Privacy Policy

Last updated: 10 March 2026

Introduction

This Privacy Policy explains how Jonah and Associates Pty Ltd (ABN 86 679 045 044), a company incorporated in Victoria, Australia (“we,” “us,” or “our”), collects, uses, shares, and protects your personal information when you use the gotta.blog platform (the “Service”).

This policy applies to everyone who uses gotta.blog, including:

  • Creators — people who register an account to create and manage a blog, publish content, or send newsletters.
  • Readers and Subscribers — people who visit blogs hosted on gotta.blog, subscribe to newsletters, or pay for premium content.

We believe in being straightforward about data. We don't sell your information, we don't serve ads, and we collect only what we need to provide and improve the Service.

This Privacy Policy should be read alongside our Terms of Service.

Information We Collect

Information you provide directly

  • Account registration: Your name, email address, and password when you create a gotta.blog account.
  • Profile information: Display name, bio, avatar image, and social media links you choose to add.
  • Blog content: Posts, pages, images, media files, and any other material you publish through the Service.
  • Payment information: All payment processing is handled by Stripe. We do not store your credit card number, bank account details, or other sensitive financial information. We receive and store Stripe customer identifiers and basic transaction metadata (amounts, dates, subscription status) to manage your account.
  • Newsletter subscriptions: When Readers subscribe to a Creator's newsletter, we collect their email address and subscription preferences.
  • Support communications: Emails, feedback, and other messages you send to us.

Information collected automatically

  • Usage analytics: Pageviews, referral sources, popular content, and feature usage. We use first-party analytics only — no third-party tracking pixels or ad network trackers.
  • Device and browser information: Browser type, operating system, and screen resolution, collected to optimise how your blog renders for visitors.
  • IP addresses: Collected for security purposes, rate limiting, and approximate geolocation (country or region level only). We do not use IP addresses for advertising or tracking.
  • Cookies: We use minimal, functional cookies only — for session authentication and user preferences. We do not use advertising cookies, third-party tracking cookies, tracking pixels, web beacons, or browser fingerprinting. See the Cookies and Tracking section below.

Information processed through AI features

When you use AI-powered features (such as SEO optimisation or writing assistance), the relevant content is sent to the selected third-party AI provider for processing. The providers we use include OpenAI, Anthropic, and OpenRouter.

Important points:

  • AI processing happens only when you actively use an AI feature. Your content is never automatically sent to AI providers without your action.
  • gotta.blog does not use your content to train AI models. Third-party providers have their own data use policies — we encourage you to review them. We use API configurations designed to minimise data retention by these providers.
  • You can choose your preferred AI provider in your account settings.

Information from third parties

  • Stripe: Payment confirmation, subscription status, and payout details (for Creators using paid subscriptions).
  • Imported content: If you use our import tools to migrate from WordPress, Substack, or Ghost, we process only the data you explicitly upload.

How We Use Your Information

We use your information for the following purposes:

  • Providing the Service: Hosting your blog, publishing your content, delivering newsletters, rendering pages for readers.
  • Processing payments: Managing subscriptions, processing transactions through Stripe, and handling refunds.
  • Transactional communications: Sending account verification emails, password resets, payment receipts, and renewal reminders.
  • Delivering newsletters: Sending email newsletters on behalf of Creators to their subscribers.
  • AI features: Processing content through AI providers when you use SEO optimisation, writing tools, or other AI-powered features.
  • Service improvement: Analysing aggregate, anonymised usage data to understand how the Service is used and how to improve it.
  • Security and fraud prevention: Detecting and preventing fraud, abuse, spam, and security threats.
  • Legal compliance: Fulfilling legal obligations, responding to lawful requests from authorities, and maintaining tax and financial records.
  • Service updates: Communicating important changes to the Service or these policies.

We do not sell your personal information. Ever.

We do not serve advertisements or share your data with advertisers.

