Privacy Policy

    Last updated: 26 August 2026

    1. About This Policy

    This Policy explains how SEOforGPT ("SEOforGPT", "we", "us" or "our") processes personal data when you visit seoforgpt.io, use our AI visibility and content platform (the "Service"), connect another service or MCP client, or contact us.

    We are the controller for account, billing, website, support and business-operation data. Where a business customer submits personal data for us to process solely on its behalf, that customer is the controller and SEOforGPT acts as its processor.

    Contact: hey@seoforgpt.io.

    2. Data We Process

    We receive data from you, your use of the Service, services you connect and public sources you ask us to analyze.

    CategoryWhat it includes
    Account and billingName, email, authentication information, company, subscription and limited payment details
    Customer contentPrompts, text, files, images, brand and competitor information, website content, search queries and generated outputs
    Connections and MCPConnected-service profile and authorization data, permissions, site identifiers, tool inputs and outputs, and connection status
    Usage and deviceIP address, browser and device data, referral URL, pages viewed, interactions, timestamps and diagnostic information
    Analytics and marketingAnalytics events, session replay, advertising events and campaign information, subject to your choices
    CommunicationsSupport requests, feedback and other correspondence

    3. Why We Process Data

    PurposeLegal basis (Art. 6 GDPR)
    Provide accounts, AI features, MCP tools, connected services, publishing and supportContract performance Art. 6(1)(b)
    Process payments and invoicesContract performance Art. 6(1)(b); Legal obligation Art. 6(1)(c)
    Secure, troubleshoot and improve the Service; prevent fraud and abuseLegitimate interest Art. 6(1)(f)
    Analytics and marketingConsent Art. 6(1)(a), or legitimate interest Art. 6(1)(f) where permitted
    Meet legal obligations and establish, exercise or defend legal claimsLegal obligation Art. 6(1)(c); legitimate interest Art. 6(1)(f)

    Account, billing and connection data is required to provide the relevant Service. Other data is optional, but some features may not work without it. If we rely on your consent, you may withdraw it at any time without affecting earlier processing.

    4. Cookies

    We use essential cookies to operate and secure the Service. With your consent where required, we also use analytics and marketing technologies. You can manage these through our consent banner and your browser settings.

    5. Retention

    We retain personal data only as long as needed for the purposes above:

    • Account and customer content: while the account is active and up to 12 months after closure;
    • Financial records: 7 years;
    • Support communications: 24 months;
    • Raw crawler and AI-referral events: 90 days; account-level aggregates may remain for the account lifetime;
    • MCP and OAuth operational logs: up to 7 days;
    • Connected-service authorization: until revoked, disconnected or no longer needed;
    • Backups: up to 30 days.

    OAuth credentials are time-limited; refresh authorization lasts up to 30 days unless renewed. Some expired OAuth and registered-client metadata has no fixed automatic deletion period and remains protected until removed through the connection or account lifecycle or operational cleanup.

    These periods may be extended where required by law, security, fraud prevention or legal claims. Service providers may apply their own retention terms. Under Anthropic's standard commercial API terms, API inputs and outputs are ordinarily deleted within 30 days, subject to applicable terms and exceptions. Claude chat retention is controlled by your Claude plan and settings.

    6. MCP and Connected Services

    When you connect Claude or another MCP client, the client sends user-approved tool inputs to SEOforGPT and receives tool results. The client provider separately processes the surrounding conversation under your relationship with that provider.

    We do not intentionally retain a separate copy of the surrounding chat. Tool calls may access or change ordinary SEOforGPT account records, which follow the customer-content retention period above.

    We use protected authorization information only to provide the connection you request. Operational logs contain limited diagnostic data and do not intentionally include raw credentials or full tool payloads. Disconnecting a service stops future access but does not automatically delete content already stored in your SEOforGPT account or at a destination you selected.

    7. Recipients

    We do not sell personal data. A provider receives data only where needed for the relevant service or feature.

    RecipientData and purposeWhen
    Netlify and SupabaseAccount, content and usage data needed to host, operate and secure the ServiceCore Service infrastructure
    Anthropic APIRelevant prompts, instructions and customer content for AI-assisted content generation and reviewFeature-dependent
    Claude or another MCP client you selectTool inputs and outputs; the client provider separately processes your conversationAt your direction
    OpenAI, Perplexity and Google GeminiPrompts, relevant platform content, brand and competitor information, public search context and generated responses for AI analysis, visibility testing, metadata and optional researchFeature-dependent; Perplexity is optional
    Firecrawl and Brave SearchPublic URLs, website content and search queries used for crawling, research and discoveryFeature-dependent
    Sentry, PostHog, Reddit advertising and BrandfetchError and performance telemetry, user/account identifiers, analytics events, sampled session replay, advertising events, and brand names or domains used to retrieve logosAs applicable to the website or feature
    Stripe, Resend and SlackBilling and subscription data, email address and message content, and limited registration, support or billing notificationsAs needed for these services
    Google, GitHub, Google Search Console and RedditOAuth profile and authorization data, Search Console properties and performance data, or Reddit content and authorized posting dataWhen you select the connection
    WordPress.com, Wix, Webflow and NotionConnection identifiers, credentials and content you instruct us to publish or retrieveWhen you select the destination
    Your self-hosted WordPress or Ghost site, or configured webhook destinationCredentials and generated content sent to the destination you control or designateAt your direction

    We may also disclose information to professional advisers, transaction parties or authorities where legally necessary. Some recipients act as our processors; others process data under your relationship with them or at your direction. Their own terms and privacy notices may apply.

    8. International Transfers

    Some recipients process data outside the European Economic Area. Where GDPR transfer rules apply, we rely on the mechanism applicable to the recipient and service, such as an adequacy decision or Standard Contractual Clauses. Contact us for information about applicable safeguards.

    9. Security

    We use appropriate technical and organisational safeguards designed to protect personal data. No service can guarantee absolute security.

    10. Your Rights

    Subject to conditions and limitations under the GDPR, you have the right to:

    1. Access your personal data;
    2. Rectify inaccurate or incomplete data;
    3. Erase data ("right to be forgotten");
    4. Restrict processing;
    5. Object to processing based on legitimate interests or direct marketing;
    6. Data portability (receive data in machine‑readable format);
    7. Withdraw consent at any time;
    8. Lodge a complaint with your competent data protection authority.

    To exercise your rights, email hey@seoforgpt.io.

    11. Other Information

    The Service is not directed to children under 16. We do not use personal data for decisions producing legal or similarly significant effects based solely on automated processing.

    We may update this Policy by posting a revised version here. For material changes, we will provide additional notice where appropriate. Questions and privacy requests may be sent to hey@seoforgpt.io.

    Version 1.1 – Effective 26 August 2026