Draft — under review, not yet in effect
Wellpage Privacy Policy
Effective date: to be set on publication.
Who we are
Wellpage (wellpage.com) is a marketing platform for small businesses: campaigns, landing pages, email, social posts, reviews, and a simple CRM, with AI-assisted content creation we call the Marketing Brain. This policy explains what information we collect, why, where it goes, and the choices you have — in plain English.
Information we collect
Account information. Your name, email address, password (stored as a secure hash by our authentication provider), workspace name, and team membership/roles.
Business and brand information you provide.Your business profile (name, address, hours, services, links, brand voice), Brand Library uploads (documents, photos, logos), and the persistent “Brand Memory” notes Wellpage keeps to ground what it writes for you.
Your customers’ contact data. Contacts you add, import, or capture through your landing-page forms (names, emails, phones, tags, custom fields, opt-in status). You own this data; we process it only to run your marketing.
Content you create. Campaigns, emails, landing pages, social posts, and their edit and send history.
Usage and billing. Plan, metered usage (e.g. AI generations), payment status via our payment processor (we never store full card numbers), and technical logs (errors, security events, an audit trail of meaningful actions).
AI assistants and the Wellpage connector
Wellpage can connect to AI assistants (such as Claude or ChatGPT) through our connector. If you choose to connect one:
— The assistant acts only with the access you authorize, scoped to your workspace, using a revocable connection token. Every action it takes is recorded in your workspace’s audit trail.
— The assistant can prepare and edit drafts and read your marketing data. Irreversible actions — sending email, publishing, spending, connecting accounts, deleting, payments, and permissions — always require your explicit in-app approval. The assistant only receives a link; you take the action.
— Content the assistant reads or drafts passes through that assistant’s platform, governed by that platform’s own privacy terms. We don’t sell or share your data with those platforms beyond what the connection you authorized requires.
You can disconnect an assistant at any time, which revokes its token.
How we use information
To provide the service: build and send your campaigns, host your pages, store your contacts, and show your results. To ground AI generation in yourbrand (your profile, library, and memory — with a visible “Sources used” record). To meter usage, bill plans, prevent abuse, and keep the service secure. We do notsell your data or your customers’ data, and we don’t use your customers’ contact data for anything except your own marketing.
Who processes data for us
We use a small set of service providers, each only for its job:
— Supabase (database, authentication, file storage) and Vercel (hosting).
— Stripe (payments and subscriptions).
— Mailgun (marketing email you send) and Postmark (transactional email such as invites and password resets).
— Anthropic(AI text generation) and an image-generation provider for AI images. Only the content needed for the specific generation is sent (your brief, relevant brand context); we don’t send your contact lists to AI providers.
— A social publishing provider for scheduling and posting to your connected social accounts, and a stock-photo provider when you search stock images.
— Sentry (error monitoring).
Retention and deletion
Your data stays as long as your account is active. If you delete content, it’s removed from your workspace; short-lived backups age out on a schedule. When you close your account, we delete or anonymize your workspace data within a reasonable period, except records we must keep (e.g. billing records) or that are needed to enforce our terms. You can also ask us to delete specific data — see contact below.
Security
Data is encrypted in transit, access is scoped per workspace at the database layer (row-level security), staff actions that touch customer data are audit-logged, and connector access uses scoped, revocable tokens. No internet service can promise perfect security, but we build so that a mistake in one place doesn’t expose everything.
Your choices and rights
You can access and update your information in the app, export your contacts, opt out of optional notifications (they’re off by default), disconnect any connected assistant or social account, and request a copy or deletion of your data. Depending on where you live (e.g. EEA/UK GDPR, California CCPA), you may have additional statutory rights — we honor requests regardless of geography.
Recipients of email sent through Wellpage can unsubscribe via the link in every marketing email; suppression is enforced automatically.
Children
Wellpage is a business tool and isn’t directed at children under 16; we don’t knowingly collect their data.
Changes and contact
If this policy changes materially, we’ll note it here and, for significant changes, tell you in the app or by email. Questions or requests: aaron@wellpage.com.