Skip to content

Privacy Policy

Last updated

The short version: we store what Serpwright needs to find, write and publish articles for your site. Your keys and tokens are encrypted. We never sell your data or use it to train AI models, and deleting a workspace deletes its data.

1.Who we are

Serpwright (“we”, “us”) is software that turns your Google Search Console data into researched, published articles. Serpwright operates serpwright.com and the Serpwright app, and is the controller of the personal data described here. You can reach us at hello@serpwright.com.

For the content and site data you put into a workspace, you decide what goes in and why. We process it on your behalf to provide the service.

2.What we collect

We only collect what the product needs to work.

  • Account details: your name, email address and, if you sign in with Google, your Google profile picture. If you use a password, we store only a salted hash of it.
  • Sign-in sessions: a session token, the IP address and the browser user agent of each signed-in session, so we can keep you signed in and spot abuse.
  • Workspace settings: your site's domain, brand voice, target audience, focus topics, publishing preferences and team members.
  • Search Console data: for the one property you connect, search queries, pages, clicks, impressions, click-through rate and average position. See Google user data below.
  • Your site's pages: URLs, titles and text from the public pages listed in your sitemap, used to suggest internal links and avoid duplicate topics.
  • Content you create: titles, briefs, articles, revisions, cover images, optimization suggestions and the publishing log.
  • Credentials you give us: AI provider keys, CMS credentials (such as a WordPress application password or a Shopify or Webflow token), webhook secrets and your Google refresh token. These are encrypted before storage (see Security). API keys we issue to you are stored only as a hash.
  • Purchase records: the amount, currency, date and status of your payment and your Stripe customer ID. Stripe collects your card details directly; we never see or store your card number.
  • Usage records: for each AI call, the model used and its token counts, so you can match usage to your provider's bill. We also keep server logs of requests and errors.

3.How we use it

  • To run the service you asked for: find title ideas, research, write, publish and track articles.
  • To sign you in, keep your account secure and prevent abuse.
  • To send emails about your account: verification, sign-in links, trial reminders, receipts and pipeline notifications you can turn off.
  • To take payment and keep the records the law requires.
  • To fix bugs and keep the service running, using logs and error reports.

We do not sell your personal data, we do not use it for advertising, and we do not use your content or Search Console data to train AI models. Our legal bases, where the GDPR applies, are performing our contract with you, our legitimate interest in running a secure service, and complying with legal obligations.

4.Google user data

Serpwright asks Google for two kinds of access, and only when you choose to grant them.

  • Sign in with Google (openid, email, profile): your name, email address and profile picture, used only to create and sign in to your account.
  • Search Console (https://www.googleapis.com/auth/webmasters): requested separately, from a workspace's settings, when you connect Search Console. We use it to read search analytics (queries, pages, clicks, impressions, click-through rate and position) for the property you select, to submit your sitemap, and to check whether pages we published for you are indexed. We ask for this scope rather than the read-only one because sitemap submission requires it. We never add or remove users, properties or verification records.

How we use and share this data:

  • Search Console data is used only to provide features you can see in Serpwright: title ideas, briefs, rank tracking and optimization suggestions for your own site.
  • To generate titles and briefs, relevant queries and page data are sent to the AI provider you chose, using your own API key. Nothing is sent to an AI provider you did not configure.
  • We do not sell Google user data, use it for advertising, or use it to train or improve general AI or machine learning models.
  • People at Serpwright do not read your Google user data unless you ask us to for support, it is needed for security or to comply with the law, or it has been aggregated and anonymized for internal operations.
  • Your Google refresh token is encrypted at rest and used only on our servers. Disconnecting Search Console in Serpwright revokes it at Google. You can also remove Serpwright's access at any time from your Google Account permissions.

Serpwright's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.Who processes your data

We use a small number of service providers, each only for the job listed:

  • Cloudflare: hosting, database, file storage, email delivery, and the built-in models that index your pages and draw default cover images.
  • Stripe: payment processing, tax calculation and receipts.
  • Google: sign-in and the Search Console API.
  • The AI and image providers you connect (OpenAI, Anthropic, OpenRouter, MiniMax, Replicate): they receive the prompts needed to write your content, under your own account with them and their terms.
  • Search results providers (Brave Search, or SerpApi or DataForSEO if you add your own key): they receive the search queries we research, never your account details.
  • The CMS or webhook you connect: receives the articles you publish.

We may disclose data if the law requires it, or to a buyer if Serpwright is sold, in which case this policy continues to apply to your data.

6.Cookies

We use only the cookies needed to keep you signed in and to protect sign-in flows. Your light or dark theme choice is kept in your browser's local storage. We do not use advertising or cross-site tracking cookies.

7.How long we keep it, and deleting it

  • Deleting a workspace removes its Search Console data, page index, titles, briefs, articles, revisions, performance history, publish log, credentials and settings from our database immediately. Published articles on your own site are not touched.
  • Disconnecting Search Console revokes our access at Google and deletes the stored token.
  • Deleting your account: email hello@serpwright.com from the address on the account and we will delete your account and every workspace you own within 30 days.
  • Backups and derived copies: database backups, and copies such as hosted cover images and the search index of your pages, are purged within 30 days of deletion.
  • Purchase records are kept for as long as tax and accounting law requires, usually up to 7 years.
  • Trial accounts that end without a purchase stay read-only, so you can come back to them. Ask us and we will delete one at any time.

8.Security

AI keys, CMS credentials, webhook secrets and Google tokens are encrypted with AES-256-GCM before they are stored, and decrypted only inside the server step that makes the outbound call. They are never logged or sent to your browser; the app shows only the last four characters. All traffic uses HTTPS. Every database query is scoped to a workspace you belong to, with a role check. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you without undue delay.

9.Your rights

You can ask to access, correct, export or delete your personal data, or object to or restrict how we use it. Email hello@serpwright.com and we will reply within 30 days. If you are in the EU, UK or a US state with a privacy law, you also have the right to complain to your local data protection authority. We don't sell or share personal data as those terms are defined under California law.

10.International transfers

Our providers run infrastructure in many countries, including the United States. Where personal data leaves the EU or UK, we rely on the providers' Standard Contractual Clauses or an equivalent safeguard.

11.Children

Serpwright is a business tool and is not meant for anyone under 16. We do not knowingly collect their data.

12.Changes to this policy

If we change this policy in a way that matters, we will update the date above and email account owners before the change takes effect.

Questions about this page: hello@serpwright.com. See also our Terms of Service.