Skip to main content

Privacy policy

Last updated: 1 August 2026

This policy describes what personal data Vupie collects on vupie.com and inside the Vupie application, why it is collected, where it is kept, and what you can ask us to do with it. It is written to be read, not skimmed past.

1. Who we are and how to reach us

Vupie researches, writes and publishes sourced articles to customer sites and measures the result. We are based in the European Union, and the service is hosted there.

For the data described in this policy, Vupie decides how and why it is processed and acts as the controller under the GDPR. For content and data that customers bring into the service, such as articles, connected search data and CMS credentials, Vupie processes on the customer's instructions as a processor, and a data processing agreement is part of signup.

Questions, requests and complaints about data go to [email protected]. Mail reaches a person, and a person answers.

2. The data we collect

Visitors. Browsing this site requires no account and no consent. The consent layer on every page is Passiro, and it loads before any other script so that non-essential scripts, including analytics, stay blocked until you have made a choice. If you decline, the site still works.

Waitlist signups. Joining the waitlist stores the name you enter, your email address, your website, the interest you select, and the IP address the form was submitted from. The IP address is kept to prevent abuse of the form.

Account holders. An account stores your email address, your name and a hash of your password. The password itself is never stored. Signing in sets a session cookie, which the application needs in order to work.

Billing. Payments will be processed by Stripe. Card numbers go to Stripe, not to Vupie.

Connected accounts. The service runs on data you choose to connect. Planning and measurement read from your own Search Console and Analytics accounts, and publishing integrations connect to your own CMS accounts. Vupie reads what the feature needs and nothing beyond it, and you can revoke a connection at any time from the account it was granted in.

Correspondence. Writing to us stores the correspondence, so that we can answer and keep track of what was agreed.

3. Purposes and legal bases

We process personal data on the legal bases the GDPR provides:

  • Performance of a contract (Article 6(1)(b)): running your account, producing and publishing articles, operating the integrations you connect, and billing.
  • Steps taken at your request before a contract (also Article 6(1)(b)): the waitlist, and contacting you when your spot opens.
  • Legitimate interests (Article 6(1)(f)): keeping the service secure, preventing abuse of public forms, and communicating with you about the service you use.
  • Consent (Article 6(1)(a)): analytics and any other non-essential cookies or scripts. Consent is asked for before anything loads and can be withdrawn at any time.
  • Legal obligation (Article 6(1)(c)): records we are required to keep, such as invoicing and accounting records.

We do not sell personal data, and we do not run advertising on it.

4. AI processing

Articles are produced with large language models operated by third-party providers. To deliver the service, customer content and data from connected accounts are sent to those providers to research, draft, review and score articles. The providers act as subprocessors under contract.

Customer content is processed to deliver the service and is not used to train models. Every article keeps a record of which models were involved, when, and from which sources.

5. Subprocessors

We use a small number of subprocessors, each under a data processing contract, in these categories:

  • Hosting and data storage, in the European Union.
  • Payment processing: Stripe.
  • Consent management: Passiro.
  • AI model providers, for the processing described in section 4.
  • Search and results data used for planning and measurement.

Every subprocessor is documented, and the current list is available on request at [email protected]. Integrations you connect yourself, such as Search Console, Analytics or your CMS, are your own accounts with those providers and are governed by their terms, not ours.

6. Where data lives

Hosting and data storage are in the European Union. Where a subprocessor processes personal data outside the EU, the transfer is covered by safeguards the GDPR recognises, such as the European Commission's standard contractual clauses.

7. How long we keep data

We keep personal data for as long as it is needed for the purpose it was collected for, and no longer. In practice:

  • Account data is kept for the life of the account and deleted when the account is deleted, except records we are legally required to keep, such as invoices.
  • Waitlist entries are kept until you are onboarded or until you ask to be removed.
  • Data read from connected accounts is kept only as long as the feature that uses it needs it. Revoking a connection stops the flow.
  • Your articles are exportable at any time, and deleted on account deletion.

8. Your rights

Under the GDPR you can ask for access to the data we hold about you, have it corrected, have it deleted, have its processing restricted, receive it in a portable format, and object to processing based on legitimate interests. Where processing rests on consent, you can withdraw the consent at any time without affecting what happened before.

Send access, export and deletion requests to [email protected]. We answer within the time limits the GDPR sets. You can also complain to a data protection supervisory authority, in the EU country where you live or work or where you believe the problem occurred.

9. Cookies and consent

Consent on this site is managed by Passiro, a consent management platform. The Passiro script loads before any other script, which is what keeps non-essential scripts blocked until you have decided. Strictly necessary cookies, such as the session cookie that keeps you signed in, do not require consent and are the only cookies set without it.

You can change or withdraw your consent at any time through the consent settings on this site, and the change takes effect immediately.

10. Changes to this policy

When this policy changes, the new version is published on this page and the date at the top is updated. If a change materially affects account holders, we tell them by email before it takes effect.