Content Engine Grader Privacy Policy
Effective date: August 20, 2026
Last updated: August 20, 2026
Policy URL: https://grader-api.goflydragon.com/privacy
Content Engine Grader (the “Extension”) is provided by FlyDragon, Inc. (“FlyDragon,” “we,” “us,” or “our”). This Privacy Policy applies specifically to the Extension and its grading API. FlyDragon’s websites are covered by FlyDragon’s separate website privacy policy.
FlyDragon, Inc.
235 Knollwood Way
Manchester, NH 03102
United States
hello@goflydragon.com
+1 (505) 958-7980
1. What the Extension does
When you ask it to, Content Engine Grader reads the current public webpage and creates a limited snapshot of its article content and structure. It proposes a target keyword for you to review or change. After you confirm the keyword, FlyDragon’s grading API compares the page with current public Google results and returns a score, checklist and recommendations.
The initial release uses a fixed United States, English-language, desktop-search benchmark. DataForSEO supplies the public search result set and content from selected public comparison pages. OpenAI helps classify the submitted page and limited comparison-page content. FlyDragon’s server-side rules calculate the final score.
The Extension does not continuously monitor your browsing. During every newly issued access session, it requires you to review the in-product notice and affirmatively consent before you can grade a page. It then accesses a page only after you click the Extension on that tab and choose to grade it. It blocks obvious loopback and private-network pages and warns you not to grade confidential, logged-in or unpublished material, but it cannot reliably identify the access status of every ordinary HTTPS page.
2. Information we handle
Access, installation and security information
We handle:
- the email address you enter, stored as a normalized but unverified label;
- a random installation identifier created and stored in the Extension;
- an HMAC-protected representation of that installation identifier in the application database;
- the network address from which a request reaches the API and an HMAC-protected representation of that address for security controls;
- a random access token stored in
chrome.storage.localand a cryptographic hash of that token on the server; - access-token creation, expiry, last-use and revocation times;
- access issuance, successful-grade and provider-attempt records used for limits and abuse controls; and
- security-ban records keyed to an HMAC-protected email label, installation identifier or network address, together with a reason, time and optional expiry.
We do not send a verification code or other message to the email address. Entering an address does not prove that you own it and does not create a verified identity. We use it only as a service-access, usage and abuse-control label. We do not add it to a marketing list or use it for marketing.
The application database does not store the raw installation identifier, raw access token or raw network address. A network address necessarily reaches DigitalOcean and RunCloud infrastructure so the request can be delivered and may appear in restricted infrastructure security logs as described below.
Information from a page you choose to grade
The Extension may send the following allow-listed information from the page you choose:
- the page origin and path, with query strings, fragments, embedded usernames and passwords removed;
- the page title, language, H1 and other headings, meta description, canonical metadata and selected Open Graph metadata;
- visible article text, introductory copy, list items, table text, figure captions and alternative text;
- link destinations, labels, nearby context, category and whether a link is internal or external;
- author names and publication or update dates exposed in the page or supported structured data; and
- diagnostic counts such as words, paragraphs, headings, lists, tables, figures and links.
The snapshot is size-limited and is designed to exclude raw HTML, form fields and values, passwords, cookies, browser storage, request headers, hidden editor content and pages other than the page you explicitly grade. It does not collect your general browser history. Query strings and URL fragments are removed before transmission.
Search and comparison information
The service also handles:
- the proposed target keyword, any correction you make and the keyword you confirm;
- the fixed United States, English, desktop-search settings and capture time;
- public Google result titles, snippets, ranks, domains and URLs; and
- headings, text, word count and availability signals from up to ten candidate public result pages while the service looks for suitable comparisons; and
- the three suitable public comparison pages, when three are available, that are used in the final benchmark.
DataForSEO receives the confirmed keyword and fixed search settings to obtain public Google results. It may also receive up to ten candidate public result URLs so the service can retrieve those pages and select three suitable comparisons. DataForSEO does not receive the content snapshot from the page you chose to grade.
Local Extension information
The Extension stores the following in chrome.storage.local, not in cookies:
- the random installation identifier;
- the active access token, its expiry and the email label you entered; and
- a versioned, session-scoped record that you accepted the page-processing notice for the current access session.
Signing out removes the local access record and its processing acknowledgement and asks the API to revoke the server token. The Extension also removes that acknowledgement when the session expires or the API rejects it as unauthorized. A replacement access session—including one issued for the same installation, the same email label or a changed email label—does not inherit the prior session’s acknowledgement. You must review and accept the notice again. Clearing Extension storage or uninstalling the Extension removes all of these local items.
Rewrite prompt and clipboard
When a result qualifies for rewrite help and you select Copy full rewrite prompt, the Extension builds the prompt locally from the current snapshot and the recommendations already returned to you. It writes that prompt to your clipboard only after your click. FlyDragon does not receive a second copy, store the copied prompt or control the AI service into which you later paste it. The privacy terms of that chosen service apply after you paste it there.