How We Share Information

We share your information only in the following limited circumstances:

  • Stripe: For payment processing. Stripe acts as an independent data controller for payment data.
  • AI providers (OpenAI, Anthropic, OpenRouter): When you use AI features, relevant content is sent to your selected provider for processing. These providers act as data processors under contract with us.
  • Cloudflare: Provides image object storage and delivery, media transformations, DNS, and Turnstile bot protection. Cloudflare acts as a data processor and sub-processor where applicable.
  • PostHog: Receives anonymous, redacted technical errors only. Browser error reporting is optional and consent-gated. Server operational errors are reported independently because server processes cannot read the browser preference. We disable page views, session replay, product analytics, and identity profiles.
  • Email delivery infrastructure: Newsletter delivery is handled by our integrated email infrastructure, operated by a related entity within Jonah and Associates Pty Ltd. This entity processes email data solely to deliver newsletters on behalf of Creators and is bound by equivalent data protection standards.
  • Law enforcement and legal requests: We may disclose information when required by law, court order, subpoena, or other legal process, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity. We will notify you before your information becomes subject to a different privacy policy.
  • Aggregate and anonymised data: We may share anonymised, aggregated data for research or reporting purposes. This data cannot be used to identify you.

We never sell personal data to third parties.

International Data Transfers

Some image delivery and bot-protection traffic uses Cloudflare's global network, so that data may be processed in countries where Cloudflare operates.

For EU/EEA and UK users: When your data is transferred outside the EEA or UK, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs), adequacy decisions by the European Commission, or the EU-US Data Privacy Framework where applicable.

For Australian users: Overseas disclosures of personal information comply with Australian Privacy Principle 8. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles information in accordance with the Australian Privacy Principles.

The primary countries where data processing occurs include the United States, European Union member states, the United Kingdom, and Australia, based on the locations of our infrastructure providers and AI service providers.

Data Retention

  • Active accounts: We retain your data for as long as your account is active.
  • Deleted accounts: When you delete your account, we delete your personal data within 30 days, except where we are required by law to retain certain records (for example, financial and tax records are retained for 7 years under Australian tax law).
  • Blog content: Removed from public access immediately upon account deletion. Purged from backups within 90 days.
  • Newsletter subscriber data: Retained as part of the Creator's blog. If a Creator's blog is deleted, associated subscriber data is deleted with it.
  • AI processing: Content sent to AI providers is subject to their respective retention policies. gotta.blog does not separately retain AI processing inputs or outputs beyond what is stored as part of your published content.
  • Analytics data: Aggregated analytics are retained indefinitely. Individual-level analytics data is purged after 12 months.

Your Rights

Rights for all users

Regardless of where you live, you can:

  • Access your personal data by contacting us or through your account settings.
  • Correct inaccurate information in your account settings or by contacting us.
  • Delete your account and associated data at any time.
  • Export your content and data through the export feature in your account settings.
  • Withdraw consent for optional processing (such as AI features or marketing emails) at any time.
  • Unsubscribe from any creator's newsletter at any time using the link in every email.

Additional rights for EU/EEA and UK residents (GDPR)

If you are in the EEA or UK, you also have the right to:

  • Access your personal data (Article 15) and receive a copy.
  • Rectify inaccurate data (Article 16).
  • Erase your data (“right to be forgotten”) (Article 17).
  • Restrict processing of your data in certain circumstances (Article 18).
  • Data portability — receive your data in a structured, machine-readable format (Article 20).
  • Object to processing based on legitimate interests (Article 21).
  • Not be subject to automated decision-making, including profiling, that produces legal effects (Article 22). Note: gotta.blog does not currently make automated decisions with legal or similarly significant effects.
  • Lodge a complaint with your local data protection supervisory authority.

Additional rights for California residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and share.
  • Delete your personal information.
  • Opt out of the sale or sharing of personal information. Note: we do not sell or share your personal information as defined by the CCPA.
  • Non-discrimination — we will not discriminate against you for exercising your privacy rights.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information.

Additional rights for Australian residents

Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

  • Access your personal information (APP 12).
  • Correct inaccurate personal information (APP 13).
  • Use a pseudonym or remain anonymous where practicable (APP 2).
  • Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Australian Privacy Principles.

How to exercise your rights

To exercise any of these rights, contact us at contact@gotta.blog. We will respond to all requests within 30 days. We may ask you to verify your identity before processing your request.

Cookies and Tracking

gotta.blog uses minimal functional and preference cookies:

  • Session cookies: To keep you logged in during your browsing session. These are essential for the Service to work.
  • Preference cookies: To remember your settings (such as theme preferences or editor configuration). Also essential.
  • Optional error reporting: The host-only gotta_analytics_consent cookie stores your granted or denied choice for one year. After you grant permission, PostHog may store browser state used only to send redacted technical errors.

