Privacy Policy

Last updated 8 October 2026View as Markdown

This Privacy Policy explains how Inhype Live Limited, trading as SEOFix ("SEOFix", "we", "us" or "our"), collects, uses, shares and protects personal data. It covers:

  • our website at seofix.ai;
  • the SEOFix web application;
  • the REST API at api.seofix.ai and the MCP server at mcp.seofix.ai;
  • the seofix command-line tool;
  • the SEOFixBot crawler.

We comply with the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"), and, where it applies, the EU General Data Protection Regulation ("EU GDPR").

Who we are

The controller of your personal data is:

Inhype Live Limited Company number 13379772, registered in England and Wales Email: [email protected] (subject line "Privacy request")

We have not appointed a Data Protection Officer, because the law does not require one for our processing. Please send any privacy question to the address above.

Summary

  • We collect what we need to run your account and your audits. This means your name and email, your team, the sites you add, the public pages we crawl for you, and, if you connect them, Google Search Console and Cloudflare.
  • We do not sell personal data. We do not use advertising or analytics cookies, and we do not use your data to train AI models.
  • Our providers host and process data for us under contracts. The main ones are DigitalOcean, Cloudflare, Stripe, Google, Twilio SendGrid and Slack.
  • You can access, correct, export or delete your data. Email [email protected].

The data we collect

Data you give us

Data Examples
Account Name, email address, password (stored only as a one-way hash), and the time you accepted our Terms.
Google sign-in If you sign in with Google: your name, email address, Google account ID and profile picture, as shared by Google.
Team Team name, members, invitations (the invited email address), roles.
Sites and settings Website addresses, audit settings, monitoring schedules, alert preferences, webhook URLs, verification method.
Billing Plan, billing interval, Stripe customer and subscription IDs, invoice amounts and dates. Card details are collected and stored by Stripe, never by us.
Support What you write to us by email, and our replies.

Data created when you use SEOFix

Data Examples
Audit data The URLs SEOFixBot fetched for you, HTTP status codes, response headers, page titles, meta tags, headings, links, word counts, structured data, response times, the issues found and fix tasks.
Fix history Fix tasks you or your agents verified, recheck results, and Search Console figures before and after each fix.
API and agent use API keys (stored as a hash; only a short prefix stays visible), when they were last used, and the audits and requests made with them.
Agent connections When you run npx seofix connect: the client name, and the hostname of the computer and the agents it configured, so you can recognise the key later.
Integration credentials Cloudflare API token, Google OAuth tokens and your sites' crawler secrets. These are encrypted at rest and never shown in full in the app.

Data from Google and Cloudflare (only if you connect them)

  • Google Search Console (read-only scope webmasters.readonly). We receive:

    • the list of properties you can access, and your permission level for each;
    • per-page clicks, impressions, click-through rate and average position;
    • daily totals;
    • URL Inspection results, such as index status, Google-selected canonical, last crawl time and robots state.

    We do not store the search queries people used to find your site.

  • Cloudflare (with the API token you create). We read your zone details, and create and manage the DNS verification record and the firewall skip rule for SEOFixBot.

Data collected automatically

Data Details
Server logs IP address, user agent, requested URL, referrer, time and response status. Our web server and Cloudflare record these for security, abuse prevention and troubleshooting.
Rate-limit counters Short-lived counters keyed by IP address or network prefix (for example to limit anonymous preview audits and login attempts). They expire within hours.
Acquisition source On your first visit we may record the website that referred you (host name only), the page you landed on and any campaign (UTM) parameters in a first-party cookie. If you sign up, this is saved with your account so we know which channels bring users. See our Cookie Policy.
Cookies Strictly necessary cookies for sign-in, security and the preview flow. See the Cookie Policy.

Anonymous preview audits

If you start a preview audit from our homepage without an account, we process the website address you enter and your IP address. We use your IP address only for the preview rate limits. An unclaimed preview is deleted 24 hours after it is created. If you sign in within that time, the preview is added to your account.

People whose websites we crawl

SEOFixBot crawls a website only when a SEOFix user starts an audit of it. Users must own the site or be authorised to audit it. The crawler fetches publicly available pages. It follows robots.txt and does not log in, submit forms or bypass access controls.

