Privacy Policy
This Privacy Policy explains what personal data seoapp.ai (the "Service") collects, for what purpose and on what legal basis it processes it, and what rights you have. The data controller is Katarzyna Górecka, ul. Nowogrodzka 31, 00-511 Warszawa, NIP: 7412060624, contact: admin@seoapp.ai.
1. Data controller
The controller of your personal data is Katarzyna Górecka, ul. Nowogrodzka 31, 00-511 Warszawa, NIP: 7412060624.
For any data-related matters and to exercise your rights, contact admin@seoapp.ai.
2. Definitions
GDPR - Regulation (EU) 2016/679. Personal data - information about an identified or identifiable natural person. User - anyone using the Service. Controller - the entity in section 1.
3. Data we process
Account data: email address, name, password stored as an encrypted hash.
Project and content data: website addresses, keywords, briefs and content you provide, and articles generated on your request.
Integration data: access tokens for third-party services (e.g. Google Search Console, Shopify) stored encrypted (see sections 6-7).
Payment data: handled by an external payment provider - we do not store full card numbers.
Technical and usage data: IP address, device and browser type, event logs, usage metrics.
Correspondence and support chat: the content of messages you send us (including the on-site chat).
Waiting list / newsletter: an email address you provide voluntarily.
Webinar and event registration data: first name, email address, phone number and information about your participation and orders placed as part of the event offer.
Shared access data: the email address of a person you invite to view or collaborate on your site in the Service.
Referral partner data: full name or company name, address, tax/VAT ID, phone, promotion channels and their addresses, payout details (bank account or PayPal address), invoices you issue, plus the IP address, time and version of the programme terms you accepted.
4. Purposes and legal bases
Providing the service and performing the contract - Art. 6(1)(b) GDPR.
Billing, security, service improvement and analytics - legitimate interest, Art. 6(1)(f) GDPR.
Newsletter, waiting list and optional marketing cookies - your consent, Art. 6(1)(a) GDPR (withdrawable anytime).
Organising webinars and events (registration, personal access link, email and SMS reminders) - performance of the contract, Art. 6(1)(b) GDPR; marketing communication after the event - your consent, Art. 6(1)(a) GDPR. Free access to an event is provided in exchange for your data and marketing consent (Art. 32a of the Polish Consumer Rights Act) - alternatively you can purchase paid access (PLN 99 gross) without any consents by writing to admin@seoapp.ai.
Tax and accounting obligations - Art. 6(1)(c) GDPR.
5. Cookies
We use cookies necessary for the Service to work (e.g. keeping you logged in) and - with your consent - analytics cookies.
With your consent, marketing tools (the Meta pixel - see section 8) also run on the Service's marketing pages (e.g. webinar pages). When you arrive via a referral link or an ad, we set a cookie used to attribute the referral (referral programme, 60 days) and to remember the traffic source.
You can change cookie settings in your browser at any time.
We self-host our fonts (Inter, Outfit, JetBrains Mono) on our own server - we do NOT use the Google Fonts CDN, so your IP address is not sent to Google for fonts.
6. Google user data (Google API Services User Data Policy)
When you connect your Google account, we access data via Google OAuth - only within the scopes you consent to. You can revoke access at any time by disconnecting the integration in the Service or at myaccount.google.com/permissions.
What Google user data we access: from Google Search Console - the list of your sites and search performance statistics (queries, clicks, impressions, positions, URLs).
How we use it: solely to provide and improve the user-facing features of the Service - SEO analysis of your website, content topic selection, performance reports for published articles and indexing status. We do not use Google user data for advertising (including targeted, personalized or interest-based ads), do not sell it to data brokers, do not use it to determine credit-worthiness, and do not use it for any purpose unrelated to providing or improving the Service's features. We do not use Google user data to develop, improve or train non-personalized AI and/or ML models - neither our own nor third-party ones.
With whom we share it: we do not sell Google user data and do not transfer or disclose it to third parties. Exceptions: the hosting provider on whose servers the Service runs (a data processor); AI model providers - only the fragments of statistics (e.g. Search Console queries) necessary to generate content or recommendations for you within the Service's features, and these providers may not use this data to train their models; public authorities where required by law; other parties - only with your explicit consent.
How we protect it: OAuth tokens are stored encrypted, data is transmitted only over encrypted connections (TLS/HTTPS), access is limited to authorised personnel (access control) and we maintain backups. No one on our team views your Google user data unless you request support and consent to it, it is necessary for the security of the Service (e.g. investigating abuse or a bug), or we are legally obliged to.
Retention and deletion: we keep Google user data for as long as the integration is active. When you disconnect the integration we delete the access tokens, and the retrieved Google data is deleted or anonymised within 30 days at the latest. Deleting your account also deletes your Google data. You can also request deletion by emailing admin@seoapp.ai.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
7. Shopify store data
When you connect your Shopify store, you install our app in the store and Shopify issues us an access token - only within the permissions shown at install time. You can revoke access at any time by uninstalling the app in your Shopify admin or by disconnecting the integration in the Service.
What we access: your store's address (domain) and basic store information, the store's blog content (posts we publish and update on your request), and - if you use internal linking - the list of products and collections (names and URLs) so articles can link to them.
What we do NOT access: your store's customer (buyer) data, orders or payment data - we do not request such permissions.
Retention: we keep store data for as long as the integration is active. When you uninstall the app or disconnect the integration, we delete the access token and store data within 48 hours (we also honour the automated data-erasure requests sent by Shopify - GDPR webhooks). You can also request deletion by emailing admin@seoapp.ai.
8. Recipients
We share data with trusted processors solely to deliver the Service:
hosting/infrastructure provider; payment processor (subscriptions); invoicing provider (Fakturownia); email delivery providers - transactional and marketing (SendGrid, MailerLite); SMS gateway provider (webinar and event reminders); AI model providers that process the content of your requests; search-results data providers - limited to website addresses and keywords; Telegram - for support chat handling; Google - for the Google integrations (Search Console, Analytics - see section 6); Shopify - for the Shopify store integration (see section 7); Meta Platforms - for measuring ad performance (pixel / Conversions API on marketing pages, only with your consent).
AI model providers process the content of your requests solely to generate the content or recommendations you ask for, and do not use it to train or improve their models.
We do not sell personal data.
9. International transfers
Some providers (e.g. AI services) may process data outside the European Economic Area. In such cases we apply appropriate safeguards, in particular Standard Contractual Clauses approved by the European Commission.
10. Retention
We keep account data for the duration of your use of the Service and as long as needed for billing and to establish or defend claims. After account deletion, data is erased or anonymised, except where retention is legally required (e.g. accounting).
Webinar and event registration data is kept until the event has taken place and the materials have been sent; data processed based on marketing consent - until you withdraw it.
Referral programme: a partner's billing details (address, tax ID, bank account) are deleted together with the account, rejected applications are removed after 12 months, and invoices and payout records are kept for 5 years from the end of the tax year (accounting obligation) - commission records are anonymised so they no longer point to a person.
11. Your rights
You have the right to access, rectify, erase, restrict and port your data, to object and to withdraw consent at any time.
You may also lodge a complaint with a data protection authority. To exercise your rights, write to admin@seoapp.ai.
12. Automated processing
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
13. Security
We use technical and organisational measures to protect data, including encryption of sensitive data (such as integration tokens), access control and backups.
14. Children's data
The Service is not directed at persons under 16 and we do not knowingly collect their data.
15. Changes to this Policy
We may update this Policy. We will notify you of material changes in the Service or by email. The last-updated date is shown at the top.
16. Contact
For privacy matters write to admin@seoapp.ai.