Privacy policy
This explains what SEO Tracker for AI collects, why we collect it, who else gets to see it and what you can ask us to do about it. We have written it to be read, not to be survived.
The short version
We collect what the product needs to work: your account details, the websites and keywords you ask us to watch, and the measurements we take of those websites. We do not sell your data, we do not run advertising, and we put no tracking cookies on this site. If you connect Google Search Console, our access is read only and that data is used solely to show you your own reporting.
1Who we are
SEO Tracker for AI is operated by Lumatech Ltd, a company registered in England and Wales, company number 06082377. We are the data controller for the personal data described in this policy.
In this policy, “the service” means this website at seotrackerforai.com and the application at app.seotrackerforai.com. For anything to do with privacy or your data, email us at hello@seotrackerforai.com.
2What we collect
Your account
Your name, email address, and a password stored only as a one-way hash (we never see or store the password itself). We record whether your email has been verified, whether you have turned on two-factor authentication and the secret needed to check your codes, which workspace you belong to and your role in it, and any invitations sent to or by you.
Billing details
Your plan, subscription dates, billing address, VAT number if you give us one, any discount code applied, and the invoices we issue you. Card payments are handled entirely by Stripe. Card numbers never reach our servers and we cannot see them.
What you ask us to monitor
The domains you add, the keywords and locations you track, the competitors you name, the questions you want asked of AI assistants, the notes and annotations you record against your charts, and the site context you write to describe your business. This is your content. Some of it may contain personal data if you choose to put personal data in it, for example a person’s name as a keyword or in a note.
Measurements we take of websites
Search rankings, backlinks, page speed results, technical audit findings, security and domain health checks, AI visibility results and AI readiness scores. This is information about websites rather than about people, and it is gathered from publicly available sources or from data providers. Our scanner identifies itself honestly when it requests pages, and signs its requests so any site can verify the traffic came from us.
Technical and security records
When you sign in we store a session record containing your IP address and browser user agent, so you can see and end your own sessions and so we can investigate suspicious access. Our hosting platform, Cloudflare, produces operational logs of requests to the service. We also use Cloudflare Turnstile on the sign-up, sign-in and password reset forms to tell people apart from bots.
Enquiries
If you fill in the interest form on this site, we collect the name, company and email address you give us, and the message is emailed to us so we can reply. If you email us, we keep that correspondence.
3Google Search Console data
Connecting Google Search Console is optional. If you do connect it, you are taken to Google to sign in, and Google (not us) asks you to approve read-only access to your Search Console data. We never see your Google password.
What we store as a result of that connection:
- The email address of the Google account that authorised us, so you know which login is linked.
- A refresh token, which lets us pull your data on a schedule. It is encrypted at rest with AES-GCM using a key held separately from the database.
- The performance data itself: clicks, impressions, average position and click-through rate, broken down by search query, page, device and day, for up to the 16 months Google retains.
Our Limited Use commitment
SEO Tracker for AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain terms: we request read-only access and nothing more, we use your Search Console data only to provide the reporting features you signed up for, we do not sell it, we do not use it for advertising, and we do not use it to train generalised artificial intelligence or machine learning models. No human at our company reads it except where you have asked us to help with a support problem, where it is needed to investigate a security incident or abuse, or where the law requires it.
You can disconnect at any time from the Connections page in the app, and you can revoke our access independently at your Google account permissions page. When you disconnect, we delete the stored refresh token.
