Skip to content

Privacy Policy

Last updated 27 August 2026

This policy explains what YoDon collects, why, who else sees it and how to get it back or deleted. The short version: we collect what the Service needs to write and publish your articles, your WordPress credentials are encrypted and never shared with an AI provider, and nothing here is sold to anyone.

1. Who is responsible for your data

Ravinaro LLC-FZ, Dubai, Meydan Grandstand is the controller of personal data processed through YoDon.

For anything in this policy, including a request to see or delete your data, write to info@ravinaro.com or use the contact form.

2. What we collect

You give us

  • Account details β€” name, email address and a hashed password. If you sign in with Google we receive your name, email address, profile picture and Google's stable account identifier instead of a password.
  • Connected site credentials β€” the site URL, the WordPress username and the Application Password or connector token. Secrets are encrypted at rest with AES-256-GCM and are never shown back to you or sent to any AI provider.
  • Content you write β€” prompts, topics, business context, saved article styles, and anything you type into a support ticket or the contact form.
  • Billing details β€” handled by Stripe. We store the Stripe customer and subscription identifiers and your plan. We never see or store card numbers.

We generate or collect automatically

  • Generated content β€” articles, images, research notes and the source URLs behind them.
  • Usage records β€” which model ran at which step, token counts and the cost of each run, so both of us can see what an article cost.
  • Operational logs β€” request and error logs, and a log of emails sent to you.
  • Bot-protection signals β€” Cloudflare Turnstile inspects the browser on sign-up, sign-in and the contact form. It is designed not to track people across sites.

3. Why we use it, and on what legal basis

  • To provide the Service β€” generating and publishing articles, running your automations, showing your usage. Basis: performance of our contract with you.
  • To bill you and keep the records tax law requires. Basis: contract and legal obligation.
  • To email you about verification, published articles, paused automations, low credits and support replies. Basis: contract. Optional notifications can be turned off.
  • To keep the Service secure and working β€” bot protection, abuse prevention, debugging. Basis: our legitimate interest in a service that is not overrun.

4. What the AI providers receive

Producing an article means sending your prompt, the site context you supplied and the intermediate drafts to the AI provider handling that step, and sending the topic to a web-search provider. Providers used today: OpenAI, Google (Gemini), Anthropic and DeepSeek.

We use these providers through their paid APIs. OpenAI, Anthropic and Google state that API content is not used to train their models by default, and typically retain it for a limited period for abuse monitoring. DeepSeek processes and stores data in the People's Republic of China under its own policy, which is materially different β€” if that matters to you, tell us and we will confirm which providers are configured for your pipeline.

We never send your WordPress credentials to any AI provider. They receive the writing task, not the keys to your site.

5. Who else processes your data

These are the companies we rely on to run the Service:

ProviderWhat it doesWhere
CloudflareHosting, the database, image storage and bot protection (Turnstile)Global edge network
StripeSubscription and one-off payments. Card details go to Stripe, never to usUnited States / Ireland
ResendSending transactional emailUnited States
OpenAIArticle research, writing and imagesUnited States
Google (Gemini)Article research and writingUnited States
Google (Sign-in)Optional Google sign-inUnited States
AnthropicArticle research and writingUnited States
DeepSeekArticle writing, when selected as the model for a stepPeople's Republic of China

We do not sell personal data, and we do not share it with advertisers. We may disclose data where the law requires it, or to establish or defend legal claims.

6. How your site credentials are protected

  • Secrets are encrypted at rest and decrypted only to make a request to your site.
  • They are never returned to the browser, logged, or included in an error message.
  • You can revoke an Application Password from your own WordPress admin at any time, which cuts our access immediately.
  • Disconnecting a site in YoDon deletes the stored credential.

7. How long we keep things

  • Account and content β€” for as long as the account exists, then deleted or anonymised within 30 days of closure.
  • Site credentials β€” until you disconnect the site or close the account.
  • Billing records β€” as long as tax and accounting law requires, which is generally several years, regardless of account closure.
  • Operational and email logs β€” short-lived, kept only as long as they are useful for debugging and abuse prevention.

8. International transfers

We operate from Dubai, United Arab Emirates. and our providers are located in several countries, including the United States and, for one AI provider, the People's Republic of China. Where data leaves a jurisdiction that restricts transfers, we rely on the appropriate safeguards for that route β€” for transfers out of the EEA or the UK, the standard contractual clauses in our providers' data-processing terms.

9. Your rights

Depending on where you live you may have the right to:

  • ask what we hold about you and get a copy;
  • have inaccurate details corrected;
  • have your data deleted;
  • receive it in a portable format;
  • object to, or ask us to restrict, processing based on legitimate interests;
  • withdraw consent where we relied on it;
  • complain to your data-protection authority.

These rights come from the UAE Personal Data Protection Law, the GDPR and UK GDPR, and the CCPA/CPRA in California, among others. Write to info@ravinaro.com and we will answer within 30 days. We do not sell or share personal information as those terms are defined by Californian law, and we do not discriminate against anyone for exercising a right.

10. Cookies

We use only what the Service needs to function, and no advertising or analytics trackers:

  • a session cookie that keeps you signed in, and a short-lived cookie that remembers your light/dark preference;
  • cookies set by Cloudflare Turnstile while it runs the bot check;
  • cookies set by Stripe on the checkout and billing-portal pages.

Because none of these are used for advertising or cross-site tracking, there is no consent banner to click through.

11. Children

The Service is for business use by adults. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we will remove it.

12. If something goes wrong

If a security incident affects your personal data we will investigate, contain it, notify the relevant authority where the law requires, and tell affected customers by email without undue delay.

13. Changes to this policy

We will update this page when our practices change and move the "last updated" date. For material changes β€” a new category of data, or a new kind of processor β€” we will also email account holders.