Legal

Privacy Policy

Last updated: October 6, 2026

This Privacy Policy explains how seosorted.ai (“seosorted”, “we”, “us”) collects, uses, and shares information when you use our website and services.

By using seosorted.ai, you agree to the collection and use of information in accordance with this policy.

1. Information we collect

We collect information you provide directly, information generated as you use the service, and information from third-party integrations you choose to connect.

  • Account information — your name, email address, and authentication identifiers when you sign up or sign in.
  • Workspace and content data — the sites, keywords, articles, and other SEO data you create or import into your workspace.
  • Connected integrations — data we access on your behalf from services you authorize, such as Google Search Console, Google Analytics, YouTube, and your CMS, together with the access credentials and the site, collection and field identifiers needed to keep publishing there. See the sections below for what each integration stores.
  • Billing information — processed by our payment provider (Stripe); we do not store full card numbers.
  • Usage and device data — log data, IP address, browser type, and interactions with the product, used to operate and improve the service.

2. How we use your information

  • To provide, maintain, and improve the service, including generating SEO audits, articles, and analytics.
  • To authenticate you and secure your account and workspace.
  • To process payments and manage subscriptions.
  • To communicate with you about your account, updates, and support requests.
  • To detect, prevent, and address fraud, abuse, and technical issues.
  • To comply with legal obligations.

3. Google user data

When you connect Google Search Console or Google Analytics, we request read-only access through Google OAuth. We request the narrowest scopes that support the features you use, and we never request write access to your Google account.

  • https://www.googleapis.com/auth/webmasters.readonly — reads the Search Console properties you select, along with their queries, clicks, impressions, and index coverage, so we can report your search performance, surface ranking opportunities, and measure the impact of articles you publish.
  • https://www.googleapis.com/auth/analytics.readonly — reads the Google Analytics 4 properties you select and their reports, so we can attribute sessions, engagement, and conversions to the pages and articles in your workspace.

seosorted.ai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means we use Google user data only to provide and improve the user-facing features described above; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you; we do not use it for advertising, advertising personalization, or credit-scoring purposes; we do not sell it; and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

Google user data is not used to train foundation models. OAuth tokens are stored encrypted and used only to make requests on your behalf. You can disconnect a Google integration at any time from your workspace integration settings, or revoke our access directly at https://myaccount.google.com/permissions; disconnecting stops all further access and deletes the stored tokens.

4. YouTube API Services

seosorted.ai uses YouTube API Services. When you connect a YouTube channel, we request read-only access through Google OAuth. By connecting YouTube you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms), and Google's handling of your data is described in the Google Privacy Policy (https://policies.google.com/privacy).

  • https://www.googleapis.com/auth/youtube.readonly — reads the channel on the account you connect (its ID, title, handle, thumbnail, country and public subscriber and video counts) and that channel's videos (titles, descriptions, tags, thumbnails, publish dates, durations, privacy status, and view, like and comment counts), so we can show your published videos, suggest topics and target keywords, and check whether your videos are cited in Google AI Overviews.
  • https://www.googleapis.com/auth/yt-analytics.readonly — reads your channel's daily analytics (views, impressions, impression click-through rate, and subscribers gained and lost), so we can chart your channel's performance and analyse what is working.

How we use and share it: YouTube data is used only to provide the YouTube features in your workspace. To produce channel analyses, topic ideas and scripts you request, relevant video and analytics data is processed by our AI infrastructure provider, Azure AI Foundry, solely to generate that output. We do not sell YouTube data, use it for advertising, or share it with any other third party except as required by law. The Limited Use commitments in the Google user data section above apply to YouTube data as well.

Storage and retention: we store an encrypted OAuth token and the data listed above in our database in Microsoft Azure (East US). We refresh it from YouTube every day while your channel is connected and never keep YouTube API data for more than 30 days without refreshing it. We do not place cookies or read data on your device to access YouTube; the connection runs entirely server-side.

Revoking access and deletion: you can disconnect YouTube at any time from your workspace integration settings. Disconnecting revokes our token with Google and deletes the stored channel details, videos, daily analytics, AI Overview citation checks and channel analyses. You can also revoke our access through the Google security settings page at https://security.google.com/settings/security/permissions; once access is revoked, we delete the stored YouTube data within 30 days. To request deletion at any other time, email hello@seosorted.ai.

