Privacy Policy
Last updated: September 30, 2026
ZenSEO operates the service at https://zenseo.app. This privacy policy explains how ZenSEO handles information when you use the service.
Information we process
- Account information supplied through email, GitHub, or Google sign-in, including your name, email address, profile image when provided, and account identifiers. Authentication records may also include your IP address, browser user agent, session identifiers, and verification records.
- Google OAuth credentials associated with your connected Google account. Additional Search Console and indexing permissions are requested when you connect Search Console properties. These credentials let us list those properties, read sitemap declarations, and call the Google Indexing API when you enable it.
- Optional Google service-account credentials. These are validated against the selected Search Console property and encrypted before storage using AES-256-GCM.
- Optional IndexNow keys and public key-file locations, along with verification timestamps.
- Connected Search Console properties, permission levels, sitemap URLs, indexing settings, and run history. Run history includes timestamps, trigger, status, URL counts, provider results, and sanitized errors.
- Organization membership and access records used to authorize shared sites.
- Public sitemaps, discovered URLs, modification timestamps when supplied, and per-URL notification state used to avoid duplicate submissions.
- Product analytics and technical diagnostics, such as page URLs, referrers, page interactions, browser and device information, performance measurements, IP-derived metadata, and application errors, when the relevant services are enabled. PostHog may also capture session replays if recording is enabled in the project settings.
We do not request payment information for the free service. We do not sell personal information.
How we use information
We use this information to authenticate you, authorize site access, synchronize Search Console properties, discover sitemap URLs, run configured indexing workflows, secure and troubleshoot the service, and understand product usage. When configured, we also send internal signup notifications to help operate the service.
Cookies and browser storage
We use authentication cookies to maintain your signed-in session. When PostHog is configured, its analytics uses cookies and browser storage to associate interactions with a browser and session. Vercel Web Analytics and Speed Insights collect usage and performance measurements without using cookies. You can restrict cookies or clear browser storage in your browser settings, although restricting authentication cookies may prevent sign-in.
Third-party services
ZenSEO uses the following third-party services for the features you use:
- Google and GitHub for account sign-in, and Google Search Console and the Google Indexing API for connected-site features.
- Convex for backend storage and processing, and Vercel for hosting, Web Analytics, and Speed Insights.
- PostHog for product analytics, error tracking, and session replay when configured and enabled.
- Slack for internal signup notifications when a webhook is configured. These notifications include your name, email address, account identifiers, and signup timestamp.
- Public sitemap and IndexNow key-file URLs associated with your sites, and IndexNow endpoints for configured search-engine notifications.
Third-party handling is governed by the applicable provider terms and privacy policies. Google's requirements for handling API data are described in the Google API Services User Data Policy. Google documents its Indexing API for pages containing JobPosting or BroadcastEvent structured data; enabling the integration does not establish that a URL is eligible. Submission does not guarantee crawling, indexing, traffic, or ranking.
Storage and retention
ZenGrow's retired content features may have left legacy records in existing deployments, including uploaded or fetched source text, research results, article briefs and drafts, revisions, publication records, and API-key hashes. Retiring those features and removing their database schema definitions does not automatically delete these records. They are no longer used for new content research, generation, or publication and remain subject to access controls and the deletion-request process below until removed. External providers may retain data previously sent to them under their own policies; the retired features used DataForSEO for keyword and search-result research and Vercel AI Gateway and its model providers for content processing.
Service-account credentials are encrypted at rest, and OAuth tokens are encrypted by the authentication service. Account records, site configuration, sitemaps, and per-URL notification state are stored until removed through a supported deletion process. Removing a site archives it and stops its indexing workflows; it does not automatically erase its stored credentials, discovered URLs, or associated records. Completed indexing-run history is scheduled for deletion after 90 days through a daily cleanup job; cleanup backlogs may delay removal. Security, legal, and dispute records may be retained longer where required. Retention by third-party services is also subject to their applicable policies and settings.
Your choices and deletion requests
You can disable an indexing engine, remove a service account, remove an IndexNow key, or revoke Google authorization through your Google account settings. Revoking authorization stops future authorized access but does not automatically delete information already stored by ZenSEO. To request account or associated data deletion, email support@zenseo.app. We may need to verify your identity and your authority over shared site data before completing a request.
Security and changes
No service can guarantee absolute security. We use access controls, authorization checks, encryption for service-account credentials, secret redaction, and limited retention to reduce risk. We may update this policy as the service changes and will post the revised date here.
Questions or privacy requests can be sent to support@zenseo.app.