Skip to content

Legal

Privacy Policy

Last updated: September 4, 2026

SEOIoT (“we”, “us”) provides an autonomous AI marketing team for websites and mobile apps. This policy explains what we collect, why, how long we keep it, and the choices you have. It applies to seoiot.com, the SEOIoT web app, the mobile app and our APIs.

1. What we collect

Account data: name, email, password hash, company, country and billing currency.

Product data you give us: website URLs, product descriptions, app-store links, goals, brand-voice notes and corrections you make to the knowledge base.

Integration data: OAuth tokens or API keys for services you connect (Search Console, GA4, CMSs, social networks, video platforms, app stores, mailboxes) and the metrics, content and reviews those services return.

Usage data: pages visited, actions taken, device and browser information, IP address and approximate location, collected through server logs and privacy-respecting analytics.

Payment data is processed by Stripe (USD) and Razorpay (INR). We store only the payment identifiers and the last four digits of a card, never full card numbers.

2. How we use it

To operate the service: crawling your site, planning, writing, publishing, posting, tracking rankings and citations, replying to reviews and producing reports — as configured by your autonomy settings.

To bill you: reserving, charging and refunding credits and issuing invoices.

To keep you informed: approval requests, low-balance alerts, weekly and monthly reports and security notices. Marketing emails are opt-in and can be unsubscribed at any time.

To improve the product: aggregate, de-identified usage metrics. We do not train foundation models on your private content.

3. AI processing

Agents use third-party large-language-model, search, image and voice providers to do their work. Your product context and the specific task content are sent to these providers under contracts that prohibit training on your data. Provider lists are available in the Integrations page and on request.

4. Integrations and credentials

Credentials for connected services are encrypted at rest with per-environment keys (Fernet), scoped to your organization and never shared across tenants.

We request the narrowest scopes each agent needs. You can disconnect any integration instantly from the Integrations page, which revokes our access and deletes stored tokens.

5. Sharing

We share data only with: (a) sub-processors that run the service (cloud hosting, databases, storage, email delivery, payment processors, AI providers); (b) the third-party platforms you explicitly connect, to publish on your behalf; and (c) authorities when required by law.

We never sell personal data.

6. Retention

Account and product data are kept for as long as your organization is active. After deletion, backups are purged within 30 days. Financial records are kept for the period required by tax law. Content published to your own channels remains yours and is unaffected by deletion.

7. Your rights

Depending on where you live (including GDPR and India's DPDP Act), you may access, correct, export or delete your personal data, object to processing and lodge a complaint with a supervisory authority. Export and deletion are available in Settings; for anything else, email privacy@seoiot.com.

8. Cookies

We use strictly necessary cookies for sign-in and security, and a first-party analytics cookie you can decline. We do not use third-party advertising cookies.

9. Security

Encryption in transit (TLS) and at rest, role-based access, audit logs for credit transactions and admin actions, and regular dependency and infrastructure reviews. Report vulnerabilities to security@seoiot.com.

10. Children

SEOIoT is a business tool and is not directed at children under 16. We do not knowingly collect their data.

11. Changes and contact

We will notify account owners by email of material changes at least 14 days before they take effect. Questions: privacy@seoiot.com.