Privacy Policy
Last updated August 28, 2026
SEO Web Boss (“we”, “us”) provides an SEO content platform for local businesses. This policy explains what we collect, why, and what we do with it. It covers seowebboss.com and the SEO Web Boss dashboard.
Each customer’s published blog has its own privacy notice on the customer’s own domain, covering visitors to that blog. This policy is about our relationship with our customers.
Information we collect
Account information
When you sign up we collect your business name, work email, and website address. We use your email to sign you in (we use emailed sign-in links, so we never ask for or store a password) and to send service notices.
Email we send you
Two kinds, and they are treated differently. Service email is the mail the product cannot work without — your sign-in link, a notice that a post went live, a warning that a connection needs reconnecting, or anything about your subscription. You cannot turn that off while your account is open, because it is how we tell you things you need to know.
The monthly summary is different: once a month we email you what was published, what we told the search engines about, and the numbers we actually hold for that month. It is not required for the product to work, so every one of those emails carries a one-click unsubscribe link, and the unsubscribe works without signing in. Turning it off stops only that summary — your service email keeps arriving. You can start it again from the same link. We record the date you asked to stop, so that we can answer you if one ever reaches you afterwards.
We do not sell or rent your email address, and we do not send you marketing on behalf of anyone else.
Payment information
Subscription payments are processed by Square on Square’s own hosted checkout. We never see, receive, or store your card details. We store only the identifiers Square returns — a customer id, a subscription id, plan, status, and renewal date — so we know whether your account is active.
Content and site data
We store the business details you provide for content generation (service areas, licence details where your industry requires disclosure, brand settings), the topics and posts produced for you, and per-post performance figures.
Those performance figures include the search terms people typed to reach your pages, as Google Search Console reports them to us. We store the top term for each post, show it to you in your reports, and keep it for as long as we keep the rest of your content data. Bing reports search terms to us as well, for the site as a whole — see the Bing section below.
Google user data
If you choose to connect a Google account, we request only these scopes, and only the ones for the products you connect:
- Google Analytics (
analytics.readonly) — read-only. To show traffic and engagement for your posts in your reports. - Search Console (
webmasters.readonly) — read-only. To show impressions, clicks, average position, and the search terms people used to reach your posts. We store the top term for each post and show it back to you. - Google Business Profile (
business.manage) — to publish local posts to the Business Profile you authorise, and to read that profile’s performance figures for your reports. - Your email address and basic profile (
openid,email) — to identify which Google account was connected, so you can see it and disconnect it.
We request these only when you click Connect, and Google asks you to pick the account and approve the access. You can revoke it at any time from your Google account permissions, or by disconnecting in your SEO Web Boss settings.
Limited Use
SEO Web Boss’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features you see in your dashboard and reports.
- We do not sell Google user data, and we do not use it for advertising.
- We do not transfer it to others except as necessary to provide those features, for security purposes, or to comply with the law.
- Humans do not read it, except with your explicit consent, for security purposes, to comply with the law, where the data has been aggregated and anonymised, or where a member of our staff needs it to run or support the service. That last one is real and we would rather name it than leave it implied: our operators can see your Search Console and Analytics figures in our internal console — your business named, alongside impressions, clicks, average position, pageviews and the top search term for a post — and, when helping you with a problem, can view your reports as you see them. It is how we tell whether your content is working, answer you when you ask, and find a fault before you do. That access is restricted to staff accounts, is not used for anything else, and is never sold, shared or used for advertising.
- We do not use Google user data to develop, improve, or train generalised AI or machine-learning models.
How connected tokens are stored
Access and refresh tokens are encrypted at rest and are only ever used by our backend to make the calls described above. They are never sent to your browser. When you disconnect an integration, or when your account is closed, we revoke the grant with Google and delete the stored tokens.
