Legal
Privacy policy
Version 2026-08.3 · Effective 19 August 2026
This policy explains what personal data Joseph Omaita, trading as Baboon Ventures ("AIPenPen", "we", "us") collects, why we hold it, who helps us process it, and what you can ask us to do about it. It covers clients who order articles, the writers and editors who produce them, and visitors who run a free content audit before they have an account of any kind.
For the data described here, we are the data controller. We operate from Kenya and handle personal data under the Kenyan Data Protection Act, 2019; where the GDPR or UK GDPR applies to you, we honour those rights too.
1. What we collect
When you run a free content audit. The audit sits in front of everything else, so this happens before you have an account. We keep the niche you describe, the website address if you give one, and which of the listed problems you ticked — that is what the audit is researched and written from. If you choose to unlock the full report, we also keep your email address: no account is created and we never ask you for a password. We keep a salted, one-way hash of your IP address, which exists to be counted — it is how one script is stopped from running the tool a thousand times — and not the address itself. The finished report and the sources it cites are stored with the audit.
When you create an account. Your name, email address, and a one-way hash of your password — we never store the password itself. Plus the roles your account holds, which decide what you can see.
When you place an order. Everything you type or import: article titles, briefs and instructions, keywords, the website the articles are for, delivery preferences, and any spreadsheet or file you upload. If you link a Google Sheet, we fetch the sheet's contents once through Google's export endpoint.
If you connect a WordPress site. The site address and an application password. The password is stored encrypted, decrypted only in memory at the moment we publish, and never written to logs or error reports. You can revoke it at any time.
When you pay. Card payments go through Lemon Squeezy, LLC, our merchant of record. We never see or store your card details. We receive the transaction reference, the amount, and whether it succeeded — and they handle the rest as their own controller, under their privacy notice.
If you are invoiced instead, you pay by bank transfer and no card is involved. We store the invoice, the amount, and the transfer reference we matched your payment against; your bank details reach us only as whatever your bank shows on that transfer, and we do not ask you for account numbers. Where we owe you a refund on an invoiced order we will ask for the account to send it back to, and we keep those details only as long as the refund takes.
Automatically, as you use the site. Your IP address and the country derived from it (we use this to decide whether the service is available where you are), your session cookie, and server request logs. We also keep an internal audit trail of actions taken on orders — who transitioned what, and when — which is how disputes get resolved and how the money in the system stays explainable.
If you write, edit or get paid through the platform. For writers and editors: identity details, the phone number your M-Pesa payout goes to, your earnings ledger, and your work history on the platform.
When you contact us. The message you send and our reply.
2. Why we hold it, and on what basis
| What for | Basis |
|---|---|
| Researching and writing the free content audit you asked for, and unlocking the full report | Taking steps at your request, before any contract exists |
| Emailing you about an audit you ran — the report itself, and following up about it | Our legitimate interest in following up on something you asked us to produce |
| Counting audit requests against a hashed IP address and an email address, so a free tool is not abused | Our legitimate interest in running a service that is not being abused |
| Creating your account, taking your order, producing and delivering articles | Performing our contract with you |
| Sending transactional email — order confirmations, "an article is ready", payout notices | Performing our contract |
| Paying writers and editors, and keeping the earnings ledger | Contract, and legal obligation |
| Keeping accounting and tax records | Legal obligation |
| Security, fraud prevention, abuse investigation, access control by region | Our legitimate interest in running a service that is not being abused |
| Resolving disputes about what happened on an order | Our legitimate interest, and yours |
We do not send marketing email unless you ask us to — with one exception, and it is one you opt into by using it: if you unlock a free content audit, we may write to you about that audit. Tell us to stop and we will, and it is the only thing that address is used for. We do not sell, rent or share personal data for anyone else's advertising.
3. Cookies and local storage
Short list, because it is a short list:
- A session cookie, set when you sign in, so the site knows it is still you. It is strictly necessary — without it you cannot stay signed in.
- Your theme preference, stored in your browser's local storage so the site loads in light or dark without a flash. It never leaves your browser.
