Privacy Policy
SEOGraphy("we", "our", "us") respects your privacy. This policy explains what we collect, how we use it, and the choices you have. It applies to our web application and the free SEOGraphy Chrome extension.
What we collect
- Account information. Email, name, and profile image you provide at sign-up (or that your Google account provides on OAuth sign-in).
- Authentication token. After you sign in, we issue a short-lived session token. The SEOGraphy Chrome extension caches this token locally (in
chrome.storage.local) so you stay signed in across browser sessions without logging in twice. The token lives on your device and is sent to our API only to authenticate your enhancement requests. - Prompt content. The prompts you submit for enhancement, the enhanced output, and the quality scores calculated for each prompt. The extension only reads the input field on an AI site at the moment you click Enhance or Interview - nothing is transmitted before you explicitly trigger an enhancement.
- Usage metadata. Per-account daily enhancement counts (used to enforce plan limits), timestamps, the AI platform used (ChatGPT, Claude, Gemini, Grok, Perplexity, Copilot, DeepSeek), and your plan tier.
- Billing. Handled by Stripe on our web app. The Chrome extension never sees payment data. We do not see or store your card details.
- Login activity. When you sign in or sign out, we record the timestamp, IP address, browser user-agent, and approximate country. This helps you detect unauthorised access to your account and lets us understand product engagement in aggregate. We do not sell or share this data.
How we use it
Your prompts are sent to a third-party AI LLM provider to perform the enhancement. We store the original prompt and its enhanced version so you can access your history. We use aggregate usage numbers (prompts enhanced, quality score lifts) to improve the product.
We do not sell, rent, or share your data with third parties for advertising or profiling.
Content moderation
Before any prompt is sent to our AI provider, we run it through a lightweight filter that rejects prompts falling into the categories listed in our Terms of Service (drugs, adult content, personal messaging and dating, spam and phishing, hate speech, excessive profanity) and prompts that are too short or vague to enhance meaningfully. Rejected prompts are never transmitted to the AI provider, never appear in your history, and do not count against your daily limit.
We do, however, keep an internal audit record of rejected prompts - the original text, the rejection category, timestamp, IP address, browser user-agent, and platform it was submitted from. This is used solely to identify accounts that repeatedly attempt disallowed content so we can enforce our Terms of Service. These records are not shared with third parties.
Chrome Extension
The SEOGraphy Chrome extension is the client that adds the Enhance button to supported AI chat sites. Because browser extensions warrant an explicit data disclosure, here is exactly what it does and does not handle.
Data the extension sends to our servers:
- The prompt text from the input field of a supported AI site - but only when you click Enhance or Interview. No background reading, no keystroke logging.
- Your cached session token, attached as an Authorization header so our API knows which account is making the request.
Data the extension stores locally on your device (via chrome.storage.local, not transmitted anywhere):
- Your cached session token.
- Your theme preference (light or dark).
- Your button customisation (position, shape, colour) and enabled-platform toggles.
- Your popup vs side-panel preference.
Data the extension does not collect:
- Web history. Content scripts only run on the AI chat sites listed in the extension manifest, and only to inject the Enhance button. We do not track which pages you visit, page titles, or visit timestamps.
- Location. We do not access GPS, device location, or derive geolocation from your IP beyond the approximate country recorded in the login activity log above.
- Personal communications. We do not read your emails, texts, DMs, or any chat conversation content. Prompts sent to an AI chatbot through the Enhance flow are treated as website content you explicitly submit, not interpersonal messages.
- Financial information. The extension never handles card numbers, transactions, or credit data. All billing runs through Stripe on our web app.
- Health information. Never collected.
- Keystrokes, clicks, or mouse movement on AI sites. The extension only reads the contents of the input field at the moment you click Enhance.
We do not sell or transfer user data to third parties outside of approved use cases (Stripe for payments, our AI LLM provider for the enhancement itself, a managed PostgreSQL database for data storage, and Resend for transactional email). We do not use your data for advertising, profiling, creditworthiness scoring, or any purpose unrelated to the single purpose of enhancing the prompts you choose to submit.
Your data, your control
- You can delete any enhancement from the History page.
- You can export your saved prompts from the Library page.