Bing Webmaster Tools and your domain’s DNS
This one is not something you connect — we do it for you during setup, so it is worth stating plainly. We register your website in Bing Webmaster Tools under an account we operate, not an account of yours. To prove control of the site, your blog serves a verification tag, and where we run your domain’s DNS as part of the service we also add a verification record to it. If your DNS is not with us, we do not add a record and we register only your blog path. There is no separate Microsoft consent screen for this and you are not asked to approve it step by step: it happens as part of taking your site live. What we may and may not do with your domain’s DNS is set out in our Terms of Service. It is part of how the service runs rather than something you can switch off while keeping the rest; if you do not want it, that is a conversation to have with us before we take your site live.
We register the whole domain, not just the blog we write. That is not a convenience — Bing reports no performance data at all for a single folder, so registering only your blog path would return nothing. The consequence is the part you should know: this gives us your site’s Bing search performance for every page on it — impressions, clicks, average position, the search terms people used, and the crawl errors Bing found — including pages we did not write and had no hand in.
We use those figures to report on how your site is performing in search. Because the site sits in an account we operate rather than one of yours, our staff can see this data in the Bing console alongside the other sites in that account — this is not data we can hold at arm’s length the way we do your connected Google accounts. Access to that console is limited to the people who need it, like any other production system. We do not sell it, and we do not use it for advertising.
When your account closes, removing the site from that account and deleting the verification record from your DNS happens automatically, in the same teardown that revokes your connected accounts. We identify the record three ways: the name we stored when we created it, the name Microsoft gives back, and — if neither is available — the single Bing verification record in the zone we set up for you. One honest limit remains, and it is deliberate: if there is more than one such record we leave them all alone, because one of them may be a Bing claim you set up yourself and we would rather leave ours behind than delete yours on the way out. So if you ever find one of our records still in your DNS, email support@seowebboss.com and we will remove it.
LinkedIn data
If you connect LinkedIn, we ask for three permissions and no others: openid and profile, which identify which LinkedIn account was connected so you can see it and disconnect it, and w_member_social, which is what lets us post to your own profile on your behalf when one of your blog posts goes live.
We do not read your feed, your connections, your messages, or anyone else’s posts — the permission we hold does not allow it and we do not ask for one that would. We store your LinkedIn access token encrypted at rest, and the identifier we need in order to post. Nothing is posted without a post of yours going live first, and automatic posting is off unless you turn it on.
Disconnecting LinkedIn in Settings → Integrations deletes the stored token. Posts already published to your profile stay there — they are yours, on your account, and only you can remove them.
Meta (Facebook and Instagram) data
If you connect a Facebook Page or an Instagram professional account, we receive data from Meta’s platform in order to publish on your behalf and to report on how those posts performed. We hold it under Meta’s Platform Terms and Developer Policies, and this section describes it specifically because those terms only permit us to use platform data in the ways our policy actually names.
What we receive and store:
- the list of Pages you administer, so you can choose which one to connect — we store only the one you pick;
- an access token for that Page or account, encrypted at rest, and the identifiers we need to post to it;
- the name and profile image of the connected Page or account, so the dashboard can show you which one is connected;
- the identifier of each post we publish, and the reach and engagement figures Meta returns for it.
What we do with it:
- publish the posts you have approved, and nothing else;
- show you how those posts performed, in your own dashboard.
What we never do with it. We do not sell or rent it. We do not use it for advertising or to build an advertising profile. We do not use it to train, retrain, or fine-tune any AI model — including the third-party AI providers named below, which are never sent your Meta data. We do not combine it with data from other customers.
Who at SEO Web Boss can see it. Our staff can see a connected account’s name and its post performance through an access-controlled internal console, and can enter your dashboard to support you. That is ordinary operations rather than an exception, and we would rather say so than claim nobody ever looks. Access is limited to staff who need it, and it is never used for advertising, never sold, and never used to train a model.
Deletion. Disconnecting the integration in Settings deletes the stored tokens and the identifiers immediately. All Meta platform data is deleted promptly on request — see our data deletion page — and when you close your account, without waiting for the general retention period below.
The Meta Pixel is a separate thing. If you supply a Meta Pixel ID for your own blog, we embed that pixel on your site and Meta sets cookies on your visitors’ browsers. That is your pixel, collecting your visitors’ data under your own relationship with Meta; we neither receive nor store what it collects. Your blog’s own privacy notice discloses it to your visitors.
