Privacy Policy
The short version
- We collect what’s needed to run your account, plus the site and client data you choose to put in.
- We don’t sell your data, and we don’t train AI models on your workspace.
- Section 5 lists every outside company that receives data, and what each one gets. No vague “trusted partners”.
- Much of what you store belongs to your clients. Section 6 is about that specifically.
- Email [email protected] to get a copy of your data or have it deleted.
- 1. Who we are
- 2. What we collect
- 3. Data from accounts you connect
- 4. Why we use it
- 5. Who else receives data
- 6. Your clients’ data
- 7. AI features
- 8. Cookies
- 9. How long we keep things
- 10. Security
- 11. Your rights
- 12. Children
- 13. Where data is held
- 14. Changes
- 15. Contact
1. Who we are
AlmaSEO LLC, a South Carolina limited liability company, operates AlmaSEO — the application at app.almaseo.com and this website. We’re the data controller for the information described here.
This policy is written from what the software actually does rather than from a template, which is why it names specific companies instead of “selected partners”.
2. What we collect
Your account
Your email address, a name, and a password — stored as a salted PBKDF2-SHA256 hash, never as text we can read. We also record when you signed up, your plan and trial dates, and, if you used one, the invite code.
At signup we record the IP address you registered from, plus how you arrived: the referring page, the landing page, and any campaign tags in the link (utm_source and friends). This is how we tell which marketing actually works.
Your workspace
Everything you put in: the sites you add and their business details, the work you log, content you write or generate, keywords, reports, invoices, notes, and the settings for each client. If you use SSH Workspace, the connection details for servers you choose to connect.
Technical records
Our servers keep access logs containing your IP address, browser user-agent, the pages requested and when. We record sign-in attempts with their IP address, to spot someone trying to break into an account. Errors are recorded with the page, the IP address and the technical detail needed to fix them. Activity entries in your workspace also carry the IP address of the action.
Payment
We never see or store your card number. Card details are entered directly with Stripe. We hold only Stripe’s reference identifiers, your plan, and invoice records.
3. Data from accounts you connect
When you connect a third-party account, we receive data from it on your behalf and cache it so the product is fast. You choose what to connect, and you can disconnect at any time from within the application.
| You connect | We receive |
|---|---|
| Google Search Console | Queries, pages, clicks, impressions, positions, index status. We request permission to submit sitemaps as well as to read. |
| Google Analytics | Traffic and engagement metrics. Read-only. |
| Google Business Profile | Profile details, performance figures, and reviews — including the reviewer’s name and review text. |
| Google Ads | Campaign and keyword performance. |
| WordPress | Publishing access to the sites you connect, stored as an application password. |
| Stripe (for your own invoicing) | Permission to create customers and take payments on your behalf, under your Stripe account. |
| Slack | Permission to post alerts into the channel you choose. |
Access tokens for connected accounts are stored so the connection keeps working without asking you to sign in repeatedly. They’re never shown in the interface.
4. Why we use it
- To run the service — the whole product is built on this data. Without it there’s nothing to show you.
- To bill you — subscriptions, invoices, and metering Data Credits.
- To keep accounts secure — sign-in records, rate limiting, and spotting unusual access.
- To support you — answering your emails, which sometimes means looking at your account.
- To email you about your account, your trial, and things you asked to be told about.
- To improve the product — aggregate usage patterns and which features get used.
Where the UK or EU GDPR applies, our lawful bases are performance of a contract (running the service), legitimate interests (security, product improvement, understanding which marketing works), legal obligation (tax and accounting), and consent where we ask for it.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
5. Who else receives data
These are the outside companies that process data as part of running AlmaSEO. Each receives only what its job requires.
| Company | What it does | What it receives |
|---|---|---|
| Stripe | Payments and subscriptions | Your billing details and card data (entered directly with them). When you invoice your own clients, their names, email addresses and amounts. |
| Connected accounts and analytics | Requests for the data in section 3. Google Analytics also runs on our own pages. | |
| SE Ranking | Search data — rankings, keyword volumes, backlinks, AI visibility | Domains, URLs and keywords you look up. Not your identity. |
| SerpAPI | Live search-result lookups | Search queries and domains. |
| OpenAI | Content generation and analysis | The prompts and context sent by those features — which can include business details, page content, and Business Profile review text. |
| Anthropic | AI assistance in SSH Workspace | Context from the servers you connect. Runs on an API key you supply, under your own agreement with Anthropic. |
| SendGrid | All email delivery | Recipient addresses and message content — including email we send to your clients on your behalf. |
| Slack | Alerts, if you connect it | The alert content you’ve enabled, which can include review text and reviewer names. |
| Cloudflare | Hosting and delivery of this website | Standard request data for pages you visit. |
| Google PageSpeed Insights | Performance testing | The URLs being tested. |
| Bing Webmaster Tools | Bing search data. Off unless enabled. | Site URLs and queries. |
| Mailchimp | Only if you connect your own Mailchimp account | Whatever that integration sends, using your own API key. |
We also disclose information where the law requires it, to protect our rights or someone’s safety, and to a buyer if the business is ever sold — in which case we’d tell you before your data moved.
