Privacy Policy

Effective Date: 10 February 2026 Last Updated: 20 February 2026

DiscoverWorthy ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform ("Service").

This policy applies to all users of the Service, regardless of location. Additional jurisdiction-specific disclosures may apply—see our UK GDPR Data Processing Addendum, CCPA/CPRA Privacy Notice, US State Privacy Addendum, and AU Privacy Collection Notice for details.


1. Data Controller

DiscoverWorthy is the data controller responsible for your personal information.

2. Information We Collect

2.1. Information You Provide Directly

DataWhen CollectedPurpose
Email addressAccount registrationAuthentication, communications
Full nameProfile setup (optional)Display name, attribution
Organization name and typeOrganization creationWorkspace identification
Website domainOrganization setupBlog publishing, crawler
Billing emailSubscription setupInvoice delivery
Blog post contentContent creationPublishing, AI processing
Brand voice guidelinesBrand settingsAI content tone matching
Products/services informationOrganization settingsAI content context
Team member details (name, role, specialties, email, photo)Team setupAuthor attribution, AI matching
Customer story data (name, email, company, project, conversation)Story submissionCase study generation
Referral data (name, email, title, company, LinkedIn, photo)Referral submissionProfile recommendations
Competitor names (blocklist)"Never Mention" settingsAI content filtering

2.2. Information Collected Automatically

DataHow CollectedPurpose
IP addressServer logsSecurity, geographic location
User agent stringHTTP headersDevice/browser identification
Session tokensAuthentication cookieSession management
Page views (path, title, referrer, UTM params)Analytics trackingUsage analytics
Device info (type, browser, OS, screen size)Analytics trackingUsage analytics
Geographic location (country, region)IP-based lookupAnalytics, regional pricing

2.3. Information from Third Parties

SourceDataPurpose
StripeCard last 4 digits, brand, expiryPayment display
Brave SearchSERP keyword rankingsKeyword tracking

2.3.1. Google Search Console

When you connect Google Search Console, we access the following data using the webmasters.readonly scope (read-only—we do not modify your Search Console settings):

DataPurpose
Site URLs and permission levelsIdentify which sites you can connect
Search queries driving traffic to your siteSEO analytics and content optimization
Page-level click and impression dataBlog performance analysis
Click-through rate (CTR) and average positionKeyword opportunity identification
Device breakdown (desktop, mobile, tablet)Audience analytics
Daily search performance time seriesTrend analysis

2.3.2. Google Business Profile

When you connect Google Business Profile, we access the following data using the business.manage scope:

Data we read:

DataPurpose
Account ID, name, and typeIdentify which business accounts you manage
Location details (business name, address, phone, website, category, hours)Display your business information
Google Maps URI and Place IDLink to your Google listing, enable review request campaigns
Customer reviews (reviewer name, profile photo, star rating, comment, timestamps)Review management and response
Existing review repliesDisplay reply history
Local posts (content, type, media, call-to-action, status)Post management
Performance metrics (search and Maps impressions, direction requests, phone call clicks, website clicks)Business performance analytics
Search keyword impressionsUnderstand how customers find your business

Data we write:

ActionPurpose
Post replies to customer reviewsHelp you respond to reviews (with your approval)
Delete review repliesAllow you to remove replies
Create local posts (text, media, events, offers)Help you publish updates to your Google listing
Delete local postsAllow you to remove posts

We do not:

  • Modify your business information (name, address, phone, hours, etc.)
  • Delete or modify customer reviews themselves
  • Access your Google Ads data
  • Access data from any Google service beyond Search Console and Business Profile

3. How We Use Your Information

We use your personal information for the following purposes:

  • Service delivery: Account management, content generation, blog publishing
  • AI content generation: Your content, brand voice, team info, and customer data are sent to Azure OpenAI (GPT-4o) to generate blog posts, social posts, case studies, and other content
  • Cover photo generation: Blog titles and keywords are sent to Azure DALL-E 3
  • Google Business Profile management: Displaying your reviews, publishing posts, and showing performance insights within our dashboard
  • SEO analytics: Combining Google Search Console data with our content tools to identify keyword opportunities and track blog performance
  • Payment processing: Subscription billing via Stripe
  • Communications: Account verification, billing notifications, feature updates, story invitations, reminders
  • Analytics: Understanding how the Service is used to improve it
  • Security: Fraud prevention, rate limiting, abuse detection
  • Legal compliance: Tax records, responding to legal requests