How we use your information
- To generate, publish, and distribute content for you.
- To show you how that content is performing.
- To run your subscription and send service notices.
- To keep the service secure and to diagnose faults.
We do not sell your personal information, and we do not share it with third parties for their own marketing.
Who we share it with
We use a small number of processors, each for one purpose: hosting, DNS and content delivery (Vercel and Cloudflare), our database and job queue, email delivery for sign-in links and notices, payment processing (Square), and the AI providers that generate draft content. They may process your data only on our instructions.
The AI writing providers are Anthropic and OpenAI, both processing in the United States, and Moonshot AI (Kimi), which processes in Singapore. What we send them is the material needed to write your article: your business profile, service areas, the topic, and your writing-style settings.
We also use Google (Gemini) for two narrower jobs, and it belongs on this list for the same reason the others do. The first is making the picture at the top of a post: we send the article’s title, your industry, and your service area, and nothing else. The second is checking whether AI assistants mention your business when someone asks them a question in your field — that check sends your business name and service areas as part of the question being asked. We do not send either one your customer or enquiry data.
Once a week we also send your performance figures. The feature that decides what to write about next reads how your published posts actually did — Search Console impressions, clicks and average position, and Analytics pageviews — and asks a model which subjects earned attention, so the next ones are chosen on evidence rather than guesswork. That request is about YOUR posts only; it is never combined with another customer’s figures, and it goes only to a provider whose terms forbid training on it (see the next paragraph). We say this plainly because “we send AI providers what is needed to write your article” would leave you picturing topics and copy, and your Analytics numbers are neither.
Those requests travel through Vercel. Vercel already hosts this service and your blog. It now also carries our requests to the AI writing providers — we route them provider by provider, so at any given time this may be some of them or all of them — handing each request to the provider that answers it. Where it applies, the material described above reaches Anthropic, OpenAI or Moonshot by way of Vercel rather than directly, and Vercel is a processor of it. Vercel does not train on what passes through, and the provider’s own terms — described next — still govern what that provider may do with it. We also pin each request to the provider named above rather than letting it be served by whoever else offers the same model, so a provider that processes outside the United States still does: Moonshot requests go to Moonshot, in Singapore.
One difference between them is worth stating rather than leaving you to find. Anthropic’s and OpenAI’s API terms do not permit them to train their models on what we send. Moonshot’s default terms do permit it, unless a separate written agreement says otherwise. Because of that we withhold one category of data from Moonshot entirely: the performance analysis derived from your Google Search Console and Analytics figures is never included in a request to a provider that may train on it. If you would rather your content did not go to Moonshot at all, your writing model is yours to choose in Settings, and the choice is reversible at any time.
We also publish content on your behalf to the channels you connect — that is the product working as intended, and only to accounts you have authorised.
Retention
We keep account and content data for as long as your account is open. If you close your account we delete or anonymise your data within 90 days, except where we must keep records longer for legal or accounting reasons. Connected-integration tokens are revoked and deleted at closure rather than at the end of that window.
The Bing Webmaster registration described above is part of that teardown: the site is removed from our account and the verification record deleted when the account closes.
Your rights
You can ask us to access, correct, export, or delete your information by emailing support@seowebboss.com, or follow the step-by-step route on our data deletion page. If you are a California resident, you may exercise your rights under the CCPA/CPRA — including the right to know, to delete, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined there.
Security
Data is encrypted in transit. Integration tokens are encrypted at rest. Access to production systems is limited to people who need it. No system is perfectly secure, and we will not claim otherwise — if a breach affects you, we will tell you.
Children
SEO Web Boss is a business product and is not directed to anyone under 18. We do not knowingly collect information from children.
Changes
If we change this policy we will update the date at the top, and we will email you before any change that materially reduces your rights.
Contact
support@seowebboss.com
See also our Terms of Service.
Questions about this document? support@seowebboss.com
