How Your Data Travels Through the Pipeline
When you enter a keyword and hit "Generate," here is the exact sequence:
- Your seed keyword and project settings leave your browser over a TLS-encrypted connection.
- The system builds a research prompt and sends it to the language model API (OpenAI or Google Gemini) via their Enterprise API endpoints.
- The API returns generated text. Cluster Writer processes it — structuring headings, injecting entity maps, formatting for WordPress.
- If auto-publish is enabled, the finished article is pushed to your WordPress site through its REST API using your Application Password.
- After delivery, your generation request is logged as a timestamp and credit deduction. The full text of your prompts and outputs is not stored on my servers after processing completes.
That's it. Five steps. No side channels, no background processes siphoning your strategy into a training dataset.
Zero Data Training Policy
The API calls Cluster Writer makes to OpenAI and Google Gemini use commercial API endpoints — not the free consumer-facing chatbots.
What this means in practice:
- Per OpenAI's API data usage policy, data sent through the API is not used to train their models.
- Per Google's Gemini API terms, API inputs are processed for response generation only.
Your keyword research, your topic clusters, your content briefs — none of it feeds back into any model's training loop. Your SEO strategy stays yours.
Project-Level Data Isolation
Each user account operates in its own isolated environment. Your projects, keyword lists, WordPress credentials, and generation history are not accessible to other accounts.
There is no shared workspace, no collaborative editing between strangers, no "community content pool." One account, one silo.
Credential Encryption
Cluster Writer stores two types of sensitive credentials:
- LLM API Keys (your OpenAI or Gemini keys, if you bring your own)
- WordPress Application Passwords (used for auto-publishing)
Both are encrypted at rest using AES-256 encryption. They are decrypted only at the moment of an API call, held in memory for the duration of the request, and never written to application logs.
Scoped Authentication Protocol
I don't see your WordPress admin password. The system uses WordPress Application Passwords — a scoped authentication method that grants publishing access without exposing your main login credentials.
Payment Security
I don't handle your credit card. Payment processing runs entirely through third-party processors (Gumroad, Stripe). Card numbers, CVVs, and billing details never touch my servers. I receive only a transaction confirmation and the amount paid.
What We Cannot Guarantee
No system is invulnerable. I can tell you what I control:
- Encrypted connections (TLS in transit, AES-256 at rest)
- Data isolation between accounts
- No model training on your inputs
- No credential logging
What I cannot control: the internal security practices of OpenAI, Google, Stripe, or your WordPress hosting provider. I select providers with strong security track records, but their infrastructure is theirs to manage.
If a breach affecting your data ever occurs on my end, I will notify you directly within 72 hours, in compliance with GDPR breach notification requirements.
Your keywords. Your clusters. Your strategy. Not mine, not OpenAI's, not anyone else's.
