Privacy
Last updated September 15, 2026
Who we are
The controller of your personal data is Florian Jousselin, operating Backdrip under NIP 5214178784 and REGON 545666665. You can contact us about privacy at contact@scapin.co.uk.
AI-assisted profiles, articles, and submissions
When you ask Backdrip to inspect a website, we may send text from its public pages and public metadata to OpenAI to prepare editable project fields. For article research and writing, we also send relevant saved project details and identifiers, target keywords, audience and tone settings, competitor URLs, source material, media URLs, and information about existing articles. This can include unpublished article titles and summaries used to avoid duplicate topics.
If you enable Enrich with Google Search in your article settings, selected search queries from a connected Google Search Console property may be included as keyword seeds sent to OpenAI for article planning. This option is off by default and is separate from showing Search Console reports in your dashboard. See the Google Search Console section below.
Our AI-assisted submission engine can use OpenAI or Anthropic to interpret directory page content and plan submission actions using relevant project fields and the browser interaction history. Article and profile prompts do not include directory passwords, integration access tokens, or full payment-card data.
We keep an internal audit record containing the source pages, the website profile, generated fields and articles, research sources, keyword planning results, model and response identifiers, token usage, estimated cost, timing, and errors. These records support quality checks, troubleshooting, job recovery, and cost control.
Legal bases
We process account, billing, project, article, submission, and integration data when necessary to provide the service and perform our contract with you. We process records required for tax, accounting, fraud prevention, and other legal obligations where the law requires it.
We rely on our legitimate interests to secure and troubleshoot the service, prevent abuse, verify submissions, and improve reliability, provided those interests do not override your rights. Where we specifically ask for consent, you may withdraw it at any time without affecting earlier processing.
Data we collect
We collect the information needed to run Backdrip: your account details, email address, project websites, project copy, company and contact details, categories, pricing, logos, images, screenshots, social links, and other fields you choose to add.
We also store backlink targets, submission status, live URLs, link attributes, notes, login details created for submissions, Domain Rating checks, and performance data connected to your project.
Article data includes keyword and editorial settings, drafts, generated text and covers, research and source URLs, publication and indexing status, and job history. Connection data can include your Google account email and selected property, GitHub repository and branch, Vercel project and team identifiers, and encrypted access or refresh tokens.
How we use data
We use your data to create and manage backlink submissions, prepare project profiles, research and generate articles, set up and publish to your connected blog, check publication and indexing status, show your dashboard, send service emails, debug issues, prevent abuse, and improve Backdrip.
When you paste a URL, we may fetch your public website to pull useful project details such as title, tagline, description, logo, and other public metadata.
Submissions to third-party websites
Backdrip works by submitting your project information to third-party websites. Information included in a submission may become public on those websites and will be handled under their own privacy practices.
If we create an account for a submission target, we may store the related login information so you can see the receipt and so we can manage updates or checks later.
GitHub and blog publishing
When you connect GitHub, we use your token to list accessible repositories and branches and inspect the selected website's files for supported blog setup and publishing. We store the token encrypted, along with the selected destination and connection status. We may store setup plans, relevant file content or changes, commit and pull request identifiers, and publishing results to carry out and verify the work you request.
Article content, covers, and setup changes are sent to GitHub when you authorize setup or publishing, including through autopilot. They may become public through your repository or deployed website. GitHub and your hosting provider process this information under their own terms and privacy practices.
Google Search Console
When you connect Google Search Console, we store your Google account email, selected property, and an encrypted refresh token. We access authorized properties and performance reports such as search queries, pages, clicks, impressions, and average positions. We store daily figures and report snapshots and may inspect the indexing status of your published article URLs.
Article planning can use selected search queries as keyword seeds sent to OpenAI. Query performance figures help us prioritize topics within Backdrip. Keyword planning records may retain the selected queries and their metrics alongside the resulting article strategy. We record your choice, the notice version, who agreed, and when. Turning enrichment off stops future query use for article planning without disconnecting dashboard reporting. Previously generated articles and planning records are not automatically erased. We do not use Google data to train a general-purpose AI model, sell it, or use it for advertising.
Backdrip's use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including applicable Limited Use requirements. Connecting Google does not by itself authorize every new use of your data. New purposes require the applicable notice and consent before they are enabled.
