Privacy Policy
What Seovyn collects, why, who helps us run it, how long we keep it, and the choices you have.
Last updated
The short version
- We collect what we need to run your SEO content agent: your account, your website and brand details, the articles we create for you, and basic usage data.
- We never sell your personal data, and there are no ads on Seovyn.
- To do the work you ask for, your content is sent to AI model providers. We don't train our own models on it.
- Product analytics runs only if you press Accept on the cookie banner.
- To see, correct, export or delete your data, email hello@seovyn.com.
Who we are
Seovyn ("we", "us") is an autonomous SEO content service at seovyn.com and app.seovyn.com. For anything about your data, write to hello@seovyn.com.
For the personal data of your account we are the controller. When the content you give us contains other people's personal data (for example an author's name on your site), we handle it on your instructions as a processor. If you need a data processing agreement, write to hello@seovyn.com.
What we collect
Your account. Your name and email address, and either a password (we store only a salted hash, never the password) or the identity Google or GitHub gives us when you sign in with them: your name, email address and that provider's user ID. We record whether you have confirmed your email.
Your workspace. Your website address and anything you tell us about the brand: name, one-line description, audience, tone, point of view, country, author name and call to action. Keyword targets, publishing settings, and anything you upload or paste into your knowledge base.
Connections you set up. When you connect a publishing destination (WordPress, Shopify, Webflow, Framer, Wix, Notion, Ghost, GitHub or a webhook) or Google Search Console, we store the access details needed to use it on your behalf. Tokens and secrets are encrypted at rest and used only to publish for you or read your search data. Search Console access is read-only.
Content we handle for you. The public pages of your website that we read to understand your niche, public pages we look at for research (competitors, forums, videos), the drafts and published articles we write, your approvals and rejections, and the history of what was delivered where. If you connect Search Console, we keep snapshots of your search queries, clicks, impressions and positions.
Billing. Payments are handled by Dodo Payments, which is the seller of record. We never see your card details. We keep Dodo's customer and subscription IDs, your plan, its status and the billing-period dates.
Support. What you write to us by email or in the chat, with your name and email if you are signed in, and the page you were on.
Newsletter. Your email address, if you subscribe. We email you a link first and only subscribe you when you click it.
Browser Agent. If you use it, the task you gave it, the steps it took, and what it saw on the pages it worked on, so you can review the session.
Usage and technical data. The days you opened the dashboard, what happened in your pipeline (kept for 90 days), a log of AI calls with token counts and cost but not the text (kept for 180 days), your IP address and browser details in server logs and for rate limiting and abuse prevention, and error and performance data from our servers.
Analytics, only with your consent. If you press Accept, we record page views on seovyn.com, and two events from the product, account created and first article published, against your user ID. This never includes your email, name, article text or IP address. See the cookie policy.
How we use it
- To provide Seovyn: read your site, research, write, score and publish articles, and run the autopilot settings you choose.
- To keep it secure, prevent abuse and fix problems.
- To bill you and to send the emails you need: confirmations, password resets, receipts, and alerts when something needs your attention.
- To send product guidance and occasional updates by email. These have an unsubscribe link; essential emails about your account do not.
- To understand how the product is used and improve it, using analytics only if you accepted it.
- To meet legal obligations and to protect our rights.
We do not sell your personal data, do not share it for advertising, and do not use your content to train our own models.
AI processing
To write, check and classify content, we send the text needed for each task, such as pages from your site, your brand details and the draft, to model providers: OpenRouter, which routes requests to the underlying model vendors, and Google (Gemini). They process it to return a result to us. Their own terms govern how long they keep API data. We choose what to send for each task and don't send your credentials.
Why we are allowed to use your data (GDPR and similar laws)
| What we do | Legal basis |
|---|---|
| Run your account and the service you asked for | Performing our contract with you |
| Security, abuse prevention, fixing and improving the service, product emails | Our legitimate interests |
| Product analytics, cookies that aren't essential, newsletter | Your consent, which you can withdraw at any time |
| Tax and accounting records, responding to lawful requests | Legal obligation |
Who we share it with
We use these providers to run Seovyn. Each receives only what it needs for its job.
| Provider | What it does for us | What it can see |
|---|---|---|
| Amazon Web Services (India, Mumbai) | Hosts the application | Everything we process, on our servers |
| MongoDB (Atlas) | Our managed database | Account and workspace data |
| OpenRouter and Google (Gemini) | Generate and check content | The text sent for each task |
| Dodo Payments | Takes payment, handles tax and invoices | Your name, email, billing details and payment |
| Volanea | Sends our transactional and product emails | Your name, email, plan, website address and product activity |
| Zealoop | Support chat | Your messages, IP address, the page you are on, and your name and email if signed in |
| Mixpanel | Product analytics, only with your consent | Your user ID, page views and the two events above |
| New Relic | Performance and error monitoring | Technical data from our servers |
| Sign-in, Search Console API, and the fonts the dashboard loads | For fonts, your IP address; for sign-in and Search Console, only if you use them | |
| GitHub | Sign-in and publishing | Only if you use them |
| Cloudflare | Storage and delivery for Seovyn-hosted sites | Only if you use that feature |
| Slack | Internal alerts to our team | Technical alerts, which can include account identifiers |
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a sale or reorganisation of the business, in which case we will tell you and this policy keeps applying.
Where your data goes
Our application servers are in India (Mumbai). Our database and several of the providers above operate in other countries, including the United States. Where the law requires it, we rely on safeguards such as standard contractual clauses when data leaves your region.
How long we keep it
| Data | Kept for |
|---|---|
| Your account, workspace and articles | Until you delete them or close your account |
| Connection credentials | Until you disconnect the destination or close your account |
| Pipeline activity | 90 days |
| Research signals from public pages | 60 days |
| AI call log (token counts and cost, no text) | 180 days |
| Search Console snapshots | 400 days |
| Payment and invoice records | As long as tax and accounting law requires |
| Sign-in session | 7 days |
Backups are deleted on their normal schedule after the live data is removed.
Your choices and rights
Depending on where you live, for example under the GDPR in the EU and UK, the Digital Personal Data Protection Act in India, or California law, you can ask us to:
- tell you what we hold about you and give you a copy;
- correct it, or delete it;
- move it to another service;
- stop or limit certain uses, and withdraw consent you gave.
There is not yet a self-serve button for deleting an account. Email hello@seovyn.com from the address on the account and we will act on it within 30 days, and tell you when it is done. You can unsubscribe from marketing emails with the link in any of them, and you can change your cookie choice at any time (see the cookie policy). If you are unhappy with how we handled a request, you can complain to your local data protection authority.
Security
Traffic to Seovyn is encrypted in transit. Passwords are stored as salted hashes. Access tokens and secrets for your connections are encrypted at rest. Sign-in sessions use an HttpOnly cookie. No system is perfectly secure; if you find a vulnerability, please tell us at hello@seovyn.com.
Children
Seovyn is a business tool for people 18 and over. We don't knowingly collect data from children.
Changes
If we change this policy in a way that matters to you, we will email you or tell you in the dashboard before it takes effect. The date at the top shows when it last changed.
Contact
hello@seovyn.com