Privacy Policy
Last updated: July 15, 2026
1. Introduction
This Privacy Policy explains how Seolfy (“we”, “our”, “us”) collects, uses, shares, and protects your personal data when you use Seolfy (the “Service”) or visit seolfy.com.
Seolfy is operated as a personal side project, not as a registered company. We are committed to processing your personal data lawfully, fairly, and transparently in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws where they apply to you.
Data controller
Seolfy (personal project)
Email: info@seolfy.com
2. Personal Data We Collect
2.1 Data You Provide
- Account data: name, email address, password (hashed), company name, country.
- Billing data: billing address, payment instrument details (processed and stored by our payment processor; we receive metadata and a token, not full card numbers).
- Brand and configuration data: website URL, brand voice settings, target audience, content preferences, language settings, integration credentials and access tokens for connected platforms (WordPress, Shopify, Wix, HubSpot, FTP, RSS, Google Search Console, Meta, and others).
- Communications: the contents of emails, support tickets, and messages you send us.
2.2 Data Collected Automatically
- Usage data: features used, content generated, articles scheduled and published, settings changes, dashboard interactions, errors.
- Device and connection data: IP address, browser type and version, operating system, time zone, language settings, referring URLs.
- Cookies and similar technologies: see Section 7.
2.3 Data From Third Parties
- From your connected platforms: when you connect a platform such as Google Search Console, we receive metrics, page URLs, queries, and other data that platform exposes based on your authorization.
- From payment processors: transaction status, country, last four digits of payment instrument, fraud signals.
- From authentication providers: if you sign in with a third-party identity provider, we receive the identifiers and profile fields they share with us.
2.4 Special Categories
We do not intentionally collect special categories of personal data (such as health, racial or ethnic origin, or biometric data). Do not enter such data into the Service.
3. How We Use Personal Data
3.1 To Provide the Service (legal basis: contract, Article 6(1)(b) GDPR)
- Create and maintain your account.
- Generate keywords, articles, and images according to your settings.
- Publish content to your connected platforms.
- Display analytics from Google Search Console and similar sources.
- Provide customer support.
3.2 For Billing (legal basis: contract, Article 6(1)(b) GDPR)
- Process payments, refunds, and chargebacks.
- Calculate and remit applicable taxes where required.
3.3 To Secure and Improve the Service (legal basis: legitimate interests, Article 6(1)(f) GDPR)
- Detect, prevent, and investigate fraud, abuse, security incidents, and Terms violations.
- Monitor performance and stability.
- Analyze usage in aggregate to improve features.
3.4 To Communicate With You (legal basis: contract and legitimate interests; consent for marketing where required)
- Send service announcements, security notices, billing notices, and product updates relevant to your account.
- Send marketing communications with your prior consent where required by law. You can opt out at any time using the unsubscribe link or by emailing info@seolfy.com.
3.5 To Comply With Law (legal basis: legal obligation, Article 6(1)(c) GDPR)
- Respond to lawful requests from public authorities.
- Enforce our Terms of Service.
3.6 No Training of Third-Party AI Models
We do not use Customer Content to train third-party AI models. The AI providers we use operate under contractual terms that prohibit training their models on customer API inputs and outputs.
4. How We Share Personal Data
We do not sell personal data.
We share personal data with:
4.1 Service Providers
We rely on trusted third-party providers to operate the Service, including cloud infrastructure, database and storage, payment processing, email and support platforms, analytics and error monitoring, AI model providers, and authentication providers. These providers are bound by data processing terms requiring confidentiality, security, and GDPR compliance where applicable.
4.2 Integration Partners You Connect
When you connect a third-party platform, we exchange data with that platform as needed to perform the Service you have requested. Those platforms operate under their own privacy policies.
4.3 Legal and Safety
We may disclose personal data when we believe in good faith that disclosure is required to comply with a legal obligation, protect the rights and safety of Seolfy and our users, investigate fraud or security incidents, or enforce our agreements.
5. International Transfers
Some of our service providers may be located outside the EU/EEA, including in the United States and the United Kingdom. Where we transfer personal data outside the EU/EEA to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
You can request information about safeguards in place by writing to info@seolfy.com.
6. Data Retention
- Account and configuration data: for the duration of your account, plus up to 90 days after closure.
- Billing records: as long as required for accounting and tax purposes.
- Support records: up to three years after the last interaction.
- Security logs: up to two years.
After applicable retention periods, we delete or irreversibly anonymize personal data.
7. Cookies and Similar Technologies
We use cookies, pixels, local storage, and similar technologies on seolfy.com and within the Service:
- Strictly necessary: authentication, session management, security, and load balancing. These cannot be switched off without affecting the Service.
- Functional: remember your preferences and language settings.
- Analytics: help us understand how the website and Service are used so we can improve them.
Where required by law, we obtain your consent before loading non-essential cookies. You can also control cookies through your browser settings.
8. Your Rights
Subject to applicable conditions and exceptions, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of personal data in certain circumstances.
- Restriction of processing in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority in your country of residence.
To exercise these rights, email info@seolfy.com. We respond within 30 days where possible.
9. Security
We implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit (HTTPS/TLS), hashed passwords, role-based access controls, and incident response procedures. No method of transmission or storage is 100% secure.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact info@seolfy.com and we will take appropriate steps to delete it.
11. AI Processing
The Service uses artificial intelligence to research keywords, generate articles and images, and assist with related tasks. AI output may be inaccurate or incomplete. We do not use Customer Content to train third-party AI models. Automated decision-making within the meaning of Article 22 GDPR is not used in the Service.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If a change is material, we will notify you by email and/or in-product notice before it takes effect. The “Last updated” date at the top reflects the most recent revision.
13. Contact
For privacy questions or to exercise your rights: info@seolfy.com