Privacy Policy
Effective date: July 1, 2026
This Privacy Policy is current as of July 1, 2026 and may be updated as Byline grows. Material changes will be notified per Section 9.
1. What we collect
Byline (“we,” “us,” or “our”) collects only what it needs to run your account and provide the service:
Account information. Your email address and password, managed through our authentication provider, Supabase. Passwords are stored by Supabase in hashed form; we do not see or store your password in plain text.
Billing information. Payments are handled by Stripe. We receive limited billing details from Stripe (such as your plan, status, and renewal date) but we never store your card numbers — those are handled entirely by Stripe.
WordPress connection credentials. To publish on your behalf, we store the WordPress Application Passwords and site details you provide. These are encrypted at rest using Supabase Vault and are removed when the related site becomes dormant or is disconnected.
Content data. The sources (RSS feeds) you connect, the article drafts we generate for you, and delivery history — what was sent to which site, and when.
Limited technical data. Basic server logs generated by our hosting providers in the ordinary course of running the service. We do not currently use third-party analytics, advertising, or tracking tools.
2. How we use it
We use your information to operate and provide the service: to fetch your sources, generate drafts, deliver them to your connected WordPress sites, secure and support your account, and bill you correctly.
AI processing. To generate a rewritten draft, the content of the source item you selected is sent to Anthropic’s API, which produces the Output. Under Anthropic’s commercial terms, the inputs and outputs sent through its API are not used to train its models.
Billing. We use Stripe to process payments and manage subscriptions.
Transactional email. Account emails — such as sign-up confirmation and password resets — are sent through Supabase Auth. These are service messages tied to your account, not marketing.
We do not sell your personal information, and we do not use it for advertising.
3. Who we share it with
We share information only with the service providers (“subprocessors”) that make Byline work, and only as needed for them to provide their service to us:
Supabase — authentication, database, and encrypted credential storage (Vault).
Stripe — payment processing and subscription management.
Anthropic — AI processing that generates your drafts.
Vercel — hosting for the Byline web application.
Railway — hosting for the background worker that fetches and delivers content.
We also connect, at your direction, to the WordPress sites and RSS sources you choose. Beyond these providers, we do not sell or rent your personal data, and we do not share it for advertising. We may disclose information if required by law or to protect our rights, users, or the service.
4. Retention and deletion
We keep your account data for as long as your account is active. Sites and sources that become dormant (for example, after a downgrade) are retained for 180 days so you can reactivate them, and may be permanently deleted after that. WordPress credentials are destroyed as soon as a site becomes dormant or is disconnected.
You can ask us to delete your account and associated data at any time by emailing hello@wpbyline.com. Some records may survive deletion where we are legally required to keep them — for example, invoices and payment records held by us or by Stripe for tax and accounting purposes.
5. Security
We protect your information with encryption in transit (HTTPS), encrypted storage of your WordPress credentials in Supabase Vault, and row-level security that isolates each account’s data so one customer cannot read another’s. We never expose your WordPress credentials to your browser; they are used only by our server-side code.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will act promptly and notify you as required by law.
6. Your rights
You can access and update your account information from within the app, and you can request correction or deletion of your data by emailing hello@wpbyline.com. We will respond within a reasonable time.
Byline is a US-based service. If you are a California resident, you have the right to know what personal information we collect, to request its deletion, and not to be discriminated against for exercising those rights — and, as stated above, we do not sell your personal information. If you are in the European Union or United Kingdom, you may have rights to access, correct, delete, or restrict the processing of your personal data; you can exercise them the same way, by contacting us. We honor these requests as a matter of practice, regardless of where you are located.
7. Cookies
We use a small number of cookies that are strictly necessary to run the service — chiefly the session cookies from Supabase that keep you signed in. We do not currently use advertising or third-party analytics cookies. If that changes, we will update this policy and this section first.
8. Children
Byline is a business tool intended for adults. It is not directed at children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
9. Changes and contact
We may update this Privacy Policy as Byline grows. If we make material changes, we will notify you by email or through an in-app notice before they take effect, and we will update the effective date at the top of this page.
Questions about this policy or your data? Reach us at hello@wpbyline.com.