Privacy Policy

Last Updated: January 13, 2025

At SerpaxAI ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI visibility and SEO intelligence platform (the "Service").

By accessing or using SerpaxAI, you agree to this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: When you create an account, we collect your email address, name, company name, job title, phone number (optional), and password.
  • Website and Property Data: URLs, domains, and website properties you choose to monitor and track.
  • API Keys: Third-party API keys you provide for integrations (OpenAI, Google, Anthropic, Perplexity, etc.). These are encrypted at rest using industry-standard encryption.
  • Payment Information: Billing details processed through our secure payment processor. We do not store complete credit card numbers on our servers.
  • Communication Data: Information you provide when contacting our support team or responding to surveys.

1.2 Information Collected Automatically

  • Usage Data: Information about how you interact with our Service, including features used, pages visited, and actions taken.
  • Device Information: Browser type, operating system, device identifiers, and IP address.
  • Cookies and Tracking: We use cookies and similar technologies to maintain your session, remember preferences, and improve your experience.
  • Analytics Data: Aggregated data about Service performance and usage patterns.

1.3 Information from Third-Party Services

  • Google Search Console: When you connect your Google Search Console account, we access search performance data, indexing status, and keyword rankings for your connected properties.
  • Social Media Platforms: When you connect social media accounts (LinkedIn, Twitter/X, Facebook, Instagram), we access publishing capabilities and analytics data you authorize.
  • Advertising Platforms: When you connect Google Ads or Meta Ads accounts, we access campaign performance data and metrics.

2. How We Use Your Information

We use the information we collect to:

  • Provide and Improve Services: Deliver SEO analysis, AI visibility tracking, keyword rankings, backlink monitoring, and other core features.
  • Generate Insights: Create AI-powered recommendations, content briefs, and optimization suggestions.
  • Send Alerts and Notifications: Notify you about ranking changes, visibility updates, and important events.
  • Process Transactions: Handle subscription payments, billing, and account management.
  • Communicate: Send service updates, security alerts, and respond to your inquiries.
  • Analyze and Improve: Understand usage patterns to enhance our Service and develop new features.
  • Ensure Security: Detect, prevent, and address technical issues, fraud, and security threats.
  • Comply with Legal Obligations: Meet legal requirements and respond to lawful requests from authorities.

3. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We work with trusted third-party providers who assist in operating our Service (cloud hosting, payment processing, email delivery). These providers are contractually obligated to protect your data.
  • AI Model Providers: When you use AI features, relevant data may be sent to AI providers (OpenAI, Anthropic, Google, Perplexity) according to their privacy policies. We only send necessary data for generating insights.
  • Legal Requirements: We may disclose information if required by law, subpoena, or government request, or to protect our rights, safety, or property.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity.
  • With Your Consent: We may share information for other purposes with your explicit consent.

4. Data Security

We implement comprehensive security measures to protect your data:

  • Encryption: All API keys and sensitive credentials are encrypted at rest using AES-256 encryption. Data in transit is protected using TLS 1.3.
  • Authentication: We support two-factor authentication (2FA/MFA) using TOTP-based authenticator apps.
  • Access Controls: Strict role-based access controls limit data access to authorized personnel only.
  • Infrastructure Security: Our infrastructure is hosted on secure cloud providers with SOC 2 compliance.
  • Regular Audits: We conduct regular security assessments and vulnerability testing.
  • Incident Response: We maintain incident response procedures and will notify affected users of any data breach as required by law.

5. Data Retention

We retain your information for as long as necessary to provide our Services and fulfill the purposes described in this policy:

  • Account Data: Retained while your account is active and for a reasonable period after account deletion to comply with legal obligations.
  • Usage Analytics: Aggregated analytics data may be retained indefinitely in anonymized form.
  • Historical SEO Data: Crawl history and SEO metrics are retained to provide trend analysis and historical comparisons.
  • Billing Records: Financial records are retained as required by tax and accounting laws.

6. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and personal data, subject to legal retention requirements.
  • Data Portability: Request your data in a machine-readable format.
  • Opt-Out: Unsubscribe from marketing communications at any time.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
  • Object: Object to certain types of data processing.

To exercise these rights, please contact us at privacy@serpaxai.com or through your account settings.

7. International Data Transfers

Our Service is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using our Service, you consent to such transfers. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy.

8. Third-Party Services and Links

Our Service integrates with and may contain links to third-party services. These services have their own privacy policies:

  • Google: Google Search Console, Google Ads, Google Analytics
  • Meta: Facebook, Instagram advertising
  • AI Providers: OpenAI, Anthropic, Google AI, Perplexity
  • Social Platforms: LinkedIn, Twitter/X

We encourage you to review the privacy policies of any third-party services you connect to SerpaxAI.

9. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@serpaxai.com, and we will take steps to delete such information.

10. GDPR Compliance (European Economic Area Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on: (a) your consent, (b) performance of our contract with you, (c) our legitimate business interests, or (d) legal obligations.
  • Data Protection Officer: For GDPR-related inquiries, contact our privacy team at privacy@serpaxai.com.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.

11. CCPA Compliance (California Users)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to Know: You may request information about the categories and specific pieces of personal information we have collected.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
  • Do Not Sell: We do not sell personal information as defined under the CCPA.

To exercise your CCPA rights, contact us at privacy@serpaxai.com.

12. Cookie Policy

We use cookies and similar tracking technologies:

  • Essential Cookies: Required for basic functionality, authentication, and security.
  • Functional Cookies: Remember your preferences and settings.
  • Analytics Cookies: Help us understand how you use our Service to improve it.

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect Service functionality.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification. We encourage you to review this Privacy Policy periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: