Effective 7 August 2026 — applies to everyone who uses SeoGrep.

Privacy Policy

A plain-language summary of what SeoGrep collects during beta, who it goes to, and what you can ask us to do with it.

What we collect

We collect the email address you use to create an account, your account credentials (handled by our authentication provider), and the site data needed to run your analyses. If you connect Google Search Console, we store that connection's Google refresh token encrypted at rest, and we ask Google for read-only access only — SeoGrep never requests permission to change your property. Payments are handled by Paddle, our merchant of record — we never see your full card details.

How we use it

We use your email to send account email — the address confirmation link, the one-time welcome message, and a password reset link when you ask for one. Account and site data are used to run the crawls, audits, and analyses you request and to operate the service.

Data retention

During beta, we retain your crawl data and Search Console data while your account is active. Report outputs are kept for the lifetime of your account, and every report you generate also gets an unguessable public link so you can share it — anyone holding that link can open the report without signing in. To have your data deleted, email us at support@seogrep.com — with the one exception described under Your rights below.

Processors we use

We use Supabase for authentication and our database, Netlify to host the website, and Fly.io to run the analysis service; the database and the analysis service both run in Japan (Tokyo), a jurisdiction covered by an EU adequacy decision. Cloudflare Turnstile runs the bot check on our sign-up, sign-in, and password-reset pages, so those three pages load a script from Cloudflare and Cloudflare sees that request. Paddle is our merchant of record for payments and billing, Resend sends transactional email, and PostHog, hosted in the EU, receives product analytics keyed to a hashed identifier rather than your email address. When you connect Search Console we call Google's API with your read-only token, and the keyword and competitor tools send the keywords and domains you ask about to DataForSEO. These providers process data only to deliver those functions.

Google user data

SeoGrep's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice, your Search Console data is fetched with your read-only token only to run the analyses and reports you ask for, is stored only on the infrastructure named above that runs the service, is never used for advertising, and is never sold.

AI training

Your site data is never used to train AI models.

Your rights

You can request access to or deletion of your data by emailing support@seogrep.com. We honor GDPR and KVKK rights, including access and erasure. One exception is worth stating plainly: the credit ledger is append-only by design, so the entries showing what you bought and what you spent are kept as accounting records rather than erased. Those entries are tied to your account record, so that record is kept alongside them. Everything else goes: your crawl data, your Search Console data and the stored token, and your report outputs together with their share links.

Changes to this policy

We may update this policy. When we do, the effective date at the top of this page changes.

Contact

For any privacy request, email us at support@seogrep.com.