Draft for owner and legal review.
This document has not been reviewed or approved by a lawyer. Highlighted values and review notes must be resolved before it is published. It is not served in production until it is complete and approved.
Legal
Privacy Policy
- Effective date:
- [To be confirmed: effective date]
- Last updated:
- [To be confirmed: last updated date]
1. Who we are
This policy explains how [To be confirmed: legal entity name] (“Serpify”, “we”, “us”), of [To be confirmed: registered address] , handles personal information when you visit this website or use the Serpify application, its API and its MCP server.
2. Information you provide
- Account details: your name, email address and password. Passwords are stored as one-way hashes, never in readable form. If you add two-factor authentication or a passkey, we store what is needed to verify it.
- Workspace and team details: workspace name and timezone, the email addresses of people you invite and the role and projects you give them.
- Project content: the websites (domains), keywords, AI questions, competitors, target pages, tags and notes you add, and any keyword file you import (the file itself is read and not kept).
- Branding: the agency or company name, colour, footer text and logo you add for reports.
- Report and alert settings: report schedules and the email addresses of their recipients, alert rules, a Slack incoming-webhook address and webhook endpoints you configure.
- Free tools and requests: if you use a free tool or ask us for help on public Serpify pages, the website, brand or topic you enter and, where you choose to give them, your name, email address, website, budget and notes, and whether you agreed to hear from us.
- Messages: what you send us by email.
3. Information collected when you use Serpify
- Session information: when you are logged in to the application, your session record includes your IP address and browser user agent.
- Sign-up source: when you arrive at Serpify’s public pages from a link or advert, we record where you came from: campaign (UTM) tags, advert click identifiers, the referring website and the page you landed on. If you sign up or submit a request, this is saved with your account or request.
- Usage records: which features use your plan’s allowances and data, such as research credits, so we can apply plan limits and costs.
- Free tools: for public tools, we keep a one-way hash of your IP address (not the address itself) to limit abuse.
- Security and administration: actions taken by Serpify administrators on accounts are recorded, with the administrator’s IP address.
- Search and AI data: to provide the service we collect search results, AI assistants’ answers, the sources they cite and Google Business Profile information for the keywords, questions and businesses you track. These come from public sources and can include names or other details of people and businesses that appear in them.
This website (the marketing site) has no forms, does not use cookies and does not run analytics. Requests to it are handled by our hosting infrastructure, which may log them.
4. Connected services
- Google Search Console and Google Analytics 4: if you connect a Google account, we request read-only access to Search Console and Analytics, and your Google account email. We store the access credentials encrypted, and import search queries, pages, clicks, impressions and positions from Search Console, and sessions, engaged sessions and key events (including visits referred by AI assistants) from GA4 for the properties you choose. When you disconnect, we ask Google to revoke our access and delete the stored credentials; data already imported stays in the project.
- Slack: if you add a Slack incoming webhook, we store its address encrypted and send alert digests to that channel.
- Webhooks, API and MCP: if you create API tokens or webhook endpoints, we store tokens as hashes and webhook secrets encrypted, and send alert data to the endpoints you choose. Records of webhook deliveries, including what was sent, are kept for 30 days.
5. Payment processing
Payments are handled by Razorpay. You enter payment details with Razorpay, and Serpify does not receive or store your full card details. We pass Razorpay your name and email address to pre-fill checkout, and receive and keep subscription and payment identifiers, amounts, currency, status and the notifications Razorpay sends us about your subscription.
6. Cookies and similar technologies
This website
This marketing website does not set cookies and does not use analytics or advertising tags.
The Serpify application
- Necessary: a session cookie and a security (CSRF) cookie while you use the application, and a “remember me” cookie if you choose to stay logged in.
- Preferences: your light or dark appearance choice (a cookie and your browser’s local storage, for up to one year) and whether the sidebar is open (up to seven days).
Serpify’s public tool and request pages
- Sign-up source: a first-party cookie that remembers how you arrived (campaign tags, advert click identifiers, referring site and landing page) for up to 90 days.
- Your consent choice: a cookie that remembers whether you allowed advertising measurement, for up to 180 days.
- Advertising measurement (only with your consent, where enabled): Meta’s pixel and its cookies. When you sign up, start a trial, subscribe, or submit a request, we may also send Meta a one-way hash of your email address and account ID, your IP address and browser user agent so we can measure our adverts.
- Bot protection: forms on these pages use Cloudflare Turnstile, which receives your IP address to check that a person is submitting the form.
- Visitor statistics (where enabled): Plausible Analytics.
7. How we use information
- to provide the service: run rank checks, AI answer checks, research and reports, and show you the results;
- to send service emails: account verification, password resets, invitations, trial reminders, alerts and the reports you schedule;
- to bill you and manage subscriptions, plan limits and usage budgets;
- to keep the service and accounts secure and prevent abuse;
- to answer your messages and requests;
- where enabled and allowed, to measure our advertising and understand where sign-ups come from.
We don’t sell personal information. We don’t currently send marketing newsletters.
8. Service providers
We use these providers to run Serpify. Each receives only what it needs for its task.
- DataForSEO: search results, keyword data, Google Business Profile data and AI assistants’ answers. Receives the keywords, domains, business listings and AI questions you track.
- Anthropic (where enabled): AI drafting and classification features. Receives the business details, questions, competitor names and excerpts of AI answers needed for the feature you use.
- Razorpay: payments (see section 5).
- Google: when you connect Search Console or Analytics (see section 4).
- Cloudflare: bot protection on public forms.
- Meta and Plausible (where enabled): see section 6.
- Email delivery: [To be confirmed: email delivery provider] , to send service emails.
- Hosting: [To be confirmed: hosting provider and location] , where the application and its data are stored.
We may also disclose information if the law requires it, or to protect Serpify, our users or others.
9. How long we keep information
These periods are applied automatically:
- generated PDF reports: 180 days;
- webhook delivery records: 30 days;
- free tool runs and free AI visibility snapshot requests, including any name and email given: 6 months;
- application sessions: deleted after expiry (by default, two hours of inactivity);
- expired API tokens: deleted a day after they expire.
Other information is kept while your account exists. When you delete your user account, the workspaces you own are deleted with it, including their projects, keywords, results, reports, integrations and subscription records, except for records we keep for billing, security or legal reasons.
10. Security
We protect accounts and data with measures including hashed passwords, optional two-factor authentication and passkeys, limits on login attempts, encrypted storage of connected-service credentials and webhook secrets, hashed API tokens, signed webhooks, and role-based access within workspaces. No method of storage or transmission is perfectly secure, and we can’t guarantee absolute security.
11. Your choices and requests
- You can update your name, email address and password in your profile settings.
- You can disconnect Google, Slack and webhooks, and delete API tokens, at any time.
- You can delete your account in your profile settings. Cancel any paid plan first.
- On Serpify’s public pages you can decline advertising measurement in the consent banner.
- To ask for a copy of your information, a correction or deletion, or to ask about anything else in this policy, email [To be confirmed: privacy contact email] .
If your information is in a workspace that belongs to someone else (for example, you were invited to a workspace or receive its reports), please contact that workspace’s owner as well.
12. International users
Serpify’s service providers may process information in countries other than yours.
13. Children
Serpify is a business service and is not directed at children. You must be at least [To be confirmed: minimum age] years old to create an account.
14. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If a change is significant, we will tell account holders by email or in the application.
15. Contact
Questions about this policy or your information: [To be confirmed: privacy contact email] . [To be confirmed: legal entity name] , [To be confirmed: registered address] .