Site Direction ("we," "us," "the app"), operated by Dragon Website Services, is a content-strategy tool for WordPress bloggers. This page explains what data we collect, why, and how it's handled.
What we collect
- Account info: your email address and password. Password authentication is handled by our provider, Supabase, and we never see or store your raw password.
- Website data you connect: if you link your Google Search Console and Google Analytics accounts, we read (never modify) your search performance and traffic data, such as clicks, impressions, page views, and similar metrics, for the specific properties you authorize.
- Content data: post titles, URLs, and categories from your WordPress site, which you provide directly when setting up a site in the app.
- Billing info: handled entirely by Stripe. We store only your Stripe customer/subscription IDs and plan status. We never see or store your card details.
- Usage data: which features you use and how often, so we can enforce fair usage limits on metered features (like keyword lookups) and keep the product running reliably.
Google user data specifically
If you connect Google Search Console or Google Analytics, we request read-only access to that data. We use it solely to power the dashboards and recommendations inside this app. We do not sell it, share it with third parties, use it for advertising, use it to determine creditworthiness or lending eligibility, or use it to train any generalized AI/ML models. You can revoke access at any time from your Google Account permissions page, which immediately stops all access. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
- Encrypted in transit: the entire app, and every connection to it, runs over HTTPS/TLS. Data is never sent unencrypted.
- Encrypted at rest: our database provider, Supabase, encrypts all stored data, including your connected Google Search Console and Analytics data, using AES-256 encryption, automatically and at all times.
- Access control: database-level security policies restrict data access to the account and workspace that owns it. Your data is never visible to another customer's account.
- Google tokens: your Google OAuth access is stored server-side only. It's never exposed to the browser or any client-side code, and you can revoke it at any time from your Google Account permissions page, which takes effect immediately.
Who else sees your data
We use the following services to run the app. Each processes data on our behalf:
- Supabase: database and authentication
- Vercel: hosting
- Stripe: billing and payment processing
- Google: Search Console and Analytics data, if you connect them
- DataForSEO: keyword search-volume and related-keyword lookups, for the terms you explicitly search
- Resend: transactional email (invitations, daily digest)
- Sentry: error monitoring, so we can find and fix bugs
We do not sell your data, and we do not share it with anyone for advertising purposes.
Cookies & local storage
We use cookies and browser local storage to keep you signed in and to cache your data so pages load instantly on return visits. We don't use tracking or advertising cookies.
Data retention & deletion
We keep your data for as long as your account is active. If you'd like your account and associated data deleted, contact us at the address below and we'll process the request.
Your rights
You can access, correct, or delete your data at any time by contacting us, and you can disconnect any Google account connection yourself at any time from within the app or from your Google Account settings.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.