Legal
Privacy Policy
Last updated 14 August 2026
1. Who we are
Seomely is an independently operated service. For any privacy question or request, including access, correction, export and deletion, contact privacy@seomely.com. We answer within 30 days. For the purposes of the GDPR we are the data controller for the account data described below.
2. What we access in your Google account
When you connect Search Console, Seomely requests exactly one OAuth scope:
https://www.googleapis.com/auth/webmasters.readonly
This is a read-only scope. It does not permit us to modify anything in your Search Console account. We cannot submit sitemaps, change settings, request removals, or add and remove users, because the permission to do so is not contained in the token we hold.
Using that scope, we read:
- Your list of Search Console properties, so you can choose which one to monitor, together with your permission level on each.
- URL inspection results for URLs belonging to the property you selected. This is the indexing status Google reports: coverage state, indexing state, robots.txt state, page fetch state, the canonical Google selected, the canonical you declared, the last crawl time, the sitemaps the URL was found in, and referring URLs.
We do not request or access Search Console performance data, your Gmail, Drive, Calendar, Contacts, or any other Google service.
3. Limited Use
Seomely's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the index monitoring features you signed up for. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except the sub-processors listed in section 7, and we do not allow humans to read it except where you have explicitly asked us to for support, where required by law, or where necessary for security purposes such as investigating abuse.
4. What we store
- Account details from Google sign-in: your name, email address, and profile picture URL.
- OAuth tokens. We store the refresh token issued by Google so that scheduled checks can run while you are not signed in. It is stored in our database and used only to obtain access tokens for the calls described above.
- Project configuration: the domain and Search Console property you connected, your sitemap URL, your IndexNow key, and your alert preferences.
- Your URL inventory: the URLs found in your sitemap, when each was first and last seen, and the last-modified date your sitemap declares.
- Indexing history: every inspection result we receive from Google, kept over time. This history is the core of the product. It includes the raw response body from the URL Inspection API for the URL in question.
- Events and submissions: the state changes we detect, and a log of URLs we notified the IndexNow network about.
What we do not store
We do not fetch, render, or store the content of your pages. The only file Seomely ever requests from your own server is your sitemap, and, if you enable IndexNow, the key verification file. Your pages themselves are never requested by us, so Seomely adds nothing to your crawl load.
5. Why we store it (legal basis)
We process this data to perform the contract you entered into when you created an account, namely to monitor the indexing status of your URLs and alert you when it changes. Where we process data for security and abuse prevention, the legal basis is our legitimate interest in keeping the service available and safe.
6. How long we keep it
- Indexing history is retained for as long as your account is active, because its value comes from being long-running. Free accounts are limited to 90 days of history; older records on free accounts are deleted automatically.
- Account and project data is retained until you delete the project or your account.
- On account deletion, all of the above is permanently deleted within 30 days, including your OAuth tokens and your full indexing history. Backups containing the data are rotated out within a further 30 days.
7. Who else processes it
We use a small number of sub-processors to run the service. They process data on our instructions only:
- Vercel — application hosting and execution.
- Neon — the Postgres database where your data is stored.
- Polar — payment processing and invoicing for paid plans. Polar acts as merchant of record. We never see or store your card details.
- Resend — delivery of alert and account emails.
We do not sell your data, and we do not share it with advertisers or data brokers. Ever.
8. Where it is processed
Our infrastructure is hosted in the United States. If you are in the European Economic Area or the United Kingdom, your data is transferred outside your region on the basis of the European Commission's Standard Contractual Clauses, which each of our sub-processors has entered into.
9. Your rights and how to exercise them
You can access, correct, export, or delete your data at any time from your account settings, or by emailing privacy@seomely.com. You may also object to or restrict processing, and you have the right to lodge a complaint with your local supervisory authority.
Revoking Google access. You do not need us to do this. Go to your Google account permissions and remove Seomely. Every scheduled job for your properties stops as soon as the token is rejected. Revoking access does not delete data we already hold, so if you want that removed too, delete your account or email us.
10. Security
Data is encrypted in transit and at rest. Access to production systems is limited to personnel who need it and is protected by multi-factor authentication. API keys are stored only as SHA-256 hashes, so a copy of our database does not yield usable keys.
11. Children
Seomely is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes
If we change this policy in a way that materially affects how we handle your data, we will email you before the change takes effect. The date at the top of this page always reflects the current version.