Legal
Privacy policy
LAST UPDATED AUGUST 25, 2026
This policy explains the data we read, what we keep, and the controls you have before anything becomes public or available to an AI client.
What we access
When you connect Google Search Console, we request the read-only scope (webmasters.readonly) plus your basic Google profile. This lets us show your name, email, and profile picture in your private dashboard, list the properties you can manage, and read Search performance, sitemap status, and URL Inspection results for the site you choose. We cannot modify your site or Search Console settings. If you authorize an AI client through our MCP server, you choose which of those Search Console properties it may read and which property it should use by default. If you separately connect Google Analytics, a different OAuth client requests analytics.readonly for GA4 properties and web streams you choose. If you connect GitHub, you choose which repositories the GitHub App can access; the site-activity view reads repository details, languages, and commit history.
What we store
We store your basic Google profile, a server-side Search Console OAuth refresh token, and the list of eligible properties so the private dashboard can present a picker. For listed properties we store daily performance by selected search surface, device, country, and search appearance, plus selected URL Inspection and sitemap receipts, an inventory of your site's known page URLs used by the indexing view, and — if you set up IndexNow — the generated IndexNow key and a record of each page URL you submit with its acceptance status. We store SEO chat threads, questions, answers, progress, and credit usage so you can reopen a conversation and continue it. An MCP authorization stores the AI client name, selected properties, default property, creation and last-use times, and hashes of its rotating access and refresh tokens. The complete tokens are not stored. MCP access tokens expire after one hour and rotating refresh tokens expire after thirty days. Identical MCP tool results may be cached for fifteen minutes, then expire. MCP usage records contain the account, tool name, status, timing, and quota counters; they do not contain query text, page URLs, or Search Console result rows. If you optionally connect a TrustMRR startup, we store its public profile link, website, payment-provider label, verified revenue totals, aggregate customer and subscription counts, growth figure, and last refresh time after confirming its website or linked App Store seller website matches your Search Console property. You do not give us a TrustMRR or payment-provider API key. If you use a paid plan, we also store saved launch dates, owner-only query and page comparison snapshots, watched queries, private SEO audits, and bounded Site Checks. Daily Search Receipts retain aggregate totals, exact comparison dates, a bounded set of top query and page changes for ninety days, traffic-goal state, delivery state, and summary history. Site Checks retain page URLs and response state, extracted metadata, content fingerprints, internal-link sources and anchor text, findings, fixes, and separate field and lab performance measurements; the latest thirteen successful checks are retained. We also store Workbench tasks, task-scoped conversations and agent handoffs, structured Fix Kits and Article Kits, selected options, verification state, action status, usage records, portfolio and report preferences, and the Stripe identifiers needed to provide access. Growth agent connections store a token hash and prefix, scope, creation time, and last-use time; the complete token is shown once and is not stored. If you connect GitHub, we store the installation and selected repository identifiers, repository name, default branch, PR job status, generated branch, pull-request URL, and changed-file paths. The activity view also stores daily commit and unique-contributor counts, 90-day totals, repository statistics, and language totals. Commit messages and contributor identities are not stored. We do not store GitHub user access tokens or installation access tokens. If you separately connect Analytics, we store a separate refresh token, Google subject and granted scopes, the verified GA4 property and web stream, daily aggregate traffic metrics, top-page and channel totals, and AI-attributed sessions, engaged sessions, provider, and referral source. We do not store GA4 user identities, individual events, conversions, revenue, or full payment-card details.
What we publish
Only what you opt into: your listed site's daily clicks, impressions, CTR, and average position. Top queries, pages, device/country/search-appearance breakdowns, AI-referred visits, the Google Analytics traffic summary, and GitHub repository activity each follow their own owner visibility control. A public Analytics summary contains aggregate trends, top pages, and channel totals. A public GitHub summary contains daily commit totals, aggregate repository statistics, and language mix; private repository names and links stay private. Anonymous listings never show either integration. Index status, URL Inspection results, and sitemap evidence appear only in your private dashboard. A Launch Receipt is public only when you turn on its public share link. Daily Search Receipts, custom traffic goals, daily commentary, SEO action plans, Site Checks, performance evidence, watched queries, agent bundles and tokens, Opportunity Radar signals, your Google profile, and unlisted properties stay private.
Publishing connections
If you connect WordPress, Shopify, Webflow, Wix, Ghost, BigCommerce, HubSpot, Notion, Sanity, or a custom webhook, we store the destination settings and an encrypted copy of the provider token, API key, application password, or signing secret you enter. We decrypt that credential only to test the connection or send an Article Kit after you choose Create draft or Publish now. We store the destination, publication status, provider item ID, and returned page URL. Content API and custom-component connections use a token shown once; we store only its hash. Anyone who has that token can read the articles you add to that feed until you replace or remove the token. Removing a connection deletes its saved credential and publication records from SEO Receipts, but it does not delete posts already created in the provider.
