Legal

Privacy Policy

Last updated 21 August 2026

1Who we are

Sitemo.ai operates Sitemo and is responsible for the personal data described in this policy. Reach us about privacy at support@sitemo.ai.

This policy explains what we collect when you use the service, why we use it, who we share it with, how long we keep it, and the rights you have over it.

It covers our own service. If you're a visitor who submitted something on a site one of our customers built, see Data on customers' sites — that data belongs to the customer, not to us.

2What we collect

  • Account information — your name and email address, and authentication details. Passwords are stored in hashed form and we never see them in plain text.
  • Content you provide — anything you upload or create using the service, and the instructions you give it.
  • Billing information — your billing email and subscription status. Card details are handled by our payment processor and don't reach our servers.
  • Usage and technical data — IP address, browser type, timestamps, pages requested and similar log data, along with counters for the limits your plan applies.
  • Communications — messages you send us through the contact form or by email.

We don't buy personal data about you from third parties, and we don't build advertising profiles.

3How we use it

  • To provide, operate and maintain the service.
  • To take payment and manage your subscription.
  • To keep the service secure — preventing fraud and abuse, and debugging problems.
  • To respond to your enquiries and send service messages you need to receive.
  • To improve the product, generally using aggregated or de-identified data.
  • To send marketing email, where you've opted in — withdrawable at any time.
  • To comply with our legal obligations.

Where data-protection law requires a legal basis, ours is the performance of our contract with you, our legitimate interest in operating and securing the service, compliance with legal obligations, or your consent — whichever fits the purpose above.

4AI processing

Some features send your instructions and the content being worked on to third-party AI providers so they can be processed. We use those providers under commercial terms that don't permit them to train their models on the content we send, and we don't train models on your content either. Please don't enter anything into a prompt that you wouldn't want processed by a third party — card numbers, passwords, or someone else's confidential information. What those features can and can't do is set out in AI Accuracy & Limitations.

5Cookies

We use cookies and similar technologies to sign you in, remember your preferences, and keep the service secure. The Cookie Policy explains which categories we use and how to manage them.

6Who we share it with

We don't sell personal data. We share it only with service providers who help us run the service, each handling only what their role requires and bound by contract not to use it for their own purposes. They fall into these categories:

  • Hosting, storage and content-delivery providers.
  • Authentication and database providers.
  • Payment processing.
  • Email delivery.
  • AI providers, for the features described above.
  • Analytics and error monitoring, where used.

Beyond that, we disclose personal data only where the law requires it, in response to a valid legal request, or to establish or defend legal claims. If the business is sold or merged, data may transfer as part of that; this policy continues to apply until it is replaced.

7Data on customers' sites

When someone submits a form or otherwise provides data on a site built by one of our customers, that customer decides what happens to it. In data-protection terms they are the controller and we are a processor acting on their instructions; we don't use that data for our own purposes. Submissions are stored against that customer's site and kept separate from other customers' data.

If you're a visitor asking for access, correction or deletion, contact the business whose site you were on — they're the ones able to act on it.

If you're a customer, that data is yours and the obligations to your own visitors are yours. We'll help you meet a request against data we hold on your behalf.

8How long we keep it

We keep personal data for as long as your account is open and for as long as we need it for the purposes above. After that:

  • Content you delete, and accounts you close, are removed from the live service promptly and cleared from routine backups within 90 days.
  • Billing records are kept for as long as tax and accounting law requires, regardless of account closure.
  • Technical logs are kept for a short rolling period unless needed for security.

Export anything you want to keep before deleting it; deletion can't be reversed.

9Your rights

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct it if it's wrong;
  • delete it;
  • provide it in a portable format;
  • restrict or object to a particular use;
  • withdraw consent you previously gave, without affecting what was done beforehand.

To exercise any of these, write to support@sitemo.ai or use the contact form. We'll respond within the time the law allows, normally one month. If you're unhappy with how we've handled your data, please tell us first; you also have the right to complain to the data-protection authority where you live.

10International transfers

Our providers operate globally, so your data may be processed outside the country you live in, including in the United States. Where that happens, we rely on the safeguards recognised for international transfers — such as standard contractual clauses — in our contracts with each provider.

11Security

We use appropriate technical and organisational measures to protect personal data: data is encrypted in transit and at rest, access to production systems is limited to those who need it, and customers' data is kept isolated from one another. No system is perfectly secure; if a breach puts your rights at risk we'll notify you and the relevant authority as the law requires. To report a vulnerability, write to support@sitemo.ai.

12Children

The service is intended for business use and isn't directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we'll delete it.

13Changes to this policy

We may update this policy from time to time. The "last updated" date at the top of this page always reflects the current version.

For changes that materially affect you, we'll give notice by email or in the product rather than relying on you to re-read this page.

14Contact us

Questions about this policy, or about the data we hold, can go to support@sitemo.ai or through our contact page.

Sitemo.ai. Contact us at support@sitemo.ai.