Privacy Policy
Version 1.0 · Last updated 1 August 2026 · Effective 1 August 2026
CapraSEO is an SEO tool operated by CapraSEO Inc. ("CapraSEO", "we", "us"). You connect websites you own, we read search and analytics data for those sites, and an AI assistant answers questions about it. This policy explains what we collect, why, who else touches it, how long we keep it, and how to get it back or delete it. It is written to be read, not to be survived.
1. Google user data, and our Limited Use commitment
Most of what makes CapraSEO useful is data that belongs to you and lives in your Google account. We take a deliberately narrow slice of it.
When you connect Google, we request these scopes and no others:
openidandemail— to identify your account and sign you in.https://www.googleapis.com/auth/webmasters.readonly— read-only access to Google Search Console: your verified properties, and the clicks, impressions, positions, queries and pages Google reports for them.https://www.googleapis.com/auth/analytics.readonly— read-only access to Google Analytics 4: sessions, engagement, key events (conversions), revenue where your property reports it, and the traffic sources and landing pages behind them.
Both are read-only. CapraSEO cannot change, publish, or delete anything in your Search Console or Analytics account, and never attempts to.
Limited Use. CapraSEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Concretely, that means: we use Google user data only to provide and improve the features you asked for; we do not sell it; we do not use it for advertising or transfer it to advertisers or data brokers; we do not use it to build unrelated profiles; and no human at CapraSEO reads it except with your explicit permission (for example, when you ask us to investigate a support issue), where it is necessary for security, or where the law requires it.
Google Search Console and Analytics data is never used to train AI models, and is never made available to any other CapraSEO customer.
How your Google data is stored and separated
To keep the product fast we cache the figures Google returns rather than re-requesting them on every page load. That cache is keyed on the domain, and it is access-controlled: a request only ever returns Search Console or Analytics figures for a domain when the account making the request has a matching verified Google property of its own. Another customer looking at the same domain cannot see your measured numbers — they see only third-party estimates, which are public data.
We store a Google refresh token so your reports stay current without you signing in every day. It is held server-side, is never sent to your browser, and is deleted the moment you disconnect — see section 15.
2. What we collect
| Category | Examples |
|---|---|
| Identifiers | Email address, name, profile picture URL, Google account identifier, account and user IDs |
| Google property data | Verified properties, clicks, impressions, positions, queries, pages, sessions, conversions, revenue |
| Configuration | Domains you add, competitors, target keywords, market and language, report schedules, alert settings |
| Content you create | Conversations with the assistant, generated articles, images, videos and screen recordings |
| Publishing credentials | WordPress application passwords, stored server-side only |
| API tokens | Tokens you create for external AI clients — stored only as a SHA-256 hash |
| Commercial | Package purchased, amount, time, Stripe reference, token balance and charge history; for crypto payments, the transaction reference and paying wallet address |
| Technical | IP address, browser user-agent, pages requested, timestamps, error logs |
We do not collect special-category data (health, biometrics, political opinions and the like), and we ask you not to put such data into the product. We never receive your Google password, and we never see full card numbers.
3. Where it comes from
- From you — everything you type, upload, configure or connect.
- From Google, with your authorisation — your profile basics at sign-in, and Search Console / Analytics figures for properties you have verified.
- From your browser automatically — the technical data above.
- From third-party data providers — public SEO data about domains (rankings, backlinks, estimated volumes). This describes websites, not people, and we do not receive personal data from these providers.
4. How we use it
- To run the features you use: reports, rankings, backlinks, competitor analysis, content generation, alerts, scheduled reports.
- To answer your questions. When you ask the assistant something, the relevant data for the domain in focus is sent to the AI model that answers it — see section 6.
- To bill you accurately and show you where your tokens went.
- To email or alert you about your account and the sites you monitor.
- To keep the service secure, prevent abuse, and diagnose faults.
- To comply with law, and to establish or defend legal claims.
We do not sell your personal data, and we do not use it for advertising. We do not share it for cross-context behavioural advertising.
5. Legal bases (UK/EU)
| Basis | Applies to |
|---|---|
| Contract | Running the account and delivering the features you signed up for, including billing |
| Consent | Connecting Google Search Console and Analytics. Withdrawable at any time, without affecting the rest of your account |
| Legitimate interests | Security, fraud and abuse prevention, service reliability, and product improvement that does not involve Google user data |
| Legal obligation | Tax and accounting records; responding to lawful requests |
6. AI models and your data
Chat answers, articles, images and videos are produced by third-party AI models reached through OpenRouter. To answer a question we send the model your prompt plus the relevant context for the domain in focus, which may include your Search Console and Analytics figures.
Two commitments about that:
- We instruct our AI providers not to train on data we send, and we select providers and routing options that support that. We do not train models on your data ourselves.
- Google user data is subject to the Limited Use terms above. Sending it to a model to answer your question is providing the feature you asked for; it is not a transfer for any other purpose.
AI output can be wrong. It is a suggestion, not advice, and you remain responsible for what you publish.
7. Who we share it with
We use a small number of sub-processors. Each receives only what its job needs. The current list, with what each one gets, is maintained at capraseo.com/legal/subprocessors/.
