Privacy policy.
1. Information we collect
Account information: name, email address, and password when you create an account.
Usage data: how you interact with the Service — features used, pages visited, actions taken.
Content data: keywords, projects, generated content, and other data you create through the Service.
Payment information: billing details are processed securely by Stripe. We do not store credit card numbers.
2. How we use your information
- To provide and improve the Service
- To process payments and manage subscriptions
- To send service-related communications
- To analyse usage patterns and optimise performance
- To ensure security and prevent abuse
3. Data sharing
We do not sell your personal data. We may share data with:
- Service providers: Supabase (database), Stripe (payments), AI providers (content generation)
- Legal requirements: when required by law or to protect our rights
4. AI data processing
When you use AI content generation features, your input data (keywords, topics) is sent to third-party AI providers (OpenAI, Anthropic, Google). These providers process data according to their own privacy policies. We do not use your content to train AI models.
5. Google API services — limited use
LumiSeo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect your Google Ads account to LumiSeo:
- We access the Google Ads API (
adwordsscope) only to fetch keyword research data — search volume, competition level, CPC, and related keyword ideas — for seed keywords you supply within the platform. - We call only read-only methods:
KeywordPlanIdeaService.GenerateKeywordIdeasandKeywordPlanIdeaService.GenerateKeywordHistoricalMetrics. We do not create, read, modify, or delete campaigns, ad groups, ads, budgets, billing data, conversions, or audiences. - We do not use Google user data for advertising or transfer it to third parties.
- We do not use Google user data to train AI or machine learning models.
- Keyword data is stored only within the authenticated user's own workspace and is deleted when the user disconnects the integration or deletes their account.
- You can revoke LumiSeo's access at any time from Settings → Integrations → Disconnect Google Ads, or directly at myaccount.google.com/permissions.
6. Data security
We implement industry-standard security measures including encryption in transit (TLS), encrypted database connections, row-level security, and secure authentication via Supabase Auth.
7. Data retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law.
8. Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Export your data in a portable format (JSON export available)
- Object to or restrict processing
- Withdraw consent at any time
9. Cookies
We use essential cookies for authentication and language preferences. We do not use tracking or advertising cookies. See our cookie consent for details.
10. Children
The Service is not intended for children under 18. We do not knowingly collect data from children.
11. Changes
We may update this policy from time to time. We will notify users of significant changes via email or in-app notification.
12. Contact
For privacy inquiries: privacy@lumiseo.com