4Why we use it, and our legal bases
UK data protection law requires us to have a lawful basis for each use of personal data. Ours are these.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account, take the measurements you asked for, show you the results | It is the service you signed up for | Contract |
| Send service email: verification, password resets, invitations, invoices, notices about the service | You cannot use an account you cannot verify or recover | Contract |
| Take payment and issue invoices | To bill you correctly and to meet UK tax and accounting rules | Contract and legal obligation |
| Keep sign-in records, run bot checks, monitor for abuse | To keep accounts and the service secure | Legitimate interests (securing our service) |
| Diagnose faults and improve the product | To fix what is broken and build what is needed | Legitimate interests (running and improving a service you use) |
| Reply to your enquiry from the interest form | You asked us to get in touch | Legitimate interests (responding to a request you made) |
We do not send marketing email to customers unless you have asked to receive it, and every such email carries an unsubscribe link. We do not make automated decisions that produce legal or similarly significant effects about you, and we do not profile you for advertising.
5AI assistants and MCP
The product lets you connect an AI assistant to your account through MCP, so you can ask questions of your own data in plain English. Two things are worth being clear about.
- That connection cannot reach your website, your billing or your account. A connected assistant can read your reporting data, add keywords, AI visibility questions and competitors to your tracking within the allowance your plan includes, and leave notes on your charts. It cannot change your settings, your plan, your billing or your account, and it cannot spend beyond your plan.
- When you use it, your data goes to your assistant’s provider. If you connect an assistant and ask it about your rankings, the data it requested is sent to whoever operates that assistant, and their privacy terms apply to what happens next. That transfer happens because you asked for it, at the moment you ask. We do not send your data to AI providers on our own initiative, and we do not use your data to train AI models.
Separately, the AI visibility feature asks public AI assistants the questions you configured, to see whether your site is mentioned. Those questions are the ones you wrote. They do not contain your account details.
7Where your data is held
Our database is hosted by Cloudflare, and the service runs on Cloudflare’s network, which serves requests from data centres around the world. Several of our suppliers are based in the United States. Where personal data leaves the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with the supplier’s own technical safeguards. You can ask us for details of the safeguards used for any particular supplier.
8How long we keep it
- Account and workspace data: for as long as your account is open, then deleted within 90 days of closure unless we have to keep it for one of the reasons below.
- Measurement history: for the life of your account. History is the point of a tracker, so we do not trim it while you are using it.
- Invoices and tax records: six years from the end of the accounting period, as UK tax law requires.
- Google Search Console tokens: deleted as soon as you disconnect, or when Google revokes them.
- Sign-in sessions: until they expire or you sign out.
- Operational logs: kept short term for troubleshooting, in line with our hosting platform’s retention.
- Enquiries and support email: up to two years after the conversation ends.
9How we protect it
- Everything travels over HTTPS. There is no unencrypted route into the service.
- Passwords are stored as one-way hashes, and must be at least 12 characters.
- Two-factor authentication is available on every account, and we recommend it.
- Google refresh tokens are encrypted at rest with a key that is not stored in the database.
- Sign-up, sign-in and password reset are protected by a bot check.
- Access to production data is limited to the people who need it to run the service.
No service can promise perfect security. If a breach happens that is likely to put your rights at risk, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you without undue delay where the law requires.
11Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong or incomplete.
- Delete your data, where we do not have to keep it for legal reasons.
- Restrict or object to how we use it, including anything based on our legitimate interests.
- Provide your data in a portable, machine-readable format.
- Withdraw consent, where we relied on consent, without affecting what came before.
Email hello@seotrackerforai.com and we will respond within one month. There is no charge. Account deletion is currently handled by us on request rather than by a button in the app, and we will confirm once it is done.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
Where you use the service to monitor websites, you decide what goes into your workspace. If that includes personal data, you are the controller of it and we process it for you under section 6 above. We are happy to sign a data processing agreement if your organisation needs one.
12Age of users
This is a business tool. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
13Changes to this policy
We update this policy when the product changes or the law does. The date at the top always shows the current version. If a change materially affects how we use your personal data, we will email account holders rather than rely on you noticing.
Contact us
Privacy questions, data requests, or anything in this policy that does not make sense: hello@seotrackerforai.com.
Lumatech Ltd, registered in England and Wales, company number 06082377. If you need a postal address for a formal request, ask and we will provide it.