Connected Vercel traffic data
If you connect your Vercel account, we store your access token encrypted and use it to list accessible projects and teams. For the project you select, we retrieve aggregate visitor and page-view counts, referring websites, and page paths to display traffic in your dashboard. We store the selected project, team, connection status, and errors. Reports are fetched from Vercel and may be temporarily cached. This is separate from analytics on Backdrip's own website.
Integrations and providers
Stripe processes subscription payments and hosts checkout and billing management. We share your account email and billing identifiers with Stripe and store customer, subscription, payment-status and paid-period records. We do not store your full payment card details.
We use service providers including Supabase for database and authentication, Vercel for hosting and analytics, Stripe for billing, Resend for email, Browserbase for browser automation, OpenAI for AI-assisted profiles, article research and generation, and submission assistance, Anthropic when used for submission assistance, GitHub for repository access and publishing, Ahrefs for Domain Rating, and Google when you connect Search Console. Browser automation may process submitted project fields and login sessions needed for directory accounts. We limit the information shared to what is needed for each provider's role and use contractual and other safeguards required by applicable data protection law.
If we check Domain Rating by Ahrefs, we send the relevant domain to Ahrefs and store the result so we can show current and historical values.
International transfers
Some providers may process data outside Poland or the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another safeguard recognized by data protection law. Contact us if you need more information about the safeguards used for a particular provider.
Cookies and analytics
Backdrip uses essential session technology to keep you signed in and secure your account. We also use Vercel Analytics to understand basic website and product usage. We do not use this data to sell personal information or run third-party advertising profiles.
Emails
We send service emails such as login, account, alert, and project status messages. We may also send important product or policy updates related to Backdrip.
Weekly project summaries include backlink activity and published article counts. These summaries are sent for projects with a current paid subscription, including a cancelled subscription until its paid period ends. Draft articles are not counted as published. Account, billing, and essential policy messages may still be needed after a subscription ends.
Disconnecting integrations
Disconnecting GitHub removes the saved token from the active connection and disables new article work through that connection. Article content, settings, and publishing history remain in Backdrip. Existing commits, pull requests, published pages, and deployments are not undone. Public availability checks may finish for an article already being published.
Disconnecting Google removes the saved connection token, daily Search Console records, and report snapshots from the active database. Previously generated articles and keyword planning records are separate and are not automatically deleted. Disconnecting Vercel removes its saved connection and token. Disconnecting is different from deleting your Backdrip account or deleting information held by a provider. You can also revoke access directly with the provider.
Retention
We keep account-level records of free-project eligibility and article, submission and setup usage while your account exists. These records prevent the free allowance from resetting when a project or integration is deleted. They are separate from the content and connection records shown in your dashboard.
Account, project, article, and submission records are retained while you keep them in Backdrip, including saved history accessible after a subscription ends. Cancelling billing is not an account deletion request. Email contact@scapin.co.uk to request deletion of your account, a project, or personal data in generated content and planning records.
Retention after a deletion request depends on the record's purpose: billing and accounting records may be retained for applicable legal recordkeeping periods, and relevant security or dispute records for as long as necessary to investigate an incident or resolve a claim. Copies in backups and provider systems may remain until their applicable retention cycles expire. We assess deletion requests against these obligations and explain any applicable exception.
Deleting data from Backdrip does not automatically remove articles from your repository or website, listings on third-party websites, or copies held by search engines. Those copies must be managed with the website or provider concerned.
Your rights
Depending on where you live, you may have rights to be informed and to access, correct, erase, restrict, or receive a portable copy of your personal data. You may also object to processing based on legitimate interests and withdraw consent where consent applies. Email us at contact@scapin.co.uk to exercise a right.
You may lodge a complaint with the President of the Polish Personal Data Protection Office or your local supervisory authority. Backdrip does not make decisions about you that produce legal or similarly significant effects using only automated processing.
Security
We use technical and organizational measures to protect Backdrip data, but no internet service can be guaranteed to be perfectly secure. Keep your account access safe and tell us if you believe something is wrong.
Changes
We may update this policy as Backdrip changes. When we make material changes, we will update this page and, when appropriate, notify you by email or in the product.