Last updated: 26 August 2026
This Policy explains how SEOforGPT ("SEOforGPT", "we", "us" or "our") processes personal data when you visit seoforgpt.io, use our AI visibility and content platform (the "Service"), connect another service or MCP client, or contact us.
We are the controller for account, billing, website, support and business-operation data. Where a business customer submits personal data for us to process solely on its behalf, that customer is the controller and SEOforGPT acts as its processor.
Contact: hey@seoforgpt.io.
We receive data from you, your use of the Service, services you connect and public sources you ask us to analyze.
| Category | What it includes |
|---|---|
| Account and billing | Name, email, authentication information, company, subscription and limited payment details |
| Customer content | Prompts, text, files, images, brand and competitor information, website content, search queries and generated outputs |
| Connections and MCP | Connected-service profile and authorization data, permissions, site identifiers, tool inputs and outputs, and connection status |
| Usage and device | IP address, browser and device data, referral URL, pages viewed, interactions, timestamps and diagnostic information |
| Analytics and marketing | Analytics events, session replay, advertising events and campaign information, subject to your choices |
| Communications | Support requests, feedback and other correspondence |
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provide accounts, AI features, MCP tools, connected services, publishing and support | Contract performance Art. 6(1)(b) |
| Process payments and invoices | Contract performance Art. 6(1)(b); Legal obligation Art. 6(1)(c) |
| Secure, troubleshoot and improve the Service; prevent fraud and abuse | Legitimate interest Art. 6(1)(f) |
| Analytics and marketing | Consent Art. 6(1)(a), or legitimate interest Art. 6(1)(f) where permitted |
| Meet legal obligations and establish, exercise or defend legal claims | Legal obligation Art. 6(1)(c); legitimate interest Art. 6(1)(f) |
Account, billing and connection data is required to provide the relevant Service. Other data is optional, but some features may not work without it. If we rely on your consent, you may withdraw it at any time without affecting earlier processing.
We use essential cookies to operate and secure the Service. With your consent where required, we also use analytics and marketing technologies. You can manage these through our consent banner and your browser settings.
We retain personal data only as long as needed for the purposes above:
OAuth credentials are time-limited; refresh authorization lasts up to 30 days unless renewed. Some expired OAuth and registered-client metadata has no fixed automatic deletion period and remains protected until removed through the connection or account lifecycle or operational cleanup.
These periods may be extended where required by law, security, fraud prevention or legal claims. Service providers may apply their own retention terms. Under Anthropic's standard commercial API terms, API inputs and outputs are ordinarily deleted within 30 days, subject to applicable terms and exceptions. Claude chat retention is controlled by your Claude plan and settings.
When you connect Claude or another MCP client, the client sends user-approved tool inputs to SEOforGPT and receives tool results. The client provider separately processes the surrounding conversation under your relationship with that provider.
We do not intentionally retain a separate copy of the surrounding chat. Tool calls may access or change ordinary SEOforGPT account records, which follow the customer-content retention period above.
We use protected authorization information only to provide the connection you request. Operational logs contain limited diagnostic data and do not intentionally include raw credentials or full tool payloads. Disconnecting a service stops future access but does not automatically delete content already stored in your SEOforGPT account or at a destination you selected.
We do not sell personal data. A provider receives data only where needed for the relevant service or feature.
| Recipient | Data and purpose | When |
|---|---|---|
| Netlify and Supabase | Account, content and usage data needed to host, operate and secure the Service | Core Service infrastructure |
| Anthropic API | Relevant prompts, instructions and customer content for AI-assisted content generation and review | Feature-dependent |
| Claude or another MCP client you select | Tool inputs and outputs; the client provider separately processes your conversation | At your direction |
| OpenAI, Perplexity and Google Gemini | Prompts, relevant platform content, brand and competitor information, public search context and generated responses for AI analysis, visibility testing, metadata and optional research | Feature-dependent; Perplexity is optional |
| Firecrawl and Brave Search | Public URLs, website content and search queries used for crawling, research and discovery | Feature-dependent |
| Sentry, PostHog, Reddit advertising and Brandfetch | Error and performance telemetry, user/account identifiers, analytics events, sampled session replay, advertising events, and brand names or domains used to retrieve logos | As applicable to the website or feature |
| Stripe, Resend and Slack | Billing and subscription data, email address and message content, and limited registration, support or billing notifications | As needed for these services |
| Google, GitHub, Google Search Console and Reddit | OAuth profile and authorization data, Search Console properties and performance data, or Reddit content and authorized posting data | When you select the connection |
| WordPress.com, Wix, Webflow and Notion | Connection identifiers, credentials and content you instruct us to publish or retrieve | When you select the destination |
| Your self-hosted WordPress or Ghost site, or configured webhook destination | Credentials and generated content sent to the destination you control or designate | At your direction |
We may also disclose information to professional advisers, transaction parties or authorities where legally necessary. Some recipients act as our processors; others process data under your relationship with them or at your direction. Their own terms and privacy notices may apply.
Some recipients process data outside the European Economic Area. Where GDPR transfer rules apply, we rely on the mechanism applicable to the recipient and service, such as an adequacy decision or Standard Contractual Clauses. Contact us for information about applicable safeguards.
We use appropriate technical and organisational safeguards designed to protect personal data. No service can guarantee absolute security.
Subject to conditions and limitations under the GDPR, you have the right to:
To exercise your rights, email hey@seoforgpt.io.
The Service is not directed to children under 16. We do not use personal data for decisions producing legal or similarly significant effects based solely on automated processing.
We may update this Policy by posting a revised version here. For material changes, we will provide additional notice where appropriate. Questions and privacy requests may be sent to hey@seoforgpt.io.
Version 1.1 – Effective 26 August 2026