Legal
Privacy policy
What Topical Map stores, where it goes and how to delete it. This describes the hosted service at topicalmap.app as it works today.
Last updated: 8 October 2026
Operated by Nut Hub
What we store
Your account
Your email address, an optional name, and your password stored only as a salted scrypt hash. We also store which organization you belong to and your sign-in sessions.
Your projects
Brand details, the brand documents you upload (split into passages so pages can quote them), personas, research results, keyword clusters, topical maps, briefs, pages and their review history.
Provider settings
The API keys you add for search-data and AI providers, and the application password for a WordPress site you connect. They are encrypted at rest with AES-256-GCM and never sent back to your browser; the app shows only the last four characters.
Usage records
A log of the tasks you run and their estimated credit cost. We hold no payment details, because nothing is billed.
All of this is kept in a PostgreSQL database operated for the service.
What leaves the service, and when
Data is sent to a third party only when you run a task that needs it, and only to the services you chose:
Search-data providers you connect
DataForSEO, Serper or SerpApi receive the search queries for that task. The free built-in tool sends queries to Google and YouTube autocomplete.
AI providers you connect
OpenAI, Anthropic, Google or the OpenAI-compatible endpoint you set receive the instructions for the task, the brief, and the passages from your brand documents that the page needs. What they keep is governed by your agreement with them.
Public knowledge bases
Service and place names may be looked up on Wikidata to identify them precisely. These lookups contain no personal data.
Your WordPress site
Approved pages you choose to publish are sent to the site you connected.
Cookies and tracking
We set a session cookie (tm_session, HttpOnly) to keep you signed in and a cookie that remembers whether you read the site in Arabic or English. Your browser also keeps interface preferences such as the colour theme.
There are no advertising cookies, tracking pixels or third-party analytics on the site or in the app.
Who can see your data
Members of your organization can see its projects. The people who run the service can access stored data when they need to operate or repair it.
We do not sell your data, share it for advertising, or use your content to train models.
Keeping and deleting data
We keep your data while your account exists. You can delete a project from the project switcher, which removes its records. To delete your whole account and organization, email us from the address you signed up with.
Data you sent to an AI or search-data provider is held under that provider’s own policy; ask them to delete it.
Questions
For privacy questions or a data request, email support@topicalmap.app.