Privacy Policy
Last Updated: July 2026
At SEOVault AI, we take your privacy and the security of your WordPress content seriously. This Privacy Policy explains how the SEOVault AI Chrome Extension, the SEOVault AI Web App, the SEOVault AI WordPress plugin, and the SEOVault website collect, use, and protect your information.
1. What Data We Access and Why
SEOVault AI is designed to assist WordPress authors with SEO analysis, content optimization, internal linking, and writing support — using either our Chrome extension or a lightweight WordPress connector plugin that links the SEOVault AI web app to your site.
WordPress Content
When you use the extension, we access content inside your Gutenberg editor, including:
- Draft text
- Headings
- Titles
- Metadata
- User-selected text
This access is used only to provide SEO analysis, diagnostics, AI-assisted features, and internal link suggestions.
No Permanent Storage of Drafts
Your WordPress drafts are processed in real time.
- We do not permanently store full article drafts
- We do not archive or reuse your content
- We do not publish or share your drafts
Temporary processing may occur solely to return requested results.
2. AI Processing & Data Handling
SEOVault AI uses third-party AI and search APIs to power analysis, diagnostics, and content generation features.
When you use AI-powered features:
- Portions of your content, selected text, or focus keywords may be sent to external APIs (such as Gemini, OpenAI, Perplexity, Mistral, or other LLMs) only to generate results
- Data is processed on demand and is not used to train our own models
- We do not sell, reuse, or distribute your content
- You remain the owner of all content at all times
3. Third-Party Services and APIs
To deliver SEO insights and AI functionality, SEOVault AI integrates with third-party services.
AI & Research Providers
To deliver high-precision SEO analysis and content generation, SEOVault AI utilizes an orchestration of industry-leading Large Language Models (LLMs) and real-time search APIs. This system dynamically selects the most capable processing engine for each specific task (such as SERP analysis or content drafting).
All data transmitted to these third-party providers is processed in real-time, is not used to train the underlying models, and is protected by enterprise-grade confidentiality agreements.
Pro Tip for Data Safety: While our enterprise-grade API configurations ensure your data is not used for training, as a general best practice for all AI-powered tools, we recommend that you do not include highly sensitive personal information (such as passwords, financial records, or private identification numbers) within your WordPress drafts when utilizing AI analysis features.
Authentication
Google Authentication — used to securely manage user accounts and subscriptions. We only access basic profile information (such as email address) to identify your account.
Google Search Console and Google Analytics Access
SEOVault AI accesses Google user data only after a workspace owner or administrator explicitly connects a Google account through Google OAuth and grants the requested permissions.
For this integration, SEOVault AI requests the following Google OAuth scopes:
openidemail-
https://www.googleapis.com/auth/webmasters.readonly -
https://www.googleapis.com/auth/analytics.readonly
SEOVault AI uses these scopes for read-only access. SEOVault AI does not write to, modify, or delete data inside a user's Google Search Console or Google Analytics account.
Data Accessed
When a user connects Google Search Console and Google Analytics, SEOVault AI may access, collect, or process the following Google user data:
- Basic Google account information needed to identify the connected account, such as the connected Google account email address.
- Search Console property metadata, such as site/property identifiers and permission level.
- Search Console performance data for selected date ranges, including pages, queries, clicks, impressions, click-through rate, and average position.
- Google Analytics 4 property metadata, including property IDs and display names.
- Google Analytics 4 traffic and landing page data for selected date ranges, including landing page paths, session source, session medium, default channel group, sessions, engaged sessions, engagement rate, average session duration, bounce rate, conversions, and page views.
- OAuth connection metadata, including granted scopes, connection timestamp, and an encrypted refresh token used to maintain the authorized connection.
Data Usage
SEOVault AI uses Google user data only to provide and improve user-facing SEO and AI Visibility features inside the user's workspace. This includes:
- Allowing users to connect a Google account and select Search Console and Google Analytics properties for their workspace.
