Legal · Updated 2026-09-02

Privacy Policy

We collect the minimum data needed to run audits, bill credits, and send notifications.

What we collect

Account data (name, email, avatar) via Clerk. Audit inputs (domain, competitors, keywords) you submit. Operational metadata (job timestamps, error categories). Payment metadata from Stripe or Digistore24 (no card numbers stored).

How we use it

To deliver your audits, manage credits, and send transactional notifications. We do not use customer audit content to train models.

Cookies

Strictly necessary cookies for authentication. Optional analytics cookies (GA4) are off by default and only enabled with consent.

Subprocessors

Clerk (auth), Stripe and Digistore24 (payments), AWS / Cloudflare (storage), Anthropic (audit pipeline LLM), Resend (email), Google (Search Console and Analytics APIs, only when you connect them), plus the SEO data providers named in your report. Full list available on request.

Google user data

The Visibility feature lets you connect your own Google accounts to overlay your first-party data on our modeled estimates. Connecting is optional and you initiate it. When you connect, we request read-only access to:

  • Google Analytics (analytics.readonly) — we list your GA4 properties so you can pick one, then read aggregate sessions, users, and conversions via the GA4 Data API.
  • Google Search Console (webmasters.readonly) — we list your verified sites and read clicks, impressions, and positions.

We use this data only to display your own metrics back to you inside the Visibility dashboard. We never write to, modify, sell, or share it, use it for advertising, or allow humans to read it except with your explicit consent for support, or as required for security or law. OAuth tokens are stored encrypted at rest. You can disconnect at any time from Visibility → Settings → Connections, or revoke access at myaccount.google.com/permissions; on disconnect we delete the stored tokens.

AISEOTool's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

We apply the following safeguards to all customer data, and to sensitive Google user data in particular:

  • Encryption in transit — all data moves over TLS (HTTPS). We never transmit your data over unencrypted connections.
  • Encryption at rest — Google OAuth access and refresh tokens are sealed with authenticated AES-256-GCM envelope encryption before they are written to the database; keys are held outside the database and are not accessible to the application's read paths.
  • Least-privilege access — we request read-only Google scopes only, and no employee or contractor can access your connected Google data except with your explicit consent for support, or as required for security or by law. Access is logged.
  • Retention and deletion — OAuth tokens are kept only while a connection is active; on disconnect we delete the stored tokens, which stops all further access to your Google data. Aggregate metrics already shown in your dashboard are retained for trend history and are deleted on an account-deletion request. You can also revoke access directly at myaccount.google.com/permissions.
  • Isolation — Google user data is stored per project and used only to render your own metrics back to you; it is never pooled across customers, sold, shared, or used to train models.

Your rights

Access, export, or delete your data: [email protected]. We respond within 30 days.