Webflow app · Privacy

Publicator AI for Webflow — Privacy & data handling

What the Publicator AI Webflow app accesses, what it stores and where, and how to have it deleted.

Last updated:

At a glance

This page explains how the Publicator AI app for Webflow (the Designer Extension and its connection to the Webflow Data API) handles data. It supplements the full Publicator AI privacy policy (in Hungarian), which covers your Publicator AI account, billing and the publicator.ai website.

  • The app requests only four Webflow permissions: sites:read, sites:write, cms:read and cms:write.
  • It creates and updates article items only in the CMS collection you choose, and it adds no code, scripts or tracking to your published site.
  • Your Webflow access token is stored encrypted on Publicator AI servers in the EU and is never sent to your browser.
  • Your site’s colors and fonts are read only when you click Detect appearance, and sent to Publicator AI only after you click Approve & sync.
  • Disconnect deletes the stored token and revokes it at Webflow.

Who is responsible

Publicator AI is operated by Bálint Barnabás Ádám EV., a sole proprietorship registered in Hungary, which is the data controller for the data described on this page.

  • Registered office: Géza fejedelem útja 8., 1029 Budapest, Hungary
  • Registration number: 58606801 · Tax number: 48302135-1-41
  • Contact: info@publicator.ai · Data protection requests can also be sent to jogi@publicator.ai

We process this data to provide the integration you asked for — publishing your Publicator AI articles to your Webflow site (GDPR Art. 6(1)(b), performance of a contract).

What the app accesses

The app requests only these Webflow OAuth scopes, for these purposes:

ScopeWhat it is used for
sites:readIdentify the Webflow site(s) you authorize (site ID, name and domain), so the right site is linked to your Publicator AI project; read its domain to build each published article’s live URL; and check the app’s own webhooks.
sites:writeRegister the app’s webhooks, so that unpublishing, archiving or deleting one of the app’s article items in Webflow is reflected in Publicator AI.
cms:readList your CMS collections so you can choose one, read the fields of the chosen collection, and — when you run the Categories & tags sync — read that collection’s items.
cms:writeCreate the article collection and any missing fields, and create, update, publish and delete the app’s own article items.

Inside the Webflow Designer, the app reads the ID of the site that is open, so it knows which site to link. It reads your site’s color and font Variables only when you click Detect appearance, shows you what it found, and sends them to Publicator AI only when you click Approve & sync.

The Designer Extension keeps your Publicator AI project API key in your browser’s local storage for that site, so you stay connected. Your publicator.ai password is never stored. The extension contains no analytics or tracking.

What we store and where

Everything below is stored in Publicator AI’s database, hosted by Supabase in the European Union (Ireland), and is tied to your Publicator AI project.

Webflow OAuth access token

Why
Lets our servers call the Webflow Data API for your site (publishing, collection setup, sync). Stored encrypted; never sent to your browser.
Kept until
Deleted immediately when you click Disconnect; otherwise kept while the site is connected, and deleted with your project.

Webflow site ID

Why
Records which Webflow site your Publicator AI project publishes to (with the granted scopes and timestamps).
Kept until
Unlinked from your project on Disconnect; deleted with your project.

Collection ID, collection name and field map

Why
Records which collection receives your articles and which of its fields hold the content, image, SEO and other values.
Kept until
Cleared on Disconnect; deleted with your project.

Webflow item IDs of published articles

Why
Stored with each article the app publishes (and its live URL where available), so a re-publish updates the existing item instead of creating a duplicate.
Kept until
Kept with your articles in Publicator AI until you delete them or your project.

Categories and tags

Why
Only when you run the Categories & tags sync: the category and tag names found on the chosen collection’s items, so new articles use taxonomies that exist on your site.
Kept until
Kept in your project’s category and tag list until you delete them or your project.

