ContentPilot

Privacy Policy

Last updated: 7 October 2026

1. Who we are

ContentPilot is operated by Clobie Enterprise Limited ("ContentPilot", "we", "us", "our"), a company registered in England and Wales, company number 15377973, registered office Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA. We decide how and why your personal information is used, so we are its controller under UK data protection law.

For any privacy question, request, or complaint, contact us at privacy@usecontentpilot.com.

2. Scope

This policy covers app.usecontentpilot.com and usecontentpilot.com, and applies wherever you access them from. It doesn't cover third-party sites we link to, or the platforms you choose to connect your account to (X, TikTok, Instagram, YouTube, LinkedIn, Facebook, Threads). Their own privacy policies apply to how they handle your data.

3. Information we collect

Account information. Your name, email address, and password (or, if you sign in with Google, the basic profile information Google shares with us: your name, email, and profile picture).

Content and brand information. The niche, primary platform, posting goal, tone of voice, and content preferences you set during signup or in Brand settings; any social media handles you add; content ideas, scripts, hooks, and posts you create or save; images and videos you upload to your Media Bank; and links, files (PDFs, documents, audio) and pictures you attach to a new idea. An attached file is kept privately only until it is read, then deleted; we keep the words read from it, with the idea. For a business workspace, the offers you list (names, dates, prices, what is included, how to book and photos) and, if you ask us to read it, your business's website address and what we found on it (offers, contact details, customer reviews as quoted on the site, colours and logo). What we find is only added to your brand when you choose to add it; a logo you add is copied into your Media Bank.

Connected social accounts. If you connect a social account to publish or schedule posts, we store which platform and account you've connected (e.g. "Instagram: @yourhandle") so we know where to publish. See Section 6 for how this actually works.

Billing information. Paid plans are sold by Stripe as the seller of record: Stripe handles payment and tax, collects your payment details, billing address and country directly, and uses them under its own privacy policy. We never see your card number. When you start checkout we give Stripe your email address and an account reference so it can link the purchase to your account, and Stripe tells us your plan, your subscription's status and dates, and whether a payment failed. We keep those details with your account.

Technical and usage information. Standard web request data (IP address, browser type, pages visited, timestamps), authentication session data, and usage logs we use for rate-limiting and abuse prevention (e.g. daily generation limits).

Partner applications. If you apply to our partner program at app.usecontentpilot.com/partners, we collect your name, email address, country, the platforms and handles or links you list, the size of your audience (as a range) and what you tell us about how you'd share ContentPilot. If you're signed in when you apply, we note which account applied.

Support communications. Anything you send us via email or in-app support requests.

Invites. If you invite someone, we keep your invite code and which accounts joined through it. If you arrive through someone's invite link, the code travels in the signup page's address and is saved with your account when you create it; no cookie holds it. To check that nobody invites themselves, we compare the two accounts' email addresses and the social handles they add. The person who invited you sees your first name and whether you've joined, nothing more.

Waitlist. If you joined our waitlist before launch, we keep your email address, when you joined, and the answers you gave on the form (what you post about, what you find hardest, your platforms, and whether you asked for updates). We use them to give you early access and its waitlist offer (matched to the email you sign up with) and to send you the waitlist emails, with your answers used to make them relevant; the reminder about founding prices goes only to people who asked for updates. Every waitlist email has an unsubscribe link. We delete the entries of people who never signed up and didn't ask for updates once the launch offers have ended.

