Privacy Policy
Last updated: February 2026
ZEZI B LLC (“we,” “us,” “our”) operates the Draft2Publish WordPress plugin and website (draft2publish.ai). This Privacy Policy explains how we collect, use, store, and protect your information when you use our products and services.
1. Information We Collect
1.1 Account & Profile Data
- Email address (via WordPress or Freemius registration)
- WordPress user ID
- Site URL where the plugin is installed
- Subscription tier and billing status
1.2 API Keys (User-Provided)
You provide your own API keys for third-party AI providers. We store these in your WordPress database (aics_*_api_key options) on your server. We do not transmit or store your API keys on our servers.
Supported providers: Google (Gemini), OpenAI (GPT), Anthropic (Claude), DeepSeek, Perplexity, Replicate (Flux images), Leonardo.ai
1.3 Content & Configuration Data
- Niche topics, categories, and content schedules
- Region, language, and style preferences
- AI model and provider selections
- Word count and formatting settings
1.4 Usage Data
- Daily and weekly article generation counts
- Last-generation timestamps
- Subscription usage relative to tier limits
1.5 Generated Content Metadata
- Generation configuration per post (
_aics_generation_config) - Primary source URL used for research (
_d2p_primary_source_url)
1.6 Security & Log Data
- IP address, user ID, endpoint/action, user-agent, and timestamps (stored in
wp_aics_security_logdatabase table) - Rate-limit, lockout, and ban transients
- System activity logs including status messages and operational metadata
2. How We Use Your Information
We use collected information to:
- Provide the service: Generate content, manage schedules, enforce tier limits
- Maintain security: Detect abuse, enforce rate limits, prevent unauthorized access
- Improve the product: Understand usage patterns to improve features (aggregated, not individual)
- Communicate: Send account-related emails (billing, support, critical updates)
- Comply with legal obligations: Respond to lawful requests, enforce our Terms of Service
We never use your content, topics, or API keys for our own purposes, training, or resale.
3. Data Shared with Third Parties
3.1 AI Providers (User-Directed)
When you generate content, your prompts, topics, keywords, and research context are sent directly from your server to the AI providers you’ve configured. These requests use your API keys and are governed by each provider’s own privacy policy and terms of service.
We do not control or have access to the data processed by these providers. You are the data controller for these transmissions.
3.2 Freemius (Licensing & Payments)
We use Freemius for license management, subscription billing, and plugin updates. Freemius may collect email address, site URL, WordPress environment data, subscription and payment information, and plugin usage telemetry.
3.3 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Storage & Security
4.1 Where Data Is Stored
- Plugin data (API keys, settings, logs, content metadata) is stored in your WordPress database on your hosting server. We do not maintain a separate copy.
- Account/billing data is stored by Freemius on their infrastructure.
- Website data (contact forms, email communications) is stored on our servers in the United States.
4.2 Security Measures
- API keys are stored as WordPress options (encrypted if your hosting supports it)
- Security logging tracks access attempts with IP, user-agent, and timestamps
- Rate limiting and lockout mechanisms protect against brute-force attacks
- All external API calls use HTTPS/TLS encryption in transit
4.3 Data Retention
- Security logs: Retained for 90 days, then automatically purged
- Activity logs: Retained for 30 days
- Usage counters: Reset daily/weekly per tier schedule
- Account data: Retained while your account is active; deleted within 30 days of account deletion request
- Generated content: Remains in your WordPress database under your control indefinitely
4.4 Data on Uninstall
When you deactivate and delete the Draft2Publish plugin, plugin options (aics_*), the security log table (wp_aics_security_log), and post metadata remain in your WordPress database unless manually removed. We recommend using a database cleanup plugin or manually removing these entries if you wish to fully delete all Draft2Publish data.
5. Your Rights
5.1 All Users
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your account and associated data
- Export your data in a portable format
- Opt out of non-essential communications
5.2 EEA / UK Residents (GDPR)
You also have the right to restrict processing, object to processing, data portability, withdraw consent, and lodge a complaint with your local data protection authority.
Lawful bases: Contract performance, legitimate interests (security, product improvement), consent (marketing), and legal obligation.
5.3 California Residents (CCPA)
You have the right to know what personal information we collect, request deletion, opt out of sale (we do not sell your data), and non-discrimination for exercising your rights.
6. Cookies & Local Storage
| Type | Name | Purpose | Duration |
|---|---|---|---|
| Local Storage | aicsActiveTab |
Remembers your active admin tab | Persistent (until cleared) |
We do not use tracking cookies. Our website may use essential cookies for site functionality.
7. Children’s Privacy
Draft2Publish is not directed at children under 16. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by updating the “Last Updated” date, sending email notification for significant changes, and displaying a notice in the plugin dashboard.
9. Contact Us
For privacy-related questions, data access requests, or complaints:
ZEZI B LLC
Deerfield Beach, FL 33441, USA
Email: [email protected]
We aim to respond to all privacy requests within 30 days.