Privacy Policy

Last updated 11 August 2026

BlogZilla is an AI-assisted blog and content publishing studio operated by GLOWFISH INCUBATOR FZCO, a free zone company registered in Dubai, United Arab Emirates (“Glowfish”, “we”, “us”). Glowfish is the controller of the personal data described here.

This policy explains what we collect, why we collect it, who we share it with, how long we keep it and how you can have it deleted. It covers the BlogZilla web application at blogzilla.me, its API, and the blogs published through it. Our Terms of Service govern your use of the service itself.

In short: we do not sell personal data, we do not use it for advertising or profiling, and we do not use your content to train artificial intelligence models.

1. Information we collect

  • Account details — your name and email address. If you sign in with a password, we store only a securely hashed version of it, never the password itself. If you sign in with Google, we receive your name, email address and profile picture from your Google account so we can create and identify your account.
  • Content you create or upload — sites, articles, drafts, keywords, brand guidelines, images and reference documents you add to your workspace, together with the prompts and instructions you give the service.
  • Data from accounts you connect — only where you choose to connect them. See sections 3 and 4.
  • Billing information — the plan you are on and your billing contact details. Card details are entered directly with our payment processor; we never receive or store them.
  • Technical and operational records — the requests your browser or integrations make to us, the outcome and timing of those requests, and the account they belong to. Credentials, tokens and authorisation codes are removed before anything is recorded.
  • Audience measurement on published blogs — for blogs published through BlogZilla we record page views, scroll depth and clicks against a random session identifier held in the reader’s browser. It is not linked to a name, email address or account, and we do not use it to identify readers or to advertise to them.

2. How we use information, and on what basis

  • To provide the service — creating, editing, scheduling and publishing content, and carrying out the actions you ask for on accounts you have connected. Basis: performance of our contract with you.
  • To show you performance and content insight from the data you have chosen to connect. Basis: performance of our contract with you.
  • To authenticate you and protect accounts against unauthorised access, abuse and fraud. Basis: our legitimate interest in a secure service.
  • To administer subscriptions — applying plan allowances and processing payment. Basis: contract and legal obligation.
  • To communicate with you — service and account messages, and support you ask for. Basis: contract and legitimate interest. Marketing email, where we send it, is separate and you can opt out at any time.
  • To diagnose faults and improve reliability using technical records and aggregated usage. Basis: legitimate interest.
  • To meet legal obligations and to establish, exercise or defend legal claims. Basis: legal obligation and legitimate interest.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not make decisions producing legal or similarly significant effects about you by automated means.

3. Google user data

Connecting a Google service is entirely optional — BlogZilla works without it. When you choose to connect one, we request the narrowest scope that does the job, and both of them are read-only:

  • Google Search Console (webmasters.readonly) — to read clicks, impressions, click-through rate and average position for the properties you select, so BlogZilla can show how your published content performs and suggest what to write next.
  • Google Sheets (drive.file) — per-file access to the single spreadsheet you choose in Google’s own file picker, so that its rows can be used as a data source for your content and charts. This scope grants access only to files you have explicitly picked: BlogZilla cannot see, list or open anything else in your Google Drive.

These scopes cannot create, edit or delete anything in your Search Console properties or your Google Drive. We read only the specific property or spreadsheet you choose, and only while the connection is active.

The credentials that keep the connection alive are encrypted before storage and are used solely to refresh access for the features above. They are never sent to your browser or to any third party. You can disconnect at any time from within BlogZilla, which deletes the stored credentials, and you can revoke our access directly at myaccount.google.com/permissions.

Limited Use. BlogZilla’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide or improve the user-facing features described above; we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you; we do not use it for advertising; we do not sell it; and we do not allow humans to read it, except where you have given specific consent (for example when you ask for support), where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.

4. Facebook and Instagram data

Connecting a Meta account is optional and exists for one purpose: so you can share an article you have already published to a Facebook Page and an Instagram professional account that you administer. If you never connect one, we receive no data from Meta at all.

When you connect, we receive and use the following:

  • Confirmation that you signed in to Facebook and authorised the connection. We do not build a profile of you from it.
  • The list of Facebook Pages you administer, with each Page’s name and picture and whether an Instagram professional account is linked to it, so that you can choose which one to connect. Pages you do not choose are discarded and never stored.
  • The name and picture of the Page you selected, and the username of the linked Instagram account, so the connection can be displayed back to you and so we can detect when it has expired and needs renewing.
  • Access credentials for the selected Page, used only to post the content you explicitly ask us to post.

What we do with it, and what we never do:

  • We publish only when you press publish, only the article and caption you chose, and only to the account you selected. We never post automatically, never post to an account you did not select, and never post third-party content.
  • We do not read comments, messages, reactions, follower lists, media or any other user-generated content on your Page or Instagram account.
  • We do not sell, rent or transfer Meta Platform Data, do not use it for advertising, profiling or eligibility decisions, and do not combine it with data from other sources for those purposes.
  • Access credentials are encrypted before storage, are never exposed to the browser, and are used for nothing beyond the features described here.

