Privacy Policy
Last updated: June 12, 2026
1. What we collect
- Account data — your email address and password (stored as a hash by our auth provider), plus workspace settings.
- Site data — pages we crawl from websites you add (titles, headings, copy excerpts, technical signals), generated brand profiles, recommendations, and the changes you approve.
- Search Console data — query and performance rows for your verified properties, only after you connect Google Search Console.
- Billing data — handled by Stripe; we store your plan, subscription status, and Stripe customer ID, never card numbers.
- Waitlist emails — if you join the briefing list, just your email and where you signed up from.
2. How we use it
To run the product: crawl and analyze your sites, generate brand-grounded recommendations, stage the changes you approve, and measure outcomes afterward. We also use aggregate, de-identified usage to improve recommendation quality. We do not sell personal data, and we do not use your private data to advertise to anyone.
3. Google user data (Limited Use)
When you connect Google Search Console, we access your property's search performance data via Google's API using OAuth tokens you grant. That data is used solely to ground your site's recommendations and to measure the before/after impact of changes you ship — features visible to you in your workspace. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never let humans read it except for debugging with your consent, security, or legal compliance. Disconnecting Search Console revokes our access; you can also revoke it from your Google account settings.
4. Who processes data for us
We run on a small set of infrastructure providers, each used for a specific job:
- Supabase — database, authentication, and file storage
- Vercel — application hosting
- Inngest — background job queue
- Stripe — payments and subscription management
- Anthropic (Claude) — AI analysis and draft generation
- Voyage AI — text embeddings for semantic retrieval
- DataForSEO — search results and keyword data
- Google — Search Console API, only when you connect it
Connected-service tokens (GitHub, WordPress, Linear, Google) are stored encrypted at rest and used only to provide the features you invoke.
5. Cookies
We use first-party cookies for authentication and session management only — no third-party advertising or cross-site tracking cookies.
6. Retention and deletion
Workspace data is retained while your account is active. Deleting a site removes its pages, recommendations, and intelligence data. If you delete your account or ask us to, we delete or de-identify your data within 30 days, except billing records we're required to keep. Shared research caches store no personal accounts — only public-web content keyed by source.
7. Security
All traffic is encrypted in transit (TLS); data is encrypted at rest by our providers; integration tokens are additionally encrypted at the application layer; and every database table enforces row-level security so workspaces are isolated from each other.
8. Your rights
You can access, correct, export, or delete your data — most of it directly in the app, and anything else by emailing us. Depending on where you live (e.g. EU/EEA, UK, California), you may have additional statutory rights; we honor reasonable requests regardless of geography.
9. Changes and contact
We'll update this policy as the service evolves and note the date above; material changes get an in-app or email notice. Questions or requests: support@seoperator.ai.