Privacy Policy

Last updated: July 13, 2026

1. Introduction

pepe.business ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, password (hashed)
  • Profile information: workspace name, profile settings
  • Payment information: handled by Stripe; we do not store your credit card details
  • Connected accounts: OAuth tokens for social platforms you connect (stored encrypted)

2.2 Information Collected Automatically

  • Usage data: API calls, posts published, analytics data
  • Device information: IP address (anonymized), browser type, operating system
  • Cookies: session cookies for authentication; no tracking cookies

2.3 AI-Generated Content

When you use Auto-Pilot or Generate Suite, we process your input (URLs, prompts, content) through AI providers (such as OpenAI) to generate text, images, and videos. The generated content is stored in your account and is not used to train AI models.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To process payments and manage subscriptions
  • To send service-related communications (account verification, billing, security alerts)
  • To monitor and analyze usage patterns to improve user experience
  • To detect, prevent, and address technical issues, fraud, or security violations
  • To comply with legal obligations

4. Data Sharing

We do not sell your personal information. We may share your data with:

  • Service providers: Stripe (payments), OpenAI (AI generation), Cloudinary (media storage), hosting providers
  • Social platforms: When you publish content, we share it with the platforms you have connected
  • Legal authorities: If required by law, court order, or to protect our rights and safety

5. Data Security

We implement industry-standard security measures including:

  • AES-256 encryption for OAuth tokens and sensitive data at rest
  • TLS 1.3 for data in transit
  • PBKDF2 password hashing (100,000 iterations)
  • HMAC-SHA256 signatures for webhooks
  • Regular security audits and SOC 2 Type II compliance

6. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we remove all personal data within 30 days, except where retention is required by law (e.g., financial records for 7 years).

7. Your Rights

7.1 GDPR Rights (EU/EEA Users)

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Request limited processing of your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests

7.2 CCPA Rights (California Users)

  • Know: Request disclosure of personal information collected
  • Delete: Request deletion of personal information
  • Opt-out: Opt-out of the sale of personal information (we do not sell your data)
  • Non-discrimination: Equal service regardless of rights exercised

To exercise these rights, contact us at privacy@pepe.business.

8. International Data Transfers

Your data is hosted in the United States (Virginia). If you access the Service from outside the US, your data will be transferred to the US. We use Standard Contractual Clauses (SCCs) for transfers from the EU/EEA to ensure adequate protection.

9. Children's Privacy

The Service is not intended for individuals under the age of 13 (or 16 in the EU). We do not knowingly collect information from children. If you believe we have collected information from a child, contact us immediately.

10. Cookies

We use essential cookies for authentication (session management). We do not use tracking, advertising, or analytics cookies. Third-party services (Stripe, OpenAI) may use their own cookies as described in their respective privacy policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before the changes take effect.

12. Contact

If you have questions about this Privacy Policy or your data, contact our Data Protection Officer at privacy@pepe.business.