seoduh seo made simple Start 14-day free trial →

Privacy policy

Last updated 9 September 2026

Draft. This describes what the product actually does today, written from the code and the database schema. The bracketed fields still need real values and a lawyer should read it before it goes live.

Who we are

[Legal entity name], [registered address], [company number], is the controller of the personal data described here. Write to hello@seoduh.com about anything on this page.

What Seoduh does with data, in one paragraph

Seoduh reads the analytics accounts you connect, keeps the numbers so it can compare periods, and joins them with the changes you make to your site. Every connection is read-only. Seoduh never publishes, edits or deletes anything in your accounts or on your site.

What we collect

Your account

You sign in with your Google account, through Firebase Authentication. It is the same account that holds your Search Console access, so connecting your data is one step rather than two. From that sign-in we store your email address, your display name and profile picture if Google returns them, and the Firebase user id. We also store which workspaces you belong to and your role in them. Signing in gives us your identity only; reading Search Console needs the separate permission described below, which you grant explicitly.

Your sites

The name, canonical URL, domain and timezone of each site you add, plus the settings you choose: sections, digest preferences, alert rules, notes you write on the timeline and items on your to-do list.

Data from the sources you connect

Nothing is fetched until you connect a source, and each connection can be removed at any time in Settings. What we request:

SourceAccessWhat we read
Google Search Consolewebmasters.readonly Impressions, clicks, click rate, position by date, query, page and country; URL inspection results; sitemaps
Google Analytics 4analytics.readonly Sessions and engagement for organic and assistant traffic
Bing Webmaster Toolswebmaster.read Bing clicks, impressions, index and crawl status
CloudflareAPI token you create Zone analytics: crawler activity, HTTP status counts, cache behaviour per path
Microsoft ClarityData-export token you create Aggregated behaviour per page: rage clicks, dead clicks, quickbacks, scroll depth
GitHubRepository you point us at Releases and their notes, so they land on your timeline without you writing them down

Seoduh also reads things that are public: your sitemap, your robots.txt, the Chrome UX Report for your pages, and Google's published announcements about search updates.

What we derive and keep

Report snapshots, a cache of provider responses, daily indexing and crawl history, page issues, sitemap URLs and their status over time, alerts we raised, and a record of the digests we sent. This is what makes week-on-week comparison possible.

Payment

Checkout and billing run through Dodo Payments, our payments processor. Card details go to them and never reach us. We store the customer id, subscription id, plan and status they send back, plus the billing email you gave them.

Technical logs

Our servers run on Cloudflare, which records standard request logs including IP address and user agent for security and debugging. [Confirm the retention period Cloudflare is configured for.]

How credentials are protected

OAuth refresh grants and the API tokens you paste are encrypted with AES-256-GCM before they are written to the database, with a key held as a server secret. They are decrypted only to call the provider on your behalf. The scopes above are read-only, so even a compromised grant cannot change anything in your accounts.

Why we are allowed to process it

Who else sees it

We do not sell data and we do not share it for advertising. It reaches these processors because the product needs them:

We may also disclose data where the law requires it, and to a buyer if the business is sold, in which case this policy travels with it.

Where it is processed

Cloudflare runs the service across its global network, so processing may happen outside the European Economic Area. Transfers rely on the standard contractual clauses in our agreements with each processor. [Confirm before publishing.]

How long we keep it

Your rights

You can ask for a copy of your data, correct it, delete it, take it elsewhere in a portable form, object to processing based on legitimate interests, or withdraw consent. Email hello@seoduh.com and we will answer within a month. You can also complain to your data protection authority; ours is [supervisory authority].

Cookies

This marketing site sets no cookies and runs no analytics or advertising scripts. The app stores your sign-in session in your browser so you stay logged in. There are no third-party tracking cookies anywhere in the product.

Children

Seoduh is a tool for running websites and is not intended for anyone under 16.

Changes

When this policy changes we update the date at the top, and for anything material we email account owners before it takes effect.