We do not intend to collect personal data from the pages we crawl, and our checks look at technical page elements, not at individuals. A crawled page can still contain personal data, for example a name in a page title or an email address in a link. Such data is stored as part of the audit, for the user who requested it, and deleted with the audit data as described below.

For the data on crawled pages, we act as a processor on behalf of the SEOFix user who started the audit. That user decides why the site is audited and is the controller. If you own a website and want to stop SEOFixBot, see SEOFixBot or block SEOFixBot in your robots.txt. To ask about an audit of your site, contact [email protected].

Purpose Legal basis (UK/EU GDPR)
Creating and running your account and teams, running audits, showing reports, providing the API, MCP server and integrations Performance of our contract with you (Article 6(1)(b))
Taking payments, managing subscriptions and credits, keeping invoices Contract (6(1)(b)) and legal obligation for tax and accounting records (6(1)(c))
Sending service emails: email verification, invitations, monitoring alerts you turn on, billing and security notices, changes to our Terms Contract (6(1)(b)) and our legitimate interest in operating the Service (6(1)(f))
Security: preventing abuse, fraud, unauthorised crawling and attacks, rate limiting, investigating incidents Legitimate interests (6(1)(f))
Understanding how SEOFix is used and which channels bring users, improving features and fixing bugs, using aggregated statistics Legitimate interests (6(1)(f))
Internal notifications to our team about account activity (for example a new sign-up or a failed audit), so we can support users and spot problems Legitimate interests (6(1)(f))
Responding to support requests Contract (6(1)(b)) and legitimate interests (6(1)(f))
Complying with the law, responding to lawful requests, establishing or defending legal claims Legal obligation (6(1)(c)) and legitimate interests (6(1)(f))
Product news or marketing emails (only if we send them) Your consent, or our legitimate interest for existing customers where the law allows. You can unsubscribe at any time.

Where we rely on legitimate interests, we have balanced them against your rights. You can object at any time (see Your rights).

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. Automated abuse checks, such as preview rate limits, can stop an individual request. A human reviews any decision to suspend an account.

Google API Services: Limited Use

SEOFix's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features of SEOFix that you can see in the app: sign-in, site verification, Search Console reports, indexing triage, fix ranking and traffic from fixes.
  • We do not transfer Google user data to others, except as needed to provide or improve those features, to comply with the law, or as part of a merger, acquisition or sale of assets with notice to you.
  • We do not use Google user data for advertising, including retargeting or personalised advertising.
  • We do not allow humans to read Google user data, unless we have your affirmative consent for specific data, it is needed for security purposes such as investigating abuse, it is needed to comply with the law, or the data is aggregated and anonymised for internal operations.
  • We do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models.

You can disconnect Google Search Console in SEOFix at any time, or revoke our access at myaccount.google.com/permissions. When you disconnect, we delete the stored Google tokens. Search Console figures already imported for your sites stay until you delete the site or your account.

AI agents and AI training

SEOFix is designed to be used by AI coding agents. When your agent calls the SEOFix API or MCP server, the data it requests is sent to that agent. Through the agent, it may reach the agent's provider, for example Anthropic, OpenAI or Cursor. That transfer happens on your instruction and under your agreement with the provider, and we are not responsible for how the provider uses the data.

We do not use your account data, audit data, Search Console data or any other Customer Data to train AI models, and we do not sell or license it to anyone who does.

Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only as follows.

Service providers (processors)

These providers process personal data on our behalf, under contracts that require them to protect it and use it only on our instructions:

Provider Purpose Location
DigitalOcean, LLC Servers and databases that run SEOFix Frankfurt, Germany (EU)
Cloudflare, Inc. Content delivery, DNS, security and DDoS protection for our websites. R2 object storage for archived audit data. Global network; USA
Stripe Payments Europe, Ltd. / Stripe, Inc. Payment processing, subscriptions, invoices, fraud prevention Ireland, USA
Google LLC / Google Ireland Ltd. Google sign-in, Search Console API, URL Inspection API, and PageSpeed Insights API where Core Web Vitals checks are enabled USA, Ireland
Twilio Inc. (SendGrid) Sending transactional emails USA
Slack Technologies, LLC Internal notifications to the SEOFix team about account and platform activity. These include name, email address, site domains and audit summaries; IP addresses are truncated. USA
Ploi B.V. Server management and deployment tooling Netherlands (EU)

