Privacy Policy

Cedar Stream Media
Effective date: September 7, 2026. This version replaces the policy dated February 8, 2024.

Cedar Stream Media is a web design, SEO and website hosting business in Sandpoint, Idaho, operated by Loren Whitney (“we”, “us”, “our”). This policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.

It covers five things:

  1. Our website, cedarstreammedia.com
  2. Website hosting and care for our clients
  3. The voice note recorder at cedarstreammedia.com/voice/
  4. Cedar Stream Social, our social media posting service for client websites
  5. Billing at billing.cedarstreammedia.com

If you have a question about any of it, email info@cedarstreammedia.com.

1. Our website

Contact and quote forms. When you fill in a form on our site, we receive what you type: usually your name, email address, phone number, business name and your message. Each submission is emailed to us and is also stored in the website’s database so that nothing is lost if an email goes astray. We use it to reply to you and to prepare a proposal. We keep submissions for as long as we may need to follow up, and delete them on request.

Analytics. We use Google Analytics to understand how people find and use the site. It records the pages you visit, how you arrived, your approximate location, and your device and browser, using cookies. We do not use it to identify you personally. You can block analytics cookies in your browser or with Google’s opt-out browser add-on. Google’s own privacy policy describes how Google handles this data.

Server and security logs. Our hosting provider (Hostinger) and Cloudflare, which sits in front of the site to protect and speed it up, keep short-lived logs of requests, including IP address and browser type, for security and performance. We look at these only when something goes wrong.

Cookies. Beyond the analytics cookies above, the site sets only the cookies WordPress needs to work, such as remembering that you are logged in if you have an account.

2. Website hosting and care for our clients

If we host or maintain your website, we hold:

  • Your account details: name, business name, email address, phone number, postal address, domain name, and your agreement with us.
  • Your website: its files, database, media, and daily backups kept on a rolling seven-day cycle.

Your website and everything in it belong to you. We access it only to maintain it and to deliver the services you have contracted for, and never for any other purpose. We do not share it with anyone except the providers we need to run the service: Hostinger for servers, Cloudflare for DNS, content delivery and security, and Google Workspace for email. You can ask for a complete export of your site at any time, and we provide it within three business days.

3. The voice note recorder at /voice/

The recorder lets clients and prospective clients answer a few questions out loud, so that we can write their website copy in their own words.

What we collect. Your name and business name, which are asked for above the record button; the audio recordings themselves; how long each one runs; which prompts you answered; and the date. Your IP address is stored only as a one-way hash used to limit abuse. The stored value cannot be turned back into your address.

Where it goes. Recordings are stored on our web server in a folder that cannot be read from the web, under random file names. When you finish a session, a summary is emailed to us. Only Cedar Stream Media staff with administrator access can listen to a recording. Recordings are never published, shared or used for anything except the work you asked us to do.

Transcription. We do not transcribe recordings automatically. When we choose to transcribe one, the audio is sent to ElevenLabs, a speech-to-text provider, which returns the text to us. ElevenLabs processes it under its own privacy policy and terms. The transcript is stored with the recording.

Retention. We keep recordings and transcripts while the project they support is active, and delete them when you ask. Incomplete uploads are deleted automatically after 24 hours.

The recorder does not ask for your email address and sends nothing to you.

4. Cedar Stream Social

4.1 What it is

Cedar Stream Social is a service for businesses whose websites we build or host. It has two parts: a plugin installed on your WordPress website, and a hosted service we run on Cloudflare, which we call the hub. The service drafts social media posts from your own website content, shows them to you for approval, and publishes the posts you approve to the Facebook Page, Instagram account or Google Business Profile listing you connect, at the time you choose. The service’s terms of service are published separately.

4.2 What the plugin reads from your website

To set up your business profile and to write posts, the plugin reads:

  • Your site name, tagline, time zone, logo and colour palette.
  • Business details you have already published on the site, such as your address, phone number, opening hours, map location and links to your social profiles, including the structured data your site publishes for search engines.
  • Your services and contact pages, and the titles and dates of your recent articles.
  • The full text of a published article, at the moment a post about that article is being drafted.
  • The images you choose for the photo pool, and the image chosen for a post.
  • Technical details: the site address, the administrator email address, the WordPress, PHP and plugin versions.
  • Usage counts: how many drafts were written and how many posts were published this month, and the estimated cost of drafting.

