Privacy policy
Last updated: September 2, 2026
This policy explains what data SEOWren collects, why we collect it, how we protect it, and what control you have over it. We have written it in plain language rather than legal boilerplate.
Information we collect
We collect only the information necessary to provide and improve our rank tracking service:
- Account information: Your name, email address, and username when you sign up.
- Project and keyword data: The domains and search terms you add for tracking.
- Ranking data: Search engine positions we retrieve on your behalf.
- Usage data: How you interact with our platform (pages visited, features used) to improve the experience.
- Google account data: Only if you choose to connect Google Search Console or Google Analytics. See Google User Data below for exactly what we read and store.
- Payment information: Processed securely through Lemon Squeezy. We never store your full card details on our servers.
How we use your data
- To provide and maintain the rank tracking service.
- To send you ranking alerts, reports, and important account notifications.
- To process payments and manage your subscription.
- To improve our product based on aggregated, anonymized usage patterns.
- To respond to your support requests and provide customer service.
We do not sell your personal data to third parties.
Google User Data (Search Console and Analytics)
SEOWren can connect to Google Search Console and Google Analytics 4 so that your search performance and organic traffic appear alongside the keyword rankings we track for you. These connections are optional: SEOWren works without them, and you choose which properties are linked. This section sets out what we access, why, and what happens to it afterwards.
What we request, and why
.../auth/webmasters.readonly: Read-only access to Google Search Console. Used to list the properties your Google account can access so you can pick which ones to link, and to read search performance for the linked properties: queries, pages, clicks, impressions, click-through rate, average position, and index coverage counts..../auth/analytics.readonly: Read-only access to Google Analytics 4. Used to list your GA4 properties so you can pick which ones to link, and to read organic-traffic metrics for the linked properties: sessions, users, pageviews, bounce rate, and average session duration..../auth/userinfo.emailand.../auth/userinfo.profile: Your Google account’s email address and basic profile, so we can show you which Google account a connection belongs to and confirm you are reconnecting the right one.
Every scope we request is read-only. SEOWren cannot create, modify, or delete anything in your Google Search Console or Google Analytics account, and it does not request access to any other Google service: not Gmail, Drive, Contacts, Calendar, or your Google Ads data.
What we store
- The OAuth access and refresh tokens Google issues, encrypted at rest in our database. They are decrypted only in memory, at the moment we call a Google API on your behalf.
- The email address and display name of the connected Google account, shown in your dashboard so you know which account is linked.
- The identifiers of the Search Console and GA4 properties you link, and your permission level on them.
- The metrics listed above, stored as dated rows so we can chart them over time and include them in your reports.
We never receive or store your Google password, and we never ask for one. Authorization happens on Google's own sign-in screen.
How we use it
Data obtained through these connections is used for one purpose: to provide the SEOWren features you asked for. That means displaying your performance in your dashboard, charting it over time, generating your reports, and raising the alerts you have configured. Specifically:
- We never sell Google user data.
- We do not use it for advertising, retargeting, audience building, or creditworthiness or lending purposes.
- We do not use it to train, develop, or improve generalized or non-personalized artificial intelligence or machine learning models, and we do not permit anyone else to.
- AI features are the one case where Google data leaves our systems. When you ask SEOWren to generate an AI recommendation or report for a project or keyword, we include aggregated Search Console metrics for that project (top queries with their clicks, impressions, click-through rate, and average position) in the prompt we send to our AI model provider (currently one of Anthropic, OpenAI, Google Gemini, or OpenRouter, depending on the model configured). This happens only when you trigger an AI feature, only for the project you are analyzing, and only to produce that output for you. We use these providers under their standard API terms, which do not permit submitted data to be used to train their models.
- Apart from the AI processing described above, we do not transfer Google user data to third parties, except as necessary to run the service (for example, our hosting provider, which stores the encrypted database on our behalf), to comply with applicable law, or with your explicit consent.
- Nobody on our team reads your Google user data as a matter of course. There are three exceptions: our support team may look at it with your explicit permission while working on a request you have raised, our engineers may access it where that is necessary to investigate a security incident or abuse of the service, and we will disclose it where the law requires us to.
Limited Use disclosure
SEOWren's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention, disconnection, and revoking access
- We keep Google user data only for as long as the connection is active and you still want the feature.
- Disconnecting Search Console or Google Analytics from your SEOWren dashboard deletes the stored OAuth tokens for that connection, along with the linked properties and every metric we pulled through it.
- Deleting your SEOWren account removes these connections and all data derived from them, along with the rest of your account data.
- You can revoke SEOWren's access directly from Google at any time at myaccount.google.com/permissions. Doing so immediately stops any further access, and we recommend also disconnecting inside SEOWren so the stored data is cleared.
Questions about Google data specifically, or a request to have it deleted, can be sent to support@seowren.com.
Cookies
We use two kinds of cookies:
- Essential cookies: Required to sign you in, keep your session secure, remember your preferences (like dark mode), and store your cookie choice. These are always active.
- Analytics cookies: Set by Google Analytics and PostHog to understand how the platform is used. These are only set if you accept them.
When you first visit, we ask for your consent before setting any non-essential cookies. You can withdraw your consent at any time by clearing cookies in your browser, and we'll ask again on your next visit.
Third-party services
We work with a small number of third-party providers to operate our service:
- Search engine APIs: To retrieve ranking data for your keywords.
- Google APIs: The Search Console API and Google Analytics Data API, if you connect them. We call these on your behalf with the read-only authorization you grant; we do not share your data with Google beyond the API requests needed to read it back.
- Payment processors: Lemon Squeezy helps us handle checkout, subscription billing, tax collection, fraud controls, and related payment operations.
- Analytics and error tracking: Google Analytics (Google LLC) and PostHog help us understand product usage and diagnose errors. These run only with your cookie consent.
- Hosting providers: To run our infrastructure reliably.
These providers only access the minimum data needed to perform their function and are bound by their own privacy policies.
When you make a purchase, billing data needed to complete the transaction is processed by Lemon Squeezy as the merchant of record. You should also review Lemon Squeezy's own terms and privacy materials for details about how payment information is handled on their side.
Data retention
We retain your account data and ranking history for as long as your account is active. If you delete your account, we will remove your personal data within 30 days. Aggregated, anonymized data may be retained for analytics purposes.
Your rights
You have the right to:
- Access your personal data at any time through your account settings.
- Update your information through your profile page.
- Export your ranking data and reports.
- Delete your account and all associated data.
- Object to certain data processing activities.
Data security
We protect your data with industry-standard security measures including encryption in transit (TLS), encrypted passwords (bcrypt), and secure session management. We regularly review our security practices to keep your information safe.
Changes to this policy
We may update this privacy policy from time to time. When we make significant changes, we'll notify you via email or through a notice on our platform. We encourage you to review this page periodically.
Contact us
If you have questions about this privacy policy or how we handle your data, email us at support@seowren.com or reach out through our contact page.