Privacy Policy

Last updated: August 4, 2026

1. Introduction

Semantic.io ("we," "us," or "our") operates the semantic.io website and the Semantic AI SEO Harness platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this policy, please do not access the Service.

2. Information We Collect

Account Information: When you register, we collect your name, email address, and authentication credentials (password hash or Google OAuth tokens). We never store plaintext passwords.

Google Search Console Data: When you connect your Google Search Console account, we access and store your search performance data (queries, clicks, impressions, position, CTR) via the Google Search Console API. This data is stored indefinitely while your account remains active.

Third-Party API Data: If you connect Ahrefs or Semrush, we store your API key (encrypted at rest) and cache keyword/backlink data retrieved through those APIs.

Usage Data: We automatically collect information about how you interact with the Service, including pages visited, features used, timestamps, and device/browser information.

Payment Information: Payment processing is handled by Stripe. We do not store full credit card numbers. We retain only your Stripe Customer ID and subscription status.

3. How We Use Your Information

  • To provide, operate, and maintain the Service
  • To process your transactions and manage your subscription
  • To analyze your SEO performance data and generate actionable insights
  • To execute automated SEO actions on your behalf (when Tier 2 or Tier 3 automation is enabled)
  • To send you service-related communications (account alerts, billing notices, feature updates)
  • To send newsletter content if you have subscribed or opted in during registration
  • To improve and personalize the Service
  • To detect, prevent, and address technical issues or abuse

4. Data Storage and Retention

Active accounts: All data — including Google Search Console historical data — is retained indefinitely while your account remains active. There is no rolling window or automatic purge. This allows you to analyze long-term trends, seasonal patterns, and year-over-year performance.

Cancelled accounts: After cancellation, your data is retained in a read-only state for 30 days. During this period, you may log in to export your data. After 30 days, all personal data and associated analytics are permanently deleted from our systems.

Infrastructure: Data is stored in encrypted databases hosted on secure cloud infrastructure. All data in transit is encrypted via TLS 1.3. Backups are encrypted at rest and retained for disaster recovery purposes only.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share data only in the following circumstances:

  • Service providers: Stripe (payments), Google Cloud (infrastructure), and email delivery services — each bound by data processing agreements.
  • Legal requirements: When required by law, subpoena, or government request.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
  • With your consent: When you explicitly authorize sharing (e.g., publishing content to your WordPress site via our integration).

6. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of all personal data we hold about you.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request that we limit processing of your data.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent for newsletter or marketing communications at any time.

To exercise any of these rights, contact us at privacy@semantic.io. We will respond within 30 days.

7. Cookies and Tracking

We use essential cookies for authentication (session tokens) and preference storage. We use privacy-respecting analytics (no third-party tracking pixels, no cross-site tracking). We do not use Google Analytics. Our analytics are first-party and do not share data with advertising networks.

8. Security

We implement industry-standard security measures including encryption at rest and in transit, secure authentication (bcrypt password hashing, OAuth 2.0), rate limiting, and regular security audits. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: privacy@semantic.io
Website: https://semantic.io