What it never reads. Visitor analytics, customer records, orders, form submissions, comments and user accounts never leave your site. The part of the plugin that selects content reads only published posts and pages. This is enforced by an automated test in our build, not by policy alone.

4.3 Your business profile

During setup the plugin proposes details it found on your site, and you confirm or correct them: what you do, the area you serve, facts about the business such as years in operation, words you never want used, and topic ideas. The confirmed profile is stored on your website and on the hub, and is sent to Anthropic as context whenever a post is drafted.

4.4 The posts

Drafts are written by an AI model, Anthropic’s Claude, from your article text and your profile. Every draft is stored on your website, which holds the master copy. When you approve a post, its text, its link and its chosen image are uploaded to the hub so that it can be published at the scheduled minute even if your website is offline at that moment.

The hub does not keep your article text or site content. It keeps only a word count and a fingerprint of each article, which is a hash used to avoid drafting the same article twice.

4.5 Connecting Facebook, Instagram and Google Business Profile

When you click Connect, you are sent to Facebook or Google to sign in and grant permission, and then you choose which Page, account or listing to connect on a screen hosted by our hub. Nobody chooses for you.

What we receive from Meta (Facebook and Instagram). An identifier that Meta creates for you for our app only; the list of Pages and professional Instagram accounts you manage, as identifiers and names; and access tokens that allow our service to post to the one you chose.

The permissions we ask Facebook for, and what each one is used for.

What we receive from Google. Where Google Business Profile is offered: the list of Business Profile listings you manage, and a token that allows our service to publish posts to the listing you choose, under the permission Google calls “manage your Business Profile listings”.

Where the tokens live. On the hub only, encrypted with a key that is never stored beside them. A token is never stored on your website, never included in your website’s backups, and never shown to you or to anyone else. A copy of the hub’s database on its own cannot reveal a token. Each night we check every token’s health with the provider, and the plugin tells you if a reconnection is needed.

4.6 Who we share data with

We share data only with the providers we need to run the service, and only the data each one needs.

To be precise about the two flows people ask about most: your article text goes to Anthropic only. Meta and Google receive only the finished posts you approve.

4.7 How long we keep things

4.8 Your choices

  • Disconnect a channel at any time from the plugin’s Settings screen. The token is revoked with the provider and deleted from the hub immediately, and posts scheduled for that channel are cancelled.
  • Remove our app in your Facebook or Google settings. Meta and Google notify us, and we delete the connection in the same way.
  • Ask Meta to have your data deleted. Meta sends us the request automatically. We delete every Facebook and Instagram connection linked to your Facebook account and give you a confirmation code and a status page. The steps are on our data deletion page.
  • Turn posting off with the Posting switch in Settings. Nothing publishes while it is off.
  • Export everything. A complete archive of your posts, approvals and delivery history is available from the plugin or by asking us.
  • Correct your profile at any time in the plugin, or ask us to correct anything else we hold.
  • Delete your account. Email us from the address on file. We confirm within two business days, offer an export first, and then delete everything listed in section 4.7.

4.9 Platform terms

We do not sell personal data, and we do not use anything received from Facebook, Instagram or Google for advertising, profiling, or any purpose other than providing this service to you. Our use of information received from Meta’s APIs is subject to Meta’s Platform Terms and Developer Policies. Cedar Stream Social’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Billing

Invoices and payments are handled at billing.cedarstreammedia.com through Stripe. We hold your name, business name, email address, billing address, what you have bought and your invoice history. Card details are entered on Stripe’s pages and never touch our servers; Stripe’s privacy policy covers them. We keep billing records for as long as tax and accounting rules require, which is seven years.

6. Security

We use HTTPS everywhere, keep access tokens encrypted, limit access to our systems to the people who need it, place Cloudflare in front of our sites, and take daily backups. No method of transmission or storage is completely secure, and we cannot promise absolute security, but we take reasonable and current measures to protect what you give us.

7. Children

Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us personal information, email us and we will delete it.

8. Changes to this policy

When we change this policy we post the new version here and update the effective date at the top. If a change materially affects how we handle Cedar Stream Social data, we also email the clients who use it before the change takes effect.

9. Contact

Cedar Stream Media
Sandpoint, Idaho
info@cedarstreammedia.com
https://cedarstreammedia.com/contact-us/