Last Updated: August 24, 2026
This Privacy Policy explains what information the operator of AI SEO Manager ("we", "us", "our") collects when you use AI SEO Manager (the "Service"), how we use it, and the choices you have. It describes the Service as actually implemented — no more, no less.
This document was prepared for AI SEO Manager and should be reviewed by qualified legal counsel before publication. Business-specific details that have not been supplied yet are marked as pending rather than replaced with placeholder text.
AI SEO Manager is a software service that crawls websites you register, analyses them for search-engine optimization issues, generates recommendations, and — only with your explicit approval — executes and verifies changes through a connector you configure.
This policy applies to information collected through the Service, including the website, the application dashboard, and connected third-party services. By using the Service you agree to the collection and use of information as described here.
We collect information in three ways: information you provide directly (such as your account details), information collected automatically when you use the Service (such as usage and device data), and information retrieved from third-party services you choose to connect (such as Google Search Console).
We do not collect special categories of personal data, and the Service is not designed to process the personal data of your own website's visitors.
When you register, we collect your email address and authentication credentials. If you sign up with a Google account, we receive the basic profile information Google provides to complete sign-in.
Authentication is handled by our authentication provider. Passwords are never visible to the application in plain text.
To provide the Service you register website URLs, along with a display name you choose. We store the normalized domain, validation results (HTTPS reachability, robots.txt fetch results, discovered sitemaps), and the crawl configuration you set.
When a crawl runs, our crawler fetches the public pages of your registered websites and stores the technical facts it observes: HTTP status codes, titles, meta descriptions, canonical links, headings, word counts, internal and external links, image alt attributes, and structured data.
This data is used to compute your SEO Health Score, detect issues, and generate opportunities and recommendations. Crawl data is stored per workspace and is isolated from other customers by database row-level security.
If you connect Google Analytics 4, we import analytics metrics for the property you select — such as traffic, engagement, and conversion metrics — and use them to prioritize opportunities and display reports in the dashboard.
When you connect a third-party service, we store the connection state and the OAuth tokens required to keep the connection working. Tokens are stored encrypted and are used only server-side, only for the sync operations the integration exists to perform.
Disconnecting an integration stops all future data retrieval from that service.
If you connect Google Search Console, we use the Google API to retrieve search analytics rows for your verified properties: queries, pages, clicks, impressions, click-through rate, and average position. If you connect Google Analytics 4, we retrieve analytics metrics for the property you select.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Access requested is read-only: the Service cannot modify your Search Console or Analytics configuration. Google data is used only to provide the features described in this policy — reporting, keyword intelligence, and grounding recommendations in your real traffic — and is not used for advertising, sold, or shared with third parties other than the infrastructure providers required to operate the Service.
We use the information we collect to: provide, operate, and maintain the Service; crawl and analyse your registered websites; generate and execute the recommendations you approve; synchronize data from integrations you connect; meter AI usage against your plan; secure the Service and enforce workspace isolation; and communicate with you about your account.
The Service uses AI models to draft recommendations from evidence collected about your registered websites (crawl facts and, where connected, your search and analytics data). Issue detection itself is deterministic and does not use AI.
AI generation is metered as 'AI actions' against your workspace's plan allowance. AI-drafted recommendations are never applied to your website without your explicit approval.
Recommendations are drafted by third-party AI models through the Service's AI gateway. Whether the AI provider may use prompts for model training depends on that provider's current terms; the operator will confirm the exact policy and publish it here before public launch. The Service itself does not use your data to train models.
The Service runs on managed cloud hosting and database infrastructure. The specific provider list will be published here before public launch. The categories of providers we use are: application hosting and database infrastructure, authentication services, payment processing, and AI model providers for recommendation drafting.
A current list of subprocessors will be available on request once the privacy contact address is published — pending: This detail must be completed by the business owner before public launch. It is intentionally shown as pending rather than filled with placeholder text.
We apply technical and organizational measures appropriate to the Service: encryption of data in transit, encrypted storage of integration tokens, database row-level security enforcing per-workspace isolation, server-side-only handling of secrets, and audit logging of approval and execution actions.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We retain your account, website, crawl, and recommendation data for as long as your account is active so the Service can provide history, trends, and audit trails. A detailed retention schedule (including how long crawl history is kept after account closure) will be published here before public launch.
You may request deletion of your account and associated data; the privacy contact address for such requests will be published here before public launch.
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
To exercise any of these rights, contact the privacy address that will be published on this page — pending: This detail must be completed by the business owner before public launch. It is intentionally shown as pending rather than filled with placeholder text. We will respond within the timeframe required by applicable law.
Your information may be processed in countries other than your own, where our infrastructure providers operate. Where required, we rely on appropriate safeguards for such transfers; the specific transfer mechanisms applicable to the operator will be published here before public launch.
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children.
The Service links to and integrates with third-party services such as Google. Your use of those services is governed by their own terms and privacy policies, which we do not control.
We may update this policy from time to time. The 'Last Updated' date at the top of this page shows the current version. Material changes will be communicated through the Service or by email where appropriate.
Legal company name: pending — This detail must be completed by the business owner before public launch. It is intentionally shown as pending rather than filled with placeholder text.
Business address: pending — This detail must be completed by the business owner before public launch. It is intentionally shown as pending rather than filled with placeholder text.
Privacy contact email: pending — This detail must be completed by the business owner before public launch. It is intentionally shown as pending rather than filled with placeholder text.