Privacy Policy

What Seovyn collects, why, who helps us run it, how long we keep it, and the choices you have.

Last updated

The short version

  • We collect what we need to run your SEO content agent: your account, your website and brand details, the articles we create for you, and basic usage data.
  • We never sell your personal data, and there are no ads on Seovyn.
  • To do the work you ask for, your content is sent to AI model providers. We don't train our own models on it.
  • Product analytics runs only if you press Accept on the cookie banner.
  • To see, correct, export or delete your data, email hello@seovyn.com.

Who we are

Seovyn ("we", "us") is an autonomous SEO content service at seovyn.com and app.seovyn.com. For anything about your data, write to hello@seovyn.com.

For the personal data of your account we are the controller. When the content you give us contains other people's personal data (for example an author's name on your site), we handle it on your instructions as a processor. If you need a data processing agreement, write to hello@seovyn.com.

What we collect

Your account. Your name and email address, and either a password (we store only a salted hash, never the password) or the identity Google or GitHub gives us when you sign in with them: your name, email address and that provider's user ID. We record whether you have confirmed your email.

Your workspace. Your website address and anything you tell us about the brand: name, one-line description, audience, tone, point of view, country, author name and call to action. Keyword targets, publishing settings, and anything you upload or paste into your knowledge base.

Connections you set up. When you connect a publishing destination (WordPress, Shopify, Webflow, Framer, Wix, Notion, Ghost, GitHub or a webhook) or Google Search Console, we store the access details needed to use it on your behalf. Tokens and secrets are encrypted at rest and used only to publish for you or read your search data. Search Console access is read-only.

Content we handle for you. The public pages of your website that we read to understand your niche, public pages we look at for research (competitors, forums, videos), the drafts and published articles we write, your approvals and rejections, and the history of what was delivered where. If you connect Search Console, we keep snapshots of your search queries, clicks, impressions and positions.

Billing. Payments are handled by Dodo Payments, which is the seller of record. We never see your card details. We keep Dodo's customer and subscription IDs, your plan, its status and the billing-period dates.

Support. What you write to us by email or in the chat, with your name and email if you are signed in, and the page you were on.

Newsletter. Your email address, if you subscribe. We email you a link first and only subscribe you when you click it.

Browser Agent. If you use it, the task you gave it, the steps it took, and what it saw on the pages it worked on, so you can review the session.

Usage and technical data. The days you opened the dashboard, what happened in your pipeline (kept for 90 days), a log of AI calls with token counts and cost but not the text (kept for 180 days), your IP address and browser details in server logs and for rate limiting and abuse prevention, and error and performance data from our servers.

Analytics, only with your consent. If you press Accept, we record page views on seovyn.com, and two events from the product, account created and first article published, against your user ID. This never includes your email, name, article text or IP address. See the cookie policy.

How we use it

  • To provide Seovyn: read your site, research, write, score and publish articles, and run the autopilot settings you choose.
  • To keep it secure, prevent abuse and fix problems.
  • To bill you and to send the emails you need: confirmations, password resets, receipts, and alerts when something needs your attention.
  • To send product guidance and occasional updates by email. These have an unsubscribe link; essential emails about your account do not.
  • To understand how the product is used and improve it, using analytics only if you accepted it.
  • To meet legal obligations and to protect our rights.

We do not sell your personal data, do not share it for advertising, and do not use your content to train our own models.

AI processing

To write, check and classify content, we send the text needed for each task, such as pages from your site, your brand details and the draft, to model providers: OpenRouter, which routes requests to the underlying model vendors, and Google (Gemini). They process it to return a result to us. Their own terms govern how long they keep API data. We choose what to send for each task and don't send your credentials.

Why we are allowed to use your data (GDPR and similar laws)

What we doLegal basis
Run your account and the service you asked forPerforming our contract with you
Security, abuse prevention, fixing and improving the service, product emailsOur legitimate interests
Product analytics, cookies that aren't essential, newsletterYour consent, which you can withdraw at any time
Tax and accounting records, responding to lawful requestsLegal obligation

Who we share it with

We use these providers to run Seovyn. Each receives only what it needs for its job.

ProviderWhat it does for usWhat it can see
Amazon Web Services (India, Mumbai)Hosts the applicationEverything we process, on our servers
MongoDB (Atlas)Our managed databaseAccount and workspace data
OpenRouter and Google (Gemini)Generate and check contentThe text sent for each task
Dodo PaymentsTakes payment, handles tax and invoicesYour name, email, billing details and payment
VolaneaSends our transactional and product emailsYour name, email, plan, website address and product activity
ZealoopSupport chatYour messages, IP address, the page you are on, and your name and email if signed in
MixpanelProduct analytics, only with your consentYour user ID, page views and the two events above
New RelicPerformance and error monitoringTechnical data from our servers
GoogleSign-in, Search Console API, and the fonts the dashboard loadsFor fonts, your IP address; for sign-in and Search Console, only if you use them
GitHubSign-in and publishingOnly if you use them
CloudflareStorage and delivery for Seovyn-hosted sitesOnly if you use that feature
SlackInternal alerts to our teamTechnical alerts, which can include account identifiers

We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a sale or reorganisation of the business, in which case we will tell you and this policy keeps applying.

Where your data goes

Our application servers are in India (Mumbai). Our database and several of the providers above operate in other countries, including the United States. Where the law requires it, we rely on safeguards such as standard contractual clauses when data leaves your region.

How long we keep it

DataKept for
Your account, workspace and articlesUntil you delete them or close your account
Connection credentialsUntil you disconnect the destination or close your account
Pipeline activity90 days
Research signals from public pages60 days
AI call log (token counts and cost, no text)180 days
Search Console snapshots400 days
Payment and invoice recordsAs long as tax and accounting law requires
Sign-in session7 days

Backups are deleted on their normal schedule after the live data is removed.

Your choices and rights

Depending on where you live, for example under the GDPR in the EU and UK, the Digital Personal Data Protection Act in India, or California law, you can ask us to:

  • tell you what we hold about you and give you a copy;
  • correct it, or delete it;
  • move it to another service;
  • stop or limit certain uses, and withdraw consent you gave.

There is not yet a self-serve button for deleting an account. Email hello@seovyn.com from the address on the account and we will act on it within 30 days, and tell you when it is done. You can unsubscribe from marketing emails with the link in any of them, and you can change your cookie choice at any time (see the cookie policy). If you are unhappy with how we handled a request, you can complain to your local data protection authority.

Security

Traffic to Seovyn is encrypted in transit. Passwords are stored as salted hashes. Access tokens and secrets for your connections are encrypted at rest. Sign-in sessions use an HttpOnly cookie. No system is perfectly secure; if you find a vulnerability, please tell us at hello@seovyn.com.

Children

Seovyn is a business tool for people 18 and over. We don't knowingly collect data from children.

Changes

If we change this policy in a way that matters to you, we will email you or tell you in the dashboard before it takes effect. The date at the top shows when it last changed.

Contact

hello@seovyn.com