superseo.sh/privacy
Privacy Policy
What we collect, why we collect it, who sees it, and how to delete it. No 40-page PDF.
Last updated 20 August 2026
Who we are
SuperSEO.sh is an SEO and AI-visibility product at https://superseo.sh. It is operated by SilverArk Media (“we”, “us”).
For privacy questions, deletion requests, or anything in this policy, email hello@superseo.sh.
What this covers
This policy covers the SuperSEO.sh website, the free site scan, scan reports, accounts, the dashboard, emails we send, and related APIs.
It does not cover third-party sites you ask us to scan, or the processors we use (Whop, Google, and the rest) when you are on their sites. Checkout happens on Whop. Sign-in with Google or X happens on those providers.
Using SuperSEO.sh means you also agree to our Terms of Service.
What we collect
We collect as little as we can still run the product with. Here is the actual list.
Free scan
When you submit a URL, we fetch publicly available pages on that site: robots.txt, /llms.txt, titles, meta descriptions, and similar checks. We store the domain, scores, findings, and a short slug so we can show the report.
Anyone can scan any public URL, the way a browser can. We do not need an account for that. We rate-limit by IP so the scan is not a free DDoS button.
Scan report email
If you enter an email to unlock the full report, we store that address, tie it to the scan, and send the report. We also add the address to our email audience (currently Resend, and sequences or a newsletter via Sequenzy) so we can send product email about SuperSEO.sh — how it works, pricing, new features. Every marketing email has a one-click unsubscribe. We do not sell your address.
Accounts
If you sign in, we store your name, email, profile image if the provider sends one, and a session. There are no passwords. Sign-in is a magic link via Resend, or OAuth with Google or X.
Sessions live in Postgres. The cookie is better-auth.session_token. We also store IP address and user-agent on the session row for security (stolen-cookie checks, abuse).
Your projects
Sites you add, crawl results, issues, keywords, rankings, speed checks, sitemaps, GEO scores, LLM mention checks, social mentions, launch checklist state, and the copy-paste fix prompts we generate. That is the product. We keep it so the dashboard works.
Integrations you connect
Optional, per project: Google Search Console, Google Analytics 4, DataFast, Bing, Yandex, and similar. OAuth tokens and API keys are encrypted at rest with AES-256-GCM. We use them only to pull data for that project. Disconnect anytime and we stop using the token.
Billing
Payments go through Whop. We never see or store your card. Whop tells us your membership, email, plan, and status so we can unlock Indie, Growth, Scale, or Lifetime. Manage, upgrade, or cancel in the Whop portal.
Emails we send to members
Magic links, scan reports, rank and broken-page alerts, weekly digests, and account mail are transactional. Product sequences and a newsletter are marketing. Unsubscribe from marketing in one click. You cannot unsubscribe from security and sign-in mail and still use the account — those emails are the login.
Analytics
The marketing site loads DataFast (datafa.st) for privacy-friendly web analytics: pages, referrers, devices, countries. It is not an ad network. We use it to see what copy works, not to profile you across the internet.
LLM mention checks
If you use AI visibility tracking, we send the buyer-intent prompts you choose to models via OpenRouter (GPT, Claude, Gemini-class, and similar). We store whether your brand was mentioned, whether your domain was cited, and a short excerpt. Those providers process the prompt under their own terms.
Social mentions
If mentions are on, we search Reddit and X for the brand or domain keywords you configure, and store permalinks, subreddit or handle, and a simple sentiment label.
Automatically collected
Server logs (IP, user-agent, path, status, timing) for security, rate limits, and debugging. We do not sell logs. We do not use them for ads.
Why we use it
Under GDPR and UK GDPR, we need a legal basis. Here they are.
- Contract. Running your account, crawls, scans, rankings, alerts, magic links, and the paid product.
- Legitimate interests. Securing the service, stopping abuse, improving the scan and dashboard, understanding which marketing pages work, and fetching public pages you asked us to scan.
- Consent. Marketing email after a scan or signup. Social login permissions. Optional integrations. You can withdraw consent without losing the core product, except where the feature is the integration.
- Legal obligation. Tax, accounting, and requests from law enforcement we are required to answer.
