SEO Studio

SEO Studio

Privacy Policy

Effective July 17, 2026 · SEO Studio is operated by Thencan Designs (“we”, “us”).

SEO Studio is a workspace where marketing agencies plan, research, and track SEO work for their clients. This policy explains what information the product handles, why, and the control you have over it. The short version: your workspace’s data belongs to your workspace, we don’t sell it, and connections to outside services are read with the narrowest access that makes the product work.

1. Information we collect

  • Account information — your email address and, if you sign in with Google, the name and email on that Google account.
  • Workspace content — the clients, sitemaps, keywords, notes, research results, and settings you and your teammates create in the product.
  • Integration credentials — when a workspace owner connects a service (Google, ClickUp, Notion, Slack, Semrush), we store the access credential for that connection encrypted (AES-256-GCM) on our servers. Credentials are readable only by our server processes, never by other users and never in the browser.
  • Data from connected services — see section 5 for Google specifically. For project-management tools (ClickUp, Notion) we read and write the tasks your workspace chooses to sync; for Slack we send the notifications you configure; for SEO data providers we retrieve rankings and keyword metrics for the clients you set up.
  • Usage and log data — standard server logs (requests, timestamps, errors) used to operate and debug the service.

2. How we use information

Only to provide and improve the product: showing your workspace its own data, running the research and tracking features you invoke, sending the notifications you configure, and keeping the service secure and reliable. We do not sell personal information, we do not share workspace data across workspaces, and we do not use your data for advertising.

3. Where data lives

Application data is stored in a managed Postgres database (Supabase) with row-level security isolating each workspace, and the application is hosted on Vercel. Service providers that process data on our behalf: Supabase (database and authentication), Vercel (hosting), and the providers your workspace explicitly connects (Google, ClickUp, Notion, Slack, Semrush, DataForSEO for keyword data, GitHub for feedback tickets). Each receives only what its integration requires.

4. Sharing within and outside your workspace

Teammates you invite to a workspace see that workspace’s data. Client-facing share links show a read-only view of a single plan; they expose only the fields marked public, can be revoked at any time, and never expose credentials or other clients.

5. Google user data (Search Console & Analytics)

When a workspace owner connects Google, we request read-only access to Google Search Console (webmasters.readonly) and Google Analytics (analytics.readonly). We use this access solely to retrieve search performance data (clicks, impressions, click-through rate, positions, queries and pages) and analytics data (sessions, conversions) for the website properties your workspace explicitly maps to its clients, and to display that data and derived insights inside the product to members of that workspace. We store retrieved metrics in your workspace’s database records, and the Google refresh token encrypted as described above. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your permission for support, for security investigation, or where required by law.

SEO Studio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google at any time from the Integrations screen (which deletes the stored credential and stops all retrieval), and you can also revoke SEO Studio’s access from your Google Account permissions.

6. Retention and deletion

Data is kept while your account and workspace exist. Deletions in the product are hard deletes — removing a client, connection, or workspace removes its records rather than hiding them. You can delete your account from the workspace settings screen, which removes your account data; workspace data you created remains with the workspace it belongs to. Backups age out on our database provider’s standard schedule.

7. Cookies

We use cookies only to keep you signed in and to remember in-app preferences. No advertising or cross-site tracking cookies.

8. Security

All traffic is encrypted in transit (HTTPS). Integration credentials are encrypted at rest with keys held outside the database. Workspace isolation is enforced at the database row level. No method of storage is perfectly secure, but access to production systems is limited to the people who operate the service.

9. Children

SEO Studio is a business tool and is not directed at children under 16.

10. Changes and contact

We’ll update this page when the policy changes and note the new effective date above. Questions or requests (including data export or deletion): sam@thencandesigns.com.

Terms of Service · Sign in