Others

  • Your team. Members of a team can see the team's sites, audits, API keys (by prefix), members and invitations.
  • Integrations you turn on. When you turn on IndexNow, the URLs you submit go to the IndexNow protocol and its participating search engines, such as Bing and Yandex. Webhook payloads go to the URL you configure.
  • Legal requirements. We may disclose data where required by law, court order or a valid request from a public authority. We may also disclose it to protect the rights, property or safety of SEOFix, our users or others.
  • Business transfers. If we are involved in a merger, acquisition or sale of assets, personal data may be transferred to the new owner. This Privacy Policy continues to apply to it, and we will tell you in advance.

International transfers

Our main servers are in the European Union (Frankfurt, Germany). Some providers process data in the United States and other countries outside the UK and the European Economic Area. When data is transferred out of the UK or EEA, we rely on:

  • adequacy decisions, including the EU-US Data Privacy Framework and the UK Extension to it where the provider is certified;
  • or the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum.

You can ask us for a copy of the relevant safeguards at [email protected].

How long we keep data

Data Retention
Account, team and site data While your account is active. Deleted within 30 days after you close your account or delete the site, except as listed below.
Audit page-level data (pages, links, issues) Kept for the 3 most recent full audits of each site. Older audits are archived and removed from the app. Their summaries, such as the health score trend, stay with the site. Archived data is deleted when the site or account is deleted. See Data retention.
Unclaimed anonymous previews 24 hours
Recheck (Verify fix) results Archived after 7 days; the result summary stays with the fix task.
seofix connect requests Deleted about a day after they expire, are used or are denied. Each code is valid for 10 minutes.
Search Console data While the site exists in SEOFix. Google tokens are deleted when you disconnect.
Billing records and invoices 6 years after the end of the financial year they relate to, as UK tax law requires
Server and security logs Typically up to 90 days, longer only where needed to investigate an incident
Support emails Up to 3 years after the conversation ends
Backups Overwritten on a rolling basis, usually within 30 days

Security

We protect personal data with appropriate technical and organisational measures, including:

  • encryption in transit (HTTPS/TLS 1.2+) for all our endpoints;
  • hashing of passwords and API keys;
  • encryption at rest of integration tokens and crawler secrets;
  • isolation of each team's data in the application;
  • an origin firewall that only accepts traffic through Cloudflare;
  • server-side request forgery protections on the crawler and webhooks;
  • access to production systems restricted to authorised staff.

No system is completely secure. If you believe you have found a security problem, please email [email protected].

Data breaches. If a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, where required. Where the risk is high, we will tell you without undue delay.

Your rights

Under UK and EU GDPR you have the right to:

  • Access the personal data we hold about you and get a copy (Article 15);
  • Rectify inaccurate or incomplete data (Article 16);
  • Erase your data ("right to be forgotten") (Article 17);
  • Restrict our processing in certain circumstances (Article 18);
  • Data portability: receive data you provided in a structured, machine-readable format, or have it sent to another provider (Article 20). Most audit data is also available through the REST API;
  • Object to processing based on legitimate interests, and to direct marketing at any time (Article 21);
  • Withdraw consent at any time where we rely on consent, without affecting earlier processing (Article 7(3)).

To exercise a right, email [email protected] from the address on your account with the subject "Privacy request". We may need to verify your identity. We respond within one month. This can be extended by two further months for complex requests, in which case we tell you. There is normally no charge.

You also have the right to complain to a data protection authority. In the UK that is the Information Commissioner's Office: ico.org.uk, helpline 0303 123 1113. In the EU you can contact the authority in the country where you live or work. We would appreciate the chance to address your concern first.

California and other US states

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act and similar state laws. Residents of those states may request access to, correction of or deletion of their personal information by emailing [email protected]. We will not discriminate against you for exercising these rights.

Children

SEOFix is a business tool intended for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy when our processing or the law changes. We will publish the new version on this page and update the "Last updated" date. If we make material changes, we will notify account holders by email or in the app before the changes take effect.

Contact

Inhype Live Limited (trading as SEOFix) Company number 13379772, registered in England and Wales Email: [email protected] (subject line "Privacy request")

UK supervisory authority: Information Commissioner's Office, ico.org.uk, 0303 123 1113