Last updated: August 6, 2026
This policy explains what blogcms collects, why, and who else touches it. There are two groups of people to keep separate: customers (you, with an account) and readers (people visiting blogs published with blogcms).
The blogcms dashboard sets a single session cookie to keep you signed in. That is the only cookie we set. We do not run advertising or cross-site tracking cookies.
Blogs published with blogcms include a small, cookieless analytics beacon. It is designed so no consent banner is needed:
If you publish a blog with blogcms, you are the controller of your readers’ data and we process it on your behalf.
When you use the AI helper, slug suggestions, or image generation, we send the relevant inputs — your keyword, any context you type, the post’s title and text, and your blog’s name — to our AI providers so they can return a draft, suggestion, or image.
We do not use your content to train models, and our providers act as processors under their API terms. Research features may also perform web searches based on your keyword.
We keep the list short and use established providers:
Account and content data is kept while your account is open. When you delete a blog or your account we remove it from active systems; residual copies may remain in encrypted backups for a short period before rotating out. Aggregated analytics counts may be retained without identifying anyone.
You can access, correct, export, or delete your data at any time — most of it directly from the dashboard or the API. Depending on where you live, you may also have rights to restrict or object to processing, or to lodge a complaint with your data protection authority. Contact us and we will help.
Traffic is encrypted in transit with TLS. API keys are stored hashed, never in plain text, and shown only once at creation. Access to production systems is limited to people who need it. No system is perfectly secure, but we take this seriously and will notify you promptly about any breach affecting your data.
Our providers operate globally, so your data may be processed outside your country, including in the United States. We rely on those providers’ standard contractual protections for such transfers.
blogcms is not intended for people under 16, and we do not knowingly collect their data.
We will update this page when our practices change, and revise the date above. Material changes will be announced by email or in the dashboard.
Questions, or want your data removed? Use the contact page and we will respond promptly.