5. Connected CMS platforms (Webflow, WordPress, Shopify, webhooks)

When you connect a CMS so that seosorted.ai can publish for you, you authorize it through that platform's own OAuth screen and choose which site we may access. Unlike our Google integrations, a CMS connection necessarily includes write access, because publishing an article means creating content in your CMS. We never modify your designs, themes, or site settings, and we only write to the single collection or blog you select.

  • Webflow — we request sites:read, cms:read and cms:write. We read the list of sites and CMS collections you granted, and the fields on the collection you choose, so you can map each part of an article to the right field. We create and update items only in that collection.
  • WordPress, Shopify and generic webhooks — we use the credentials or endpoint you supply to create posts and upload the images attached to them.

What we store from a CMS connection: an encrypted access token, and the identifiers needed to publish again — the site ID, collection or blog ID, the site's display name, and the field mapping you configured. For each article we publish we also store the item ID the platform returns and its public URL, so we can update or unpublish that article later. We do not copy your existing CMS content, customer records, orders, or visitor data into seosorted.ai.

Disconnecting: you can disconnect a CMS at any time from Project Settings → Integrations. For Webflow we call Webflow's authorization-revoke endpoint, so our access ends on Webflow's side as well as ours. We then delete the stored integration record — including the encrypted token, the site and collection identifiers, and your field mapping — and clear the stored item IDs and published URLs of articles published through that connection. Articles already published remain live on your site; removing them is done in your CMS. You can also revoke our access from inside Webflow (Site settings → Apps & integrations), WordPress, or Shopify at any time.

6. Where we store your data

Your workspace data, including connected-integration credentials, is stored in Microsoft Azure in the East US region (United States). Generated images are stored in Google Cloud Storage. Job queues are held transiently in Redis within the same Azure environment. Authentication is handled by Google Firebase Authentication, payments by Stripe, and AI generation by Azure AI Foundry. If you access the service from outside the United States, your information will be transferred to and processed in the United States.

7. AI processing

The service uses AI models to generate SEO research, outlines, and content. Data you submit for generation may be processed by our AI infrastructure providers solely to produce your requested output. We do not sell your data, and we do not use your workspace content to train foundation models operated by third parties.

8. How we share information

We do not sell your personal information. We share it only with service providers who process it on our behalf under contractual safeguards, including:

  • Cloud hosting and infrastructure — Microsoft Azure (application, database and job queue) and Google Cloud Storage (generated images).
  • Authentication — Google Firebase Authentication.
  • AI generation — Azure AI Foundry.
  • SEO data providers used to power keyword, SERP, backlink and rank features.
  • Payment processing (Stripe).
  • Analytics and error-monitoring providers.
  • Where required by law, or to protect our rights, safety, and property.

9. Data retention

We retain your information for as long as your account is active or as needed to provide the service.

  • Integration credentials and data — deleted immediately when you disconnect that integration, as described above. There is no grace period and no archived copy.
  • Account deletion — when you delete your account we mark it deleted at once and stop all processing, then permanently erase it after a 7-day grace period. Signing in during those 7 days cancels the deletion. After the grace period we delete your workspaces and everything under them, including articles, keyword data, audits and integration records, and we delete your authentication record.
  • Workspace deletion — deleting a workspace removes its content and its integration records, including any stored credentials.

We may retain a limited subset of data beyond these periods where retention is required for legal, accounting, or security purposes — for example invoice records we are obliged to keep. Backups are rotated on a rolling basis and purged copies age out with them.

10. Security

We use industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS), access controls, and workspace-level isolation. Every third-party OAuth token and integration credential we hold — Google, Webflow, WordPress, Shopify and webhook secrets alike — is encrypted at rest with AES-256-GCM before it is written to the database, and is decrypted only in memory at the moment we make a request on your behalf. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise most of these rights directly in your account settings or by contacting us.

12. International transfers

We may process and store information in countries other than where you reside. Where we transfer personal data across borders, we rely on appropriate safeguards as required by applicable law.

13. Children's privacy

The service is not directed to children under 16, and we do not knowingly collect personal information from them.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date above and, where appropriate, through the service or by email.

15. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at hello@seosorted.ai.