AutopilotRank

Privacy Policy

Last updated: February 4, 2026

1. Introduction

Welcome to AutopilotRank ("we," "our," or "us"), operated by ColdStart Labs Inc. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered SEO content generation and publishing platform.

By using AutopilotRank, you agree to the collection and use of information in accordance with this policy. If you have any questions, contact us at support@autopilotrank.com.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Password (stored securely using industry-standard hashing)
  • Authentication data from third-party providers (Google, Microsoft) if you choose to sign in with OAuth

2.2 Content You Generate

When you use our content generation features, we collect and store:

  • Article prompts, topics, and keywords you provide
  • AI-generated articles and content produced by the service
  • Campaign settings and scheduling configurations

2.3 Payment Information

We use Stripe to process payments. We never see or store your full credit card details — Stripe handles all payment processing securely. Stripe stores payment information according to their Privacy Policy .

2.4 CMS Credentials

To publish content to your websites, we collect and store:

  • WordPress (or other CMS) site URLs and API credentials
  • These credentials are encrypted at rest using AES-256-GCM encryption
  • Credentials are used solely to publish content on your behalf
  • We never share your CMS credentials with third parties

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our content generation and publishing services
  • Generate AI-powered articles based on your prompts and campaign settings
  • Publish content to your connected CMS platforms on your schedule
  • Manage your account, credit balance, and subscription
  • Process payments and send transaction receipts
  • Send service-related communications (password resets, account notifications, publishing confirmations)
  • Respond to customer support requests
  • Analyze usage patterns to improve our service and detect abuse

4. Data Sharing and Third-Party Services

We do not sell your personal information. We share data with the following third-party service providers as necessary to operate the service:

  • Supabase: Provides our database and authentication infrastructure. Your account data and generated content are stored in Supabase.
  • Stripe: Handles all payment processing. Your payment details are stored and managed by Stripe under their privacy policy.
  • Brevo / Resend: Used to send transactional emails (account notifications, receipts). Your email address is shared with these providers for this purpose.
  • OpenRouter / OpenAI / Replicate (AI Providers): Your article prompts and content generation requests are sent to these AI providers to produce articles. Please review their respective privacy policies, as your input content is processed by their systems.
  • Cloudflare: Provides hosting, CDN, and edge computing infrastructure. Web traffic passes through Cloudflare's network.
  • Amplitude / Google Analytics: Used for usage analytics and product improvement. These services may collect anonymized usage data and device information.
  • Legal Requirements: We may disclose your information when required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.

5. Data Security

We implement industry-standard security measures to protect your data:

  • HTTPS encryption for all data transmission
  • AES-256-GCM encryption for stored CMS credentials
  • Secure password hashing (we never store passwords in plaintext)
  • Row-level security (RLS) for database access control
  • Access controls and authentication on all internal systems

While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your data according to the following rules: account data (profile, settings, credentials) is retained while your subscription is active and for 90 days after cancellation, after which it is permanently deleted upon request. Generated articles are retained until you delete them from your account. Payment records and transaction history are retained for 7 years as required by applicable accounting and tax law.

You may request deletion of your account and associated data at any time by contacting support@autopilotrank.com. Note that legal retention obligations (e.g., payment records) may prevent immediate deletion of all data.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Export: Request a copy of your generated content and account data in a portable format
  • Objection: Object to certain processing of your data, including direct marketing

To exercise these rights, please contact us at support@autopilotrank.com .

8. Cookies and Tracking

We use cookies and similar technologies to:

  • Maintain your session and authentication state
  • Remember your preferences and settings
  • Analyze usage patterns via Google Analytics and Amplitude
  • Improve our service and user experience

You can control cookies through your browser settings, but disabling them may affect the functionality of the service (e.g., you may be logged out).

9. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at support@autopilotrank.com.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including Canada and the United States, where our service providers operate. These countries may have different data protection laws. By using our service, you consent to such transfers. We ensure appropriate safeguards are in place to protect your data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. For material changes, we may also notify you by email. Your continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: