Privacy Policy
Last updated 9 September 2026
Who we are
AutoPSEO ("we", "us") provides a web application that reads Google Search Console, Google Analytics 4, Bing Webmaster Tools and Chrome UX Report data on your behalf and turns it into reports. This policy explains what we collect, why, and what you can do about it.
Questions about this policy: privacy@autopseo.com.
Data we collect
Account data. When you sign in with Google we store your Google account id, email address, display name and profile picture URL. We do not receive or store your Google password.
Authorisation tokens. We store an encrypted OAuth refresh token so reports can be generated without you signing in again. Tokens are encrypted at rest with AES-GCM and are never exposed to the browser.
Search data. The Search Console, Analytics and Bing metrics we fetch on your behalf: queries, pages, countries, devices, clicks, impressions, click-through rate and position. For properties where you enable stored history we keep a daily copy so history survives past Google's 16-month window.
Product data. Properties you add, tags, content groups, topic clusters, annotations, saved filters, shared reports, API keys, alert rules and team invitations.
Operational logs. Timestamps, request paths, error messages and, for sign-ins, the IP address, so we can debug problems and detect abuse.
What we do not do
We do not sell your data, we do not share it with advertisers, and we do not use it to train machine-learning models. We do not write anything to your Search Console property unless you explicitly ask us to (submitting a sitemap, requesting an inspection, or pinging IndexNow).
Google API Services
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the narrowest scopes that make the product work: read-only Search Console access, read-only Analytics access, and optionally full Search Console access only if you choose to submit sitemaps or run URL inspections from inside the app. You can revoke our access at any time from your Google account permissions page.
Legal basis and purposes
We process account and search data to perform the contract you enter into when you create an account. We process operational logs on the basis of our legitimate interest in keeping the service secure and working. Where we send product emails you can unsubscribe at any time.
Sub-processors
Cloudflare (hosting, database, cache and object storage, EU and global edge), Google (the APIs your data comes from), Stripe (payments; they receive your email and billing details, we never see card numbers), and Resend (transactional email such as team invitations). Each is bound by a data-processing agreement.
Retention
Account and product data is kept while your account exists. Stored search history is kept for as long as the property has storage enabled, up to ten years. Operational logs are kept for 90 days. When you delete your account we remove your data within 30 days, except where we must keep records for tax or legal reasons.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your data, to object to processing, and to complain to a supervisory authority. Use the export buttons in the app, or write to privacy@autopseo.com and we will respond within 30 days.
Security
All traffic is served over TLS. Refresh tokens and integration secrets are encrypted at rest. Sessions are stored server-side and identified by an opaque cookie that is HTTP-only, Secure and SameSite=Lax. Access to production data is limited to the people who operate the service.
Children
The service is not directed to children under 16 and we do not knowingly collect their data.
Changes
We will update this page when the practices change and, for material changes, notify account holders by email before they take effect.