Privacy Policy draft
QuizOut Privacy Policy.
This draft explains how the QuizOut WordPress plugin and hosted quiz-generation service handle data.
1. Who is responsible for the data
The WordPress site owner controls the articles, generated quizzes, reader interactions, and reader leads stored by the plugin on that site. [Operator legal name] operates the QuizOut generation service and account console and is responsible for the account, site, usage, billing, and inquiry information described below.
Site owners must give their readers any notices and choices required for quizzes, analytics, lead capture, cookies, or other processing they configure in WordPress.
2. Data stored by the WordPress plugin
The plugin stores generated quizzes, editor changes and approvals, placement settings, plays, answers, scores, results, analytics, and optional consent-based reader leads in the site’s WordPress database. QuizOut does not receive those reader records as part of normal plugin operation.
The site owner controls access, retention, export, and deletion for this local WordPress data. The site owner is also responsible for its WordPress host, backups, security settings, and any connected email, CRM, or analytics service.
3. Post content used for quiz generation
When a site requests a quiz, the plugin sends the post title and article content, plus generation settings, to QuizOut. QuizOut validates that input, sends it to OpenAI with provider storage disabled, and returns the generated quiz to the plugin.
By default, QuizOut does not keep the article or generated quiz as a durable product record and excludes request and response bodies from application logs. A successful response may be stored in encrypted operational cache for idempotent replay for no more than 24 hours. If an account owner explicitly enables generation sampling, QuizOut may retain a bounded, de-identified sample for up to 30 days as described in the detailed data map.
4. Account, site, usage, and billing data
QuizOut stores the information needed to operate accounts and connect sites. This may include names, encrypted email addresses, password hashes, roles, site URLs and metadata, masked API-key history, plan and subscription state, post-generation usage, audit records, and account preferences.
Stripe processes payments. QuizOut stores Stripe object identifiers and subscription state but does not receive payment-card numbers. Stripe may retain financial records it is required to keep by law.
5. Contact inquiries and service email
If you contact QuizOut, we store the name, email address, organization, website, and message you submit so we can reply. Account and service emails may include authentication, invitation, claim, billing, quota, lifecycle, and privacy-export messages.
6. Cookies
QuizOut uses essential cookies for secure sessions and account sign-in. A valid referral link may set an encrypted, HTTP-only first-touch cookie for up to 30 days so a later account signup can be attributed to the referring account. QuizOut does not use that referral cookie to build a visitor browsing history.
This draft does not authorize advertising cookies. The final policy must be checked against the production site’s actual cookie and analytics configuration before approval.
7. Retention, export, and deletion
Account owners can request an export and account erasure from console privacy settings. Account, site, usage, billing references, audit, and matching inquiry records are handled according to the retention and erasure rules in the detailed data map. Operational cache has a maximum age of 24 hours, completed background jobs are cleared after one day, and opted-in generation samples expire after 30 days.
Deletion from QuizOut does not delete quizzes or reader records stored in WordPress. Site owners must manage those records through their own WordPress site.
8. Subprocessors and international processing
QuizOut uses OpenAI for transient quiz generation, Stripe for billing, and Amazon SES for service-email delivery. Hosting and infrastructure provider details, processing locations, transfer safeguards, and the final subprocessor list must be confirmed before this draft is approved.
9. Security and your choices
QuizOut uses encrypted fields for sensitive account, billing-reference, sample, cache, and inquiry data; digest-only storage for API keys and tokens; access controls; and allowlisted audit records. No internet service can guarantee absolute security.
Account owners can manage team access, API keys, optional email, generation sampling, exports, and erasure in the console. Questions or privacy requests should be sent to [privacy contact email]. The final policy must state the applicable privacy rights and complaint route for the approved jurisdiction.
10. Changes to this policy
The approved policy will state how material changes are announced and when revisions take effect. This draft has no effective date and must not be treated as the published Privacy Policy.