What the FlyDragon application database does not store
FlyDragon’s application database does not store the raw page snapshot, confirmed keyword, selected comparison-page content, returned grade, recommendations or locally generated rewrite prompt. Short-lived in-memory caches may hold DataForSEO search results and parsed candidate public-page content, and may hold a completed grade and its recommendations so a safe retry does not repeat provider work or use another free run. These caches last for up to 15 minutes, are not written to SQLite and are cleared on process restart.
3. How we use information
We use the information described above only to:
- provide the content grade you request;
- infer and let you confirm a target keyword;
- compare the submitted page with relevant public search results;
- generate the checklist, evidence and recommendations;
- maintain installation-scoped access and enforce the free-use allowance;
- rate-limit provider work and control OpenAI and DataForSEO spending;
- identify, investigate, block and document spam, fraud or abuse;
- secure, diagnose and maintain the Extension and grading API; and
- comply with law or protect users, FlyDragon and others where necessary.
We do not sell Extension user data. We do not use or transfer the email label, page content, page URL, keyword or grading information for personalized advertising, retargeting, lending, credit decisions or unrelated profiling.
4. When information is shared
We share information only where necessary to provide and protect the Extension, comply with law or complete a permitted corporate transaction.
DigitalOcean and RunCloud
FlyDragon hosts the grading API and application database on a DigitalOcean, LLC server in the United States and uses RunCloud Sdn. Bhd. to administer that server, its NGINX reverse proxy, certificates, process supervision and backups. These providers may process the request, network, page-snapshot, access and technical information described above while providing infrastructure services. FlyDragon configures its application and reverse proxy not to log page request bodies or authorization headers. DigitalOcean and RunCloud may maintain restricted infrastructure and security records under their own service controls. See DigitalOcean’s privacy policy and RunCloud’s privacy policy.
DataForSEO
DataForSEO OU receives the confirmed keyword, fixed United States/English/desktop settings and up to ten candidate public result URLs. It returns public Google result data and candidate public-page content to FlyDragon so the service can select three suitable comparisons. It does not receive the snapshot of the page you chose to grade. DataForSEO’s general privacy policy states that API task data may be stored for up to 365 days; some individual live endpoints describe shorter or no result storage. FlyDragon therefore discloses the conservative maximum. See DataForSEO’s privacy policy and API results-storage documentation.
OpenAI
FlyDragon sends the allow-listed current-page snapshot, grading instructions and limited content from selected public comparison pages to the OpenAI Responses API. The request disables tools and sets store: false. OpenAI is not asked to browse URLs or execute instructions found inside page content. It returns structured classifications; FlyDragon’s private server-side rules determine the final score.
OpenAI states that API data is not used to train or improve its models unless the customer opts in. Under standard API controls, abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days. See OpenAI’s API data controls.
Other permitted disclosures
We may disclose information:
- to professional advisers under confidentiality obligations;
- where reasonably necessary to comply with law or valid legal process;
- where necessary to investigate or prevent malware, spam, phishing, fraud or other abuse; or
- as part of a merger, acquisition, financing, reorganization or sale of assets, subject to applicable safeguards and any notice or consent required by Chrome policy or law.
FlyDragon staff and contractors may not read submitted page content except with your specific consent for support, where necessary for security or abuse investigation, to comply with law, or after information has been aggregated and anonymized for lawful internal operations.
5. Retention
The application runs database cleanup at startup and every six hours. Retention is as follows:
| Information | Retention |
|---|---|
| Raw page snapshot, confirmed keyword, returned grade and rewrite prompt in FlyDragon’s application | Processed for the requested operation in memory and not written to the application database. Provider and infrastructure handling is described separately in this policy. |
| In-memory search, parsed candidate-page, completed-grade and recommendation caches | Up to 15 minutes; cleared on process restart and not included in SQLite backups. A completed grade is cached only to make a retry safe without repeating provider work or using another free run. |
| Email label and installation-scoped principal | Retained while needed to provide access and administer abuse controls, unless removed earlier after a verified deletion request. An inactive principal is ordinarily deleted after approximately one year by the next scheduled cleanup. |
| Active server access token record | The token normally expires after 30 days. Revoked or expired rows are rejected immediately and are removed by scheduled cleanup after the applicable cleanup window. |
| Local installation identifier, access record and notice acknowledgement | The installation identifier remains until Extension storage is cleared or the Extension is uninstalled. The access record remains until sign-out, expiry, unauthorized rejection, clearing storage or uninstall. The notice acknowledgement is limited to the current access session and is removed on sign-out, expiry or unauthorized rejection; it is not inherited by a replacement session. A changed notice version also causes the acknowledgement to be ignored. |
| Access-issuance, successful-grade and provider-attempt metadata | Needed for rolling usage, provider-spend and abuse controls; ordinarily deleted after becoming 48 hours old by the next six-hour cleanup. |
| Security bans | An indefinite ban is retained until FlyDragon revokes it or no longer needs it for security. A temporary ban is retained until it expires. Revoked or expired ban records may remain for up to a further 30 days for security administration. Ban subject identifiers are HMAC-protected. |
| OpenAI input and output | store: false disables Responses API application-state storage for the request. Under standard controls, OpenAI may retain abuse-monitoring logs containing input or output for up to 30 days, or longer if legally required. |
| DataForSEO API task data | Up to 365 days under DataForSEO’s general privacy policy. Individual endpoint documentation may provide shorter result-storage periods. |
| FlyDragon-controlled access and security logs | No page request bodies or authorization headers are logged. Other restricted access and security metadata is retained for no more than 30 days. |
| Restricted database backups | If enabled for production, rolling retention is no more than 30 days. Data removed from the active system may remain in an isolated backup until that backup expires. Backups are access-restricted, are not used for ordinary operations and are not enabled until their storage protection and restore process have been verified. |
FlyDragon uses a manual operator process for verified access and deletion requests. Where we must preserve limited HMAC-protected security-ban information to prevent ongoing abuse or comply with law, we will retain only what is necessary and explain that exception when legally permitted.
