Skip to main content

Privacy Policy

Last updated: 23 August 2026
This Privacy Policy explains what personal data Unveil SEO collects, why we process it, who we share it with and the rights you have under the General Data Protection Regulation. We collect the minimum we need to run the product and we never sell your data.
On this page

Who we are

Unveil SEO operates the internal linking platform available at unveilseo.com.

You can reach us at hello@unveilseo.com or through our contact page.

Controller and processor

We act in two different roles depending on the data, and your rights work slightly differently in each.

We are the controller for data about you as a user and as a visitor: your account details, your team membership, contact form messages, cookie consent records, and analytics or marketing signals from our marketing site.

We are a processor for the data we handle on your behalf inside the product: the content of the websites you crawl, the Search Console metrics for properties you connect, and the link configuration we deliver to your CDN. For that data you are the controller, we act on your instructions, and we do not use it for any purpose of our own. A data processing agreement is available on request.

Data we collect

Account and team data

  • Your name, email address, role and team membership.
  • Your password, stored only as a salted hash by our authentication service. We never see or store it in readable form.
  • Email verification and password reset codes, which expire after a short period.
  • Session cookies that keep you signed in.

Crawl data

  • The URLs, page titles, meta descriptions, headings and body text returned by the sites you crawl.
  • Internal and external links, anchor text, canonical tags, robots directives, HTTP status codes and word counts.
  • Derived data such as semantic embeddings, PageRank scores and clustering, computed from the content above.

Search Console data, if you connect it

  • The email address of the Google account you connect.
  • The list of Search Console properties that account can access.
  • Per URL clicks, impressions, click through rate and average position for the trailing 28 day window and the window before it.
  • An OAuth refresh token, encrypted before it is stored. See the Search Console section below.

Edge integration data, if you connect it

  • Your Cloudflare account identifier and zone identifier, plus an API token that is encrypted before it is stored.

Support, analytics and consent

  • The name, email address and message you send through the contact form or by email.
  • Usage data such as pages visited and actions taken, only when you allow analytics.
  • Marketing signals such as the company associated with your visit, only when you allow marketing.
  • A record of your cookie choices, stored with an anonymous identifier, a salted hash of your IP address, your browser user agent and a timestamp, so we can demonstrate that consent was given. We do not store your IP address in readable form.

How we collect it

We collect data directly when you create an account, use the product or contact us. We collect it automatically through cookies and similar technologies when you give consent. We collect it from your website when you run a crawl, and from Google when you choose to connect Search Console. See the Cookie Policy for details.

Why we process data

  • To provide and operate the platform and your account.
  • To produce internal linking suggestions, anchor text audits and prioritised next steps from the content you ask us to analyse.
  • To secure the service and prevent abuse.
  • To respond to your support requests.
  • To improve the product through aggregated analytics.
  • To understand interest in Unveil SEO for marketing.
  • To meet legal and accountability obligations.

Google Search Console data

Connecting Search Console is optional and only a team owner can do it. When you connect, we ask Google for read only access using the webmasters.readonly scope, plus your account email address. We never request write access and we cannot change anything in your Search Console.

What we do with it

  • We sync per URL clicks, impressions, click through rate and average position once a day, and match them to the pages in your crawl.
  • We use those metrics to rank internal linking opportunities, for example to surface pages that sit just outside the top positions.
  • We do not use Search Console data for advertising, we do not sell it, and we do not send it to the AI providers listed below.
  • No human at Unveil SEO reads your Search Console data except where you ask us to for support, where it is necessary for security purposes, or where the law requires it.

How the connection is stored

The refresh token that keeps the connection alive is encrypted with AES-256-GCM before it is written to our database, and it is never sent to your browser. Disconnecting in Settings revokes the token at Google and deletes the stored connection, its properties and all synced metrics.

Limited Use

Unveil SEO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Generating link suggestions means sending parts of your crawled content to third party AI models. We route these requests through Vercel AI Gateway, which forwards them to the model providers listed in the sub processors table.

What we send

  • Page URLs and titles.
  • Extracts of page text, including the words immediately surrounding a candidate anchor.
  • Anchor text and candidate link targets.
  • Full page content when embeddings are generated, so that pages can be compared semantically.

What we never send

  • Passwords, session tokens or verification codes.
  • Google OAuth tokens or Search Console metrics.
  • Cloudflare credentials.
  • Your account or billing details.

