Legal
Privacy Policy
Last updated:
SEO Sets ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Data we collect
Account data
When you register, we collect your name and email address. Passwords are hashed using bcrypt and never stored in plain text.
Google Search Console data
When you connect your Google account, we request read-only access to your Google Search Console data via OAuth 2.0. Specifically, we request the webmasters.readonly scope. This allows us to read your site's search analytics (queries, pages, impressions, clicks, positions). We never request write access to GSC, Google Analytics, or any other Google property.
We store a subset of your GSC data — specifically page-level metrics — to compute opportunity scores and power the dashboard. We do not sell, share, or use your GSC data for any purpose other than providing you with the SEO Sets service.
Usage data
We collect standard server logs (IP address, browser type, pages visited, timestamps) for security and performance monitoring. We do not use third-party analytics trackers (e.g. Google Analytics) on authenticated dashboard pages.
Payment data
Payments are processed by Stripe. We never see or store your card number, CVV, or full payment details. We store only a Stripe customer ID and subscription status in our database.
2. How we use your data
- To create and manage your account
- To compute SEO opportunity scores from your GSC data
- To send weekly digest emails and alert notifications (which you can unsubscribe from at any time)
- To process subscription payments via Stripe
- To respond to support requests
- To comply with legal obligations
We do not use your data for advertising, sell it to third parties, or share it with analytics platforms.
3. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data and GSC data within 30 days, except where retention is required by law (e.g. billing records, which are kept for 7 years in most jurisdictions).
4. Third-party services
We use the following sub-processors:
- Stripe — payment processing (stripe.com/privacy)
- Google — OAuth and Search Console API (policies.google.com/privacy)
- Resend — email delivery: sending account, digest, and alert emails on our behalf (your email address and message content only) (resend.com/legal/privacy-policy)
- Our hosting provider — server infrastructure
AI providers used by the AI Visibility Engine
If your plan includes the AI Visibility Engine and you run scans, we send the prompts you choose to track — together with your site's URL so the response can be checked for citations of your site — to the AI providers behind the engines your plan covers:
- OpenAI — ChatGPT engine (openai.com/privacy)
- Perplexity — Perplexity engine (perplexity.ai/privacy)
- Anthropic — Claude engine (anthropic.com/privacy)
- Google — Gemini engine (policies.google.com/privacy)
We do not send these providers your name, email address, or Search Console data — only the tracked prompt text and your site URL. The providers' responses are stored in your account so you can see citation history, and are deleted on the same schedule as the rest of your data (see Data retention above). Each provider processes API requests under its own privacy policy, linked above.
5. Cookies
We use essential cookies required for the service to function: a session cookie to keep you logged in, and a CSRF token cookie for security. With your consent, we also use Google Analytics on our public marketing pages to understand site usage; it never runs inside the authenticated app. We do not use advertising cookies. See our Cookie Policy for details.
6. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data in a portable format
- Withdraw consent for data processing
To exercise any of these rights, email us at privacy@seosets.com. We will respond within 30 days.
7. Security
We use HTTPS for all data in transit, bcrypt for password hashing, and encrypted storage for OAuth tokens. Access to production data is restricted to authorised team members only.
8. Children
SEO Sets is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it promptly.
9. Changes to this policy
We may update this policy as the product evolves. We'll notify you by email if we make material changes. Continued use after the effective date constitutes acceptance.
10. Contact
Questions? Email privacy@seosets.com.