Beyond those, we disclose personal data only:
- where the law requires it, or in response to a valid legal request — we object to requests that appear overbroad or unlawful;
- to protect the rights, property or safety of CapraSEO, our users, or the public;
- to professional advisers (lawyers, accountants, auditors) under confidentiality;
- in connection with a merger, acquisition or sale of assets. You will be told before your data becomes subject to a different privacy policy.
We publish changes to our sub-processor list on that page. If you have a data processing agreement with us that requires advance notice of new sub-processors, that agreement governs.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Life of the account, then deleted within 30 days of account deletion |
| Google refresh tokens | Deleted immediately when you disconnect, or when the account is deleted |
| Cached Search Console / Analytics figures | Life of the account; access ends immediately on disconnection or deletion |
| Your content (chats, articles, images, video) | Life of the account, then deleted within 30 days |
| Publishing credentials | Until you remove the connection, or account deletion |
| Billing and tax records | Seven years, as tax law requires. Not deletable on request |
| Server and security logs | Up to 90 days, longer only where an incident is under investigation |
| Aggregated SEO data about domains | Retained indefinitely. This describes websites, not people, and is not personal data |
Backups are cycled out on a rolling basis, so deleted data may persist in backups for a short period after removal from live systems. It is not restored to the product.
9. Security
- All traffic is encrypted in transit with TLS.
- Sensitive credentials — Google refresh tokens, publishing passwords — are held server-side and are never exposed to the browser or to other customers.
- API tokens are stored only as SHA-256 hashes. A token you lose cannot be recovered from us, only replaced.
- Access to production systems is limited to personnel who need it, and Google user data is not browsed by staff except as described in section 1.
- Payment card data never touches our servers — it goes directly to Stripe.
No system is perfectly secure. If you find a vulnerability, please report it to security@capraseo.com; we will not pursue good-faith security research.
10. Cookies and tracking
CapraSEO sets one cookie: a signed session cookie that keeps you logged in. It is strictly necessary for the service to function, expires with your session, and is not used for tracking.
Your browser's local storage holds interface preferences such as light or dark theme. That never leaves your device.
We run no advertising cookies, no third-party trackers, and no cross-site profiling. Because we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off — but we honour such signals as an opt-out of any future non-essential processing.
11. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you;
- Correct it if it is wrong;
- Delete it — you can delete your account yourself at any time;
- Export it in a portable, machine-readable format;
- Restrict or object to particular processing;
- Withdraw consent, in particular your Google connection.
Email privacy@capraseo.com. We respond within 30 days, and will not charge you or degrade your service for asking. We may need to verify your identity before acting, which we normally do by confirming control of the account email.
If you are in the UK, EU or EEA you also have the right to complain to your national data protection authority. We would rather you told us first.
12. California rights (CCPA/CPRA)
If you are a California resident, you have the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit use of sensitive personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, including for anyone under 16. There is accordingly no "Do Not Sell or Share My Personal Information" mechanism to offer — nothing is being sold or shared to opt out of.
The categories we collect are listed in section 2; the sources in section 3; the business purposes in section 4; the categories of recipients in section 7; and retention in section 8. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
You may use an authorised agent to exercise these rights, with written proof of authorisation. We will not discriminate against you for exercising them.
13. International transfers
CapraSEO Inc. is established in the United States, and some of our sub-processors operate there and elsewhere. Where personal data of UK/EEA users is transferred out of the UK/EEA, we rely on the transfer mechanisms available to those providers — generally the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), and the EU–US Data Privacy Framework where the provider is certified. A copy of the relevant safeguards is available on request from privacy@capraseo.com.
14. Automated decisions
CapraSEO scores and ranks websites — opportunities, keyword difficulty, publisher quality. It does not make automated decisions about people that produce legal or similarly significant effects, and it does not profile you. Every recommendation the product makes is advisory, and a human decides whether to act on it.
15. Disconnecting Google
You can disconnect Search Console or Analytics inside CapraSEO at any time, from the Domains page. That deletes the stored refresh token immediately and stops all further access.
You can also revoke access from Google's side at myaccount.google.com/permissions, which works whether or not you still have a CapraSEO account.
Disconnecting stops new data arriving. To remove the data already cached for your account, delete the domain or your account, or ask us at privacy@capraseo.com.
16. Breach notification
If a personal data breach affects you, we will notify you and the relevant supervisory authority within the timeframes the law requires — under the GDPR, the authority within 72 hours of becoming aware, and affected users without undue delay where the risk to them is high. Notice will describe what happened, what data was involved, what we have done, and what you should do.
17. Children
CapraSEO is a business tool, is not directed at children, and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it promptly.
18. Changes to this policy
We update the version and date at the top whenever this policy changes. If a change materially affects how we handle your data, we will give you notice in the product or by email at least 14 days before it takes effect, so you can object, export your data, or close your account. Continuing to use CapraSEO after that means you accept the updated policy.
19. Contact
CapraSEO Inc. is the controller of the personal data described in this policy.
- Privacy and data requests: privacy@capraseo.com
- Security reports: security@capraseo.com
- Everything else: legal@capraseo.com