Skip to content

SEO Masterize

Privacy

This describes what the software does, not what a template says it might. Where a sentence makes a claim about storage or sharing, the code that does it is named in the repository and checked by a test.

Not in force yet

This document is complete except for the name of the operating entity and the governing jurisdiction, which are not part of the software and have to be supplied by whoever operates this service. Until they are, this page is not published in the sitemap, is not indexed, and does not bind anyone. Everything below describes what the system actually does today.

The free check stores no report

You can run a check without an account. We fetch the address you give us, apply the rules, and return the result to your browser. The finding, the page and its bytes are not written to any database — the result exists for the length of that one request. One thing is written: a one-way fingerprint of your address, an HMAC rather than the address itself, in a single row that counts your checks against the per-visitor hourly limit. That row holds a count and a clock, every copy of this site shares it so the published limit is the real one, and it is deleted when your hour closes.

What we store when you have an account

Your email address and your chosen language. The domains you add and whether they are verified. Each audit you request, including the address you asked us to audit and when it ran. The pages we fetched, the findings we produced, and the evidence behind them — which includes the served HTML, the rendered DOM and the response headers of the site you asked us to crawl. Any share links you create, the ledger of credits bought, spent and refunded, and any finding you contest along with what you wrote.

Why we keep the bytes

Because a finding without the material it rests on is an assertion. Each stored artefact is addressed by a hash of its own content and can be downloaded from your report, so any claim we make can be traced back to the exact bytes it came from. That is the product; it is also the largest thing we hold about you, and it is deleted with the rest when you delete your account.

Sites that are not yours

When you ask us to audit an address, we make requests to that site. We identify ourselves in every request with a published user-agent token, we read and obey robots.txt before fetching anything, and we honour any crawl delay it declares. A site owner can have their domain blocked permanently by writing to us. We do not audit private or internal addresses, and we refuse a redirect that leads to one.

Cookies and tracking

Signing in sets an essential, HTTP-only cookie containing a signed session identifier. Submitting the free check also uses a separate HTTP-only cookie for at most two minutes; it carries the address between the private POST and the result, is deleted when read, and never appears in the page URL. Our edge provider may set its own strictly necessary security cookie, such as __cf_bm, to distinguish automated abuse. The application does not load advertising, behavioural analytics, fingerprinting or cross-site tracking scripts. Infrastructure providers still process ordinary request and security logs, including network address, path and user agent, under their operational retention settings. Because the browser storage we initiate is strictly necessary, there is no consent banner; any future non-essential analytics must be opt-in before it loads.

Who else receives it

Only the processors below, each for the one job named. A processor that is not configured on this deployment receives nothing at all, and the list says which those are.

How long we keep it

Until you delete it. There is no automatic expiry, because a report you paid for should still be there when you come back. You can delete everything from your account at any time and it is removed immediately and permanently, including the stored bytes. The one exception is the record of payments, which we keep for as long as tax and accounting law requires — that record contains the amount, the date and the payment reference, and no audit data.

Your rights

You can export everything we hold about your account as a single file, and you can delete all of it, both from your account settings and without asking us. You can also correct your details, object to processing, or complain to your data protection authority. If you would rather we did any of it for you, write to privacy@seomasterize.com and we will answer within one business day.

How it is protected

Every customer read is checked against the signed-in account before a row is fetched, and row-level security in the database refuses cross-tenant reads independently of that. Findings, pages and credits can only be written by the server, never by a browser — a client that could write a finding could fabricate evidence, which would make the product meaningless. Stored artefacts live in a private bucket and are served only to the account that owns them, over a URL addressed by content hash.

Children

This is a tool for people who operate websites. It is not directed at children and we do not knowingly hold data about them.

Changes

The date at the top moves when this document changes in substance. If a change affects what we do with data we already hold, we will say so by email before it takes effect.

Processors

Lovable
Serves this site and runs the application
Cloudflare
Serves this site and runs the application
Supabase
Stores your account, audits and evidence, and sends your sign-in code
Stripe
Takes payment; receives your email and the amount, never your card details from us — not configured on this deployment — receives nothing
Resend
Sends the copy of anything you contest to us, and our reply to you — not configured on this deployment — receives nothing
the configured model provider
Writes the explanation on a finding the rules have already decided — not configured on this deployment — receives nothing