Public policy
Privacy Policy
This policy explains how SiteTandem handles information when people use the application, connect websites or data sources, or authorize an AI client.
Effective date:
Introduction
SiteTandem is a controlled AI website-operations and growth platform. It connects authorized WordPress sites, search and analytics services, and compatible AI clients within a workspace.
SiteTandem is operated by MD Risalat Bari (Sole Proprietor), Bangladesh. This policy applies to the SiteTandem application at app.sitetandem.com, its customer-facing APIs, and the SiteTandem-managed authorization flows used by compatible AI clients.
Connected services such as WordPress hosts, OpenAI, Google, and Microsoft have their own terms and privacy policies. Their independent processing is not controlled by this policy.
Information users provide
SiteTandem accepts information that users provide when creating and operating an account or workspace, including:
- Account name, email address, authentication records, and email-verification information.
- Workspace identity, memberships, roles, and entitlement information.
- Connected WordPress site names, URLs, environments, usernames, aliases, capability details, and connection choices.
- Provider property mappings and choices for Google Search Console, Google Analytics 4, and Bing Webmaster Tools.
- AI Connection names, selected sites, granted permissions, and authorization decisions.
- Content, briefs, saved insights, proposals, review decisions, reasons, or instructions intentionally submitted through SiteTandem workflows.
The authentication system processes account passwords through its protected authentication boundary. SiteTandem does not present stored account passwords back to users.
Technical and service information
SiteTandem records technical information needed to operate and secure the service. This may include session identifiers, IP address, browser or user-agent information, timestamps, safe error codes, connection state, operation metadata, and audit events.
Necessary authentication cookies maintain signed-in sessions and protect account access. This public privacy-policy page does not require an account, active workspace, or existing authentication cookie. SiteTandem does not currently use product information for advertising profiling.
Connected-service information
When a user authorizes a service, SiteTandem may retrieve only the information needed for the requested, permitted operation:
- WordPress: site identity and capabilities, authorized user details, content types, posts, pages, metadata, taxonomies, revisions, and bounded content requested by the user.
- Google Search Console: authorized properties and bounded search-performance information such as queries, pages, countries, devices, clicks, impressions, position, and related provider metadata.
- Google Analytics 4: authorized properties and bounded analytics dimensions, metrics, landing-page, engagement, and comparison information.
- Bing Webmaster Tools: authorized sites and bounded search, traffic, query, and page performance information.
- ChatGPT and other authorized AI clients: the Action or tool request, authorization context, and bounded response required to carry out the user-requested SiteTandem operation.
Access remains limited by the user's account, active workspace, role, selected sites, connection state, OAuth scopes, and the permissions granted for the specific operation.
SiteTandem's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Credentials and authorization
Stored WordPress Application Passwords and supported provider refresh credentials are protected by SiteTandem's encrypted credential-storage boundary. SiteTandem does not display those stored secret values through ordinary application, MCP, or GPT Action responses.
OAuth access is controlled through tokens, scopes, current workspace membership, roles, connection state, and selected-site permissions. The shared SiteTandem Custom GPT uses confidential application credentials that are administered by SiteTandem and are not provided to customers.
Revoking an AI Connection invalidates that workspace and client's SiteTandem authorization and removes its active local OAuth grants. Disconnecting a provider stops future authorized use through that connection. Revocation or disconnection does not necessarily erase historical audit, operation, or security records retained for integrity, dispute prevention, or legal obligations.
How information is used
SiteTandem uses information to:
- Operate and secure accounts, sessions, and workspaces.
- Connect only the sites, properties, providers, and AI clients a user authorizes.
- Fulfil user-requested reads, analysis, saved workflows, proposals, and bounded draft preparation.
- Maintain idempotency, request integrity, operation state, and audit records.
- Detect misuse, enforce permissions, investigate incidents, and troubleshoot failures.
- Communicate account, service, and security information.
- Improve SiteTandem's reliability and usability.
AI and OpenAI processing
Users may access SiteTandem through ChatGPT, the shared SiteTandem Custom GPT, or another compatible AI client that they authorize. Prompts and conversations submitted to ChatGPT are also processed by OpenAI under OpenAI's own terms and privacy policy.
SiteTandem receives the Action or tool requests and authorization context needed to perform the requested SiteTandem operation. It returns only information permitted for the authorized workspace, selected sites, granted scopes, and current role. SiteTandem does not control OpenAI's independent handling or retention of ChatGPT conversations.
Users should not place passwords, tokens, private keys, or unnecessary sensitive personal information in AI conversations. WordPress and provider content returned to an AI client remains untrusted data and does not change authorization or grant new permissions.
Service providers and user-connected services
SiteTandem relies on service providers where needed to operate the application. The currently documented services include Supabase-hosted PostgreSQL for database infrastructure and Resend for transactional email delivery. The application runs on hosting infrastructure deployed and managed through Coolify. These providers may process information on SiteTandem's behalf according to their services and agreements.
OpenAI, Google, Microsoft/Bing, a connected WordPress site, and the site's hosting provider are independent services that a user chooses or authorizes for a workflow. Information sent to or received from them is also governed by their own terms and privacy practices.
This section describes the services substantiated by the current product and deployment. It is not a claim that every independent service selected by a customer is a SiteTandem subprocessor.
Retention
SiteTandem may retain account, workspace, connection, operation, proposal, insight, brief, and audit information while an account or workspace remains active and while the information is needed to provide requested services. Some records may be retained longer when needed for security, integrity, dispute prevention, backup recovery, or legal obligations.
Search Console, Google Analytics 4, and Bing report rows are retrieved live and returned transiently rather than maintained as a raw-response warehouse. WordPress Content Browser reads are also live; information intentionally saved as an insight, brief, proposal, decision, operation, or audit record is retained as part of that workflow.
Backups may retain information for a limited operational period. Revoking a provider or AI Connection stops future authorized use through that connection but may not erase historical records required for security and integrity. SiteTandem does not currently promise instant or fully automated deletion of every account or workspace record.
Security
SiteTandem uses safeguards designed for its current service, including encrypted storage for protected integration credentials, workspace and role authorization, selected-site allowlists, scoped OAuth, audit records, bounded and validated requests and responses, token-validity checks, and connection revocation controls.
Security is a shared responsibility. Users should use unique, restricted WordPress service accounts, protect their SiteTandem and connected-service accounts, grant only necessary access, and revoke connections they no longer use. No online service can guarantee absolute security.
User choices and rights
Depending on role and available product controls, users can:
- Review, limit, manage, or revoke AI Connections.
- Disconnect WordPress sites and provider connections or limit the sites selected for an AI client.
- Choose read-only access or explicitly bounded change access where SiteTandem offers that choice.
- Request access to, correction of, or deletion of personal information by contacting SiteTandem.
SiteTandem may need to verify the requester's identity and authority over the relevant account or workspace. Some information may remain where retention is necessary for security, integrity, dispute prevention, or legal obligations. Privacy rights and available remedies differ by location.
International processing
SiteTandem is operated from Bangladesh. SiteTandem and its service providers may process information in countries other than the user's own. Where applicable law requires safeguards for international processing, SiteTandem will use appropriate safeguards for the relevant service and circumstances.
Children
SiteTandem is intended for businesses, website publishers, agencies, and other professional users. It is not directed to children under 18.
Changes to this policy
SiteTandem may update this policy as the product, providers, or legal requirements change. The revised policy will be posted at this public URL, and the effective date at the top will be updated. Additional notice will be provided when required by law or appropriate for a material change.
Contact
For privacy questions or requests, email [email protected].