Privacy policy
Last updated Oct 4, 2026
This policy explains what personal data SEO for SaaS collects, why, who else handles it, how long we keep it, and your rights.
Who's responsible for your data
The controller is Marcin Piechaczek, trading as "SEO for SaaS". Our full business details are in our Terms.
For any privacy question or request, write to support@seoforsaas.dev.
The short version
We collect what we need to run your account, write your articles, and bill you: your email address, your name, your workspace, your sites, and, if you connect it, your Search Console data.
We don't sell personal data and don't show ads. We measure visits with Plausible, which uses no cookies and stores no IP addresses.
Link, our reseller, handles your payment and receives your payment details directly. We never see your card number.
To write articles we send your site's content and search data to the AI and data providers described below.
What we collect and why
Your account
| Data | Why | Legal basis | How long |
|---|---|---|---|
| Email address, name, and, if you sign in with Google, your Google profile picture link and Google account ID | Create your account and sign you in | Contract (GDPR art. 6(1)(b)) | Until you delete your account |
| Google sign-in tokens, if you sign in with Google | Complete Google sign-in | Contract | Until you delete your account |
| Workspaces you belong to, your role, and invitations you send or receive (the invited email address) | Run shared workspaces and seats | Contract | Until you leave or delete the workspace. Invitation links expire after 48 hours |
| Sign-in links and email-change links | Sign you in without a password | Contract | Each link works once and expires after 10 minutes |
Security
| Data | Why | Legal basis | How long |
|---|---|---|---|
| For each signed-in session: IP address, browser user agent, and when it started | Keep your account secure and show you your active sessions | Legitimate interest in security (art. 6(1)(f)) | Deleted when you sign out or end the session. Otherwise deleted within 90 days after it expires; we keep it that long to investigate abuse (a session lasts up to 7 days unless it's refreshed) |
| IP address with a request counter, to stop abuse of sign-in, invitations, and other sensitive actions | Rate limiting | Legitimate interest in security | About 2 days |
| For our free sitemap checker: a keyed, one-way code made from your IP address | Rate limiting. The code can't be turned back into the address | Legitimate interest in preventing abuse | About 2 days |
| A bot check on the sign-in form | Tell people from bots | Legitimate interest in security | We only receive pass or fail |
| Server logs of requests to our app and API (they can include your IP address and user agent) | Fix errors and investigate abuse | Legitimate interest | Kept briefly by our hosting provider, then deleted |
| For requests to our API with a content or API key: IP address and user agent of the calling server, with the action taken | Audit trail of what each key did | Legitimate interest in security | 90 days, then deleted automatically |
Visits to our website and app (Plausible Analytics)
We use Plausible Analytics to count visits to our public website (seoforsaas.dev and docs.seoforsaas.dev) and the app at app.seoforsaas.dev. Plausible uses no cookies, no local storage, and no other identifier stored on your device.
For each page view Plausible receives the page address, the referring site or campaign, your browser, operating system and device type, and the country, region, and city worked out from your IP address. It doesn't store your IP address or full user agent. To count unique visitors per day, it makes a one-way code from a daily salt, our domain, your IP address, and your user agent; the salt is deleted every 24 hours, so visits can't be linked across days.
The legal basis is our legitimate interest in understanding how our site is used (art. 6(1)(f)). We see only totals, never individual visitors. Plausible acts as our processor, and the data stays in the EU. See Plausible's data policy.
Billing
Link (Sold through Link, LLC, a Stripe company) is the merchant of record. When you pay, Link collects your payment details, billing address, and tax ID directly, as an independent controller under its own privacy policy (link.com/privacy). We never see your full card details.
| Data | Why | Legal basis | How long |
|---|---|---|---|
| Your Stripe customer ID, subscription ID, plan, billing period, and status | Know which plan your workspace has | Contract | While your workspace exists |
| After you delete your workspace: the Stripe customer and subscription IDs, plan, billing periods, status, and dates (no name or email) | Keep tax records | Legal obligation under Polish tax law (art. 6(1)(c); Tax Ordinance art. 86 and 70) | Until December 31 of the sixth year after the last payment |
| Order data Link shares with us (your name, email, billing address, tax ID, and order details, visible in our Stripe account) | Answer billing questions and keep accounts | Contract and legal obligation | Kept by Stripe under its own retention, unless you ask Link to delete it. Our accounting exports are kept for the period tax law requires |
Your sites and articles
| Data | Why | Legal basis | How long |
|---|---|---|---|
| The sites and apps you add, what we read from their public pages, a screenshot of the home page, and the brand profile we build from them | Write articles that fit your product | Contract | Until you delete the site or your account |
| Author details you enter for the byline (name, role, links) | Credit articles to your author | Contract | Until you change them or delete the site |
| Articles, topics, the source links behind each article, and their history | The service itself | Contract | Until you delete the site or your account |
| Article images | Illustrate articles | Contract | They stay on our media server, including after you delete a site or your account, until you ask support@seoforsaas.dev to delete them |
| A webhook address you give us, and a log of deliveries to it | Tell your site about new articles | Contract | Deliveries: 15 days |
| What you enter in onboarding before you pay (your site address, and the preview we build) | Show you a preview of your topics | Steps before a contract (art. 6(1)(b)) | Until you delete your account, which you can do anytime in account settings |
Google Search Console, if you connect it
| Data | Why | Legal basis | How long |
|---|---|---|---|
| A read-only access token for your Google account, stored encrypted | Read your Search Console data | Contract, at your request | Until someone in the workspace disconnects it, or the workspace is deleted (we also revoke it at Google). You can also remove our access in your Google account |
| Daily clicks, impressions, and positions per page and per search query, and whether each page is indexed | Site Guard, rewrites, rank tracking, and topic choice | Contract | Until you delete the site or your account. We keep it longer than Google's 16 months so you can compare over time |
Search queries are mostly words people typed into Google. Google removes rare queries that could identify someone before we receive them.
