Optmizlyoptmizly

Privacy Policy

Last updated: August 2026

1. Who We Are

Optmizly ("we", "us", "our") operates the Optmizly platform at Optmizly.com. We are the data controller for personal data collected through the Service. For privacy enquiries, contact us at privacy@Optmizly.com.

2. Information We Collect

Account data: When you register, we collect your name and email address via Clerk (our authentication provider). Payment data: When you subscribe to a paid plan, your payment information is processed by DoDo Payments. We never see or store your card details. Usage data: We record the number of analyses you run each month to enforce plan limits. Analysis data: Content, URLs and domains you submit are sent to our AI provider and to the SEO data providers listed in section 5 to generate results. AI processing is currently performed by Groq; we may use Anthropic instead, and section 5 names both. Results, along with a snippet of the submitted content and any URL analysed, are stored against your account so you can revisit them in your analysis history, and are deleted when you delete the analysis or your account. Connected-service data: If you connect Google Search Console, we retrieve and store search performance data for your properties – see section 6. Technical data: We may collect standard server logs including IP addresses and browser user-agent strings for security and diagnostics.

Prospect data (SEO Client Finder): This tool is for finding businesses to approach, so the data it stores is about those businesses rather than about you. When you search an industry and location, we send those terms to the Google Places API and receive a list of matching businesses. For each result with a website we request its homepage once and check it for technical SEO issues. We store, against your account, the business name, address, phone number and website returned by Google, the issues found, and any contact details the business publishes on that homepage - typically an email address, a telephone number and links to social profiles. These are read from the page as a visitor would find them. We do not buy contact data, do not use an enrichment provider, do not guess addresses from name patterns, and do not attempt to identify individuals; where a site offers both a general mailbox such as info@ and a named one, the general mailbox is shown first. If you contact a business you find here, you are the sender and are responsible for complying with the marketing and electronic-communications rules that apply to you. Searches are kept so you can revisit them - see section 8 - and are deleted when you delete the search or your account.

Free tools used without an account: Some tools can be used without registering, and how much of what you submit reaches our AI provider depends on the tool. The AI Regex Generator sends only a sample as context for writing the pattern – up to 15 lines, each truncated to 120 characters – and matches the rest on our own servers, so it is not sent anywhere. The E-E-A-T Checker sends the first 3,000 characters of the content you paste, because assessing that content is the analysis itself. The AI Search Readiness Audit sends nothing to any third party at all: when you give it a web address, our own servers request that page once, along with the site's robots.txt and llms.txt files if they exist, and all of the checks run on our servers with no AI provider and no data provider involved. Nothing you submit through these tools is stored: there is no account to store it against, no record is written to our database, and it is not used to train any model. To cap abuse and cost we keep a request counter in our rate-limiting store keyed to your IP address, which expires automatically within 26 hours and is not linked to any account or used for any other purpose.

3. How We Use Your Information

We use your data to: (a) provide and maintain the Service; (b) enforce monthly usage limits; (c) send transactional emails (account confirmation, subscription receipts, password resets); (d) detect fraud and abuse; (e) comply with legal obligations. We do not use your data for advertising. We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or UK, we process your personal data under the following legal bases: Contract performance – processing necessary to provide the Service you have subscribed to. Legitimate interests – security monitoring, fraud prevention, and product improvement, where these do not override your rights. Legal obligation – where we are required to retain or disclose data by law. Consent – where we ask for your explicit consent (e.g. optional marketing emails).

5. Third-Party Services

We share data with the following sub-processors to operate the Service: Clerk (authentication and user management), Supabase/PostgreSQL (database), DoDo Payments (payment processing), Groq (AI analysis – our current AI provider; content you submit is processed under Groq's API terms), Anthropic (alternative AI provider, used when configured, under Anthropic's API terms), Resend (transactional email), Vercel (hosting and edge functions), PostHog (product analytics and error monitoring), DataForSEO and OpenPageRank (keyword, ranking, backlink and domain metrics – we send the keywords, domains and URLs you analyse), and Google (Search Console, PageSpeed Insights and Maps/Places APIs, used to retrieve performance and location data for the sites you analyse or connect). Each service operates under its own privacy policy and data processing agreements. Please review Groq's privacy policy at groq.com and Anthropic's at anthropic.com.

