Privacy Policy
Last updated: August 28, 2026
SEOTrack.app ("SEO Track", "we", "us") is a self-hosted-style SEO intelligence subscription operated by BOT-HOLDINGS, LLC at seotrack.app. This policy explains what we collect through the SEOTrack.app web application and the SEOTrack.app mobile apps for iOS and Android, why we collect it, and how you can control or remove it.
The short version
We collect your login email, your workspace name, and the SEO data you enter or ask us to fetch on your behalf. We don't run ads, we don't use analytics trackers, and we don't sell or share your data. Your own provider API keys are stored encrypted and used only to run the calls you ask for. Payment is handled entirely by PayPal — we never see your card number.
What we collect
- Account data. The email address and password you sign up with, and the workspace name you choose. We use your email to send transactional messages — a welcome message, payment receipts, a payment-failure notice, and password-reset links — never marketing email you didn't ask for.
- The SEO data you give us. The domains, keywords, and competitor sites you add to your workspace to track.
- The SEO data we fetch for you. Using the keywords and domains you configure, SEOTrack.app queries live search-engine results and, if you turn the feature on, samples answers from AI assistants (ChatGPT, Claude, Gemini, Perplexity) to see whether and how your site is mentioned. The rankings, mention rates, and answer samples this produces are stored in your workspace so you can see them change over time.
- Google Search Console / GA4 data — only if you connect it. Connecting is optional and made through Google's own OAuth consent screen; we store the resulting access token (encrypted) and the search-performance and analytics figures Google's APIs return, so that your workspace can show verified numbers alongside our own sampled estimates.
- Provider API keys. SEOTrack.app is largely bring-your-own-provider: your DataForSEO key, your chosen LLM provider's key, and your WordPress site credentials (if you use the article-publishing feature) are stored encrypted in a vault keyed by a machine key that only our server holds. A key is used exclusively to make the specific calls your workspace's configuration and schedule ask for — never for any other customer's workspace, never for anything you didn't configure.
- Billing records. Your subscription status, the PayPal subscription ID, and an invoice history (date, amount, plan, paid / failed / refunded status). We never receive or store your card or bank details — PayPal processes the charge and only reports back the outcome.
- Operational logs. Standard request and error logs (timestamps, IP address, the route called) kept for security and debugging, and an in-app activity log of account-level actions (sign-up, login, cancel, plan changes) scoped to your workspace.
How your provider keys and data are used
When SEOTrack.app runs a rank check, an AI-visibility sample, or drafts an article, it calls the vendor you configured — DataForSEO for search-results data, the LLM provider you picked for AI-visibility sampling and article drafting, and your own WordPress site if you publish there — using your stored key or credentials, on your own schedule or at your request. Those calls are billed by that vendor directly to your account, at that vendor's own price; SEOTrack.app never marks the cost up, meters it for resale, or takes a cut. A monthly budget ceiling in Settings lets you cap this spend, and paid actions can be set to ask for confirmation before they run.
What we don't do
- We do not sell your data, ever, to anyone.
- We do not run advertising and we do not embed an analytics SDK or third-party tracker in the web app or the mobile apps.
- We do not share your data with any third party beyond the vendors your own configuration calls — DataForSEO, the LLM provider you selected, and your own WordPress site — plus PayPal for payment processing and, if you connect it, Google for Search Console/GA4. None of those vendors receive more than the specific request your workspace makes.
- We do not use your SEO data, your provider keys, or your account information to train any model.
Data location & security
Your workspace's data is stored in an isolated database per workspace. Secrets — provider API keys, WordPress credentials, SMTP passwords — are encrypted at rest in a vault keyed by a machine key unique to the server; losing that key would make the vault unreadable, which is why it is protected like any other production credential. All traffic to SEOTrack.app is encrypted in transit (TLS).
Data retention & deletion
You can delete individual projects, keywords, competitors, articles, or provider keys at any time from inside the app. If your subscription lapses — cancelled or a payment fails and is never resolved — your workspace is kept, but access is paused; after 90 days in that state it is archived, and 30 days after archival it is permanently erased. You do not have to wait for that clock: you can request full deletion at any time, either with the "Delete account" control in the app or by emailing [email protected] from your account's email address. Deletion removes your workspace database — every project, keyword, competitor, article, and stored key — and deactivates your login. Invoice records (plan, amount, date) are kept as required for accounting after a deletion.
Your rights
You can access, export, correct, or erase your data at any time from inside the app, or by emailing [email protected]. If you are located somewhere that grants you specific statutory rights over your personal data (for example under the GDPR or a U.S. state privacy law), those rights apply here too and we will honor a verified request within a reasonable time, and in any case within 30 days.
Children
SEOTrack.app is a business tool and is not directed at, or knowingly offered to, children under 16.
Changes to this policy
If we change this policy in a material way, we will update the date at the top of this page and, for changes that materially reduce your rights, notify active subscribers by email.
Contact
Questions, requests, or concerns about this policy: [email protected]. Governing entity: BOT-HOLDINGS, LLC.