We handle this data in accordance with the Meta Platform Terms and Developer Policies. You can disconnect at any time from within BlogZilla, which deletes the stored credentials and clears the linked account details, and you can remove our access directly from your Facebook settings under Business Integrations. See section 10 for how to have the data deleted.

5. Other services you connect

BlogZilla can also connect to content management systems and similar publishing destinations you already use, so it can publish your articles there on your instruction. We store only what the connection needs, protect any credentials in the same way as above, and use the connection for nothing else. Each destination remains governed by its own terms and privacy policy.

6. AI processing

To generate drafts, suggestions and images, the prompts and context you provide are sent to specialist AI processing providers acting on our behalf under contract. Text generation — including anything derived from a connected spreadsheet — is processed by Anthropic (the Claude API, standard commercial tier), which does not train its models on data submitted through that API. They may process that material only to return a result to us, and are not permitted to use it for their own purposes or to train their models on it. We do not route Google user data through model aggregators, gateways or model hubs. Neither we nor they use your content to train models. Some optional features may send a query — such as a topic or brand name — to external services in order to return an answer; these run only if you enable them.

7. Sharing your information

We do not sell your information. We share it only in these situations, and only to the extent needed:

  • Service providers acting on our instructions — categories: cloud hosting and storage, database services, AI processing, email delivery, payment processing, and optional search and content data sources. Each is bound by contract to protect the data and to use it only to provide its service to us.
  • Platforms you have connected — where you ask us to publish content to them.
  • People inside your own workspace — anyone you invite can see the content of that workspace.
  • Legal and safety — where required by law, or to establish, exercise or defend legal claims, or to protect the rights and safety of our users or the public.
  • Corporate transactions — in a merger, acquisition or sale of assets, with notice to you and the same protections continuing to apply.

8. Cookies and similar technologies

We use a small number of strictly necessary cookies. Signing in sets session cookies that your browser sends back to us to keep you authenticated; they cannot be read by page scripts. Blogs published through BlogZilla store a random, non-identifying session identifier used for the audience measurement described in section 1. We do not use advertising or cross-site tracking cookies. If the owner of a published blog adds their own analytics or tag manager to their site, that is covered by their own privacy policy, not this one.

9. Retention

We keep account and content data for as long as your account is active, so the service works as you expect. Credentials for a connected account are deleted immediately when you disconnect it. Signing out ends the session. Technical records are kept only for a short period for debugging and security. When your account is closed we delete or irreversibly anonymise your personal data within 30 days, except where we must retain records to meet legal, tax or accounting obligations, or to resolve a dispute. Routine backups are overwritten on a rolling schedule.

10. Deleting your data

You can have your data removed in any of these ways:

  • Disconnect a single integration. Open Integrations (or Data Connections) in BlogZilla and choose Disconnect on the service concerned. The stored credentials are deleted and the linked account details are cleared immediately. This is the fastest way to remove Facebook, Instagram or Google data.
  • Delete individual content — articles, images and documents can be deleted from within the application at any time.
  • Delete your whole account and all associated data. Email zilly@blogzilla.me from the address registered on the account with the subject “Delete my account and data”. We will confirm the request, delete or anonymise the data within 30 days, and confirm when it is done. No account is needed to make a request about data we hold — write to the same address and we will verify your identity before acting.
  • Remove our access at the platform. For Google, use myaccount.google.com/permissions. For Facebook and Instagram, use Settings → Business Integrations. Revoking access there stops any further access; email us as above if you also want the data we already hold deleted.

11. Security

Data is encrypted in transit. Credentials for the third-party accounts you connect are encrypted at rest with strong, industry-standard encryption, and passwords are stored only as secure hashes. Access to production systems is limited to the people who need it. Every workspace is isolated so that one customer cannot reach another’s data. No system is perfectly secure, but we take these measures seriously and will notify you and any relevant regulator of a breach affecting your data as required by law.

12. International transfers

Our infrastructure is hosted in the European Union. Because we operate from the United Arab Emirates and some of our providers operate globally, your data may be processed in countries other than your own. Where it is, we rely on appropriate safeguards — such as standard contractual clauses or an adequacy decision — to protect it.

13. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent where processing is based on it. You can exercise any of these by emailing us, and we will respond within the time the applicable law requires and without charge in ordinary cases.

You may also complain to your local data protection authority. Disconnecting a third-party account never affects the rest of your BlogZilla data.

Where you use BlogZilla to process personal data belonging to your own readers or customers, you are the controller of that data and we act as your processor; tell us if you need a data processing agreement.

14. Children

BlogZilla is a business tool and is not directed at children under 16. We do not knowingly collect their personal information. If you believe a child has provided us with data, contact us and we will delete it.

15. Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change is material we will tell you in the application or by email before it takes effect.

16. Contact us

GLOWFISH INCUBATOR FZCO, Dubai, United Arab Emirates.
Privacy questions, data requests and deletion requests: zilly@blogzilla.me
See also our Terms of Service.