Brand colors and fonts

Why
Only after you click Approve & sync in the Appearance tab: the colors and fonts you approved are saved as your project’s brand settings, so articles match your site.
Kept until
Kept in your project’s brand settings (editable in the dashboard) until you change them or delete your project.

If you authorize several sites when you install the app, one Webflow authorization can cover all of them; an encrypted copy of the token is then stored for each authorized site, so you can link the one you want. Tokens of sites you never link are not used; uninstalling the app from those sites revokes them, and we delete them on request. Your article content itself is created in Publicator AI; the app only copies it into your Webflow collection.

What the app never accesses

  • Your Assets library
  • Site configuration, such as robots.txt, llms.txt, hosting or domain settings
  • Custom code
  • Forms and form submissions
  • Pages (other than the CMS items in the collection you choose)
  • Your Webflow user profile (name or email address)
  • The items of collections other than the one you choose

The app adds no code or scripts to your published site, and it never publishes your whole site — it publishes only its own article items.

Retention & deletion

  • Disconnect — in the app, or Kapcsolat bontása (Disconnect) on the Integrációk (Integrations) page of the Hungarian-language publicator.ai dashboard — deletes the stored token and revokes it at Webflow, and clears the site link, collection and field settings. If another of your connected Webflow sites still uses the same authorization, the token is not revoked yet; only this site’s copy is deleted. Disconnecting in the app also removes the API key from that browser. A minimal record that the site ID was disconnected (without a token and without a link to your project) may remain so the site can be connected again; email us if you want it removed.
  • Uninstalling the app in Webflow (Site settings → Apps & integrations) removes its access to your site, and the stored token stops working — we delete it automatically the next time the app tries to use it. To delete it from our servers right away, click Disconnect before uninstalling, or afterwards Kapcsolat bontása (Disconnect) on the Integrációk page — or email info@publicator.ai and we delete it.
  • Deleting your Publicator AI project or account permanently deletes all of the data above after the 30-day grace period described in the full privacy policy.
  • Articles already published stay on your Webflow site as CMS items in every case — you can delete them in Webflow at any time.

Security

  • Webflow OAuth tokens are encrypted at rest with AES-256-GCM, are used only by our backend, and are never sent to the browser — neither to the Designer Extension nor to the publicator.ai dashboard.
  • All traffic uses HTTPS. The token store can be read only by our backend.
  • Each authorization is bound to your Publicator AI project with a signed, short-lived state. A connection link only works when it is opened from the Publicator AI app in the Webflow Designer (or from the publicator.ai dashboard), and only in the browser where it was started.
  • While you connect a site, our API sets short-lived, strictly necessary HttpOnly security cookies (pub_wf_flow, up to 15 minutes, and after an install pub_wf_claim, up to 30 minutes). They only tie the authorization to your browser and contain no personal data.
  • Webhook notifications from Webflow are accepted only with a valid Webflow signature.

Sub-processors

The following providers process data for the Webflow integration. The complete list is in the full privacy policy.

  • Supabase, Inc. — database, authentication and backend functions; stores and processes all data described above. EU (Ireland).
  • Make.com (Celonis SE) — workflow automation that triggers scheduled publishing; it handles article content and IDs, never your Webflow token. EU.
  • Hostinger International Ltd. — hosts the publicator.ai website, including these pages. EU (Cyprus).
  • AI providers (OpenAI, Anthropic, Google Gemini) — write your articles. They may receive your synced category and tag names and your approved brand settings as input, never your Webflow token. USA, under the EU–US Data Privacy Framework with Standard Contractual Clauses as a fallback.

Your rights & contact

You can ask for access to, correction or deletion of your data, restriction of or objection to its processing, and data portability. Write to info@publicator.ai (or jogi@publicator.ai); we reply within 30 days. You can also lodge a complaint with the Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH — www.naih.hu).

Full privacy policy (in Hungarian): publicator.ai/privacy-policy. Setup and troubleshooting: Publicator AI for Webflow documentation.

info@publicator.ai