Legal · Privacy

Privacy Policy.

Effective Feb 1, 2026 · Last updated Aug 5, 2026

Introduction

Welcome to SEOLadders ("we", "our", "us"). SEOLadders is an AI visibility and SEO platform built for founders who ship their own content. We help you get cited across AI assistants (ChatGPT, Perplexity, Gemini, Claude) and Google's AI surfaces — and rank on Google — through AI Optimization monitoring, Keyword Research, Competitor Gap, Rank Tracker, Article Writer, Article Optimizer, Content Refresh, SEO Agent, and AutoBlog (scheduled publishing). The same capabilities are available through a REST API, an MCP server (Claude Code, Cursor, Windsurf, Codex), and HMAC-signed webhooks. This Privacy Policy explains how we collect, use, and protect your personal information when you use the platform, website, developer interfaces, and related services.

Information We Collect

We collect information to operate and improve our service. This includes:

  • Account details (name, email)
  • Workspace settings you configure (target site URL, domain rating, brand voice profile, target audiences, locale)
  • Saved keywords, competitor lists, rank-tracking history
  • Articles you generate or edit (drafts, published versions, revisions)
  • Site-audit and optimization reports tied to your workspace
  • API keys you create (stored hashed — we never retain the plaintext after creation)
  • Webhook signing secrets and delivery logs (status, response codes)
  • Connected-platform credentials (WordPress site URL, application password)
  • Google Search Console data you connect — read-only search-performance data (queries, pages, clicks, impressions, position) and your verified site list
  • Google Analytics data you connect — read-only GA4 report data (sessions, users, page views, engagement, key events, traffic sources, countries and devices) and the property that matches your site
  • Knowledge Base content you add — pasted notes, URLs you submit, uploaded files (PDF, text, Word), and the text we extract from them
  • AI Optimization data — the prompts you track, the AI answers we collect, and the brands/competitors mentioned in them
  • Usage information (which tools you use, surface-level quota counters)
  • Payment information (processed by Polar — we never store card numbers)

How We Use Your Information

We use your data to deliver the toolkit, run the AI pipelines you trigger, and meter your subscription:

  • To run keyword research, competitor gap, and rank tracking against live SERP data
  • To generate articles, images, schema, FAQs, and citations on your behalf — using your brand voice and domain rating
  • To deliver SEO Agent audits, Article Optimizer scores, and Content Refresh detections
  • To measure your AI visibility — running the prompts you track across AI engines and summarizing how they mention you and your competitors
  • To suggest prompts and keywords from your connected Google Search Console data, and to show where your traffic comes from using your connected Google Analytics data
  • To ground generated content in the facts you add to your Knowledge Base
  • To send product and lifecycle emails (welcome, setup tips, re-engagement) — you can opt out at any time
  • To publish articles to your connected CMS (WordPress) or webhook destinations
  • To deliver signed webhook events when articles, batches, optimizations, or refreshes complete
  • To meter usage against your plan quotas and surface usage in your dashboard
  • To process payments and manage your subscription via Polar
  • To communicate updates, security notices, and support replies
  • To check whether pages on your site still load — we request URLs from your own site (identifying ourselves as SEOLaddersBot) to find broken pages that still receive search traffic
  • To read publicly available pages on the competitor sites you choose to track, for comparison in your reports

We do not sell your data, and we do not share it with advertisers.

Data Sharing

We share data with service providers strictly to deliver the features you use:

  • Supabase / cloud hosting — application data and storage
  • DataForSEO — keyword volume, KD, SERP results, rank tracking, and AI Optimization queries routed to AI engines (ChatGPT, Perplexity, Gemini, Claude) and Google's AI surfaces
  • Anthropic & OpenAI — article generation, optimization analysis, AI editing, and Knowledge Base embeddings
  • FireCrawl — scrapes the web pages and Knowledge Base URLs/files you submit, to extract their text
  • Google — when you connect Google Search Console, we access your read-only Search Console data via Google's API
  • Image generation providers — AI illustrations for your articles
  • Polar — subscription billing and payment processing
  • Resend — transactional email (magic links, status notifications)
  • WordPress sites you connect — to publish drafts and final articles
  • Webhook URLs you configure — to deliver event notifications you've subscribed to

Data Retention

We retain your personal data while your account is active. After cancellation:

  • Workspace data (articles, keywords, audits) is retained for 90 days, then permanently deleted unless you reactivate
  • Webhook delivery logs are retained for 30 days for debugging and audit
  • Anonymized usage metrics may be retained longer for service-level analytics
  • Billing records are retained as required by financial reporting regulations

You may request immediate deletion of your data at any time by contacting us — see Contact Us below.