4. How we use your information

We use your information to:

  • create and maintain your account, and keep you signed in (necessary to provide the service)
  • generate personalised content ideas, plans, and brand analysis based on your niche, platform, goals, and brand inputs (necessary to provide the service)
  • read the public posts and profiles you ask us to: your own handle, the accounts on your Watchlist, and posts you paste a link to (necessary to provide the service)
  • let you publish or schedule posts to social accounts you've connected (necessary to provide the service)
  • process payments and manage your subscription, if you're on a paid plan (necessary to provide the service / legal obligation for financial record-keeping)
  • enforce daily/plan usage limits and prevent abuse of the service (legitimate interest in keeping the service reliable and fair to all users)
  • tell you, on Today and by email at most once a day, when an account on your Watchlist posts something doing far better than usual; the email can be stopped with one click from any of them or turned off in the alert settings (necessary to provide the service you asked for by watching the account)
  • send you a few emails about your account: a welcome with your first ideas when you sign up, the next idea the following day if you have not opened ContentPilot since, a reminder if you did not finish setting up, notes before and after your free trial ends and before founding prices end, a note when your first post goes out through ContentPilot, a Monday email with how many posts went out the week before and your first ideas for the week (only while you are posting or saving ideas), and, if you have not used ContentPilot for two weeks, a reminder at most once every two months. They are written from what you told us and what is in your account (your goal, niche, posts a week, ideas and how many of your posts went out), sent once each (the Monday email at most once a week), never to an address you have not confirmed, and every one has a one-click link to stop them. We record when a link in one is opened, to tell which emails help (legitimate interest in helping you get value from an account you created)
  • review a partner application and contact you about the partner program, which you agree to when you apply; you can withdraw at any time by emailing us (consent, and steps at your request before a contract if you're approved)
  • respond to support requests (necessary to provide the service)
  • keep the service secure, find and fix errors, and investigate misuse (legitimate interest in protecting the service and our users)

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (see Section 12).

We do not use your data for advertising, and we do not sell your data to anyone, ever. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects on you.

5. AI-generated content

ContentPilot's AI features (content ideas, scripts, brand analysis, breaking down a video or post, and picture posts) are powered by an AI model provider. When you use these features, the relevant inputs, such as your niche/brand context, a topic or prompt, or a video, image, document or audio file you ask us to read (including a link, post or podcast episode you attach to a new idea, or your business's own website when you press "Read my website" on Brand, which our servers fetch from the public web for you: the homepage and up to four of its own pages), are sent to that provider solely to produce the output you asked for. Picture posts are drawn by the provider's image model from your business's details (an offer, a review, a news headline, your brand colours) and, when you added them, your own photos and logo from your Media; the picture made is stored in your Media like an upload. For a business with no logo, the profile picture copied when you connected your handle is shown to the provider once to tell a logo from a photo of a person; only a logo is kept, in your Media, as your logo.

The provider processes these inputs for us, under the terms we use its paid service on, and does not use them to train its own models. We don't use your content to train models either, and we don't retain your prompts beyond what's operationally necessary to provide the feature (e.g. brief logging for debugging, kept only as long as described in Section 11).

Some features look up recent news with Google Search: the words of your niche, or of an idea you type that mentions something current, are sent to Google as a search. Where we show those results, we also show Google's search suggestions, as Google requires; choosing one opens Google Search.

If you use the microphone to speak instead of typing, ContentPilot doesn't receive or store any audio, only the words that appear in the box. Your browser does the listening, and some browsers (such as Chrome and Safari) send the audio to their own speech service to turn it into words. That is covered by your browser's privacy policy, not ours.

6. Connected social accounts and publishing

If you choose to connect a social account (to publish or schedule a post through ContentPilot), the actual connection, including the platform login and the access tokens that let us post on your behalf, is handled by our posting service, Post for Me (its name is on the platform's permission screen when you connect), not stored on our own servers. We store a reference to that connection (which platform, which account) so the app knows what's connected, but the credentials themselves live with Post for Me. You can disconnect an account at any time from Settings, which revokes that access.

Through a connected account, we also read your own posts and their numbers (views, likes and the like) to show them in Insights and next to your posts, and keep a recent copy so those pages load quickly. It is refreshed every few hours and deleted with your account.

7. Trend and inspiration data

The trending videos and posts shown in Create and Trends are gathered from publicly available social media content using social media data providers (and YouTube's own public service for YouTube). This is public content from creators unrelated to you. We don't scrape or process data about you through this feature, only about your niche's public trending content.