- Mapping Search Console and Google Analytics properties to sites connected to the workspace.
- Displaying Google Search Signals, SEO performance, traffic insights, top pages, landing pages, and observable AI referral summaries inside the AI Visibility feature.
- Generating selected-page insights, including matching Search Console query data against the user's page content to identify SEO and AI-readiness opportunities.
- Refreshing Google access tokens server-side when needed so the authorized connection continues to work until the user disconnects it.
SEOVault AI does not use Google user data to serve ads, for retargeting, for sale to data brokers, or to train SEOVault AI or third-party AI models.
Data Sharing
SEOVault AI does not sell Google user data and does not share Google user data with advertisers, data brokers, or unrelated third parties.
Google user data may be processed by service providers that help us operate SEOVault AI, such as hosting, database, infrastructure, monitoring, and security providers. These providers process data on our behalf only as needed to provide, secure, and maintain the service.
Within SEOVault AI, Google-derived data may be visible to authorized members of the same workspace according to the workspace's access controls.
We may disclose data when required by law or when necessary to protect users, prevent abuse, enforce our terms, or secure the service.
Data Storage and Protection
SEOVault AI stores Google connection records and selected Google-derived workspace summaries in our backend systems only as needed to provide the AI Visibility feature.
OAuth refresh tokens are encrypted before storage and stored in our backend database. Google access tokens are obtained server-side when needed and are not stored as part of the workspace connection record.
Google OAuth client credentials and token-encryption keys are stored as server-side secrets and are not exposed in the browser.
Traffic between the user's browser, SEOVault AI, our backend systems, and Google APIs is protected using HTTPS/TLS encryption.
We use access controls and operational safeguards designed to limit access to Google user data to the systems and personnel needed to provide, maintain, support, and secure the service.
Data Retention and Deletion
Temporary OAuth state records are deleted after use or expire after approximately 10 minutes.
The stored Google connection record, including the encrypted refresh token, connected email, granted scopes, and connection metadata, is retained until the workspace owner or administrator disconnects Google from the Connections page or requests deletion.
Disconnecting Google stops future access to Google Search Console and Google Analytics data and deletes the stored Google OAuth connection token record. Disconnecting Google does not automatically delete Google-derived summaries that were previously imported into the workspace.
SEOVault AI may retain previously imported Google-derived workspace summaries so the AI Visibility feature can show imported results and historical context. This may include site-to-property mappings, import logs, page-level Search Console metrics, selected-page query insight summaries, Google Analytics landing page metrics, referral/source summaries, and related AI Visibility summaries.
Users may request deletion of stored Google connection data and previously imported Google-derived workspace data by emailing support@seovaultai.com. After verifying the request, we will delete the relevant Google connection records and Google-derived workspace data, subject to legal, security, fraud-prevention, and backup retention obligations.
4. Payments & Billing
SEOVault AI uses Paddle.com as its payment processor and Merchant of Record.
When you make a purchase:
- Paddle processes billing details, payment method, tax location, and transaction records
- SEOVault AI does not store your full payment information
- Paddle's handling of personal data is governed by its own privacy policy
5. Extension Permissions Explained
The SEOVault AI Chrome Extension requests certain permissions that are necessary to provide its WordPress publishing, SEO, and AI-assisted functionality.
The extension requests the following permissions strictly for product features:
- storage — used to save user preferences, local settings, connected WordPress site configuration, SEO snippets, focus mode settings, and other extension data locally within the browser.
- identity — used to authenticate users through supported sign-in providers and verify account access, subscriptions, credits, and feature entitlements.
- tabs / activeTab — used to detect when the user is working inside supported WordPress admin or editor pages and to enable user-triggered actions such as screenshot capture and page analysis.
- scripting — used to enable communication between the extension side panel and supported WordPress editor pages, including Gutenberg integration and publishing workflows.
