Privacy Policy
Last updated: August 8, 2026
What this covers
This policy explains what SeoPiece collects when you create an account and connect a website to it, why we collect it, and who else ever sees it. We built SeoPiece to be honest about how it works, and that includes this page.
Information you give us
- Account details — name, email address, and password (stored as a bcrypt hash, never in plain text). If you sign in with Google, we store your Google account ID instead of a password.
- Billing details — handled by Stripe. We store your Stripe customer ID to match webhooks to your account; we never see or store your card number.
- Project details — the domain, niche, and brand voice you tell us about each site you connect, used directly as context for the content we write for you.
- Connection credentials — WordPress Application Passwords, and OAuth tokens for Google Search Console, Facebook, and Instagram, if you connect them. These are encrypted (AES-256-GCM) before they're stored, and used only to publish content or read performance data on your behalf.
Information collected automatically
Standard server logs (IP address, request timestamps) for security and abuse prevention — for example, the rate limits on our login and public API endpoints rely on this. We don't use third-party advertising or analytics trackers on this site.
Cookies
We set one cookie: a signed, HTTP-only session token used to keep you signed in. It's not used for advertising or cross-site tracking.
Who we share data with
We use a small number of processors to run the product, each only for the purpose below:
- Stripe — payment processing and subscription billing.
- Google (Gemini API, Search Console) — content generation, and reading your site's search performance if you connect Search Console.
- DataForSEO, SerpApi — real keyword and search-result data used for research.
- Copyscape — duplicate-content scanning, only for accounts on plans that include it.
- Cloudflare Workers AI — featured image generation.
- Meta (Facebook/Instagram Graph API), Telegram — only if you explicitly connect these for publishing or notifications.
- Your own WordPress site — articles are published there using the Application Password you provide; we don't share your data with any other WordPress site.
We do not sell your data, and we do not share it with anyone for their own marketing purposes.
How long we keep it
We keep account and project data for as long as your account is active. If you delete a project or your account, we remove the associated content and credentials; billing records are kept as long as required for tax and accounting purposes.
Your rights
You can review or update your account details from the dashboard at any time, disconnect any integration (WordPress, Search Console, Facebook, Instagram) whenever you want, and request a copy or deletion of your data by reaching out through our contact page.
Changes to this policy
If we make a material change to how we handle your data, we'll post an update here and, where appropriate, notify you directly.
Questions
Reach us any time through the contact page.