Privacy Policy
Last updated: April 23, 2026
1. Introduction
This Privacy Policy explains how NewsPro ("we," "us," or "our") collects, uses, stores, and shares your personal information when you use our platform and services ("the Service"). By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
This policy applies to all users of NewsPro, including site owners (customers who create and manage news sites) and visitors to sites built on our platform.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
- Full name
- Email address
- Hashed password (we never store your password in plain text)
- Account creation date and last activity
2.2 Payment and Billing Information
We collect and store the following billing-related data:
- Card details: Last 4 digits, card brand (Visa, Mastercard, etc.), and expiration date. Full card numbers are never stored on our servers.
- Payment tokens: Encrypted tokenized references provided by our payment processor (Tranzila), stored using AES-256-CBC encryption. These tokens are used for recurring billing without re-entering your card details.
- Transaction records: Amount, currency, date, status (success/failed/refunded), and gateway reference IDs.
- Subscription details: Plan, billing period, renewal dates, trial status, and cancellation dates.
Payment processing is handled by Tranzila, a licensed payment service provider. We do not process or store raw card data. Tranzila's own privacy policy governs their handling of your payment information.
2.3 Site Configuration Data
When you create a site, we collect:
- Site name, topic description, and language preference
- Template and style selections
- Custom domain names (if configured)
- Storage usage
The topic description you provide during site creation is sent to our AI provider (xAI / Grok) to generate initial site content such as categories and sample articles.
2.4 Content You Create
All content you create or that is generated on your behalf through the Service is stored in your site's isolated database. This includes articles, breaking news, short videos, images, pages, categories, and form submissions. You retain ownership of this content.
2.5 Authentication and Security Data
For security purposes, we collect and temporarily store:
- Login attempt records (IP address, timestamp, email used) โ retained for 24 hours for rate-limiting purposes
- Remember-me tokens (stored as hashed values, valid for 30 days)
- Account activity logs (login, logout, password changes, email changes) including IP address and user agent โ retained indefinitely as a security audit trail
2.6 Analytics and Usage Data
We collect anonymized usage data about how our sales site (newspro.io) is used. This includes:
- Pages visited and navigation paths
- Traffic source (direct, search, social, referral)
- Device type, operating system, and browser type
- Country of origin (derived from a daily-rotating hash of your IP address โ your actual IP address is never stored)
- UTM campaign parameters
This tracking is server-side only and does not use third-party analytics scripts on our marketing site by default.
2.7 Affiliate and Referral Data
If you arrive via an affiliate referral link, we store a cookie (aff_id) for 30 days to attribute any signup to the referring affiliate. We record the referral relationship, commission amount, and payout details (including PayPal email if you are an affiliate receiving payouts).
2.8 Support and Communication Data
When you contact us through the support system or contact form, we collect your name, email, subject, and message content. Support chat history is retained indefinitely to provide continuity of service.
2.9 Social Media OAuth Tokens
If you connect social media accounts (Facebook, Instagram, X/Twitter, TikTok, LinkedIn, Telegram, and others) for auto-posting, we store OAuth access tokens provided by those platforms. These tokens allow us to post content on your behalf. We store the associated account ID, name, and profile picture URL. You can revoke access at any time from your dashboard.
3. How We Use Your Information
- Providing the Service โ Hosting your site, processing payments, managing subscriptions, provisioning databases and storage.
- AI Content Generation โ Sending your site topic, content prompts, and configuration preferences to AI providers (xAI/Grok, and optionally OpenAI or Anthropic) to generate content on your behalf.
- Billing and Renewals โ Charging your payment method at renewal dates, sending payment confirmation and failure emails.
- Security โ Detecting and preventing fraud, unauthorized access, and abuse of the Service.
- Support โ Responding to your questions and resolving issues.
- Service Improvement โ Analyzing aggregated, anonymized usage patterns to improve our features.
- Legal Compliance โ Complying with applicable laws, regulations, and lawful requests from authorities.
- Affiliate Management โ Tracking referrals and paying commissions.
4. Data Sharing and Third Parties
We do not sell your personal data. We share data only with the following third-party service providers, and only to the extent necessary to deliver the Service:
- Tranzila โ Payment processing, card tokenization, invoice generation.
- xAI (Grok) / OpenAI / Anthropic โ AI content generation. Content prompts (topic, site name, writing instructions) are sent to these providers. We do not send personally identifiable information such as your name or email to AI providers.