- You can delete your account from Settings. This removes your articles, ideas, websites, generated images, billing details, and profile. One small set of anti-abuse records is retained - see below.
What we keep after you delete your account
Deleting your account erases everything you created. To stop the free tier being reset by repeatedly deleting and re-registering, we retain a deliberately minimal record. We think you should know exactly what it is:
- A one-way hash of your email address, not the address itself. It is salted and cannot be reversed back into your email. Its only use is recognising that an identity has registered before.
- Counts of AI usage for the current month - how many articles, idea generations, website additions, and AI actions were used. These are plain numbers. None of your content, prompts, topics, or website addresses are kept.
- Whether a free trial was already used, so the same trial is not issued twice.
- A payment card fingerprint from our payment processor, where one exists. This is an opaque identifier, not your card number, which we never hold.
- Your IP address for a limited period (90 days by default). An IP match alone never blocks a signup and never carries usage forward, because many unrelated people share one address.
Lawful basis and retention. We rely on legitimate interest in preventing abuse of our free tier (GDPR Article 6(1)(f)). The usage counts are kept only for the calendar month they belong to and are then deleted automatically - if you return in a later month you start with a full allowance, exactly as you would have if you had never left. If you believe this processing should not apply to you, you have the right to object under Article 21; contact us and we will review it.
Security
Data is stored in a managed PostgreSQL database with row-level security so only you can read your own records. Traffic is encrypted with TLS. Authentication uses short-lived session tokens.
AI provider API keys
If you add your own AI provider API key (Anthropic, OpenAI, Google, or xAI) via Settings › AI Providers, here is exactly how we handle it:
- Encrypted at rest. Your API key is encrypted with AES-256 before being written to our database. The plaintext key is never stored. We hold only the encrypted ciphertext plus the last four characters of the key so you can identify which key you saved.
- Used only for your requests. The key is decrypted in memory only at the moment your enhancement request is processed, and only to call the AI provider on your behalf. It is never logged, never exposed in API responses, and never used for any other account.
- Never shared or sold.Your key is not shared with third parties beyond the provider it belongs to (e.g. your Anthropic key is sent only to Anthropic's API endpoint during your enhancement call).
- You control deletion.You can remove your API key at any time from Settings › AI Providers. Deletion permanently removes the encrypted ciphertext from our database.
Cookies
We use essential cookies for authentication and your preferences (such as theme). Optional analytics and marketing cookies are only set after you accept them in our cookie banner, and no non-essential cookie loads before you consent. You can change or withdraw your choice at any time from our Cookie Policy page, and we honour the Global Privacy Control (GPC) browser signal. That page also lists every cookie, its purpose, and its duration.
Sub-processors
We share data with a small set of vetted sub-processors that help us run the service (hosting, database, payments, transactional email, error monitoring, and AI processing). The current list, including each vendor's purpose and data location, is published on our Security page. We do not sell your personal information.
Data Processing Agreement
Business customers can request a GDPR Art. 28 Data Processing Agreement. See how to request a DPA.
Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect. Identifiers (name, email, account ID); commercial information (subscription plan and billing handled by Stripe); internet and network activity (login activity: timestamp, IP address, user-agent, approximate country; usage metadata); and the content you submit for processing. We collect these to provide and secure the service, as described above. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect data from children.
We do not sell your personal information,and we do not "share" it for cross-context behavioural advertising. Analytics and marketing cookies run only with your consent. You can opt out at any time using the Do Not Sell or Share My Personal Information control on our Cookie Policy page, and we treat a Global Privacy Control signal as a valid opt-out.
Your rights. You have the right to know what personal information we hold and how we use it, the right to delete it, the right to correct it, and the right to opt out of any sale or sharing. You can exercise the rights to know and delete directly: download a copy of your data or permanently delete your account from Settings. You may also email us (see Contact below) and we will respond within the timeframes the law requires.
Non-discrimination. We will never deny you service, charge a different price, or provide a different quality of service because you exercised any of these privacy rights.
Changes to this policy
If we make material changes, we will update the date above and, for signed-in users, show a notice on your next visit.
Contact
Questions? Email privacy@promptezy.com or see our Terms of Service.