Google API Services. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We use Search Console data only to provide and improve the features you see in SEO for SaaS. We don't use it for advertising, don't sell it, and don't use it to train AI models. We share it with our AI model provider and our search data provider only to choose topics for you and to write and rewrite your own articles. Our AI model provider's terms don't allow it to train on this data.
Support and email
| Data | Why | Legal basis | How long |
|---|---|---|---|
| Emails you send to support@seoforsaas.dev and our replies | Answer you | Contract or legitimate interest | 3 years after the conversation ends |
| Emails we send you: sign-in links, invitations, welcome, first articles ready, Search Console disconnected | Run the service | Contract | We send only service emails. No newsletters or marketing |
Public information about other people
To write articles, we read public web pages, search results, public discussions such as Reddit threads, and public App Store and Google Play reviews. We use this material only to research articles and cite sources, and we don't build profiles of anyone. We use the text of a post, not who wrote it, and we don't keep posters' usernames. The legal basis is our legitimate interest in writing researched articles (art. 6(1)(f)).
How long:
The research gathered for an article stays with the record of that article's run for up to 30 days after the run ends, then it's deleted. It isn't stored in our database.
Search result data is cached for up to 6 hours.
The links to an article's sources are kept with the article and deleted with it.
Free tools
Click-through rate checker and FAQ schema generator: your browser does the work. The file or text never leaves your computer.
Sitemap checker: we fetch the public site address you enter, read robots.txt, the sitemap, and up to 10 pages, then discard them. We keep only the scrambled IP code described under Security.
What you have to give us
You need an email address to create an account, and a site address to get articles; without them we can't provide the service. Everything else, such as your name, author details, or a Search Console connection, is optional.
Who else handles your data
We use service providers to run SEO for SaaS. They process data only on our instructions, under data processing terms, except where we say they act on their own behalf.
Hosting and infrastructure: servers, file storage, email delivery, and bot protection on a global network; our databases are in the EU.
AI model providers (United States): analyze your site, and research, write, check, and illustrate your articles.
Web and search data providers (outside the EEA): read your site and other public web pages, and supply search results, keyword data, discussions, and app store reviews.
Analytics (EU): Plausible, described above.
Email (may be outside the EEA): the mailbox our support address forwards to.
Accounting (Poland): our accounting service, for invoice and payout records.
These companies act on their own behalf, under their own privacy policies:
Link and Stripe handle checkout, payments, tax, invoices, and refunds.
Google handles Google sign-in and Search Console access, when you choose to use them.
For the current list of our providers, write to support@seoforsaas.dev.
Transfers outside the EEA
Some providers are in the United States or process data there. We rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses. Write to us for a copy of the safeguards.
AI and your data
We don't train AI models on your data.
Our AI model provider processes what we send it only to produce the result and, under its terms, doesn't use it to train its models.
No decision about you with legal or similarly significant effects is made by automated means.
How we protect data
Every connection uses HTTPS.
Your Search Console token and your workspace's API key are stored encrypted, and the encryption keys are kept apart from the database.
There are no passwords to leak: you sign in with an emailed link or Google.
Sign-in, invitations, and other sensitive actions are rate limited.
Deleting your account needs a sign-in within the last 24 hours.
If you're a customer: a data processing agreement
If you need a data processing agreement for the personal data we process for you (such as author bylines and Search Console data), write to support@seoforsaas.dev and we'll send one.
Your rights
You have the right to:
access your data and get a copy of it;
correct it;
delete it ("right to be forgotten");
restrict how we use it;
data portability: get the data you gave us in a common, machine-readable format;
object to processing based on our legitimate interest;
complain to a supervisory authority. In Poland that's the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). You can also complain in the EU country where you live or work.
How to use them:
Delete your account yourself on the account page. It deletes your account and the workspaces only you are in, with their sites and articles, and revokes our Search Console access at Google for those workspaces. A Search Console connection you made for a workspace others still use stays with that workspace until someone disconnects it, or you remove our access in your Google account. Article images stay on our media server until you ask us to delete them.
Everything else, including a copy of your data or deleting your article images, by email to support@seoforsaas.dev from your account's address. We may ask you to confirm the request from that address. We answer within one month, as the law requires.
Payment data held by Link: ask Link directly through support.link.com. If Link deletes your data, it also cancels subscriptions it sold you.
Children
SEO for SaaS is for businesses. We don't knowingly collect data from anyone under 18.
Cookies
We use only cookies needed to sign you in and keep you secure, plus a few settings stored in your browser. Our cookie policy lists them.
Changes to this policy
We'll publish any change here with a new date. If a change affects how we use data you've already given us, we'll email the workspace owner at least 30 days before it applies.