4. Legal Basis for Processing (UK/EU Users)

Legal BasisProcessing Activities
Contract (Art. 6(1)(b))Account management, billing, service delivery, AI content generation
Legitimate Interest (Art. 6(1)(f))Analytics, security, product improvement
Consent (Art. 6(1)(a))Customer stories, referrals, marketing emails, Google integrations
Legal Obligation (Art. 6(1)(c))Tax records, fraud prevention

5. Who We Share Your Data With

We share personal information with the following categories of service providers:

ProviderPurposeData SharedLocation
Azure OpenAI (GPT-4o)AI content generationBlog content, customer names, conversation transcripts, brand voice data, team infoUnited States
Azure DALL-E 3Cover photo generationBlog titles, keywords, excerptsUnited States
StripePayment processingEmail, payment method detailsUnited States
Stripe ConnectFreelancer payoutsBank details (handled by Stripe)United States
Google Search Console APISEO analyticsOAuth tokens; we receive search queries, clicks, impressions, and page performance dataUnited States
Google Business Profile APIReview and post managementOAuth tokens; we receive reviews, business info, performance metrics, and search keywords; we send review replies and local posts on your behalfUnited States
Brave SearchSERP keyword trackingKeywords, localeUnited States
TwilioSMS delivery (team OTP)Phone numbersUnited States
Azure Communication ServicesEmail deliveryEmail addresses, message contentUnited States
Azure SQL DatabaseData storageAll data (encrypted at rest via TDE)Australia East

Important: Customer names, company names, and full conversation transcripts are sent to Azure OpenAI without anonymization for content generation purposes. Azure OpenAI processes data under Microsoft's data protection terms and does not use customer data for model training.

We do not sell your personal information to third parties.

6. Cookies and Tracking

We use a single authentication cookie and a self-hosted analytics system. See our Cookie & Tracking Policy for full details.

  • Session cookie (session_token): httpOnly, secure, SameSite=lax, 30-day expiry. Required for authentication.
  • Analytics: Self-hosted, privacy-focused. Uses hashed daily visitor IDs (reset each day—no cross-day tracking). No third-party tracking cookies (no Google Analytics, no Facebook Pixel).

7. Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Blog contentUntil deleted by user or account closure
Billing records7 years (legal/tax requirement)
Analytics data24 months, then aggregated
Session tokens30 days from creation
Customer story transcriptsUntil story is deleted by org owner
Google OAuth tokensUntil integration is disconnected
Google Business Profile data (reviews, posts, metrics)Refreshed on each sync; not retained after integration is disconnected
Google Search Console dataRefreshed on each sync; not retained after integration is disconnected
AI-generated contentUntil deleted by user

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Restriction: Request restricted processing in certain circumstances
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time

To exercise your rights, contact us at dpo@discoverworthy.com. We will respond within 30 days (or as required by applicable law).

9. Google API Services - Limited Use Disclosure

DiscoverWorthy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google data to provide and improve user-facing features that are visible to you in our dashboard.
  • We do not transfer Google data to third parties except as necessary to provide the Service (e.g., displaying your data in our interface), as required by law, or with your explicit consent.
  • We do not use Google data for serving advertisements.
  • We do not allow humans to read your Google data unless: (a) we have your explicit consent, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.

10. International Data Transfers

Your data may be transferred to and processed in the United States, where our primary service providers are located. We implement appropriate safeguards for international transfers:

  • UK/EU Users: Standard Contractual Clauses (SCCs) or adequacy decisions
  • Australian Users: Reasonable steps to ensure overseas recipients comply with the Australian Privacy Principles (see AU Privacy Collection Notice)

11. Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption at rest (Azure SQL Transparent Data Encryption)
  • Encryption in transit (HTTPS/TLS)
  • httpOnly, secure session cookies
  • Rate limiting on authentication and API endpoints
  • Input validation and parameterized queries
  • Regular security reviews
  • Role-based access controls
  • Google OAuth tokens encrypted at rest in our database

12. Children's Privacy

The Service is not directed to children under the age of 16 (or 13 in the US). We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us immediately at dpo@discoverworthy.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Platform at least 30 days before the changes take effect. The "Last Updated" date at the top will be revised accordingly.

14. Contact Us

For privacy-related questions, complaints, or to exercise your rights:

UK Users: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Australian Users: You have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

California Users: See our CCPA/CPRA Privacy Notice for California-specific rights.

Privacy Policy | DiscoverWorthy