Legal

Privacy Policy

Effective date: September 26, 2026.

SEOAgent is operated by GrubGuru, a company registered in British Columbia, Canada. This policy explains what personal information we collect, why, who we share it with, and what choices you have. We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for people in the European Economic Area and the United Kingdom, the GDPR.

1. What we collect

  • Account information - your name, email address, and a password hash, or the basic profile Google shares when you sign in with Google.
  • Your sites and content - the sites you add, the keywords, articles, images and reports generated for them, and the credentials you store to publish to your CMS (encrypted at rest).
  • Connected accounts - when you connect Google Search Console, Google Analytics 4, PostHog or Bing Webmaster Tools, the search and traffic data for the sites you choose. See section 4 for Google data.
  • Payment information - Stripe processes payments. We receive confirmation of payment and basic billing details from Stripe; we never see or store your card number.
  • Support chats - the messages you send through in-app support.
  • Usage and security data - job logs, credit history, rate-limit counters, a security audit trail, and the IP address and browser of each signed-in session, which Settings → Account shows you as your device list.

2. How we use it

To operate your account, research keywords and generate and score articles, connect to your website and to the Google and analytics accounts you choose, process payments, answer support requests, send transactional email (password resets, notifications, invites), and enforce the budgets and rate limits that keep the Service secure and usable. With your consent, we measure how the site is used (section 5). We do not sell personal information, and we do not use it for advertising.

3. Third-party services

Data is shared with the following providers only as needed to run the features you use. The full list, with locations, is in the Data Processing Agreement.

  • Hetzner - hosting, database and backups, in Finland.
  • Stripe - payment processing, invoicing, and (when enabled) tax calculation.
  • Google - OAuth sign-in, and Search Console, Google Analytics 4 and Indexing API access when you connect them.
  • DataForSEO - keyword volume, difficulty, SERP, backlink, rank and AI-answer data used for research, rank tracking and AI-visibility checks.
  • OpenRouter (routing to Anthropic and Google models) - article drafting, scoring, rewriting.
  • Firecrawl / Jina - reading your own site's pages to build its topic model.
  • DeepSeek - answering in-app support chat messages, with the account details the answer needs (plan, credits, sites, article status).
  • Ahrefs - Domain Rating lookups for your site, its competitors and the sites that link to it. Only domain names are sent.
  • PostHog, Bing Webmaster Tools - traffic data, only when you connect them.
  • Resend - transactional email delivery.
  • Sentry - error monitoring.

We may also disclose information when the law requires it.

4. Google user data

When you connect Google, SEOAgent asks for access to Search Console (to read search performance for your sites and submit sitemaps), Google Analytics 4 (read-only, to show traffic for your sites) and, if you set it up, the Indexing API (to ask Google to crawl pages you publish). We use this data only to show it to you and to power the features you use in SEOAgent, such as picking which articles to write or refresh. We do not sell it, use it for advertising, or use it to train AI models, and people at GrubGuru read it only with your permission, for security, or when the law requires it.

SEOAgent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google in SEOAgent at any time, or revoke access from your Google Account permissions; disconnecting stops new data from being fetched, and deleting the site or your account deletes the data already stored.

5. Cookies

We set only the cookies the Service needs: a session cookie for sign-in, your theme and site choice, the website you typed at signup until your site is set up, and one that remembers you dismissed the cookie notice. If you accept analytics on that notice, Google Analytics (GA4) sets its own cookies for page-view and product-event measurement; declining keeps analytics off. You can change the answer at any time from Cookie settings in the site footer or Settings → Account, and turning analytics off deletes the analytics cookies already set. No advertising or cross-site tracking cookies. The full list is in the Cookie Policy.

6. Data retention and deletion

We keep your data while your account exists. You can delete your account yourself from Settings → Account, after confirming with your password (or, if you sign in with Google, a sign-in from the last ten minutes). Deletion removes your user record, sessions, API keys, support chats, and every workspace only you are in with everything in it - sites, articles, images, connected credentials, credit history - immediately. A workspace other people also use is handed to one of them first, or deleted with your account if you choose that. Invitations addressed to you are withdrawn, and your email address is removed from our outbound-email log and from the security audit trail. We send one email to confirm the deletion. Two things outlive the account: the audit trail itself (which records that an account existed and what it did, by an opaque id) and the record of any single-use plan activation, so it cannot be applied twice. Stripe keeps its own payment records as the law requires.

You can also delete a single site and everything in it from Settings → Site without closing your account. Database backups are taken nightly and kept for 14 days, so deleted data is gone from every backup within 14 days.

7. Your rights

You can access and correct your account data in Settings, and delete it as described above. A copy of your data in a portable form - one JSON file with your account, sign-ins, support chats, your own audit trail and every workspace you belong to - downloads from Settings → Account → Export your data. Settings → Account also lists every device signed in to your account, with a way to sign each one out, and lets you withdraw analytics consent.

Depending on where you live, you may also have the right to object to or restrict processing, and to withdraw consent. To exercise any right, or if you can no longer sign in and want your account deleted, email [email protected]; we answer within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or to the data protection authority where you live.

8. International transfers and security

Our servers are in Finland. Some of the providers in section 3 process data in other countries, including the United States, Singapore and China. Where the law requires it, those transfers rely on the provider's Standard Contractual Clauses or an equivalent safeguard. Connections are encrypted in transit, stored CMS and Google credentials are encrypted at rest with AES-256-GCM, and access to production systems is limited to the people who run the Service.

9. Children's privacy

The Service is not directed at children under 16, and we do not knowingly collect data from them.

10. Changes to this policy

We may update this policy from time to time. When we do, we update this page and the effective date above; for a significant change we make reasonable efforts to tell you before it takes effect.

11. Contact

GrubGuru
British Columbia, Canada
[email protected]