- contextMenus — used to provide user-triggered right-click actions such as screenshot capture, saving selected text to SEO Snippets, citation tools, and word-count analysis.
- host_permissions — used to allow the extension to operate on WordPress sites that the user explicitly chooses to connect, including editor integration, sitemap access, internal linking workflows, and WordPress-related functionality.
Screenshot Handling
The extension includes a screenshot utility. Images captured through this feature are processed locally through your browser and system clipboard. Screenshots are not uploaded to or stored on SEOVault AI servers unless you explicitly choose to use a feature that requires remote processing.
SEO Snippets (Local Storage)
User-selected text saved to SEO Snippets is stored locally within your browser. This information is not uploaded to SEOVault AI servers and remains under your control on your device.
AI Processing & Backend Communication
Certain premium AI features require communication with SEOVault AI backend services in order to generate results.
Examples include, but are not limited to:
- AI Humanizer
- Deep Analysis (DAC Score)
- Article Generation
- Outline Generation
- FAQ Generation
- TL;DR Generation
- Brand Kit Analysis
- Other AI-assisted content workflows
When you explicitly invoke one of these features, content necessary to provide the requested functionality may be transmitted to SEOVault AI backend services and supporting AI providers for processing.
Such content is transmitted solely for the purpose of providing the requested feature and is not used to monitor unrelated browsing activity.
Authentication
SEOVault AI uses authentication services to manage user accounts, subscriptions, credits, and premium feature access.
When you sign in, we may process basic account information such as your email address and authentication identifiers in order to identify your account and provide access to your purchased services.
Installation & Diagnostic Identifiers
The extension may generate a random installation identifier used for extension functionality, diagnostics, abuse prevention, service reliability, and account-related operations. This identifier is not intended to identify you personally.
Uninstall Feedback
If you uninstall the extension, Chrome may open an uninstall feedback page. This page may receive limited diagnostic information such as extension version, login status, subscription tier, and a non-reversible hashed account identifier to help us understand product usage and improve the service.
No article content, screenshots, SEO snippets, passwords, browsing history, or personal files are transmitted as part of uninstall feedback.
No General Browsing History Collection
SEOVault AI does not collect or store your general web browsing history.
The extension checks browser tabs only when necessary to determine whether supported WordPress pages are open, to enable connected-site functionality, or to perform actions that you explicitly request.
Permissions are used only to support SEOVault AI functionality and are not used for unrelated tracking, advertising, or monitoring of general browsing behavior.
6. SEOVault AI WordPress SEO Plugin
The SEOVault AI WordPress plugin is designed to run primarily on your own WordPress server. Core SEO features (titles, meta descriptions, schema, sitemaps, social metadata, redirects, and related settings) can operate without sending your content to SEOVault AI servers. Optional features may store data locally or communicate with external services only when you enable or configure them.
SEOVault AI does not receive visitor or content data from the plugin unless you explicitly connect the SEOVault AI web app, configure an optional webhook, or otherwise send data to us yourself.
Data Stored Locally on Your WordPress Site
Depending on which features you enable, the plugin may store the following in your WordPress database, options, or related local storage. This data remains on your server unless you export or transmit it.
- SEO settings and metadata: SEO titles, descriptions, focus keywords, robots directives, canonical URLs, Open Graph / social fields, schema, redirects, llms.txt content, and related configuration.
- Connection credentials: Site API keys used to authenticate the optional SEOVault web app or scoped integrations.
- 404 Monitor (optional): When enabled, broken request URIs may be logged locally. In advanced mode, the referring URL and visitor user agent may also be stored. Visitor IP addresses are not stored by the 404 monitor.
- API audit logs (optional / automatic for connector security): Failed authentication and related connector events may be logged with SHA-256 hashed IP and user-agent values (not raw identifiers), together with route and event metadata.
- Rate limiting: Temporary hashed identifiers may be stored as WordPress transients to limit abusive requests to the connector API.