Website and product analytics
Google Analytics records page views, referrers, device type, and general location so we can understand live traffic and improve the site. It may set first-party analytics cookies. A site address entered for the free check is moved between pages in temporary tab storage, not in the page URL. PostHog records page views, JavaScript errors, and specific product events such as report starts, authorization progress, task opens, checkout starts, and paid conversion. PostHog automatic element capture and session replay are disabled, so it does not record rendered private pages or what you type. Before a PostHog browser event is sent, URL and referrer query strings and fragments are removed. Signed-in events use a random account identifier and plan state; your name and email address are not sent to PostHog. Product events use bounded identifiers and counts without Search Console query text, target page URLs, property URLs, result rows, or generated work. We do not use analytics for advertising or personalization.
Private SEO analysis
When you ask SEO chat a question, SEO Receipts sends OpenAI your question, recent chat messages, confirmed site details, and the saved Search Console, site-check, performance, indexing, task, or change data needed to answer it. The assistant can also request bounded read-only research, including current Google results and keyword data, public page content, PageSpeed results, and saved reports for the site you selected. Those research results are returned to OpenAI as supporting data. SEO chat cannot change your site or Search Console settings. For each new published Growth-property Daily Search Receipt, SEO Receipts automatically sends Anthropic only that receipt's selected aggregate, search, page, milestone, and goal data. It does not fetch page content for the daily commentary, and the commentary does not use Workbench credits. For an SEO cycle, our rules first select up to five possible actions. SEO Receipts then sends OpenAI the saved business goal and the Search Console, current Google-result, page, analytics, indexing, and prior-decision data attached to those actions. OpenAI can approve, hold, or rule out only those actions; it cannot create a new action or change your site. When a paid owner requests a plan refresh, Fix Kit, Article Kit, task follow-up, agent handoff, or GitHub pull request, SEO Receipts sends Anthropic only the selected Search Console performance data, the relevant task, your question when applicable, and selected metadata and visible text from verified-property pages. A plan refresh can inspect up to three candidate pages; other work is restricted to its task and verified site. An Article Kit also includes its completed page brief, the verified internal URLs available to the task, and the original angle and reader outcome you submit. For a GitHub PR, we additionally send a limited repository tree and the source files selected as relevant to that task. We do not send Google OAuth credentials, GitHub tokens, account identity, email address, environment files, private keys, or unrelated account data. OpenAI and Anthropic return private work that our server validates against the supplied URLs, data, and allowed repository paths. A GitHub PR is created as a draft on a dedicated branch and is never merged or deployed automatically. All generated work requires your review.
Billing and email delivery
Stripe processes Pro and Growth checkout, subscription management, invoices, and payment methods under Stripe’s privacy terms. If you connect a TrustMRR startup, TrustMRR receives its public slug from our server and returns its verified public revenue record. Google PageSpeed Insights receives only the public owned-page URLs selected for a performance receipt and returns Lighthouse and, when available, Chrome UX data. Resend processes your connected email address, account name, and the task or report content needed to deliver messages you leave enabled. Optional reminders and reports can be turned off in Email settings or with the unsubscribe link in the message. Cloudflare hosts the application and database. These providers receive only the data needed for their role.
How Google's data is used
SEO Receipts's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Search Console and Analytics authorizations are isolated: granting, reconnecting, or revoking Analytics does not replace the Search Console token. We do not sell Google data or use it for advertising. We share it only when you choose to publish a receipt or when a provider needs it to operate a service you requested.
Revoking access
Disconnect on SEO Receipts or revoke either Google authorization at myaccount.google.com/permissions at any time. Removing an Analytics link deletes its stored traffic summaries and AI referral rows without changing Search Console. You can revoke one MCP client immediately under Dashboard, Account, Connections; its current access token and rotating refresh token stop working without disconnecting Google or another AI client. You can also revoke a Growth agent connection immediately in the Agent Desk, remove SEO Receipts from a site's selected repository in the Workbench, or revoke the GitHub App installation in GitHub settings. Removing the selected repository deletes its stored activity and language summaries. Disconnecting the account deletes both stored Google refresh tokens, MCP grants, GitHub and agent connection records, and private profile details, then freezes Search Console listings with a visible 'no longer verified' flag.
Deleting your data
Choose Delete my data in your dashboard to permanently remove your Google profile, both Google OAuth tokens, connected properties, SEO chats and credit records, MCP grants and cached tool results, public profiles, TrustMRR revenue connections, search-surface and breakdown history, URL Inspection and sitemap receipts, GA4 links and aggregate traffic rows, GitHub repository connections and activity summaries, publishing connections and credentials, publication records, top and watched queries, Daily and Launch Receipts, custom goals, Opportunity Radar comparisons, Crawl and performance receipts, agent connections, and private SEO plans. Posts already created in an external publishing provider remain there until you delete them in that provider. If you have a paid plan, we cancel its Stripe subscription immediately before deletion so billing cannot continue. Stripe may retain invoices and transaction records where legally required. The deletion cannot be undone, and deleted public profiles are blocked immediately. You may also email us if you cannot access the dashboard.
Contact
Questions or deletion requests: [email protected].