Skip to content
CrediBlog

Privacy Policy

Effective date: July 17, 2026 · Version 1.1

CrediBlog is a publishing platform where businesses draft, edit, schedule, and publish blog content under their own name, so we treat our customers' data, and the personal information of their readers, with the seriousness the work requires. This policy explains what we collect, how we use it, and the rights you have. The short answer up front: we don't sell your data, and we only ever use it to make CrediBlog work for you.

1. Who is responsible for your data

CrediBlog is operated by Sharpian (샤피안), a sole proprietorship registered in the Republic of Korea ("Sharpian", "we", "us", "our"). For personal data we handle as a controller, Sharpian is the data controller. Business registration details are available on request.

For personal data contained in the content that we process on a customer's behalf, the customer is the controller and we act as their processor; that relationship is governed by our Data Processing Agreement.

2. Who this applies to

This policy covers:

  • visitors to crediblog.com (the public website);
  • customers (businesses and their authorised users) using the CrediBlog application; and
  • readers of the hosted blog pages published on CrediBlog.

3. What we collect

  • Account data: name, email address, business name, and role, provided by you at sign-up.
  • Workspace data: for each site profile you set up: the business context you give us (niche, audience, locations, seasonality, keywords), your author details, your website and webhook URLs, and the posts you generate or edit.
  • Billing data: for paid plans purchased online, payment is processed by Paddle as Merchant of Record. We receive limited transaction data (such as a transaction ID, plan, and country) from Paddle; we do not receive or store full card numbers.
  • Usage data: feature activations, log and error events, device/browser metadata, and aggregate performance metrics, used to keep the Service stable and to prioritise work.
  • Search index: an index we build from your published posts, so we can power search, suggest related posts, and make your content discoverable across the network.
  • Communications: messages you send to us (e.g. support or sales enquiries).
  • Cookies and similar technologies: on the public site we use analytics cookies from Google Analytics and PostHog. Where the law requires opt-in consent (the EU/EEA, UK, and Switzerland), they run only after you accept on our cookie banner; elsewhere they run by default. See our Cookie Policy for details.

4. How we use personal data, and our legal bases

We use personal data to:

  • operate, secure, and support the Service you use, including generating, publishing, and syndicating content for your workspace. Legal basis: performance of a contract, and our legitimate interest in running the Service;
  • contact administrators about incidents, security, billing, and material changes.Legal basis: contract and legitimate interest;
  • improve reliability and performance using aggregate, non-identifying usage patterns. Legal basis: legitimate interest;
  • process payments and prevent fraud (via Paddle). Legal basis: contract and legal obligation;
  • respond to enquiries and access requests. Legal basis: legitimate interest / steps prior to a contract;
  • comply with law and enforce our terms. Legal basis: legal obligation and legitimate interest.

Your context is used for one thing: writing and improving content for your workspace. We do not sell your personal data, full stop. Where we rely on consent (for example, certain analytics cookies), you may withdraw it at any time.

5. How AI processing works

  • When you run AI-assisted features (such as generating draft posts, images, metadata, or search), the relevant content is sent to the AI sub-processor(s) configured for the Service.
  • Content is processed only to generate the output you request. We do not use it to train models, and the AI providers we use process it under their API / business terms, which do not permit training on customer content.
  • The AI providers we use, and their processing location, may vary by feature and plan. The current list of AI sub-processors is part of our sub-processor list (Section 6) and is available on request.
Note: this commitment holds while the Service uses the AI providers' standard API / business tiers (which do not train on submitted content). We do not route Your Content through consumer chatbot products that may train on inputs, and we keep the sub-processor list current.

6. Sub-processors

We use a minimal set of sub-processors to run the Service, which may include cloud hosting, email delivery, analytics, image sourcing, payment processing (Paddle), and AI inference. Each is bound by confidentiality and data-protection obligations consistent with this policy. The current sub-processor list, including purpose and location, is available on request at legal@crediblog.com, and material changes are notified to administrators as set out in the Data Processing Agreement.

7. International transfers

We are based in the Republic of Korea, which the European Commission recognises under an adequacy decision for transfers of personal data from the EEA. Where personal data is transferred to other countries (for example, to a cloud or AI provider), we rely on appropriate safeguards such as Standard Contractual Clauses or an equivalent recognised mechanism. Details are available on request.

8. Data retention and deletion

  • Your Content is retained for as long as your account is active. Delete a post or close your account and we remove the content and its search data from our live systems; on account termination we delete Your Content within 30 days unless you ask us to accelerate, or unless we are required by law to retain it.
  • Account and billing records are retained as long as needed for the relationship and for legal, tax, and accounting obligations.
  • Backups: where the Service maintains backups, copies of deleted data are removed or overwritten on the applicable backup retention cycle.

9. Anything you publish is public

That's the whole point: published posts appear on your hosted CrediBlog page, in network search and discovery, and (if you set it up) on your own site via our API or webhook. So treat anything you publish as out there for everyone to see.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete personal data we hold about you, and to withdraw consent. Two of those you can exercise yourself, immediately, without asking us:

  • Export. Dashboard → Settings → Your data downloads everything your account holds as a single JSON file: your account details, every site and its settings, and every post with its full text and its sources.
  • Deletion. Dashboard → Settings → Close your account cancels your subscription, takes every site you own offline immediately, and starts the deletion. Your data is held for 30 days so we can restore the account if you change your mind, then it is deleted. You can also edit your business context, edit or delete any post, and delete a single site without closing the account.

For anything else — correction, restriction, objection, or withdrawing consent — contact legal@crediblog.com; we respond within the period required by applicable law (and within 30 days as a default).

  • EEA/UK (GDPR / UK GDPR): you may also lodge a complaint with your local supervisory authority.
  • Republic of Korea (PIPA): see Section 12.
  • California (CCPA/CPRA): we do not sell or share personal information for cross-context behavioural advertising, and we do not discriminate against you for exercising your rights.

If we process your personal data on behalf of a customer(i.e. it is part of that business's content or workspace), please direct your request to that customer as controller; we will assist them as their processor.

11. Security

We protect personal data with administrative, technical, and physical measures appropriate to the risk, including encryption in transit (TLS), strict per-tenant access controls, the principle of least privilege, and logging of access to the Service. No system is perfectly secure, and we cannot guarantee absolute security. We review our security practices periodically and update them as the Service evolves. To report a vulnerability, contact legal@crediblog.com.

12. Republic of Korea (PIPA)

For users in the Republic of Korea, the following applies under the Personal Information Protection Act ("PIPA"):

  • Items processed: as described in Section 3.
  • Purposes: as described in Section 4.
  • Retention: as described in Section 8.
  • Provision to third parties / consignment: we use the sub-processors described in Section 6 to operate the Service; we do not otherwise provide personal information to third parties except as required by law.
  • Rights: you may request access, correction, deletion, and suspension of processing of your personal information.
  • Personal Information Protection Officer (개인정보 보호책임자): the Privacy Officer of Sharpian (샤피안), reachable at legal@crediblog.com.

13. Children

The Service is intended for use by businesses and their authorised staff, not by children; it is meant for people 18 and over. We do not knowingly collect personal data directly from children.

14. Changes to this policy

We may update this policy. Material changes will be posted here with an updated effective date and, where appropriate, notified to administrators.

15. Contact

Legal, privacy, and data protection: legal@crediblog.com
General and support: support@crediblog.com