We do not use your content to train our own foundation models. We do not sell personal information. We do not share it for cross-context behavioral advertising.
Who we share it with
We share data with processors who help us run SuperSEO.sh — not with random buyers. The current list:
- Neon — Postgres. Accounts, scans, projects, crawls.
- Cloudflare — hosts the SuperSEO.sh frontend.
- Whop — checkout, memberships, customer portal. Whop privacy.
- Resend — transactional email and the scan-lead audience.
- Sequenzy — email sequences and newsletter.
- Google — OAuth sign-in; optional Search Console and GA4; PageSpeed Insights for speed checks.
- X — optional social sign-in.
- DataForSEO — SERP and keyword data for rank tracking.
- OpenRouter — LLM mention checks.
- DataFast — analytics on superseo.sh, and optional as a customer integration.
- IndexNow / Bing / Yandex — indexing pings and optional webmaster integrations you connect.
- Reddit and X APIs — brand mention search when that feature is on.
We may disclose data if the law requires it, or to protect SuperSEO.sh, our users, or the public from fraud or abuse. If SilverArk Media is acquired or merges, this data goes with the product, still under a privacy policy at least as protective as this one.
Cookies
We use a short list.
- Essential session cookie —
better-auth.session_token. Lets you stay signed in. No account, no cookie of this kind. - Security / CSRF — set by the auth library as needed to keep sign-in from being hijacked.
We do not run advertising cookies. We do not run a cookie banner for ads because we do not run ads. DataFast is loaded for first-party product analytics, not to follow you around the web.
Third-party buttons (Google sign-in, Whop checkout) may set their own cookies when you use them. That is their policy, not ours.
How long we keep it
- Public scans — kept so the report link still works, and so we can improve the checks. We may prune old unclaimed scans.
- Scan-lead emails — until you unsubscribe and ask us to delete, or you delete an account tied to the same address.
- Active accounts — for as long as the account exists.
- After you cancel a paid plan — a 3-day grace period, then read-only, then we keep project data for 90 days in case you come back. Then it is purged. A deleted site stays with that account for those 90 days and cannot be added to another account.
- Account deletion — from the account page. That is a full purge: projects, crawls, keywords, integrations, OAuth tokens, sessions, login. It cannot be undone. Backups age out on their normal cycle.
- Billing records — Whop (and we) may keep invoices and membership IDs as long as tax law requires.
- Server logs — typically days to a few weeks, unless we are investigating abuse.
Your rights
If you are in the EEA, UK, or Switzerland, you can access, correct, delete, restrict, or export your personal data, and object to processing based on legitimate interests. You can withdraw consent for marketing anytime. You can complain to your local supervisory authority. We would rather fix it first — email hello@superseo.sh.
If you are in California or another US state with a privacy law: we do not sell personal information and we do not share it for cross-context behavioral advertising. You can ask what we have, ask us to delete it, and ask us not to sell or share it (we already do not). Authorized agents can write to the same address. We will not discriminate against you for exercising these rights. The product still has a price; that is not a penalty.
To use the rights: sign in and use Account → Delete, or email us from the address we have on file. We may need to verify it is you.
Children
SuperSEO.sh is for people running websites, not for children. We do not knowingly collect data from anyone under 16. If we learn we did, we delete it.
International transfers
We are a small team. Processors are in the US, EU, and other countries. When we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, plus the processor’s own transfer tools where they exist (for example a Data Privacy Framework certification).
Security
TLS in transit. Session cookies. OAuth tokens and API keys encrypted at rest. SSRF guards on outbound fetches so a scan cannot be pointed at internal network addresses. Rate limits on public scan and auth. Access to production data is limited to people who need it to run the product.
No method is perfect. If we learn of a breach that affects you, we will tell you and the regulators when the law requires it.
Changes
If we change this policy in a way that actually matters, we will update the date at the top and, for material changes, email the address on your account or post a note on the site. Continued use after the update means you accept the new policy. If you do not, delete the account and stop using SuperSEO.sh.
Contact
SilverArk Media · SuperSEO.sh
hello@superseo.sh
https://superseo.sh