Privacy Policy

Effective date: June 26, 2025

1. Who We Are

PrismSEO (“we”, “our”, “us”) operates the SaaS platform at console.prismseo.app. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Service.

For questions, contact us at support@prismseo.app.

2. Information We Collect

2a. Information you provide directly

  • Account data: first name, last name, email address, password (hashed — we never store plaintext passwords).
  • Billing data: handled entirely by Polar. We receive only your subscription status and plan; we never see your card number or banking details.
  • Content you create: keywords, article drafts, calendar plans, publishing settings.

2b. Data from third-party integrations

  • Google Search Console: When you connect your GSC account via OAuth, we read your site performance data — clicks, impressions, CTR, average position, queries, and page URLs — for the properties you grant us access to.
  • Google OAuth profile: Name and email address returned by Google during sign-in.

2c. Data collected automatically

  • Usage events: feature interactions (e.g. article generated, keyword researched) to help us understand how the product is used.
  • Log data: server-side logs including IP address, request path, and timestamps, retained for up to 30 days for security and debugging.

3. How We Use Your Data

  • To provide, operate, and improve the Service.
  • To process your GSC data and surface keyword opportunities.
  • To generate AI-assisted content using your keywords and GSC context.
  • To send transactional emails (account confirmation, password reset, billing receipts).
  • To respond to support requests.
  • To detect and prevent fraud, abuse, or security incidents.
  • To comply with legal obligations.

We do not use your data to train AI models.

4. How We Share Your Data

We do not sell your personal data. We share data only as follows:

  • OpenAI: Anonymised keyword and competitor context is sent to generate article drafts. We do not include your name, email, or identifiable information in prompts.
  • DataForSEO: Keywords are sent to retrieve search volume and difficulty data.
  • Polar: Processes subscription payments. See Polar's Privacy Policy.
  • Resend: Used to send transactional emails. Your email address is shared only to deliver emails you've requested.
  • Supabase: Our database and authentication infrastructure. Your data is stored on Supabase's servers. See Supabase's Privacy Policy.
  • Legal requirements: We may disclose your data if required to do so by law or in good-faith belief that such action is necessary to comply with a legal obligation, protect our rights, or investigate fraud.

5. Data Retention

  • Account and GSC data is retained for as long as your account is active.
  • If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or compliance reasons.
  • Anonymised, aggregated analytics data may be retained indefinitely.

6. Data Security

We implement industry-standard security measures including:

  • All data in transit is encrypted using TLS 1.2+.
  • Passwords are hashed by Supabase using bcrypt.
  • Database access uses row-level security (RLS) so each user can only access their own data.
  • API routes are authenticated — unauthenticated requests are rejected with a 401 before any data is read or written.
  • OAuth tokens (GSC) are stored encrypted in the database.

No system is 100% secure. If you believe you have found a security vulnerability, please report it responsibly to support@prismseo.app.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your account and associated personal data.
  • Export your data in a portable format.
  • Revoke Google OAuth access at any time via your Google account settings.
  • Opt out of non-essential communications.

To exercise any of these rights, email us at support@prismseo.app. We will respond within 30 days.

8. Cookies

We use session cookies set by Supabase to maintain your authenticated session. These are strictly necessary for the Service to function and cannot be disabled while using the Service. We do not use tracking cookies or advertising cookies.

9. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately.

10. International Data Transfers

Your data may be processed in countries other than your own, including the United States, where our infrastructure providers (Supabase, OpenAI, Vercel) operate. By using the Service, you consent to this transfer. We rely on our service providers' standard contractual clauses and data processing agreements to ensure appropriate protection.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance.

12. Contact

For privacy-related questions or data requests, contact us at support@prismseo.app.