Google account profile. When you sign in with Google we receive your name, email address and avatar. We use these only to create and identify your account and to send you transactional email about your own account. They are not used for advertising, not shared with third parties for their own purposes, and not used for any purpose unrelated to operating your account.
App data. Workspace settings you provide, usage logs needed to run and secure the service, and prospect data you generate (public web data about businesses).
We use app data to operate SellSEO: run the scans you request, render your reports, and send transactional email. Aggregated, non-identifying usage statistics help us improve the product.
Google user data is different. All data received from Google APIs, your sign-in profile and anything connected to a Gmail sending mailbox, is used solely to provide the user-facing features you invoked, as described in section 3. It is never used for advertising, never sold, never used to train AI or machine learning models, never used for market research or product analytics, and never used for any purpose other than providing or improving the specific feature you connected it for.
What we request. When you choose to connect a sending mailbox with Google, SellSEO requests a single
Google API scope, https://www.googleapis.com/auth/gmail.send, described on the consent screen as
"Send email on your behalf". We request no other Gmail scope.
What we can and cannot do. That scope permits sending only. SellSEO cannot read, search, download,
label, modify or delete any message in your mailbox, and cannot see your inbox, your contacts or your
attachments. We do not request gmail.readonly, gmail.modify,
gmail.metadata or https://mail.google.com/, and we hold no restricted Gmail scope.
How we use it. We call the Gmail API endpoint users.messages.send only to deliver a
message that you composed or approved inside SellSEO, one message at a time, at your instruction. We never send
on your behalf without an action you took in the app.
What we store. We store the OAuth refresh and access tokens Google issues, encrypted at rest with AES-256-GCM, so we can send on your behalf until you disconnect. We store the messages you sent from SellSEO and their delivery status. We do not copy, index or retain any other mailbox content, because we cannot access it.
Sharing. We do not sell Google user data, do not transfer it to third parties for advertising, and do not use it to train generalised AI or machine learning models. It is not used for any purpose other than delivering the messages you asked us to send.
Limited Use. SellSEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Human access. No SellSEO employee or contractor reads Google user data. The narrow exceptions, matching Google's Limited Use policy, are: with your explicit permission for a support request you raised; where necessary for security purposes such as investigating abuse; to comply with applicable law; or as part of aggregated, anonymised internal operations where the data no longer identifies you.
Revoking access. You can disconnect the mailbox at any time in SellSEO under Settings, Sending, which deletes our stored tokens and asks Google to revoke them. You can independently remove access at myaccount.google.com/permissions. Revoking stops all sending immediately.
Encryption in transit. All traffic between your browser and SellSEO, and between SellSEO and Google APIs, uses TLS (HTTPS). We make no API call over an unencrypted channel.
Encryption at rest. Sensitive credentials, including Google OAuth refresh and access tokens and SMTP passwords, are encrypted at rest with AES-256-GCM using a key held outside the web root and outside version control. Tokens are never written to application logs and never leave our server except in direct, encrypted calls to Google's own APIs.
Access controls. Production access is restricted to authorised personnel on a least-privilege basis and protected by strong authentication. Administrative actions inside the application are audit-logged. Workspace data is isolated per workspace: no other customer can read your data.
Monitoring and incident response. We log security-relevant events and review failures. If a breach affecting your personal data occurs, we will notify you without undue delay at the address on your account, along with what happened and what we are doing about it.
Backups. Encrypted at the storage layer, retained for a rolling window, and cleared within 30 days of a deletion request.
Outreach emails you send through SellSEO can include an open tracking pixel. You are responsible for disclosing tracking to your recipients where required.
Google OAuth tokens are kept only while a mailbox stays connected and are deleted the moment you disconnect it or delete your workspace. Sent-message records are kept while your account is active so your sequence history works. You can ask us to delete your account and all workspace data at any time: hello@sellseo.ai. Deletion completes within 30 days including backups.
We rely on a small set of sub-processors to operate features you invoke: hosting, transactional email delivery, search and web data providers, and AI model providers. Google user data, including Gmail tokens and message content, is not shared with any of them: it flows only between our server and Google. A current list of sub-processors is available on request at hello@sellseo.ai.