- AI crawler logs (optional): When crawler logging features are enabled and populated, visitor IP addresses and user agents may be stored only as SHA-256 hashes, together with related visit metadata such as request URL and timestamp. Raw IPs and user agents are not retained.
-
Site Health Monitor logs (local): When the
plugin is active, PHP errors at or above the configured
severity may be written locally (for example to
wp-content/debug.log). If the optional Site Health must-use helper is installed, fatal errors may also be recorded locally under your uploads directory (for exampleseovault-health-monitor/issues.jsonl). Those local files stay on your server unless an optional off-site channel below is configured.
Optional Connection to the SEOVault AI Web App
Connecting your site is optional. When you paste a valid site key
into the SEOVault AI web app, the app connects
to your WordPress site over the WordPress REST API
(seovaultai/v1). The plugin does not automatically
upload posts to SEOVault AI for AI processing in the background.
While connected, authorized API clients that hold a valid site key may read and update SEO-related content and settings on your site, which can include full post content needed for SEO and AI-assisted workflows in the web app. Disconnecting or regenerating the site key stops that access. Data handling inside the web app (including AI providers) is described in the sections above covering the SEOVault AI Web App.
Optional External Communication
The plugin may make outbound requests only for features you enable or actions you initiate:
-
IndexNow (optional): When enabled, publishing,
updating, or removing content may submit the affected URL(s)
and your IndexNow verification key to
https://api.indexnow.org/indexnow/so search engines can be notified. The IndexNow key file is publicly accessible by design of the IndexNow protocol. -
Site Health Monitor (optional off-site reporting):
Local error capture can run while the plugin is active. Off-site
visibility in the SEOVault AI web app is optional and works only
when your site is connected and/or a health webhook is
configured:
- Optional must-use helper: From the SEOVault AI web app, you may install a small WordPress must-use plugin that records fatal PHP errors locally even if the main plugin cannot fully load. That helper writes to a local issues file on your site; it does not by itself upload errors to SEOVault AI.
-
Optional webhook push: If an HTTPS webhook
URL is configured, critical or warning PHP error summaries
(message, sanitized relative file path, line number,
timestamp, deduplication hash, and site URL) may be POSTed
to that URL shortly after the error occurs. Authentication
uses an
X-Site-KeyHTTP header (the site key is not included in the JSON body). This is the near-real-time path that can populate detailed error history in the SEOVault AI web app. - Optional connected-site health summaries: When your site is connected with a site key, SEOVault AI’s backend may periodically request a health summary from your site’s REST API (about every five minutes). That summary can include status, recent issue counts, the most recent issue summary, and non-content diagnostics such as PHP version or whether the must-use helper is installed. The web app displays this health information from SEOVault AI’s service so connected users can monitor site health from the dashboard. Manual refresh may also be available in the web app.
-
Google Analytics (optional): If you enable
analytics tracking in plugin settings and provide a Measurement
ID (or custom tracking code), the plugin may output Google
tag / gtag code that loads from Google
(
www.googletagmanager.com) and sends standard analytics data according to your Google Analytics configuration. This uses credentials you provide and is not SEOVault AI’s Google OAuth integration (described separately in this policy for the web app). -
Google Maps (optional): If you configure a
Google Maps API key and use Local SEO map shortcodes, the plugin
may load the Google Maps JavaScript API from
maps.googleapis.comon pages that display the map, using the API key you provide. - Schema import from URL (admin-initiated): If an administrator uses the schema import tool and enters an external URL, the plugin may fetch that URL to parse JSON-LD / schema markup locally.
- Same-site diagnostic checks: SEO Analyzer and related tools may make loopback requests to your own site (for example sitemap, robots.txt, or homepage checks). These are not third-party transmissions.
Uninstall and Data Retention
From SEOvault AI → Tools → Data & Uninstall, site administrators can choose whether plugin data should be permanently deleted when the plugin is uninstalled.