Separately, if you choose "Use my handle" when setting up or analysing your brand, we use the same kind of provider (and YouTube's own service for YouTube channels) to read the public bio and recent public posts of the Instagram, TikTok, YouTube, X or LinkedIn account or page you name. We use them only to work out your niche and writing voice for your brand profile. Only give us a handle for an account that is yours or that you manage. The same providers read the public posts of accounts you add to your Watchlist and of posts you paste a link to.

If your public posts appear in Trends. If you're a creator whose public posts are shown in ContentPilot, here is what we hold about you and why. What: your public handle or page name, links to your public posts, their captions or text, their public numbers (views, likes, comments, shares), when they were posted, the usual reach of your recent posts, and a copy of each post's thumbnail. A user may also ask us to break a post down into its hook, structure and look. Source: the public platforms (Instagram, TikTok, YouTube, X, LinkedIn), read through social media data providers, or a link a user pastes. Purpose: trend research, showing users which posts in their niche are doing well and why, so they can make their own. We don't repost your content or use it to identify or profile you as a person. Legal basis: legitimate interests (ours and our users', in understanding what works on public platforms), weighed against yours: the posts are ones you made public, we show them with your handle and a link back, and we keep them for a short time. How long: a trending post and our copy of its thumbnail are deleted 30 days after we last fetched it (we only show posts fetched in the last 7 days). A post a user saves to their workspace stays there until they remove it or delete their account, and a creator we follow for trends stays on that list, with their usual reach, while we use it. Your rights: you can object, or ask us to remove your posts or stop following your account, by emailing privacy@usecontentpilot.com; your other rights are in Section 12.

8. Who we share information with

We share personal information only as needed to run the service, with the recipients below. We describe most of them by the job they do rather than by name. Each of them processes your information for us, on our instructions and under a written contract, except where the table says otherwise.

RecipientWhat it receives, and why
A hosting and database providerStores our database, your sign-in details and the files you upload. All of your account data passes through it.
An application hosting providerRuns the servers that serve the app and its pages, so it handles your requests (including your IP address) as they pass through.
An AI model providerProcesses the content you give it (your brand details, prompts, posts, pictures, files and links you ask us to read) to generate ideas, scripts, analyses and pictures. See Section 5.
An email delivery providerSends our emails: sign-in codes and other account emails, product emails and waitlist emails. It receives your email address and the email's contents.
A business email providerHosts our own mailboxes, so it holds what you send us when you write to us, and our replies.
Social media data providersRead public posts and profiles for us: the handle you ask us to analyse, accounts on your Watchlist, posts you paste a link to, and public trending posts in your niche. They receive the handle, link or search words, not your account details.
Post for Me (our posting service)Connects the social accounts you choose to connect, holds their access tokens, publishes and schedules your posts and pictures, and reads your own posts' numbers for Insights. See Section 6.
Error monitoringReceives technical details when something breaks (the page, the error, your browser), with sign-in codes and similar secrets removed first, so we can find and fix it.
A website builderHosts our marketing site (usecontentpilot.com) and the forms on it, and counts visits without cookies (see Section 9).
StripeSells paid plans as the seller of record and handles payment and tax: checkout, invoices, refunds and managing your subscription. It collects your payment details directly and uses them under its own privacy policy, as a separate controller, not on our instructions. It tells us your plan and your subscription's status.
GoogleIf you choose "Continue with Google", Google signs you in and shares your name, email address and profile picture with us, under Google's own privacy policy.

When you attach a link to a new idea, our servers fetch that page for you, and for a podcast episode or shared document we may look it up in the public directory or service it points to. Only the link travels, not your account details.

We may also share information with our professional advisers (such as accountants and lawyers) where needed, if required by law, to enforce our Terms of Service, or to protect the rights, safety, or property of ContentPilot or our users. If ContentPilot is ever acquired or merged, your information may transfer as part of that deal, subject to the same protections described here.