Some of these providers process data outside the European Economic Area. See Data transfers below. The suggestions the models return are recommendations for you to review and approve. Nothing is published to your site automatically, and we do not make automated decisions that produce legal or similarly significant effects.

Content we crawl for you

A crawl returns whatever is published on the site you point it at. That can include personal data belonging to other people, for example author names, staff pages, testimonials or contact details. We do not look for that data and we do not use it for anything beyond producing your analysis.

You are the controller for the content you ask us to crawl. By starting a crawl you confirm that you are entitled to crawl that site and to have it analysed on your behalf. Deleting a crawl session deletes its pages, content, embeddings and derived analysis from our database.

Cookies and tracking

We use a granular consent banner. Strictly necessary cookies, such as the ones that keep you signed in and the one that records your choices, are always active. Analytics and marketing technologies stay off until you allow them.

Our marketing site also embeds a booking widget from Cal.com, hosted in the European Union, on pages where you can book a demo. Full detail and live controls are on the Cookie Policy page.

Sub processors

We share data with the following processors only as needed to run the service. Providers marked as outside the EEA are used for AI processing of crawled content only.

ProcessorWhat it handlesWhere
Hetzner Online GmbHDedicated server running our database, authentication and crawlerHelsinki, Finland (EEA)
VercelApplication hosting and content deliveryUnited States and global edge
Vercel AI GatewayRoutes our AI requests to the model providers listed belowUnited States
Alibaba Cloud (Qwen)Semantic embeddings of crawled page contentOutside the EEA
Mistral AIAnchor text extractionFrance (EEA)
xAI (Grok)Link suggestion filteringUnited States
Moonshot AI (Kimi)Link suggestion filtering and bulk picksOutside the EEA
Inception Labs (Mercury)Fallback model when a primary model is unavailableUnited States
Xiaomi (Mimo)Fallback model when a primary model is unavailableOutside the EEA
Google LLC (Search Console API)Search performance data, only for accounts you connectUnited States
Google LLC (Analytics)Aggregated usage analytics, only with your consentUnited States
ResendTransactional email and contact form deliveryUnited States
lemlistWebsite visitor marketing signals, only with your consentFrance (EEA)
Cal.com (cal.eu)Demo booking embed on our marketing siteEuropean Union
CloudflareEdge delivery of approved links, only for customers who connect their own Cloudflare accountUnited States and global edge

Data retention

  • Account data is kept while your account is active and deleted when you close it, unless a longer period is required by law.
  • Crawl data, including page content, embeddings and derived analysis, is deleted as soon as you delete the crawl session it belongs to.
  • Search Console metrics cover a rolling 56 day span and are replaced on every sync. URLs that fall out of both windows are removed. All of it is deleted when you disconnect.
  • Edge credentials are deleted when you disconnect the site.
  • Consent records are kept as proof of consent for as long as we need to demonstrate compliance.
  • Analytics and marketing data follow the retention shown in the Cookie Policy.
  • Encrypted backups may hold copies for a short period after deletion before they are rotated out.

Data transfers

Our database, authentication and crawler run on a dedicated server in Helsinki, Finland, inside the European Economic Area. Several of the services we rely on operate outside the EEA, in particular our hosting, email and AI model providers.

Where data is processed outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses provided by the relevant processor. If you would rather your content was not sent to AI providers outside the EEA, contact us before running a crawl and we will tell you what is possible.

Security

  • All traffic to and from the platform is encrypted in transit.
  • Third party credentials, including Google refresh tokens and Cloudflare API tokens, are encrypted with AES-256-GCM before storage and are never exposed to the browser.
  • Passwords are stored only as salted hashes by our authentication service.
  • Every table enforces row level security, and application queries are scoped to your team so one customer cannot read another's data.
  • Access by our staff is limited to the people who need it to operate the service and support you.

No system is perfectly secure. If you believe you have found a vulnerability, please tell us at hello@unveilseo.com before disclosing it publicly.

Your rights

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Request deletion of your data.
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time.
  • Lodge a complaint with your local data protection authority if you believe we have handled your data unlawfully.

To exercise any of these, contact us at hello@unveilseo.com. We respond within one month. Where we act as a processor for another organisation, we will pass your request on to them.

Children's privacy

Unveil SEO is a business product and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

We may update this policy as the product evolves. When changes are material we update the date above and, where appropriate, ask you to review your cookie choices again.

Contact

For any privacy request or question, reach us at hello@unveilseo.com or through our contact page.