- Default (checkbox off): Deleting the plugin removes connection secrets and operational leftovers — including site API keys, connection state, optional health webhook URL, related rate-limit / auth transients, scheduled cron events, and the Site Health Monitor must-use helper file — but keeps SEO settings, per-post SEO metadata, redirects, 404 logs, Local SEO data, schema-related content, and other stored plugin data in your WordPress database and related local files. Those leftovers remain on your site until you delete them manually or reinstall and erase them later.
- “Erase all data on uninstall” (checkbox on): Deleting the plugin permanently removes SEOvault AI data from your site, including SEO metadata, redirects, 404 logs, Local SEO locations, schema templates, sitemap cache files, plugin settings, custom tables, and related stored files. This cannot be undone.
Uninstall cleanup runs on your WordPress site only. It does not delete your SEOVault AI web app account, subscription, or workspace data stored in SEOVault AI cloud services.
No Unauthorized Telemetry
The SEOVault AI WordPress plugin does not include hidden tracking, unauthorized usage telemetry, license verification “phone homes,” or custom update checks that transmit data to SEOVault AI servers without your setup and consent. External communication is limited to the optional features and integrations described above. WordPress.org update checks, when the plugin is distributed through WordPress.org, follow standard WordPress core behavior.
7. Data Protection & Disclosure
- No Sale of Data: We do not sell, trade, or rent your personal data or WordPress content
- Security: Data transmitted between your browser and our API partners is encrypted using SSL/TLS
- Limited Access: Only essential systems and services access data required to operate features you explicitly use
Limited Use Disclosure: Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements or for any purpose other than providing the core functionality of SEOVault AI.
8. Your Rights and Control
You are always in control of your data.
- You may stop all data access by uninstalling the extension
- You may disconnect or uninstall the WordPress plugin, regenerate site keys, and disable optional features such as IndexNow, analytics output, Maps shortcodes, 404 monitoring, and health webhooks
- You may clear locally stored preferences via your browser settings
- If applicable, you may request access to or deletion of account-related data, including stored Google connection/import data, subject to legal obligations
9. Contact Us
If you have any questions about this Privacy Policy or how SEOVault AI handles data, contact us at:
Data Protection Officer: Nuri Ciftcioglu. For formal privacy inquiries or data deletion requests, please contact us at support@seovaultai.com.
Website Privacy (SEOVaultAI.com)
The following applies to visitors of our website and the WordPress-hosted blog/documentation sections of SEOVaultAI.com.
Who We Are
Our website address is: https://seovaultai.com
Comments
When visitors leave comments, we collect the data shown in the comments form, IP address, and browser user agent string to help with spam detection. An anonymized hash of your email address may be shared with the Gravatar service.
Media
If you upload images to the website, avoid embedding location data (EXIF GPS). Visitors may download and extract location data from images.
Cookies
- Comment cookies may store your name, email, and website for convenience (1 year)
- Login cookies manage authentication and display preferences
- Publishing cookies store post ID references only and expire after 1 day
We also use analytics services such as Google Analytics and Microsoft Clarity to understand navigation patterns, clicks, scroll behavior, and usability issues across our marketing site and web app. These tools help us diagnose friction, demand, and product issues faster. Sensitive form fields and input content are masked by default where supported, and analytics preferences can be managed through our cookie controls.
Embedded Content from Other Websites
Articles may include embedded content (videos, images, articles). Embedded content behaves as if you visited the external website directly and may collect data or track interactions.
Who We Share Your Data With
If you request a password reset, your IP address will be included in the reset email.
Data Retention
- Comments and metadata are retained indefinitely
- Registered users' profile data is stored until modified or deleted
- Administrators can access this data for management purposes
Your Data Rights
You may request:
- An export of personal data we hold
- Deletion of personal data (excluding legally required records)
Where Your Data Is Sent
Visitor comments may be checked through automated spam detection services.