Trust Centre
Security controls, compliance, sub-processors, data location and vulnerability disclosure for Bloggable. Last updated 7 September 2026.
Compliance
UK GDPR / Data Protection Act 2018
Privacy Policy, Data Processing Addendum, sub-processor list and rights process published.
PECR (cookies and marketing)
Strictly necessary cookies only; cookieless analytics; unsubscribe on every marketing email.
PCI DSS
Card processing is performed by Stripe, a PCI DSS Level 1 service provider. We do not store card data.
Infrastructure certifications
Our hosting provider (Vercel) and database provider (MongoDB Atlas) hold SOC 2 Type II and ISO/IEC 27001 certifications. Their reports are available from the providers.
International transfers
Transfers out of the UK rely on UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework where a provider is certified, or the UK Addendum to the EU SCCs / IDTA. The safeguard for each provider is shown in the sub-processor table.
Security controls
Infrastructure
Hosting location
The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network.
Encryption in transit
All connections use TLS. HTTP Strict Transport Security is enabled on our domains.
Encryption at rest
The database and file storage encrypt data at rest using provider-managed AES-256 keys.
Integration credentials
Credentials for services you connect (Search Console, WordPress, Ghost, webhooks) are encrypted at the application layer before storage and deleted when you disconnect.
Backups
The database runs as a replicated cluster with automated backups.
Separate environments
Development, preview and production are separate deployments with separate credentials.
Browser security headers
Standard security headers, including HSTS, content-type, referrer and permissions policies, are set on responses.
Application
Authentication
Sign-in is by Google OAuth or a single-use link sent by email. No passwords are stored.
Role-based access
Accounts have owner, admin, member and viewer roles. Permissions are checked on the server for every request.
Tenant isolation
Every record is scoped to the account it belongs to. Content, settings, assistant memory and integration credentials are partitioned by account.
Content sanitisation
Customer-authored content is sanitised before it is rendered to readers, and embeds are limited to an allow-list of hosts.
Rate limiting
Rate limits are applied to authentication, public endpoints and other abuse-prone routes.
Outbound requests
Server-side requests to external URLs (imports, research, link previews) are restricted to prevent server-side request forgery.
Payments
Checkout, card storage and the billing portal are hosted by Stripe. We hold a customer reference and the last four digits of the card only.
AI
No training on your content
Prompts, content and outputs are used only to produce your result. Neither we nor our AI provider train models on them.
Model access
Model requests are routed through the Vercel AI Gateway to Anthropic and attributed to the requesting account.
Untrusted content
Web pages and search results are passed to models as untrusted data, not as instructions.
Confirmations
The assistant asks before destructive actions. Confirmation is verified on the server.
Memory
Preferences the assistant remembers are scoped to your account, and personal data is redacted before they are stored.
Billing
The assistant cannot buy credits, change plans or access payment details. Autopilot has a monthly budget cap per blog.
Data protection
UK GDPR and Data Protection Act 2018
We are the controller for account data and a processor for customer content and reader data. The Privacy Policy and Data Processing Addendum apply to every account.
Cookies and analytics
Our site analytics set no cookies. Reader counts on customer blogs use a hash that is discarded within 24 hours. We set no cookies on customer blogs.
Retention
Retention periods for each category of data are set out in the Privacy Policy. Content is deleted 30 days after an account closes.
Export
Published posts are available in Markdown at their own URL, and content can be exported from the app while the account is open.
Sub-processors
Every third party that processes personal data for us is listed on this page. Additions are published at least 30 days before they take effect.
Google API Limited Use
Search Console access is read-only, used only to show your own performance data in your account, and complies with the Google API Services User Data Policy, including the Limited Use requirements.
Operations
Staff access
Administrative access is restricted to named staff. Access to customer accounts is limited to support you request, security investigation and legal compliance.
Audit trail
Credit movements are recorded in an append-only ledger, including manual adjustments by staff. Scheduled jobs and administrative actions are logged.
Secrets
Secrets are held in the deployment platform’s encrypted environment configuration, not in source control.
Incident response
A personal data breach affecting your data is notified to you without undue delay and within 72 hours of our becoming aware of it.