Data Security

We use industry-standard encryption, access controls, and security measures to protect your data:

  • Data in transit: TLS 1.2+ on all endpoints
  • API keys: stored as one-way hashes — the original is shown once at creation
  • Webhook signing secrets: rotatable on demand via API or dashboard
  • Webhook payloads: signed with HMAC-SHA256 over the raw body
  • Auth: passwordless (magic-link) with short-lived tokens
  • Database: managed Postgres with row-level security policies

No method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to reasonable industry practice.

Your Rights

Depending on your location, you may have the following rights:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent at any time

Third-Party Services

SEOLadders integrates with the following third parties to deliver the toolkit. When you use these features, the respective provider's privacy policy applies to data shared with them:

  • WordPress sites you connect — you provide the URL and application password; we use them only to publish articles you trigger
  • Webhook URLs you configure — we send signed payloads to the destinations you specify
  • DataForSEO — keyword/SERP queries and AI Optimization prompts you initiate are sent to their API (which routes them to the AI engines)
  • Anthropic & OpenAI — article generation, editing prompts, and Knowledge Base embeddings are sent to their APIs
  • FireCrawl — URLs and files you submit (site scans, Knowledge Base) are sent to their API to extract text
  • Google — your Search Console and Google Analytics data is accessed via Google's API when you connect them
  • Polar — payment events and subscription state
  • Resend — transactional and product email delivery

We do not authorize any of these providers to use your content for their own product training.

AI Optimization

AI Optimization measures whether AI assistants recommend your brand. When you run a monitor, we send the buyer questions you track (your "prompts") to AI engines — ChatGPT, Perplexity, Gemini, and Claude (via DataForSEO's LLM Responses API) and Google's AI Overviews & AI Mode (via DataForSEO's SERP API) — and store the answers.

  • The prompts you track and the AI answers we collect are stored in your workspace
  • We store the brand and competitor names surfaced in those answers to compute your visibility, share of voice, and sentiment
  • These queries are routed to the AI engines through DataForSEO; we don't send your account identity to them
  • We don't control how the underlying AI engines process the queries — their own policies apply

Knowledge Base

The Knowledge Base lets you add trusted context — pasted notes, URLs, and uploaded files (PDF, text, Word) — that the Article Writer uses to ground generated content in your real facts.

  • URLs and uploaded files are fetched and parsed by FireCrawl to extract their text
  • The extracted text is split into chunks and converted into embeddings by OpenAI for retrieval
  • The content and embeddings are stored in your workspace and used only to generate your content

Uploaded files are stored in cloud storage and processed from a URL. Please add only the brand and product context you want reflected in your content — don't upload secrets or sensitive personal data you wouldn't want stored.

Google Search Console & Analytics

If you connect Google Search Console or Google Analytics, SEOLadders accesses your Google account data through Google's API using two read-only scopes: webmasters.readonly and analytics.readonly. Each is optional and connected separately. SEOLadders' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Search Console — what we access: your search-performance data (queries, pages, clicks, impressions, click-through rate and average position) and your list of verified sites. Read-only; we never modify your Search Console.
  • Search Console — why: to show the queries and pages you already rank for, spot pages that are slipping or broken, and ground the topics we suggest writing about in real demand.
  • Analytics — what we access: your GA4 property list and data streams (to identify the property matching your site), and aggregated report data — sessions, users, page views, engagement, key events, and the channels, sources, countries and devices your visits come from. Read-only; we never change your Analytics configuration.
  • Analytics — why: to show where your traffic comes from, including how much arrives from Google search and from AI assistants such as ChatGPT and Perplexity.
  • Storage: your Google OAuth tokens are stored securely per workspace and refreshed only as needed to read this data. We store the reports we read so your dashboard loads without re-querying Google on every visit.
  • Sharing: we do not sell or share your Google data, do not use it for advertising, and do not use it to train models — including to train or improve any generalized AI or ML model.
  • Control: disconnect either connection anytime from your dashboard (which deletes the stored tokens), or revoke access from your Google Account permissions page.

AI Training & Model Use

Your content stays yours. Specifically:

  • We do not train AI models on your articles, keywords, audits, or workspace data
  • We do not allow our AI providers (Anthropic, OpenAI, image gen) to retain your prompts or outputs for training — these calls run with training opt-out where supported
  • Aggregated, anonymized statistics (e.g., 'X articles generated this month' across all users) may be used for product analytics
  • Generated articles, images, and analyses belong to you — see the Terms of Service for content ownership

Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Continued use of the service after updates means acceptance of the revised policy.

Contact Us

For privacy concerns, data requests, or any questions about this policy, reach us through our community — it's the fastest way to get a response, and it's open to everyone.

Go to contact