Privacy Policy

Last updated 20 August 2026

1. What we collect

Account data: your email address (sign-in is passwordless — we email you a sign-in link; sessions are managed by our authentication provider, Supabase). Workspace and project names you choose.

Analysis data: the website URLs you submit, crawl results, keyword and competitor data, generated reports, strategies and content — stored so your history and reports keep working.

Leads: if you embed our audit widget on your site, the name/email your visitors submit is stored in your workspace for you.

Technical data: IP addresses are used for rate limiting and abuse prevention; standard server logs are kept by our hosting provider.

Crawl session cookies: if you use "Crawl behind a login", the session cookie you paste is used only for the duration of that crawl, is scoped to the audited domain, and is never stored or logged.

Publishing connections: if you connect a publishing destination (for example a WordPress site or a GitHub repository), we store the credentials or connection you provide so we can publish content there on your behalf. Disconnecting removes them.

Payments: when paid checkout is available it is processed by Stripe — we receive your subscription status, never your card details.

2. How we use it

To run the analyses you request, keep your report history, operate rank tracking and scheduled re-audits you set up, send transactional email (e.g. sign-in links, scheduled-report notifications), and protect the platform from abuse.

We do not sell your personal data, and we do not use your data for advertising.

3. Who processes it for us

We use a small set of processors to operate the Service: Vercel (hosting), Supabase (database and authentication), Anthropic (AI analysis of the content you submit), DataForSEO (search-engine data), Google APIs (optional Sheets/Slides export and page-speed data), Stripe (payments), and Resend (transactional email), plus stock-image providers when you generate images.

If you connect a publishing destination (such as GitHub or a WordPress site), content is sent to that platform when you publish — that connection is yours and under your control.

Anthropic processes submitted content through its API and does not use it to train AI models. Each processor receives only what it needs to perform its function. Public web pages you ask us to audit are fetched directly from the site in question.

Some of these providers store data outside Singapore. Where they do, we take steps to ensure it receives a standard of protection comparable to the PDPA.

4. Retention and deletion

Analysis history is retained so your workspace keeps working; you can archive projects at any time.

You can delete your account yourself from within the app — it is a hard delete that removes your account and workspace data. To delete a single workspace or specific data instead, email hello@searchblueprint.io and we will action it within 30 days.

5. Your rights

Under Singapore's Personal Data Protection Act (PDPA) you may request access to or correction of your personal data, and withdraw consent to its use (which may mean closing your account).

Requests: hello@searchblueprint.io. We respond within 30 days.

6. Cookies

We set authentication/session cookies needed to keep you signed in. We do not set third-party advertising or cross-site tracking cookies.

7. Security

Data is encrypted in transit (HTTPS) and at rest by our providers. Access to production data is restricted to the operating team. Row-level tenancy keeps each workspace's data isolated from every other workspace.

No system is perfectly secure — if we learn of a breach affecting your personal data we will notify you as required by law.

8. Changes and contact

We will signpost material changes to this policy in the app or by email.

Data protection contact: hello@searchblueprint.io.

See also our Terms of Service.