Sub-processors
Third parties that process personal data on our behalf, what they receive, where they process it, and the safeguard for any transfer out of the UK. Additions are published here at least 30 days before they take effect. List last updated 1 January 2026.
| Provider | Purpose | Personal data | Location | Transfer safeguard | Added |
|---|---|---|---|---|---|
| Vercel Vercel Inc. | Application hosting and serverless compute, global edge network, file storage for uploaded media (Vercel Blob), cookieless web analytics, and the AI Gateway that routes our model requests. | All service data in transit and at rest on the platform; uploaded media; request logs (IP address, user agent). | Ireland (Dublin region); cached public content served from a global edge network | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States | 2026-01-01 |
| MongoDB Atlas MongoDB, Inc. | Managed primary database. | All account, content, billing-metadata, support and usage records. | Ireland (Dublin region) | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States | 2026-01-01 |
| Anthropic Anthropic, PBC | Large language model inference (Claude) for research synthesis, drafting, editing, scoring, repurposing and the Joe assistant. Accessed through the Vercel AI Gateway. | Prompts and content submitted for generation — post text, voice samples, brief and topic details, Joe conversations (with personal data redacted from stored memory). Not used to train models. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs | 2026-01-01 |
| Tavily Tavily, Inc. | Web research search API used by the research and competitor pipelines. | Search queries derived from the topic, keywords and competitor URLs a customer supplies. No account identifiers. | United States | UK Addendum to the EU SCCs / IDTA | 2026-01-01 |
| Stripe Stripe Payments UK Ltd and Stripe, Inc. | Payments, subscription billing, invoicing, the customer billing portal and payment fraud prevention. | Name, email address, billing address, payment card details (entered directly with Stripe and never seen by Bloggable), transaction history. | United Kingdom, European Union and United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs | 2026-01-01 |
| Resend Resend, Inc. | Delivery of transactional, notification and product-update email; receipt of inbound support email. | Name, email address, message subject and content, delivery events (sent, bounced). | United States | UK Addendum to the EU SCCs / IDTA | 2026-01-01 |
| Google Google LLC | Sign in with Google (OAuth); and, only for customers who connect it, the Google Search Console API for search performance data. | Google account email, name and profile image at sign-in; Search Console performance data for the sites a customer authorises. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs | 2026-01-01 |
| Unsplash Unsplash, Inc. | Stock photography search and download for featured images. | Image search terms only. No account identifiers or personal data. | Canada | UK adequacy regulations (Canada) | 2026-01-01 |
Data location and retention
Location
Referr Ltd is a UK company. The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network. Other providers and their locations are listed in the sub-processor table.
Retention
- Content: while the account is open, then 30 days for export, then deleted.
- Assistant conversations: 90 days.
- Reader hashes: 24 hours.
- Billing records: 6 years, as UK law requires.
- Full schedule in the Privacy Policy.
Export and rights requests
Published posts are available in Markdown at their own URL, and content can be exported from the app while the account is open. Rights requests go to hello@support.getbloggable.com.
Vulnerability disclosure
Email hello@support.getbloggable.com with “Security” in the subject, or see /.well-known/security.txt. We do not currently run a paid bug-bounty programme.
We ask that you
- Give us reasonable time to fix an issue before disclosing it publicly.
- Do not access, modify or delete data that is not yours; use test accounts you own.
- Do not run denial-of-service, spam, social engineering or physical attacks.
- Stop and tell us immediately if you encounter personal data belonging to someone else.
We commit to
- Acknowledge your report within 2 business days.
- Keep you informed of our progress and tell you when the issue is fixed.
- Not take legal action against research carried out in good faith under these terms.
- Credit you, if you wish, once the issue is resolved.
Frequently asked questions
- Where is my data stored?
- The application runs on Vercel and the database on MongoDB Atlas, both in Ireland (Dublin region). Cached public content is served from Vercel’s edge network. Other providers and their locations are listed in the sub-processor table.
- Do you use my content to train AI models?
- No. Your content is sent to our AI provider only to produce the result you asked for, and neither we nor the provider train models on it.
- Who can see my content?
- Members of your own account, according to their role, and the public once you publish. Our staff access accounts only for support you request, security investigation or legal compliance.
- Do you have a Data Processing Addendum?
- Yes. It applies automatically to every account and is published at /legal/dpa. A countersigned copy is available on request.
- Can I delete my data?
- Yes. Closing your account unpublishes your blogs and starts a 30-day export window, after which content is deleted from live systems. You can also ask us to delete specific data at any time.
- Do I need a cookie banner on my blog?
- Not because of us. We set no cookies on customer blogs and reader counts are cookieless. If you embed third-party content such as video, that platform may set cookies and you are responsible for any notice it requires.
- How do I report a security vulnerability?
- Email hello@support.getbloggable.com with “Security” in the subject line, or use the security.txt file at /.well-known/security.txt.
- How will I know if you add a sub-processor?
- The list on this page carries the date each provider was added. Additions are published at least 30 days before they take effect, and material changes are emailed to account owners. You can object under the DPA.
Documents
Each document is versioned and available as Markdown. A countersigned DPA is available on request.