Privacy Policy
Last updated: July 2, 2026
We are committed to protecting your personal information and being transparent about what data we collect and how we use it. We comply with GDPR and applicable data protection laws.
1. Information We Collect
- Company email address (verified domain)
- Company name and website
- Contact name and information
- Account credentials (encrypted)
- Headlines, body text, and media
- Company information and contact details
- Publication dates and preferences
- Content you choose to make public
- IP address and location data
- Browser type, version, and language
- Device type and operating system
- Page views and interaction data
Payment processing is handled securely by Stripe. We do not store credit card numbers or banking information on our servers. Stripe's privacy policy: stripe.com/privacy
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process press releases and maintain your account
- Domain Verification: Confirm your company email and prevent spam
- Communication: Send important updates, notifications, and support
- AI Processing: Draft and optimize content, generate optional audio, and track citations using AI (see Section 12 for the specific providers)
- Analytics: Improve the Service and understand usage patterns
- Security: Prevent fraud, abuse, and unauthorized access
- Legal Compliance: Meet legal and regulatory requirements
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract Performance: To provide the Service you've signed up for
- Legitimate Interest: To improve the Service, prevent fraud, and ensure security
- Legal Obligation: To comply with applicable laws and regulations
- Consent: For marketing communications (you can opt-out anytime)
4. Information Sharing
We do not sell your personal information.
We may share your information only in these circumstances:
- Public Press Releases: Content you publish is publicly accessible
- Service Providers: Trusted third parties who help us operate our platform securely
- AI Processing: Content sent to AI providers for optimization (with privacy safeguards)
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
5. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption: All data in transit uses HTTPS/TLS encryption
- Database Security: Enterprise-grade database with row-level security (RLS) policies
- Access Controls: Multi-factor authentication and role-based access
- Regular Audits: Security reviews and vulnerability assessments
- Backups: Encrypted, regular backups with disaster recovery
- Monitoring: Real-time security monitoring and incident response
6. Data Retention
We retain your information as follows:
- Account Information: Until you delete your account (plus 30 days grace period)
- Published Press Releases: Indefinitely (part of public record)
- Draft Content: 90 days after last edit or deletion
- Technical Logs: 90 days for security and debugging
- Payment Records: 7 years (tax and legal requirements)
- Deleted Accounts: Personal data purged within 30 days
7. Your Privacy Rights (GDPR/CCPA)
You have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your account and data
- Right to Portability: Receive your data in a machine-readable format
- Right to Object: Opt-out of certain data processing activities
- Right to Restrict: Limit how we process your data
- Right to Withdraw Consent: Opt-out of marketing communications
To exercise these rights, email us at: [email protected]
We will respond to your request within 30 days. Note that published press releases remain public even after account deletion (they are part of the public record).
8. Cookies & Tracking
Essential Cookies
- Authentication tokens (keep you logged in)
- Security tokens (CSRF protection)
- Session management
Analytics Cookies
- Page views and user behavior
- Feature usage analytics
- Performance monitoring
Google Analytics 4
We use Google Analytics 4 (Measurement ID: G-H30WPG18EV) to understand how visitors use our Service. Google Analytics collects:
- Pages you visit and time spent on each page
- Your approximate location (city/country level)
- Device type, browser, and screen resolution
- How you found our site (search engine, direct, referral)
- User interactions and conversion events
Google signals:
When enabled, Google may collect aggregated demographics data (age range, gender, interests) from users who have enabled "Ads Personalization" in their Google account. This data:
- Provides anonymized, aggregated insights about our audience
- Enables cross-device tracking for logged-in Google users who consent
- May be used for remarketing features in Google Ads
- Is subject to Google's Privacy Policy: policies.google.com/privacy
How to opt-out: You can opt-out of personalized advertising by visiting adssettings.google.com or by disabling analytics cookies in your browser settings.
Managing Cookie Consent
When you first visit our website, you'll see a cookie consent banner asking you to accept or reject analytics cookies. Analytics cookies load only after you accept: if you reject, or simply ignore the banner, no analytics cookies are set. Your choice is stored in your browser's local storage.
