Privacy Policy
A transparent explanation of the information seou.ai collects, why we use it, how long we keep it, who helps us process it, and the choices users have.
Effective date: August 17, 2026
Overview
This Privacy Policy explains how seou Inc. and seou.ai collect, use, store, disclose, and protect personal information when people visit our websites, create accounts, accept workspace invitations, connect integrations, upload media, generate content, run SEO workflows, receive emails, or otherwise use our services.
seou.ai is a business-to-business SaaS product. We process account data, workspace data, customer content, media, integration data, security logs, and limited usage information so that customers can manage SEO planning, content workflows, media, publishing operations, and local search analysis.
If a customer uses seou.ai to process personal information about its own customers, prospects, employees, contractors, or website visitors, the customer is responsible for having a lawful basis and providing any required notices to those people. In that situation, seou.ai generally acts as a service provider or processor for the customer.
Information We Collect
We collect information directly from users, information generated by use of the service, information from connected providers, and information collected automatically for security, reliability, and product operation.
- Account information: name, email address, password hash, account status, authentication method, workspace memberships, role, invitation status, and legal acceptance records.
- Google login information: Google account identifier, verified email address, first name, last name, and profile name returned through the limited Google Sign-In scopes openid, email, and profile. seou.ai does not store Google login access tokens for basic sign-in.
- Workspace and business profile information: organization name, website, business phone, business email, address, optional Google Maps Place ID or business link selected by the user, niches, services, target cities or regions, target audience, brand tone, business goals, keywords, differentiators, and notes about topics to avoid.
- Customer content: briefs, drafts, article text, titles, slugs, meta titles, meta descriptions, custom CSS, publishing schedules, approval history, generated content, generated image metadata, and related SEO scores.
- Media information: uploaded images, original file name, MIME type, file size, image dimensions, SHA-256 hash, storage keys, optimized derivatives, thumbnails, alt text, captions, tags, scan status, processing status, and content usage counts.
- Integration information: provider names, connection status, encrypted provider credentials or refresh tokens when an integration requires ongoing access, provider hints, connected site identifiers, provider responses, and sync state.
- Google Search Console information: OAuth tokens stored encrypted, authorized site URL, granted scopes, pages, search queries, clicks, impressions, CTR, average position, date ranges, and derived SEO recommendations.
- SEO and competitive intelligence data: crawled page data, keyword research, rankings, SERP features, local business listings, reviews/activity data, PageSpeed/CrUX measurements, competitors, trend signals, AI visibility signals, and provider snapshots used to generate SEO analysis.
- Security and audit information: IP address or hash, user agent, session metadata, login attempts, rate-limit events, CSRF failures, blocked origins, permission denials, upload scan events, worker events, and admin actions.
- Support and communications: messages, email delivery metadata, password reset requests, signup verification requests, account deletion requests, and operational emails.
- Cookies, local storage, and similar technologies: session cookies, OAuth state cookies, cookie preference records, local browser preferences such as remember-me preference, and optional analytics identifiers only after consent where required.
How We Use Information
We use personal information only for legitimate business purposes connected to operating, securing, supporting, improving, and providing seou.ai. We do not sell customer workspace content or Google user data.
- Provide the service, create and authenticate accounts, verify email addresses, accept invitations, maintain sessions, and route users to the correct organization.
- Operate workspace features including SEO audits, keyword research, content planning, content generation, media management, scheduling, publishing workflows, and dashboards.
- Use business profile data to tailor SEO recommendations, AI prompts, content plans, local search analysis, and publishing suggestions to the customer's business, website, locations, services, and audience.
- Use uploaded media to optimize images, generate thumbnails, scan for malware, create metadata, attach images to content, export selected media, and serve private previews through short-lived signed URLs.
- Use Google Search Console data to show organic search performance, identify page and query opportunities, compare periods, support audits, generate strategy, and monitor SEO health.
- Use Google login data to authenticate users, link accounts, prevent duplicate accounts, and create a usable personal workspace when appropriate.
- Use AI providers to generate or improve content, briefs, metadata, image prompts, images, SEO diagnostics, and strategy outputs based on user instructions and workspace context.
- Use security data to prevent fraud, enforce rate limits, detect abuse, investigate incidents, protect tenant boundaries, validate sessions, and maintain audit trails.
- Send transactional emails such as signup verification, existing-account notices, password reset, invitation, welcome, account deletion, and service notices.
- Measure product reliability and performance, debug errors, improve workflows, and understand aggregate usage trends, subject to cookie and analytics preferences where applicable.
- Comply with legal obligations, enforce our Terms of Service, resolve disputes, and respond to lawful requests.
Google User Data
When users choose Google Sign-In, seou.ai requests only the minimum profile permissions needed to authenticate the user: openid, email, and profile. We use this data to create or sign in to an account, verify that the email is confirmed by Google, link the Google account to the seou.ai user, and maintain account security.
When an admin connects Google Search Console, seou.ai requests offline access to the Search Console data required for SEO reporting and strategy. We store the refresh token encrypted so the workspace can refresh Search Console metrics without asking the admin to reconnect every time. Access tokens are refreshed as needed and stored with expiration metadata.
