Privacy Policy
Last updated: 8 August 2026
This policy explains what data SEObotly (“we”, “the Service”) collects, why we collect it, how long we keep it, and what you can do about it. It applies to seobotly.com and the SEObotly application.
Operator. The Service is operated by SEObotly, an independent operator reachable at hi@seobotly.com. Write to that address for any privacy question, data access or deletion request, or complaint — it is a monitored mailbox and every message is answered.
1. Data we collect
| Category | What exactly | Why |
|---|---|---|
| Account | Email address, name, organisation name, hashed password | To create and secure your account |
| Sites | Domain names you add, ownership verification token, verification method | To confirm you control a domain before we crawl it |
| Audit results | Publicly accessible pages of your own verified sites: URL, status code, title, meta description, headings, word count, response time | To produce the technical SEO audit you requested |
| Google account | Your Google account ID, email address and display name, and — if you connect Search Console or Analytics — an encrypted refresh token | To sign you in and to connect Search Console or Analytics at your request — see section 4 |
| Usage | Credit and operation logs (which operation, when, how much it cost) | To enforce plan limits and answer billing questions |
Inside the application — every screen behind sign-in, atseobotly.com/app — we use no third-party analytics, no advertising pixels and no tracking cookies. The only cookie we set there is a session cookie that keeps you signed in. Nothing about the sites you audit, the keywords you research or the reports you open is sent to anyone else.
On our public marketing pages — the home page, pricing, blog and other pages outside the application — we use Google Analytics 4 to see how many people find us and which pages they read. It sets its own cookies and passes a truncated IP address to Google. It is not loaded inside the application, so it never sees your account, your sites or your data. Analytics runs only if you allow it — see the next section.
2. Cookies and your choice
We use two kinds of cookies and nothing else. There are no advertising cookies, no social network pixels and no cross-site trackers anywhere on this domain.
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| Session cookie | SEObotly | Keeps you signed in and protects forms against cross-site abuse | Until you sign out |
sb-consent | SEObotly | Remembers the cookie choice you made, so we do not ask again. Stored in your browser only; it is never sent to us | Until you clear your browser |
_ga, _ga_* | Google Analytics 4 | Counts visits and page views on the public pages. Only set after you accept | Up to 2 years |
The first two are strictly necessary: without them you cannot stay signed in and we cannot honour your own choice. They do not require consent and cannot be switched off. Analytics is different — it runs only after you accept it in the banner shown on your first visit. Until you decide, we applyGoogle Consent Mode: in the EEA, the UK and Switzerland analytics storage stays denied, so no analytics cookie is written before you have said yes.
Changing your mind costs one click. Use thelink in the footer of any page — it reopens the same panel and takes effect immediately. Withdrawing consent is deliberately as easy as giving it. Browser-level tracking blockers and the Google Analytics opt-out add-on also work, and nothing on our marketing pages depends on analytics running.
3. We only crawl sites you have proven you own
Before SEObotly crawls a domain, you must prove control of it — either with a DNS TXT record we generate, or by connecting a Google Search Console property that Google itself has already verified for you. Until that check passes, no crawl runs. This protects both you and third parties: our crawler cannot be pointed at a site its operator does not control.
4. Google user data
Connecting Google Search Console is optional. SEObotly works without it. Connecting Google Analytics is separately optional — it is requested only if you ask for it, and declining it does not affect the Search Console connection. If you choose to connect either, the following applies.
Scopes we request
We request scopes in three separate consent screens, never all at once, and each one only at the moment you ask for the feature it powers. Every scope below isread-only: we cannot add, modify or delete anything in any Google product.
- Sign in with Google (optional — you can also use an email and password):
openid,email,profile. These are requested only when you press “Continue with Google”. We use them to create or find your SEObotly account, and we store your Google account identifier, email address and display name. This screen requestsno Search Console or Analytics access. https://www.googleapis.com/auth/webmasters.readonly— Search Console. We do not request the fullwebmastersscope, because we do not need write access.https://www.googleapis.com/auth/analytics.readonly— Google Analytics 4. Requested only when you press “Connect Analytics”. We do not requestanalytics.editor any management scope.
What we do with it
Search Console:
- List the Search Console properties available to your Google account, so you can pick one.
- Read search performance metrics (clicks, impressions, average position, by page and country) for the property you connected.
- Combine those metrics with your technical audit so we can rank the issues by how much search traffic they are actually costing you.
Google Analytics:
- List the GA4 properties available to your Google account, so you can pick one.
- Read aggregate traffic metrics (sessions, users, engagement rate, average session duration, and key events where you have configured them) broken down by channel, source, country, device and page path.
- Join those metrics with your Search Console page data, so a report can show whether a page that earns search clicks actually holds the visitor’s attention.
We do not read individual user or event level data, we do not use the User Data API, and we do not attempt to identify any of your visitors.
What we store
We do not store your Search Console or Google Analytics data. Clicks, impressions, positions, sessions, users and engagement metrics are fetched live from the Google API each time you open a report, used to render that response, and then discarded. They are not written to our database.
What we do store is limited to: your Google account identifier, the email address of that account, the granted scopes, the identifier of the Search Console property and the GA4 property you selected, and a refresh token encrypted with AES-256-GCM. The encryption key is held outside the database; if a database backup were ever exposed, the token would not be usable on its own.
Limited Use disclosure
SEObotly’s use and transfer of information received from Google APIs to any other app will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not use Google user data for advertising; we do not sell it; we do not transfer it to third parties except as needed to provide the Service, comply with law, or as part of a merger or acquisition with prior notice; and we do not allow humans to read it, except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and anonymised.
Disconnecting
You can disconnect a Google account at any time from within the application, which deletes the stored refresh token immediately. You can also revoke access independently atmyaccount.google.com/permissions.
5. Third parties we share data with
| Who | What they receive | Why |
|---|---|---|
| DataForSEO | Domain names and target market (country and language) for keyword research you request | They are our search data provider. No Google user data is sent to them. |
| The API requests needed to read the Search Console data you connected | To provide the Search Console integration | |
| Google Analytics | Page views and a truncated IP address, from our public marketing pages only | To measure how people find the site — never loaded inside the application |
| Anthropic | The text of the content briefs, drafts and assistant messages you generate | They run the AI model behind those features |
| Hosting and infrastructure providers | Data at rest and in transit, as technically necessary to run the Service | To operate the Service |
We do not sell personal data, and we do not share it for advertising purposes.
6. Security
- Passwords are stored as scrypt hashes, never in plain text.
- Google refresh tokens are encrypted at rest (AES-256-GCM). If the encryption key is not configured, the Google integration is disabled entirely rather than storing tokens unprotected.
- Sessions are stored server-side and can be revoked instantly. Changing your password destroys all existing sessions.
- Traffic between your browser and the Service is encrypted with TLS.
7. Retention and deletion
- Account and site data are kept while your account is active.
- Deleting a site deletes its crawl history, audit results and issues, and unlinks any connected Search Console property.
- Disconnecting a Google account deletes the stored refresh token immediately.
- Deleting your account removes your personal data. Records we are legally required to keep, such as invoices, are retained for the statutory period.
- Usage and credit logs are retained for accounting purposes.
To request deletion, email hi@seobotly.com from the address on your account.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with your data protection authority. Write to hi@seobotly.com and we will respond within 30 days.
9. International transfers
The Service and its providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
10. Children
The Service is intended for business use and is not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes
If we change this policy in a way that materially affects you, we will notify you by email or in the application before the change takes effect. The “last updated” date above always reflects the current version.
12. Contact
Questions about this policy or your data: hi@seobotly.com.