For a list of the specific companies we use in each role, email support@usecontentpilot.com and we'll send it to you.

We do not sell your personal information, and we do not share it with anyone for their own advertising purposes.

9. Cookies

The app sets a few cookies of its own, all needed for it to work or to remember a choice you made: the sign-in session cookies that keep you signed in; one that remembers which workspace you have open (a year); and one that remembers whether you collapsed the sidebar (a year). There are no advertising cookies. On our marketing site (usecontentpilot.com), the website builder's built-in analytics counts visits. It sets no cookies and doesn't identify you: to count unique visitors, it combines your IP address and browser details with a secret that changes and is deleted every day. The app itself runs no third-party analytics or tracking. Because these cookies are needed for the service to work or only remember a choice you made, we don't show a consent banner for them. The one exception is under your control: if you choose to play an Instagram, TikTok or YouTube video inside Trends, that platform's own player loads at that moment and may set its own cookies. Nothing from those platforms loads until you click a video, and we use YouTube's no-cookie player so it stays quiet until you press play.

10. International data transfers

We're a UK company. We use providers in the UK, the European Economic Area and the United States; our database and the servers that run the app are in Ireland. Some of the recipients in Section 8 process data in the United States or elsewhere outside the UK.

Where your personal information goes outside the UK to a country the UK hasn't found adequate, we rely on the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge") where the provider is certified under it, or on standard contractual safeguards (the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses) where the provider offers them. We are putting written data processing terms in place with each provider. To get a copy of the safeguard that applies to a recipient, email privacy@usecontentpilot.com.

11. How long we keep your information

  • Account and content data: for as long as your account is active. If you delete your account from Settings, we permanently delete your data within 30 days, except anything we're legally required to keep longer.
  • Billing records: Stripe, as the seller of record, issues the invoices and keeps the sale and tax records under its own legal duties and privacy policy. The subscription details we hold (plan, Stripe references, payment status) are kept while your account exists and deleted with it. We keep our own accounting records of what Stripe pays us for as long as UK tax and accounting rules require.
  • Creators' public posts in Trends: as described in Section 7.
  • Files attached to a new idea: deleted once they have been read. A file that is never read is removed by a daily clean-up once it is a day old, and in any case when you delete your account.
  • Server and security logs: kept for up to 90 days, then deleted.
  • Partner applications: a rejected application is deleted 12 months after we decide on it. An approved one is kept while you're a partner. You can ask us to delete yours at any time.
  • Waitlist entries: as described in Section 3.
  • Support requests: kept for up to 2 years after resolution, in case you follow up.

12. Your rights

Under UK GDPR, you have the right to:

  • access the personal information we hold about you
  • correct it if it's inaccurate or incomplete
  • delete it (you can do this yourself for most data in Settings under Delete Account, or ask us directly for anything that isn't self-service)
  • restrict or object to certain processing, including anything we do on the basis of legitimate interests
  • receive a copy of your data in a portable format
  • withdraw consent at any time, where we rely on consent

To exercise any of these, email privacy@usecontentpilot.com. We'll respond within one month (or tell you within that month if a complex request needs up to two more), and may need to verify your identity first.

If you're unhappy with how we've handled your information, you also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.

13. Children

ContentPilot isn't directed at, or intended for use by, anyone under 16. We don't knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we'll delete it.

14. Security

We use industry-standard measures to protect your data: encryption in transit (HTTPS) and at rest, and authenticated, application-level checks on every read and write so you can only ever access your own account data. No system is 100% secure, but we take reasonable steps to protect your information and will notify you if we become aware of a breach affecting your data, as required by law.

15. Changes to this policy

We may update this policy from time to time. If we make a material change, we'll let you know by email or an in-app notice before it takes effect. The "Last updated" date at the top always reflects the current version.

16. Contact us

Clobie Enterprise Limited (trading as ContentPilot)

Email: privacy@usecontentpilot.com