Privacy Policy
Last updated: 22 July 2026
This policy explains what personal data Jord Digital Ltd (a company registered in England and Wales, "we") collects when you use Content Shrimp, why, and your rights. We are the data controller. For any privacy question, email support@contentshrimp.com.
1. What we collect
- Account data: your email address (we use passwordless magic-link sign-in).
- Brand data you enter: your brand voice profile, website URL, notes, uploaded references, and the content you generate and save.
- Usage data: which features you use and how many generations you run, so we can meter your plan.
- Payment data: handled by Stripe. We receive your plan and payment status but never store your full card number.
- Technical data: standard log and device information needed to run and secure the Service, plus data stored locally in your browser to make the app work.
2. How we use it
- To provide the Service — generating content from your brand profile, saving your work, and running your account.
- To bill you and manage your subscription.
- To provide support and respond to you.
- To keep the Service secure and to improve it.
3. Legal bases
We process your data to perform our contract with you (providing the Service), for our legitimate interests (running, securing, and improving the Service), to meet legal obligations, and, where required, with your consent.
4. AI processing
To generate content, we send the relevant brand context and your request to AI providers acting as our processors. We do not sell your data, and we do not use your brand data or content to train our own AI models. Our providers process your data to return a result under their own terms and do not use API content to train their models by default.
5. Who we share data with (sub-processors)
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Application hosting and delivery |
| Stripe | Subscription payments |
| xAI (Grok) | Text generation and web research |
| Google (Gemini) | Image generation (using your own API key) |
| Groq | Voice-to-text transcription |
| OpenAI | Text-to-speech for the in-app assistant |
| Apify | Public web and social research |
We share only what each provider needs to perform its function. We do not sell your personal data.
6. International transfers
Some providers are located outside the UK/EEA (for example in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as the providers' standard contractual clauses.
7. How long we keep it
We keep your data while your account is active. If you delete your account, we delete your brand data and content, keeping only what we must for legal, accounting, or security reasons for a limited period.
8. Your rights
Under UK and EU data protection law you can ask us to access, correct, delete, or export your data, and to object to or restrict certain processing. You can delete your account and its data from within the app, or email us. You also have the right to complain to the UK Information Commissioner's Office (ICO) or your local supervisory authority.
9. Security
We protect your data with access controls, per-account isolation, and encryption of sensitive secrets at rest. No system is perfectly secure, but we take reasonable measures to protect your information.
10. Cookies and local storage
We use only essential cookies and browser storage needed to sign you in and run the app. We do not run third-party advertising trackers.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children.
12. Changes
We may update this policy. If a change is material, we will let you know by email or in the app.
13. Contact
Jord Digital Ltd — support@contentshrimp.com.