6. Google User Data (Search Console Integration)

Optmizly offers an optional integration with Google Search Console. It is never enabled by default – it applies only if you explicitly connect your Google account from Settings → Integrations.

What we access: we request the read-only scope https://www.googleapis.com/auth/webmasters.readonly. This grants us permission to read, and never to modify, your Search Console data. We retrieve (a) the list of Search Console properties your Google account can access, and (b) search performance rows for the properties you sync, consisting of the search query, date, country, device, impressions, clicks, click-through rate and average position.

How we use it: this data is used solely to show you your own search performance inside Optmizly, and to improve the accuracy of the keyword, difficulty and ranking estimates the Service presents to you. It is Google's own measurement of how your site performs, and we use it to check and calibrate estimates that would otherwise come from third-party vendors.

How we store it: OAuth access and refresh tokens are encrypted at rest using AES-256-GCM and are used only to call the Google Search Console API on your behalf. Retrieved search performance rows are stored in our database against your account.

What we do not do: we do not sell this data, share it with third parties, use it for advertising, use it to train artificial intelligence or machine learning models, or make it available to other Optmizly users. Optmizly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access: you can disconnect at any time from Settings → Integrations, which revokes our token with Google and deletes it from our systems, or from your Google Account permissions page at myaccount.google.com/permissions. Disconnecting stops all further collection. Search performance data already retrieved remains stored against your account until you delete your account or ask us to remove it at privacy@Optmizly.com, at which point it is deleted.

7. International Data Transfers

Our infrastructure is primarily hosted in the United States. If you are based in the EEA or UK, your data may be transferred to and processed in the US. Where required, such transfers are governed by Standard Contractual Clauses (SCCs) or other approved safeguards under GDPR Chapter V.

8. Data Retention

We retain your account data (email, plan, usage counts) for as long as your account is active. Saved analyses, projects and any search performance data retrieved from a connected Google Search Console account are retained while your account is active, so that historical comparisons remain available to you. If you delete your account, all of this personal data is removed from our systems within 30 days, except where retention is required by law. SEO Client Finder searches, including the prospect and contact details described in section 2, are kept for your last 50 searches; older ones are deleted automatically as new searches are run, and all of them are removed if you delete your account. Monthly usage counts are reset each calendar month. Server logs are retained for up to 90 days. Rate-limiting counters for tools used without an account contain an IP address and expire automatically within 26 hours; data submitted to those tools is never stored.

9. Cookies

We use session cookies for authentication, managed by Clerk. These are strictly necessary for the Service to function. We do not use advertising or tracking cookies. You can control cookies through your browser settings, but disabling session cookies will prevent you from logging in.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data: Access – request a copy of the data we hold about you. Rectification – request correction of inaccurate data. Erasure ("right to be forgotten") – request deletion of your data. Restriction – request that we limit how we process your data. Portability – receive your data in a structured, machine-readable format. Objection – object to processing based on legitimate interests. Withdrawal of consent – where processing is based on consent, withdraw it at any time. To exercise any of these rights, contact us at privacy@Optmizly.com. We will respond within 30 days. EEA/UK users also have the right to lodge a complaint with their local supervisory authority.

11. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us at privacy@Optmizly.com and we will delete it promptly.

12. Security

We implement industry-standard technical and organisational measures to protect your data. Passwords are managed by Clerk and are never stored by Optmizly directly. All data is transmitted over HTTPS/TLS. Payment information is handled entirely by DoDo Payments and is never stored on our servers. Credentials for connected third-party accounts, such as Google Search Console OAuth tokens, are encrypted at rest using AES-256-GCM. Despite these measures, no internet transmission is 100% secure and we cannot guarantee absolute security.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email for material changes and update the "Last updated" date above. Continued use of the Service after changes constitutes acceptance of the revised Policy.

14. Contact

For privacy-related questions or to exercise your rights, contact us at privacy@Optmizly.com. We aim to respond to all requests within 30 days.

Privacy Policy – Optmizly | Optmizly