We do not use advertising cookies, third-party tracking cookies, tracking pixels, web beacons, or browser fingerprinting techniques. We do not participate in ad networks or allow third-party advertisers to place cookies through our Service.

Browser error reporting is optional and consent-gated. It does not collect page views, session replay, product analytics, or identity profiles. Withdrawing permission clears the configured PostHog browser state and stops later browser error reports.

Server operational error reporting is not controlled by this browser preference. It sends only anonymous, redacted technical errors and excludes request bodies, headers, cookies, query strings, content, email addresses, names, payloads, provider details, database URLs, credentials, and secrets.

Our first-party analytics collect aggregate usage data (pageviews, referrers) without using cookies for tracking purposes.

Optional error reports

Error reports are off.

All creator blogs hosted on gotta.blog operate under this same cookie policy.

Children's Privacy

gotta.blog is not directed at children under 16. We do not knowingly collect personal information from anyone under 16.

If we learn that we have collected personal information from a child under 16, we will take steps to delete that information as promptly as possible. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@gotta.blog.

Security

We take the security of your data seriously and implement appropriate technical and organisational measures, including:

  • Encryption in transit using TLS/SSL for all connections.
  • Encryption at rest for stored data.
  • Per-tenant database isolation — each Creator's blog uses a separate database, meaning one blog's data is architecturally isolated from another's.
  • Restricted access to application infrastructure and production data.
  • Regular security reviews of our infrastructure and practices.

No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security. We encourage you to use a strong, unique password and to keep your account credentials confidential.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or through a notification in the Service at least 30 days before the changes take effect.

Your continued use of gotta.blog after the updated policy takes effect constitutes acceptance of the changes. If you disagree with the changes, you should stop using the Service before they take effect.

The current version of this Privacy Policy is always available at https://gotta.blog/privacy with the “Last updated” date shown at the top.

California-Specific Disclosures (CCPA/CPRA)

This section provides additional disclosures required under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Categories of personal information collected

CCPA CategoryExamplesCollected
IdentifiersName, email, IP address, Stripe customer IDYes
Commercial informationSubscription history, transaction recordsYes
Internet or network activityPageviews, referrers, browser typeYes
Geolocation dataApproximate location (country/region from IP)Yes
Professional informationBio, social links (if provided)Yes
Sensory dataAvatar images, uploaded mediaYes
InferencesAggregate analytics (popular content, trends)Yes

Business purposes for collection

We collect personal information to provide the Service, process payments, deliver newsletters, provide AI features, ensure security, and improve the platform. See the “How We Use Your Information” section above for full details.

Third parties

We share information with Stripe (payments), AI providers (when you use AI features), Cloudflare (image delivery and bot protection), and our email delivery infrastructure (newsletters). See the “How We Share Information” section for details.

Sale and sharing

We do not sell or share personal information as defined by the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.

Submitting a request

To exercise your CCPA rights, contact us at contact@gotta.blog. You may also designate an authorised agent to make a request on your behalf. The authorised agent must provide written permission signed by you, and we may require you to verify your identity directly.

Australian-Specific Disclosures

This section provides additional information for users in Australia, in compliance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).

Jonah and Associates Pty Ltd is bound by the APPs and is committed to handling personal information in accordance with them.

Cross-border disclosure (APP 8)

As described in the “International Data Transfers” section, your personal information may be disclosed to recipients in the United States, the European Union, the United Kingdom, and other countries where our infrastructure providers and AI service partners operate. Before making such disclosures, we take reasonable steps to ensure that overseas recipients handle personal information consistently with the APPs.

Making a complaint

If you believe we have breached the Australian Privacy Principles, you can lodge a complaint with us at contact@gotta.blog. We will investigate and respond within 30 days.

If you are not satisfied with our response, you have the right to complain to the Office of the Australian Information Commissioner (OAIC):

  • Website: https://www.oaic.gov.au/
  • Phone: 1300 363 992
  • Email: enquiries@oaic.gov.au

Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your personal information, please contact us:

Jonah and Associates Pty Ltd
Level 31, 120 Collins Street
Melbourne, Victoria, Australia

Privacy inquiries: contact@gotta.blog
General support: contact@gotta.blog

We aim to respond to all privacy-related inquiries within 30 days.

For EU/EEA residents, if we are unable to resolve your concern, you have the right to lodge a complaint with your local data protection supervisory authority.