Skip to content
Back

Privacy Policy

Last updated: March 2026

1. Data We Collect

We collect the following data to operate That SEO Agent:

  • Account data: your name and email address, obtained via Google OAuth when you sign in.
  • Google Search Console (GSC) data: search queries, impressions, clicks, and index coverage for the sites you connect.
  • Google Analytics 4 (GA4) data: traffic metrics and event data for the properties you connect.
  • Chat messages: your conversations with the AI assistant, stored encrypted to provide session history.
  • Usage data: number of sites, data syncs, and page audits used each month.

2. Website Analytics

We use two analytics tools to understand traffic on our landing page:

  • Vercel Web Analytics: a cookie-free tool that collects fully anonymous, aggregated data (pages visited, referrer, device type, country). It stores no personal identifiers and does not allow individual user tracking. No consent is required under GDPR.
  • Google Analytics 4: we use GA4 with Consent Mode v2 and with all advertising and personalization features disabled. We use it solely to measure traffic in aggregate — not for advertising or user identification. When you reject cookies, GA4 operates in anonymous, cookieless mode and Google models the data statistically. When you accept, GA4 may use first-party cookies for more accurate measurement. In no case do we sell or share this data with third parties.

3. How We Use It

Your data is used solely to operate and improve That SEO Agent. We do not sell your data to third parties or use it for targeted advertising.

4. Google API Data

Our use of Google API data (GSC + GA4) complies with the Google API Services User Data Policy, including the Limited Use requirements. Google data is only used to provide the SEO analysis features you request — it is never used for other purposes or shared with third parties.

5. Data Security

  • All data is transmitted over encrypted connections (TLS/HTTPS).
  • Google OAuth tokens and AI API keys are encrypted at rest using AES-256-GCM with a per-user derived key.
  • Chat message content is encrypted at rest using AES-256-GCM before being stored in the database.

6. Data Retention

We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time via the Settings page or by emailing privacy@thatseoagent.com.

7. Your Rights (GDPR)

If you are in the European Economic Area (EEA), you have the following rights under GDPR:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to erasure: request deletion of your account and all personal data.
  • Right to rectification: request correction of inaccurate data.
  • Right to restrict processing: request that we limit how we use your data.
  • Right to data portability: request your data in a portable format.

To exercise any of these rights, email privacy@thatseoagent.com.

8. Cookies

That SEO Agent uses strictly necessary functional cookies for authentication (session cookies). For analytics, you can accept or reject cookie usage via the banner shown on your first visit. Vercel Analytics never uses cookies regardless of your choice. Google Analytics 4 uses first-party cookies only if you accept — otherwise it operates in anonymous, cookieless mode.

9. Contact

For privacy concerns or data requests, email us at privacy@thatseoagent.com.