- Cloud Storage Providers (e.g., Cloudflare R2, AWS S3, DigitalOcean Spaces, Google Cloud Storage) โ Storage of media files uploaded to your site.
- Email Service Providers โ Delivery of transactional emails (account notifications, billing receipts, password resets).
- Social Media Platforms (Facebook, Instagram, X, TikTok, LinkedIn, Telegram, etc.) โ Auto-posting content using your connected OAuth tokens.
- PayPal โ Only if you are an affiliate and select PayPal as your payout method.
- Google Analytics / Facebook Pixel โ Only if explicitly enabled by the platform administrator. These are optional and disabled by default.
- Law Enforcement โ We may disclose data if required by law, court order, or to protect the rights, property, or safety of NewsPro, our users, or the public.
5. Cookies and Tracking
We use the following cookies:
- Session cookie โ Required for authentication and maintaining your login session. HttpOnly and Secure flags are set. Duration: session or 30 days if "remember me" is selected.
- Platform analytics cookie (
__np_sid) โ Used for server-side analytics on our marketing site. No personal data is stored; your IP is never saved directly. Duration: 30 days. - Affiliate cookie (
aff_id,aff_landed) โ Set when you arrive via an affiliate referral link. Used to attribute signups to affiliates. Duration: 30 days.
Third-party cookies may be set by Google Analytics or Facebook Pixel if those features are enabled by the platform administrator. You can manage or block cookies through your browser settings.
6. Data Storage and Security
We take security seriously and implement the following measures:
- Each site's data is stored in a fully isolated database, separate from all other users.
- Payment card tokens are encrypted using AES-256-CBC before storage.
- Passwords are hashed using bcrypt with a cost factor of 12.
- All communications between your browser and our servers use HTTPS/TLS encryption.
- Access to production systems is restricted and logged.
- SQL injection is prevented through parameterized database queries.
- CSRF tokens are enforced on all forms and API endpoints.
While we implement strong security practices, no system is completely immune to breaches. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | For the lifetime of your account |
| Site data (articles, media, etc.) | Active period + 30 days after cancellation, then permanently deleted |
| Payment card tokens | Until you remove the card or close your account |
| Transaction records | Indefinitely (legal and accounting requirements) |
| Login attempt logs | 24 hours |
| Remember-me tokens | 30 days |
| Security audit log | Indefinitely |
| Platform analytics | 30 days (auto-expired) |
| Support tickets and chat | Indefinitely (service continuity) |
| Affiliate cookies | 30 days |
| Social media OAuth tokens | Until revoked or account closed |
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access โ Request a copy of the personal data we hold about you.
- Correction โ Request that we correct inaccurate or incomplete data.
- Deletion โ Request deletion of your account and associated personal data, subject to legal retention requirements.
- Portability โ Request an export of your content data in a machine-readable format.
- Objection โ Object to certain types of processing, such as direct marketing.
- Withdrawal of Consent โ Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Restriction โ Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, please contact us through our contact page. We will respond within 30 days. Note that we may need to verify your identity before processing requests.
9. Data Related to Your Site's Visitors
If you build a site on NewsPro, your site may collect personal data from your own visitors (such as subscriber emails, comments, contact form submissions, and analytics). As the site owner, you are the data controller for your visitors' data and are responsible for complying with all applicable privacy laws (including GDPR, CCPA, and local regulations) with respect to that data. We act as a data processor on your behalf for that data. You should maintain your own privacy policy on your site.
10. AI Providers and Data Processing
When you use AI-powered features (content generation, site builder, image creation), the following information is transmitted to our AI providers:
- Content prompts (topic, style, instructions)
- Site name and language
- Article drafts for editing and improvement
We do not send your name, email address, payment information, or other personally identifiable data to AI providers. AI providers process this data in accordance with their own privacy policies. We use xAI (Grok) as our default provider, with OpenAI and Anthropic available as alternatives.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18 without parental consent, we will delete it promptly. If you believe we have inadvertently collected such data, please contact us immediately.
12. International Data Transfers
Our services and servers may be located in different countries. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your country of residence, including countries that may have different data protection laws. We take appropriate safeguards to ensure your data remains protected in accordance with this policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. We will notify you of material changes by email or through a prominent notice within the Service at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision. We encourage you to review this policy periodically.
14. Contact
For any privacy-related questions, requests, or concerns, please contact us through our contact page. We are committed to resolving privacy concerns promptly and transparently.