6. Your clients’ data
This section matters more here than in most privacy policies, because AlmaSEO is built for people who work on other people’s websites. A large share of what you store is personal data belonging to someone who has never heard of us.
That includes: the business owner’s name, email and phone on a client record; billing contacts you add for invoicing; the email addresses reports and invoices are sent to; server credentials for their infrastructure; and, if Business Profile is connected, the names and review text of members of the public who reviewed your client’s business.
For that data, you are the controller and we are your processor — we handle it on your instructions, to provide the service to you. It follows that:
- You’re responsible for having the right to give it to us, and for telling the people concerned as their own privacy law requires.
- We won’t use it for anything except running AlmaSEO for you.
- If one of your clients contacts us directly, we’ll normally refer them to you, because it’s your relationship and your data.
- Ask us to delete a client’s data and we will.
Two specifics worth knowing before you connect things. Review text can leave the system: it’s sent to OpenAI when a feature uses reviews to generate content, and to Slack if you’ve enabled review alerts. And client portal links are unguessable but not time-limited — anyone holding the link can open that portal until you revoke it.
7. AI features
We do not use the contents of your workspace to train AI models, ours or anyone else’s.
What we do is send the material a feature needs to the model provider running it — OpenAI for content generation and analysis, Anthropic for SSH Workspace assistance — so it can produce a response. Those providers process it under their own terms. SSH Workspace runs on an API key you supply, so that traffic is under your own agreement with Anthropic rather than ours.
Treat AI features as you would any third party: don’t paste in something you wouldn’t be willing to send outside your business.
8. Cookies
Essential cookies. The application sets a session cookie to keep you signed in, and a “remember me” cookie lasting seven days if you choose it. Both are marked Secure and HttpOnly. There are also small preference cookies remembering things like which site you last had open. The service cannot work without these.
Analytics cookies. We use Google Analytics on both this website and the application, which sets its own cookies to measure visits and which pages get used. This site also stores a random session identifier in your browser’s session storage — not a cookie, cleared when you close the tab, and not tied to your identity.
Being straight with you: we don’t currently show a cookie consent banner. Analytics cookies are set when you arrive. If you’d rather not be measured, your browser can block cookies for this domain, and Google publishes an opt-out add-on for Analytics. We’d rather state this plainly than imply a consent mechanism we haven’t built.
We don’t use advertising or cross-site tracking cookies.
9. How long we keep things
While your account is open we keep your workspace, because it is the product. Some things are cleared automatically:
| What | Deleted after |
|---|---|
| Activity log entries | 90 days |
| Sites and posts you delete | 30 days in trash, then permanently |
| Generated images | 30 days |
| Sign-in records, including the IP address of each attempt | 90 days |
Other operational records — server access logs, error records and email delivery logs — are kept while they remain useful for security, debugging and accounting, and are not currently on a fixed automatic schedule. We’d rather tell you that than publish a retention period we don’t yet enforce.
When an account closes we keep the data for 30 days so an account closed by mistake can be recovered, then delete it. Backups may retain copies briefly after that until they rotate. Invoices and payment records are kept for as long as tax and accounting law requires.
10. Security
All traffic runs over HTTPS. Passwords are stored as salted PBKDF2-SHA256 hashes and are never recoverable in readable form — not even by us. Access tokens for connected accounts are encrypted at rest, with the key held outside the database. Sign-ins are rate-limited, unusual sign-in attempts are recorded, and email verification is required to activate an account.
Our servers are in the United States, and access to production is restricted to people who need it to operate the service.
No system is perfectly secure and we won’t pretend otherwise. If a breach affects your personal data we’ll tell you and any regulator we’re required to tell, without undue delay. If you believe you’ve found a vulnerability, email [email protected] — we’d much rather hear it from you.
11. Your rights
Depending on where you live, you may have the right to a copy of your data, to correct it, to delete it, to restrict or object to how we use it, to take it elsewhere in a portable form, and not to be discriminated against for exercising any of these.
How to exercise them: email [email protected]. We’ll respond within 30 days. There is no self-serve account-deletion button in the application today — deletion is handled by us on request, and we’d rather say so than point you at a screen that doesn’t exist.
The application can export several kinds of data as CSV from within your account. That covers reporting data rather than everything we hold, so for a complete copy, email us.
Deleting your account removes your workspace, including client records you added. Export anything you want to keep first.
If you’re in the EU or UK and think we’ve got something wrong, you can complain to your data protection authority — though we’d appreciate the chance to fix it first.
12. Children
AlmaSEO is a business tool and isn’t intended for anyone under 18. We don’t knowingly collect data from children. If you believe a child has given us information, email us and we’ll delete it.
13. Where data is held
AlmaSEO is operated from the United States and your data is stored and processed there. Several of the companies in section 5 operate globally and may process data in other countries.
If you’re in the UK, EU or another region with data-transfer rules, using AlmaSEO means your data is transferred to the United States, which may not offer the same protections as your home country. We rely on standard contractual clauses where our providers offer them.
14. Changes
We’ll update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we’ll email account holders before it takes effect.
15. Contact
Any question about this policy, your data, or a request to exercise your rights:
AlmaSEO LLC
Email: [email protected]
Email is the only channel — there’s no phone line and no contact form, and we’d rather tell you that than list a number nobody answers.