When a user chooses the optional Google Business Profile search, Google Maps Platform returns autocomplete suggestions in the browser. seou.ai stores only the selected display name, Place ID, and Google Maps link, not the address, category, reviews, photos, or other Places content returned during that session. This feature is governed by the Google Maps Platform Terms of Service at https://cloud.google.com/maps-platform/terms and the Google Privacy Policy at https://policies.google.com/privacy.
We use Google Search Console data only to provide and improve user-facing SEO features in seou.ai, including reporting, page/query analysis, recommendations, trend detection, and AI-assisted SEO strategy. We do not sell Google user data, use it for advertising, or transfer it to advertising platforms or data brokers.
A workspace admin can disconnect Google Search Console by contacting support or using the relevant integration controls when available. Account deletion removes linked Google account records and encrypted Google Search Console credentials associated with the deleted workspace.
AI And Generated Content
seou.ai uses AI systems to help generate SEO briefs, drafts, page improvements, metadata, image suggestions, images, and strategy recommendations. Inputs may include customer-provided business profile data, website URLs, page text, keywords, uploaded media metadata, Search Console metrics, SEO audit results, competitor data, and user instructions.
AI outputs may be inaccurate, incomplete, or unsuitable without human review. Customers are responsible for reviewing generated content before publishing, confirming factual claims, checking legal/regulatory requirements for their industry, and ensuring that generated content does not infringe third-party rights.
We do not intentionally include secrets, credentials, raw session tokens, or payment information in AI prompts. We apply input validation, unsafe text rejection, rate limits, quotas, and audit logging around AI features.
Data Retention
We keep personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required for legal, security, accounting, dispute resolution, or compliance reasons. Retention may differ by data type and customer configuration.
- Session cookies and database sessions expire after approximately 12 hours by default or 30 days when remember-me login is used.
- OAuth state cookies expire after approximately 5 minutes.
- Signup verification and password reset tokens expire after approximately 30 minutes.
- Workspace invitations expire after approximately 7 days.
- Private asset preview URLs expire after approximately 5 minutes, and private CDN media URLs default to approximately 30 minutes when enabled.
- Media export jobs and export files expire after approximately 24 hours unless downloaded or cleaned earlier.
- Uploaded images, generated content, Search Console data, SEO snapshots, workspace profile data, and integration credentials are retained while the workspace is active unless deleted by an authorized admin or removed through account deletion.
- Security logs, audit logs, rate-limit records, idempotency records, and worker records are retained as needed for security, abuse prevention, debugging, compliance, and service reliability.
- Backups may retain deleted information for a limited period before they are overwritten or deleted according to backup schedules.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include database-backed sessions, HttpOnly cookies, SameSite cookie settings, Secure cookies in production, CSRF protection, origin validation, rate limits, tenant-scoped authorization checks, audit logging, private media storage, signed private asset URLs, upload validation, malware scanning workflows, and encryption for provider secrets.
No internet service can guarantee perfect security. Customers should use strong passwords, restrict admin access, review connected integrations, and promptly report suspected unauthorized access.
Privacy Rights And Choices
Depending on location and applicable law, users may have rights to know, access, correct, delete, export, restrict, object to certain processing, opt out of certain sales or sharing, limit use of sensitive personal information, and avoid discrimination for exercising privacy rights.
California residents may have rights under the CCPA/CPRA, including rights to know what personal information is collected and how it is used or shared, correct inaccurate information, delete information, opt out of sale or sharing for cross-context behavioral advertising, limit use and disclosure of sensitive personal information, and receive equal treatment for exercising rights.
seou.ai does not sell personal information as that term is commonly understood. We also do not sell Google user data or customer workspace content. If we introduce any activity that constitutes a sale or sharing under applicable law, we will provide the required notices and opt-out mechanisms before doing so.
To make a privacy request, contact us at privacy@seou.ai. We may need to verify your identity and your authority to act for a workspace before fulfilling a request. Some data may be retained when necessary for security, legal compliance, fraud prevention, dispute resolution, or backup integrity.
Children
seou.ai is not directed to children under 13 and is intended for business users. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to seou.ai, contact privacy@seou.ai so we can take appropriate action.
International Data Transfers
seou.ai is operated from the United States and may use service providers in the United States or other countries. When personal information is transferred internationally, we rely on appropriate safeguards where required, such as contractual commitments, vendor due diligence, and data protection terms. We will update this policy if seou.ai self-certifies under a formal transfer framework such as the EU-U.S. Data Privacy Framework.
Changes To This Policy
We may update this Privacy Policy as the product, laws, vendors, or data practices change. If changes are material, we will provide appropriate notice, such as in-product notice, email, or an updated effective date. Continued use of seou.ai after an update means the updated policy applies, unless additional consent is required by law or by a connected provider policy.
Contact
For privacy questions or requests, contact privacy@seou.ai. For account or product support, contact support@seou.ai.
