Privacy Policy
Last updated: March 11, 2026
1. Introduction
This Privacy Policy explains how Nora Coaching ("we", "us", "our") collects, uses, stores, and protects your information when you use the TrendTopic Human SEO Blog Auto application ("App"), a Wix application that automatically generates SEO-optimized blog posts using artificial intelligence.
By installing or using the App, you consent to the practices described in this Privacy Policy. We are committed to protecting your privacy and handling your data in a transparent and lawful manner, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Information We Collect
When you install and use the App, we collect the following information:
- Wix Instance ID: A unique identifier for your App installation, used to associate your settings and generated content with your account.
- Wix Site ID: The identifier of your Wix website, used to manage blog publishing on the correct site.
- Member ID: Your Wix member identifier, used for account identification and access control.
- Site Owner Email: The email address of the Wix site owner, used for service communications and support.
- OAuth Tokens: Authentication tokens required to publish content to your Wix blog on your behalf. These tokens are encrypted using AES-256-GCM encryption before storage.
- App Preferences and Settings: Your selected niches, languages, publishing schedules, tone preferences, and other configuration options.
- Generated Content Metadata: Records of blog posts generated and published through the App, including titles, topics, and publication dates.
We do not collect any personal data beyond what is necessary for the App to function. We do not collect payment information directly; all billing is handled by Wix.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To generate AI-written blog content tailored to your selected niches and preferences, and to publish that content to your Wix blog.
- Authentication: To verify your identity and authorize actions on your Wix site using encrypted OAuth tokens.
- Account Management: To manage your subscription plan, usage limits, and App settings.
- Service Improvement: To monitor App performance, diagnose technical issues, and improve our services.
- Communication: To respond to support requests and send important service-related notifications.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Storage and Security
We take data security seriously and implement appropriate technical and organizational measures to protect your information:
- Database: Your data is stored in MongoDB Atlas, a cloud-hosted database service with enterprise-grade security, including encryption at rest and in transit.
- Token Encryption: All OAuth tokens are encrypted using AES-256-GCM, an industry-standard encryption algorithm, before being stored in our database. Tokens are never stored in plain text.
- Infrastructure: The App is deployed on Vercel, a serverless hosting platform that provides secure, scalable infrastructure with automatic HTTPS encryption for all communications.
- Access Controls: Access to your data is restricted to authorized personnel and automated systems required for service operation.
While we implement strong security measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we continually review and update our security practices.
5. Third-Party Services
The App relies on the following third-party services to deliver its functionality. Each service may process certain data as described below:
- Anthropic (Claude AI): Used for AI content generation. Your selected niche topics and content preferences are sent to Anthropic's API to generate blog articles. Anthropic processes this data according to their Privacy Policy. No personal user data is sent to Anthropic -- only content generation parameters.
- Undetectable.ai: Used to humanize AI-generated content. Generated article text is sent for processing. No personal user data is transmitted.
- Pexels, Pixabay, and Unsplash: Used to source royalty-free cover images for blog posts. Only image search queries (keywords) are sent to these services. No personal user data is shared.
- Wix: As the host platform, Wix processes data according to its own privacy policy. The App interacts with the Wix API to publish blog posts on your behalf.
- MongoDB Atlas: Cloud database provider used for data storage. Data is hosted in accordance with MongoDB's security and privacy standards.
- Vercel: Serverless hosting platform where the App backend is deployed. Vercel processes server requests in accordance with their privacy policy.
6. Data Retention
- Active Users: Your data is retained for as long as the App is installed on your Wix site and your account is active.
- After Uninstallation: If you uninstall the App, your account data is retained for a limited period to allow for potential reinstallation. You may request immediate deletion of all your data at any time by contacting us.
- Deletion Requests: Upon receiving a data deletion request, we will permanently remove all your personal data from our systems within 30 days, unless retention is required by law.
- Published Content: Blog posts that have already been published to your Wix site remain on your site after uninstallation. We do not retain copies of published content.
7. Your Rights
Under the GDPR (European Economic Area residents):
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: You may request that we limit how we use your data.
- Right to Data Portability: You may request your data in a structured, machine-readable format.
- Right to Object: You may object to certain types of data processing.
- Right to Withdraw Consent: You may withdraw your consent at any time by uninstalling the App or contacting us.
Under the CCPA (California residents):
- Right to Know: You may request information about the categories and specific pieces of personal data we have collected about you.
- Right to Delete: You may request deletion of your personal data.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- No Sale of Data: We do not sell your personal information to third parties.
To exercise any of these rights, please contact us at support@noracoaching.com. We will respond to your request within 30 days.
8. Cookies
The App itself does not set or use cookies. Any cookies on your Wix site are managed by the Wix platform and are subject to Wix's own cookie policy. Please refer to Wix's privacy documentation for details on their cookie usage.
9. Children's Privacy
The App is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at support@noracoaching.com, and we will take steps to delete such information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you through the App or by other appropriate means. The "Last updated" date at the top of this page indicates when the policy was last revised.
Your continued use of the App after any changes to this Privacy Policy constitutes your acceptance of the updated terms.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Nora Coaching
Email: support@noracoaching.com
Website: www.noracoaching.com
If you are located in the European Economic Area and believe that your data protection rights have been violated, you also have the right to lodge a complaint with your local data protection supervisory authority.