The free content audit sets no cookie and stores nothing in your browser — you do not need an account to run one, and it does not give you one.
We run no third-party analytics and no advertising trackers.
4. Who else processes it
We use a small set of service providers. Each one processes data on our instructions and only for the purpose listed.
| Provider | What it does | What it sees |
|---|---|---|
| Neon | Managed Postgres database (EU region) | Everything stored in the application |
| Vercel | Hosts the website and application | Request data, IP addresses, logs |
| Railway | Runs the background worker that processes jobs | Order data being processed |
| Lemon Squeezy, LLC | Card payments, receipts, tax — as merchant of record | Your payment details, name, billing country |
| Wise | Receives bank transfers against invoices we issue | Your name and whatever your bank includes on the transfer |
| Resend | Sends transactional email | Your email address and the message |
| Anthropic | Suggests keywords and lengths from your article titles during import; researches and writes the free content audit | Article titles and briefs you import; the niche and website you enter for an audit, and the live web search that research runs. Never your email address. Not used to train models. |
| Delivers finished articles as Google Docs, and reads a Sheet you link | The article content; the sheet you shared | |
| Cloudflare R2 | Stores images used in articles | Uploaded and sourced images |
Some of these only receive anything if you use the feature they serve — Google sees nothing unless you link a Sheet or take Google Docs delivery.
Writers and editors are people, not processors. Contracted writers and editors in Kenya work on your articles. They see the brief and the target website's domain — never your name, company, email or billing details.
We may also disclose information where the law requires it, or to establish or defend a legal claim.
5. Where data goes
We operate from Kenya. Our database is hosted in the EU, and several providers above are in the EU, the United Kingdom or the United States. Where a transfer needs a safeguard, we rely on the providers' standard contractual clauses.
6. How long we keep it
- Free content audits — the audit, the email address you gave to unlock it, and the report itself are deleted 365 days after the audit, by a sweep that runs monthly. Talking to you does not extend that: if the conversation went anywhere, you have an account by then, and the account is the record.
- Account data — while your account is open, and afterwards only as long as we need it for tax, accounting and legal-claim purposes.
- Order content and delivered articles — while your account is open, so you can get back to what you bought.
- Payment records — as long as accounting and tax law requires.
- Audit records — kept indefinitely. These record what the business did, not who you are, and they are what makes an order's history verifiable years later. If you close your account, we remove or pseudonymise the personal identifiers in those records rather than deleting the events themselves.
- Server logs — a short operational window, then discarded.
7. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your data, where we do not have to keep it (see the audit-record note above);
- restrict or object to a particular use, including anything we do on the basis of legitimate interest;
- export your data in a portable format.
Email support@aipenpen.com. We answer within 30 days, and we do not charge for it. If you think we have got it wrong, you can complain to the Office of the Data Protection Commissioner in Kenya, or to your local supervisory authority if the GDPR applies to you.
8. How we protect it
Passwords are hashed, never stored in a readable form. Any credential you give us for a third-party system is stored encrypted and decrypted only at the moment it is used. Traffic is encrypted in transit. Access inside the platform is limited by role, and every consequential action is written to the audit trail.
No system is perfect. If a breach affects you, we will tell you and the relevant authority as the law requires.
9. Children
The service is not for anyone under 18, and we do not knowingly collect data from children. If you believe we have, write to support@aipenpen.com and we will delete it.
10. Automated decisions
We do not make decisions with legal or similarly significant effects about you by automated means. We do use an AI model to suggest keywords and article lengths during import — suggestions you can accept, edit or ignore, and which never decide anything on their own. The free content audit is written the same way: an AI model working from a live search of your niche. It is information for you to judge, not a decision about you, and nothing in it changes what you can do here or what you would be charged.
11. Changes
We version this policy rather than editing it quietly. The version and effective date are at the top of the page, and we will tell you about material changes before they take effect.
12. Contact
Joseph Omaita, trading as Baboon Ventures — support@aipenpen.com