Privacy policy
LAST UPDATED 12 SEPTEMBER 2026
We collect what is needed to write and publish your posts, and nothing we cannot justify. Your article text is sent to Anthropic to be written and critiqued. We do not sell your data, we do not record your screen, and no analytics cookie is set unless you agree to one.
Who we are
House Style is operated by AI Venture Holdings LLC, Salt Lake City, Utah. For the purposes of the UK and EU GDPR we are the data controller for your account data, and a data processor for the content you create with the product. You can reach us at support@example.invalid or by post at Salt Lake City, Utah, United States.
The disclosure that matters most
Your post content is sent to Anthropic. To research, draft, critique and optimise an article, the product sends your brief, your brand-voice settings, your audience description, your banned-word list and the draft text itself to Anthropic’s API. Your edits are also processed there when the system works out what rule your edit implies.
This is not incidental — it is how the product works, and you cannot use it without it. Anthropic acts as our sub-processor under its commercial terms, which do not permit training on data submitted through the API. If that is unacceptable for your content, the honest answer is that this product is not for you.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, hashed password, user ID, workspace membership and role | To let you sign in and to control who sees which site |
| Site configuration | Site name, domain, brand voice, audience, SEO targets, schedule | To write posts that sound like you, on your schedule |
| Content | Briefs, drafts, published posts, titles, meta descriptions | It is the product |
| Editing history | Diffs between what was generated and what you published, and the rules induced from them | This is the learning loop. Without it the product does not improve |
| Operational | Model used, token cost, duration and outcome of each pipeline step | To meter spend, enforce your cap, and show you what you bought |
| Publishing credentials | GitHub installation IDs, WordPress and Ghost tokens | To publish to your destination. Encrypted at rest with AES-256-GCM and never written to logs |
| Search performance | Impressions, clicks and positions from Google Search Console | To feed real outcomes back into what gets written next |
| Analytics | Page views and uncaught errors | Only if you consent. See below |
What we deliberately do not collect
- No session recording and no DOM autocapture. Both are switched off in code, because the editor holds your unpublished work and replay would ship it to a third party.
- No query strings in analytics. Every URL sent to analytics is truncated at the first
?or#, so invite tokens and redirect targets cannot leak into an analytics store. - No advertising pixels, no data brokers, no cross-site tracking.
- No special-category data, no biometrics, no health data, no payment card numbers (Stripe handles those and we never see them).
Legal bases (UK/EU GDPR)
- Contract — account, site configuration, content, publishing, billing. We cannot provide the service without these.
- Legitimate interests — security logging, abuse prevention, spend metering, and aggregate service improvement. Balanced against your rights, and narrow in scope.
- Consent — analytics cookies and any marketing email. Withdrawable at any time, and withdrawing is as easy as giving it.
- Legal obligation — tax and accounting records for paid accounts.
Cookies and similar technologies
A strictly necessary cookie keeps you signed in. That one is required for the product to function and has no alternative.
Analytics set nothing until you agree. PostHog is not initialised at all until consent is granted, so no ph_* cookie exists before you click Allow. If you decline, we store your refusal in first-party localStorage — not in a cookie, because setting a cookie to record that you refused cookies would be absurd. Clear your site data to be asked again.
Who else processes your data
All are bound by contract, and all currently process in the United States.
| Sub-processor | Purpose |
|---|---|
| Anthropic | Writing, critique and rule induction |
| Supabase | Database, authentication and file storage |
| Vercel | Application hosting |
| Stripe | Payments. Card details go to Stripe directly and never touch our servers |
| Resend | Transactional email |
| PostHog | Analytics and error capture — only with consent |
| GitHub, WordPress, Ghost | Only the destination you connect, and only to publish to it |
| Google Search Console | Read-only performance data for sites you authorise |
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. There is therefore no “Do Not Sell or Share My Personal Information” mechanism to offer, because there is nothing to opt out of.
International transfers
If you are in the UK or EEA, your data is transferred to the United States. We rely on the Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified, as the transfer mechanism.
How long we keep it
- While your account is open — account, sites, posts, rules and history.
- 30 days after you delete your account — then erased from live systems. Encrypted backups age out within a further 30 days.
- 7 years — invoices and payment records, where tax law requires it.
- Immediately on disconnect — publishing credentials are destroyed when you remove a destination.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, withdraw consent, or receive it in a portable format. Write to support@example.invalid and we will respond within 30 days. You may also complain to your local supervisory authority — in the UK, the ICO.
California residents have the equivalent rights to know, delete, correct and limit under the CCPA/CPRA, and we will not discriminate against you for exercising them.
Security
Every table carries row-level security, so a request can only ever read rows for sites its owner has access to — this is enforced by the database, not by application code, and is covered by 71 automated tests. Publishing credentials are encrypted with AES-256-GCM before storage. Secrets are redacted from logs and analytics by an enforced filter. No system is perfectly secure, and we do not claim otherwise.
If something goes wrong
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell you directly without undue delay where the risk is high.
Children
This is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, write to us and we will delete it.
Changes
If we make a material change we will email account holders and update the date at the top of this page before it takes effect.