How to change or withdraw your consent:
- Cookie Preferences (easiest): Click “Cookie Preferences” in the footer at the bottom of any page to reopen the banner and change your choice at any time. Withdrawing consent is as easy as giving it.
- Browser settings: You can block or delete cookies entirely through your browser settings (Chrome, Firefox, Safari, Edge all have cookie management options).
- Google opt-out: Visit tools.google.com/dlpage/gaoptout to install the Google Analytics opt-out browser add-on.
Note: Disabling essential cookies may prevent you from using certain features of the Service, such as staying logged in to your account.
9. Third-Party Services
We rely on the following processors and sub-processors, each bound by their own data-protection terms:
Infrastructure & hosting
- Managed database, authentication & storage provider: Stores your account and press-release data (hosted in the EU, Ireland)
- Cloud application-hosting provider: Runs pressonify.ai (EU region)
- Cloudflare: Content delivery network (CDN), DNS, and security / DDoS protection
AI providers
- OpenRouter: AI model gateway that routes our requests to the model providers below
- Anthropic (Claude): Generates press-release drafts
- Google (Gemini & Knowledge Graph): SEO / structured-data optimisation and entity look-ups
- Perplexity: Scans public AI answers to track where your press releases are cited
- OpenAI: Optional text-to-speech (audio versions of press releases)
See Section 12 for how AI processing works and what each provider receives.
Payments, email & analytics
- Stripe: Payment processing (PCI DSS Level 1 certified)
- Transactional email provider: Delivers verification links, receipts, and service notifications
- Google Analytics 4: Website analytics (consent-gated: see Section 8)
Each provider has its own privacy policy and data-protection measures, and we put data-processing agreements in place with our processors. Where a provider offers it, we select API tiers that are not used to train the provider's models and that minimise data retention.
10. International Data Transfers
Your information may be transferred to and processed in countries outside your own, including the United States and EU. We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data-processing agreements with our processors
- Compliance with GDPR Chapter V requirements
- Regular assessments of data protection adequacy
Your account and press-release data are stored in the EU (Ireland) and the application is hosted in the EU. Some processors, our AI providers, Stripe, our email provider, and Google Analytics, operate in the United States; those transfers rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
11. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete it immediately.
12. AI & Data Processing
Pressonify uses AI to draft and optimise press releases, to generate optional audio versions, and to track where your releases are cited. When you use these features, the relevant content is sent to the following providers:
- OpenRouter → Anthropic (Claude): generates your press-release draft from the details you provide
- OpenRouter → Google (Gemini): SEO, headline, and structured-data optimisation
- Perplexity: scans public AI answers to detect citations of your published releases
- OpenAI: converts a release to speech if you request an audio version
Automated processing: these AI features assist you, they do not make automated decisions that produce legal or similarly significant effects on any individual (no Article 22 profiling of people). AI-assisted output is indicative, is presented as AI-generated so you can review and edit it before publishing, and can be wrong.
- Data is transmitted securely over encrypted connections (HTTPS/TLS)
- Where a provider offers it, we select API tiers that are not used to train the provider's models
- We put data-processing agreements in place with our AI processors
- AI features are optional: you can write and publish without them
In line with the EU AI Act's transparency rules (Article 50), we disclose our use of AI here and label AI-assisted press releases so readers know the content was drafted with AI and reviewed before publication.
13. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours (GDPR requirement)
- Inform relevant supervisory authorities as required by law
- Provide details about the breach and our response
- Offer guidance on protective measures you can take
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will:
- Notify you via email for material changes
- Display a prominent notice on the Service
- Update the "Last updated" date at the top of this policy
- Provide a 30-day notice period before changes take effect
15. Contact & Data Protection Officer
For privacy-related questions, concerns, or to exercise your rights, contact:
Data Protection Officer
Email: [email protected]
GDPR Requests: [email protected]
Location: Ireland (EU)
16. Supervisory Authority
If you are located in the EU/EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Ireland: Data Protection Commission
Website: dataprotection.ie
We are committed to protecting your privacy and handling your data responsibly. If you have any questions or concerns, please don't hesitate to contact us. We will respond to all privacy inquiries within 30 days.