1. Data We Collect
We collect the following data to operate That SEO Agent:
- Account data: your name and email address, obtained via Google OAuth when you sign in.
- Google Search Console (GSC) data: search queries, impressions, clicks, and index coverage for the sites you connect.
- Google Analytics 4 (GA4) data: traffic metrics and event data for the properties you connect.
- Usage data: number of sites, data syncs, and page audits used each month.
2. Website Analytics
We use two analytics tools to understand traffic on our landing page:
- Vercel Web Analytics: a cookie-free tool that collects fully anonymous, aggregated data (pages visited, referrer, device type, country). It stores no personal identifiers and does not allow individual user tracking. No consent is required under GDPR.
- Google Analytics 4: we use GA4 with Consent Mode v2 and with all advertising and personalization features disabled. We use it solely to measure traffic in aggregate — not for advertising or user identification. When you reject cookies, GA4 operates in anonymous, cookieless mode and Google models the data statistically. When you accept, GA4 may use first-party cookies for more accurate measurement. In no case do we sell or share this data with third parties.
3. How We Use It
Your data is used solely to operate and improve That SEO Agent. We do not sell your data to third parties or use it for targeted advertising.
4. Google API Data
Our use of Google API data (GSC + GA4) complies with the Google API Services User Data Policy, including the Limited Use requirements. Google data is only used to provide the SEO analysis features you request — it is never used for other purposes or shared with third parties.
5. Data Security
- All data is transmitted over encrypted connections (TLS/HTTPS).
- Google OAuth tokens are encrypted at rest using AES-256-GCM with a per-user derived key.
6. Data Retention
How long we keep each kind of data:
- Account data: your name, email, connected sites and tasks are kept for as long as your account is active.
- Audit snapshots: the most recent completed audit for each site is kept while that site is registered. Older snapshots are deleted 15 days after they run, unless a shared report still points at one.
- Shared reports: 14 days from creation, then the link stops working and the report is deleted.
- Tool results cache: between 5 minutes and 24 hours depending on the tool, then deleted.
- Activity log: 12 months. This is the record of what your account did (sites added, audits run, keys issued) shown on your dashboard.
- OAuth authorization codes: 10 minutes, and each one can only be used once.
Deleting your account: removes everything above at once and permanently. There is no grace period, and we keep no separate archive or backup copy afterwards. Google access tokens are deleted with it, which also ends our access to your Search Console and Analytics data.
You can delete your account yourself from the Settings page, or ask us to do it by emailing privacy@thatseoagent.com.
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights under GDPR:
- Right of access: request a copy of the personal data we hold about you.
- Right to erasure: request deletion of your account and all personal data.
- Right to rectification: request correction of inaccurate data.
- Right to restrict processing: request that we limit how we use your data.
- Right to data portability: request your data in a portable format.
To exercise any of these rights, email privacy@thatseoagent.com.
8. Cookies
That SEO Agent uses strictly necessary functional cookies for authentication (session cookies). For analytics, you can accept or reject cookie usage via the banner shown on your first visit. Vercel Analytics never uses cookies regardless of your choice. Google Analytics 4 uses first-party cookies only if you accept — otherwise it operates in anonymous, cookieless mode.
9. Contact
For privacy concerns or data requests, email us at privacy@thatseoagent.com.
10. OAuth Connectors
When you connect That SEO Agent as an OAuth connector (for example, via the Claude Connectors directory), the following additional data is stored and processed:
- Connector scope: The mcp scope grants the connector access to your SEO data through the MCP API. It does not grant access to your email, Google Drive, Calendar, or any other Google service.
- Actions the connector can take: Most MCP tools only read — they analyze a URL or fetch Search Console and Analytics data. Seven can change something: creating, completing and deleting tasks on a site; activating and deactivating a site; running a site audit; and creating a shared report. Creating a shared report publishes a snapshot of that site's audit at a public URL that anyone holding the link can open without signing in, and that link stays valid for 14 days. No tool can change your Google data, your billing, or your account settings.
- Token storage: OAuth access and refresh tokens issued during connector authorization are encrypted at rest using AES-256-GCM with a per-user derived key and stored in our database alongside your account record.
- Token lifecycle: Access tokens are short-lived (typically 1 hour) and are refreshed automatically using the stored refresh token. Tokens are deleted when you disconnect the connector or delete your account.
- Revoking connector access: You can revoke the connector at any time from Claude.ai Settings → Connectors. Revoking access immediately invalidates the stored tokens and removes the connector's ability to access your data.
Third-party services accessed through the connector:
- Google Search Console API — query performance and index coverage data for properties you authorize.
- Google Analytics 4 Data API — traffic and engagement metrics for GA4 properties you link.
- Google PageSpeed Insights API — public performance scores for site URLs; no authentication required.
- Google OAuth 2.0 — used to obtain and refresh access tokens; governed by Google's OAuth terms.
Data accessed through the connector is used solely to respond to your MCP tool requests. It is not stored beyond what is necessary for caching (TTL: 5 minutes to 24 hours depending on tool) and audit snapshots tied to your account. It is never shared with other users or used to train models.
11. Payments
When you subscribe to a paid plan, payments are processed by our third-party payment provider, Commet, and its payment processor. They collect the billing information needed to take payment, including your card details, which are entered directly with the processor and are never stored on our servers. We keep only a billing reference (customer and subscription identifiers) and your plan status, used to grant access and manage your subscription. Commet acts as a processor for this purpose; see Commet's own privacy terms for how it handles payment data.