6. Security
FlyDragon uses safeguards designed to protect Extension information, including:
- HTTPS for production transmission;
- narrowly scoped Chrome permissions and temporary access to the user-selected tab;
- an allow-listed, size-limited page snapshot rather than raw HTML;
- exact production Extension-origin restrictions;
- server-only OpenAI and DataForSEO credentials;
- HMAC protection for installation and network-address identifiers used in security controls;
- cryptographic hashing of server-side access tokens;
- request-size, issuance, provider-attempt, concurrency and rolling-spend limits;
- installation-, email-label- and network-address-based ban controls;
- restricted database and backup access; and
- production monitoring that does not record page request bodies or authorization headers.
No transmission or storage system is completely secure. If you believe the Extension has a security or privacy issue, contact hello@goflydragon.com.
7. Your choices and rights
- Choose whether to grade: every newly issued access session requires a fresh review and acceptance of the notice. The Extension does not create or send the page snapshot until you accept it for that session and start the grading flow.
- Review the keyword: you can review or change the proposed target keyword before the live-search comparison.
- Sign out: signing out clears the local access token and asks the API to revoke the server token.
- Remove local data: you can clear the Extension’s storage or uninstall it in Chrome.
- Access, correction or deletion: you may ask to access, correct or delete information associated with the Extension by emailing hello@goflydragon.com. The account menu shows a copyable Support ID that helps us locate the correct installation record. Because the email label is not verified, we may request that Support ID or other installation-specific information reasonably necessary to verify that the request is legitimate.
- Complain: depending on where you live, you may have additional privacy rights and may contact your local privacy regulator.
FlyDragon aims to acknowledge a privacy request within 10 business days and complete a valid verified deletion request within 30 calendar days, subject to legal and security exceptions. Uninstalling the Extension removes local data but does not itself notify FlyDragon to delete server-side records.
8. No marketing use
The email label required to access Content Engine Grader is not subscribed to marketing and is not used for marketing. If FlyDragon later offers a marketing signup, it will be separate, optional and unchecked. Declining it will not reduce access to the grader.
The Extension includes fixed links to FlyDragon’s website, including a Speak to FlyDragon link. Those links may include campaign parameters identifying Content Engine Grader as the source, but they do not append your email label, page content, keyword, grade or access token. Once you visit FlyDragon’s website, FlyDragon’s separate website privacy policy applies.
9. Chrome Web Store Limited Use
Our use and transfer of information received from Google Chrome APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
We limit Extension data to the disclosed, user-facing content-grading purpose and the security and operational work necessary to provide it. We do not sell it, use it for personalized advertising or lending, or transfer it for unrelated purposes.
10. International processing
FlyDragon is based in the United States. The API and application database are hosted on a DigitalOcean server in the United States and administered through RunCloud. OpenAI, DataForSEO and infrastructure subprocessors may process information in the United States or other countries where they operate. Where applicable law requires a transfer safeguard, FlyDragon relies on the relevant provider’s contractual commitments and recognized mechanisms, such as standard contractual clauses.
11. Children
Content Engine Grader is a business content tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us and we will take appropriate steps to remove it.
12. Changes to this policy
We may update this policy when the Extension, its providers or legal requirements change. We will update the date above and provide additional notice or obtain new consent before materially expanding how the Extension collects or uses information where required.
13. Contact us
Questions, security reports and privacy requests may be sent to:
FlyDragon, Inc.
235 Knollwood Way
Manchester, NH 03102
United States
hello@goflydragon.com
+1 (505) 958-7980