Information we collect
We collect information in three ways: information you provide directly, information collected automatically when you use the service, and information from third parties (such as Google Search Console when you connect it).
Information you provide
- Account information: name, email, password (hashed, never stored in plain text), company name, and role.
- Billing information: handled by Stripe — we receive the last four digits of your card and the issuing country, never the full card number.
- Communications: when you email us or use the contact form, we retain those messages so we can reply and reference them later.
- Content you create: projects, keyword lists, content briefs, comments, and other content you generate inside the platform.
Information collected automatically
- Usage data: pages visited, features used, query frequency, click patterns. Used to improve the product.
- Device data: IP address, browser type, operating system, screen resolution. Used for security and to render the UI correctly.
- Cookies and local storage: as detailed in our cookies section below.
Information from third parties
- Search Console + GA4 data when you authorize the connection.
- OAuth provider data (Google, Microsoft) when you sign in via SSO.
- Payment provider responses from Stripe.
How we use information
We use the information we collect to operate the service, communicate with you, improve the product, prevent abuse, and meet our legal obligations.
- Operate the platform: render the dashboard, run audits, deliver reports, sync integrations.
- Authenticate and secure your account: detect suspicious sign-ins, enforce rate limits, audit access.
- Communicate: send transactional emails (receipts, alerts, important updates) and optional product newsletters you can unsubscribe from.
- Improve the product: aggregated, anonymized analytics drive what we build next.
- Prevent abuse and fraud: block scrapers, abusive automation, and violations of the Terms of Service.
- Meet legal obligations: comply with valid legal requests, tax requirements, and accounting laws in India and the jurisdictions where we have users.
Data retention
We keep your information only as long as we need to provide the service and meet our legal obligations.
- Active account data: retained while your account is active.
- After account closure: workspace data is preserved for 90 days in case you want to reactivate, then permanently deleted unless legal retention obligations require otherwise.
- Backups: encrypted backups are retained for 30 days, then overwritten.
- Billing records: retained for the period required by Indian tax law (typically 8 years).
- Support communications: retained for up to 2 years for context on future tickets.
Your rights
Depending on where you live, you have specific rights over your personal information. We honor all of them globally, regardless of where you're located, because it's the right thing to do.
Your rights include
- Access — request a copy of the information we hold about you.
- Correction — request that we correct inaccurate information.
- Deletion — request that we delete your information (subject to legal retention requirements).
- Portability — request your information in a machine-readable format.
- Object or restrict — object to certain uses of your information, or ask us to restrict processing.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time.
- Lodge a complaint — with your local data protection authority (in the EU), the Information Commissioner's Office (UK), the California Attorney General (CA), or India's Data Protection Board (DPDP).
How to exercise these rights
Email privacy@seonova.io from the email address associated with your account. We respond within 30 days, or sooner where the law requires.
International data transfers
We're headquartered in India, with infrastructure primarily in the United States and (optionally, on enterprise plans) the European Union. This means your information may be transferred across borders to operate the service.
For transfers out of the EU/UK/India, we rely on Standard Contractual Clauses (or equivalent) between us and our sub-processors. EU enterprise customers can request data residency in the Frankfurt region; see our /security page for current availability.
Children's information
SEONova is a business product not intended for children. We do not knowingly collect personal information from anyone under 16. If you believe we have collected information from a child, email privacy@seonova.io and we will delete it.
Changes to this policy
We update this policy as our practices change. Material changes are announced by email to account holders at least 30 days before they take effect. The 'Last updated' date at the top of this page reflects the most recent meaningful change.
How to reach us
For privacy questions, data requests, or complaints, email privacy@seonova.io. For security issues, email security@seonova.io. For everything else, hi@seonova.io reaches the founding team directly.