What we collect
We collect the information needed to create and operate your account, such as your email address, profile details, login/session data, plan or billing status, and basic account preferences.
We may keep verified email history, linked sign-in-provider identifiers, project billing assignments, usage reservations and events, overage settings, and Stripe customer and subscription identifiers. Stripe receives the current account email and identifiers needed to reconcile your SERPclimber account; payment-card details are handled by Stripe rather than stored by SERPclimber.
When you use the product, we store workspace data you choose to create or connect: projects, domains, URLs, keywords, search performance data, experiments, drafts, decisions, audit logs, saved settings, and related metadata.
If you connect Google Search Console, Wix, Cloudflare, or another user-managed service, we may store connection details, permissions, account identifiers, configuration, and encrypted secrets such as API keys or access tokens. Secrets are used to operate the integrations you enable and are not displayed back to you after saving.
OpenAI, Anthropic, Ahrefs, and DataForSEO are site-managed providers. We do not ask you for credentials for them, but they may process the project data, prompts, content, queries, and URLs needed to provide generation, research, and AI Visibility features.
Chatbot conversations
If you use the assistant, we may save your conversations, prompts, responses, selected context, tool results, approvals, errors, and message metadata so you can continue work, inspect prior decisions, and improve the usefulness of the app.
The assistant may use your selected workspace context, connected account data, and recent product activity to answer your requests. We try to redact sensitive-looking values from stored tool details, but you should not paste secrets, passwords, or private credentials into chat.
Assistant requests may be processed by AI infrastructure and service providers that help us generate responses. We do not need to name those providers inside the product for this policy to apply.
If you choose to contact support through the assistant, we show a confirmation before sending your verified primary email, an AI-generated summary, and selected user-authored messages to our support address through our transactional email provider. Assistant responses, tool output, and system instructions are excluded from the raw-message section. You can review and cancel the request before it is sent.
How we use information
We use information to provide the application, authenticate users, operate integrations, run SEO workflows, draft and test content variants, publish user-approved changes, troubleshoot issues, prevent abuse, protect accounts, and communicate about the service.
We may analyze aggregated or de-identified usage patterns to improve reliability, product quality, onboarding, pricing, and support. We do not sell your private workspace data.
We may use logs, diagnostics, analytics, cookies, local storage, session storage, and performance monitoring to keep the application secure, understand feature usage, debug failures, and measure service health.
Integrations and publishing
When you connect a blog, CMS, SEO data source, content generation service, or other integration, you authorize us to send and receive the data needed to perform the actions you request or configure.
Depending on your settings and permissions, those actions may include reading site or performance data, drafting content, updating metadata, editing content, publishing variants, reverting changes, or recording the results of experiments.
User-managed integrations include Google Search Console, Wix, and Cloudflare. SERPclimber also uses site-managed providers such as OpenAI, Anthropic, Ahrefs, and DataForSEO to deliver generation, research, and AI Visibility features. The exact set evolves as we add or remove integrations.
We aim to request only the access that is useful for the workflows you enable, but you are responsible for reviewing permissions in the third-party service and deciding whether a connection is appropriate for your account.
Sharing
We share information with service providers that help us host, secure, monitor, support, bill for, and operate the product. These providers may process data only as needed to perform services for us.
Examples of categories and products we may use include payment processing (such as Stripe), product analytics and session telemetry (such as PostHog, Google Analytics, Meta Pixel, or DataFast), application performance and uptime monitoring (such as MontiAPM and similar APM tools), error tracking, cloud hosting and storage, customer support tooling, and transactional email. The specific vendors change over time as we tune the stack.
When an AI Visibility live check cites another SERPclimber project, we may copy the question and saved public answer snapshot into that cited project. Across accounts, this requires the cited domain to match a connected Google Search Console property. The recipient is not shown the originating user or project.
We may disclose information if required by law, to protect rights and safety, to investigate abuse or security issues, or as part of a merger, acquisition, financing, restructuring, or sale of assets.
If your workspace is part of an organization, admins or authorized team members may be able to access workspace data, settings, integrations, and activity associated with that workspace.
Security and retention
We use reasonable technical and organizational safeguards, including encrypted storage for integration secrets, access controls, and operational monitoring. No internet service can be made perfectly secure.
We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, keep audit history, and maintain backups. Some backup, log, or audit records may remain for a limited period after deletion from active systems.
You can disconnect integrations, remove data where the product allows it, or contact us for account and deletion requests. We may need to keep limited records where required for security, billing, legal, or operational reasons.
Your choices
You can choose what to connect, what to publish, what to put in chat, and whether to use optional automation settings. You can also manage browser controls for cookies and storage, though some features may not work correctly without them.
You are responsible for keeping your login credentials secure, limiting access to your connected services, reviewing generated content before it goes live, and maintaining your own backups of important content and sites.
Enterprise and custom arrangements
If your organization needs specific privacy, security, residency, retention, audit, or compliance commitments beyond what is described above, reach out. We can often accommodate things like a signed data processing agreement, restricted data handling, custom retention windows, dedicated infrastructure, security reviews, or single sign-on as part of a tailored arrangement.
These commitments are made in writing through an enterprise agreement or order form. Without a written commitment, the standard policy described on this page is what applies to your account.
Email [email protected] to start that conversation.
Privacy questions, data requests, or account deletion? [email protected].
