Privacy Policy
Last updated: 09/05/2026
Welcome to Pagora AI! This Privacy Policy explains what personal data we collect when you use pagora-ai.com and the Pagora AI WordPress plugin, why we collect it, how we protect it, and what your rights are under the General Data Protection Regulation (GDPR).
We've written this in plain English on purpose. If anything is unclear, please reach out — we're happy to explain.
1. Who is responsible for your data?
The data controller is a solo operator (auto-entrepreneur) based in Rennes, France, operating Pagora AI at pagora-ai.com. You can contact us at any time at [email protected].
2. What data do we collect and why?
Account data
Your email address and a hashed (never readable) password. We use this to create and manage your account and to authenticate you when you sign in.
Legal basis: performance of a contract (providing the service you signed up for).
Payment data
Billing information (card number, billing address) is handled entirely by Stripe, Inc. — a PCI-DSS-compliant payment processor. Pagora AI never sees or stores your raw card details. We only receive a transaction reference and subscription status from Stripe.
Legal basis: performance of a contract.
AI prompts & chat history
When you generate pages, your prompts and conversation turns are forwarded to Anthropic, PBC (Claude API) to produce HTML, CSS, and JavaScript output. Per Anthropic's API terms, your prompts are not used to train their models. Your chat history is stored in your own WordPress database — Pagora AI's backend does not permanently retain prompt content beyond the time needed to complete your request.
Legal basis: performance of a contract.
Technical & log data
IP addresses, HTTP request logs, and error logs collected automatically by our servers. We use this data solely for security monitoring and debugging.
Legal basis: legitimate interest (keeping the service secure and functional). Retention: 30 days, then automatically deleted.
Transactional emails
We send account confirmation emails, password reset links, and billing receipts via Mailjet SAS (France). These are triggered by your actions — we never send marketing emails without your explicit consent.
Legal basis: performance of a contract.
3. Who do we share your data with?
We rely on the following sub-processors. We do not sell your data to anyone, ever.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe, Inc. | Payment processing | USA | Standard Contractual Clauses (SCCs) |
| Anthropic, PBC | AI page generation (Claude API) | USA | SCCs; prompts not used for training |
| Mailjet SAS | Transactional email delivery | France (EU) | Within the EU — no transfer safeguard needed |
Transfers to the USA (Stripe, Anthropic) are governed by the European Commission's Standard Contractual Clauses, which provide an adequate level of protection for your personal data.
4. How long do we keep your data?
- Account data: kept while your account is active, then for 2 years after deletion (so we can handle any dispute or legal claim).
- Payment records: retained for 10 years in compliance with French accounting and tax law (Code de commerce, Art. L.123-22).
- Technical logs: automatically deleted after 30 days.
- AI prompts (backend): not permanently stored — retained only for the duration of job processing, then discarded.
6. Your rights under GDPR
Under GDPR Articles 15–22, you have the following rights regarding your personal data:
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your data ("right to be forgotten").
Receive your data in a structured, machine-readable format.
Ask us to limit processing while a dispute is resolved.
Object to processing based on legitimate interest.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
If you're not satisfied with our response, you have the right to lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés) at cnil.fr.
7. How we protect your data
We apply appropriate technical and organisational measures including HTTPS encryption in transit, hashed password storage, restricted server access, and short log retention windows. Payment data security is further assured by Stripe's PCI-DSS Level 1 certification.
8. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on the site before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.
Questions? We're easy to reach.
If you have any questions about this policy or how we handle your data, just send us an email. No ticket system, no waiting queue — it goes straight to the person running Pagora AI.
[email protected]