Privacy Policy
What personal data Seopotion collects, why, on what legal basis, who we share it with, how long we keep it, and the GDPR rights you can exercise.
- Effective
- July 29, 2026
- Last updated
- July 29, 2026
This notice explains what personal data Seopotion collects, why, on what legal basis, who we share it with, and what rights you have. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), which applies to us under Article 3(2) because we offer the Service to people in the European Union, and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), which applies to us as a data controller established in Türkiye.
1. Who is responsible for your data
The controller — the veri sorumlusu under the KVKK — of the personal data described in this notice is:
- Deniz Yazagan, sole trader, trading as "Seopotion"
- Address: Bengi Sokak 8/1, Erenköy, Kadıköy, Istanbul, Türkiye
- Email: support@seopotion.co
Seopotion is operated as a sole proprietorship, so the controller is Deniz Yazagan personally, trading under the name Seopotion.
Data protection officer: none appointed. Seopotion does not carry out the large-scale regular and systematic monitoring, or large-scale processing of special-category data, that would require a data protection officer under Article 37 GDPR. Privacy enquiries go to support@seopotion.co.
2. Controller and processor roles
We handle two different categories of data, and our role differs between them.
We are the controller of data about you as a user and customer: your account and profile data, your subscription and billing records, your support correspondence, and technical logs about how you use the Service.
We are a processor for content and data you connect to a workspace and that we process on your instructions — for example, personal data appearing in your website's pages, in content you ask us to generate or publish, or in your Google Search Console data. There, you are the controller, and our processing is governed by the processor commitments in the Terms of Service, clause 12, which you can also request as a separate signed Data Processing Agreement. This notice describes that processing for transparency, but your own privacy notice governs it toward your users.
3. What data we collect
3.1 Account and identity data
Seopotion accounts are created only through Google Sign-In. When you sign in, Google returns and we store:
- your Google account identifier (
sub), - your email address,
- your name, where Google provides it.
We never receive or store your Google password.
3.2 Workspace and website data
- the website URL you connect;
- content retrieved from your website when we scan it, and the business profile derived from it — business name, language, country, description, target audience, competitors, blog and sitemap locations, sample articles;
- your content preferences: article style, tone, internal linking rules, instructions you write for the AI, image style;
- onboarding metadata, such as how you heard about us and which publishing platforms you selected.
Scanned website content may itself contain personal data (author names, contact details, team pages). We process it as described in clause 2.
3.3 Integration data and credentials
- Google Search Console: where you connect it, we store an OAuth refresh token
encrypted with AES-256-GCM, the Google account email used, and the property you
selected. We use the token to read your search performance data (queries, clicks,
impressions, positions, pages) with the read-only
webmasters.readonlyscope. - Publishing integrations (e.g. WordPress): we store the access token or application password needed to publish, together with the connection timestamp.
3.4 Content and usage data
Keywords and content plans, generated articles and their revisions, generated images, video suggestions, publication status, quota consumption, and feature usage.
3.5 Billing data
Purchases are processed by Lemon Squeezy, our merchant of record. Lemon Squeezy collects your payment details directly — we never receive or store your card number. We store only: your subscription identifier and customer identifier at the provider, the plan and tier, subscription status, and the current billing period end date.
3.6 Technical and log data
IP address, browser and device information, request timestamps, endpoints called, error traces and performance metrics, collected by our infrastructure and application logs.
3.7 Support and marketing data
The content of emails and support requests you send us, and — where you have opted in — your subscription to product or marketing emails.
3.8 Cookies and local storage
The Seopotion application stores your session token (a JSON Web Token) and workspace state in your browser's local storage. This is strictly necessary to keep you signed in, and is not used for tracking or advertising.
We use no analytics or advertising cookies, and we embed no third-party tracking or advertising scripts. Because everything we store on your device is strictly necessary to deliver the service you asked for, no consent banner is required. If we ever introduce a non-essential cookie or similar technology, this section will list it with its purpose and duration, and we will ask for your consent before setting it.
4. Why we use your data, and our legal basis
| What we do | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Create and authenticate your account | 3.1 | Contract — Art. 6(1)(b) |
| Provide the Service: scan your site, research keywords, generate and publish content | 3.2, 3.3, 3.4 | Contract — Art. 6(1)(b) |
| Read Google Search Console performance data | 3.3 | Contract — Art. 6(1)(b), after your explicit OAuth authorisation |
| Take payment, manage subscriptions, invoicing | 3.1, 3.5 | Contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c) |
| Provide support | 3.1, 3.7 | Contract — Art. 6(1)(b) |
| Keep the Service secure, prevent abuse and fraud, enforce limits | 3.6 | Legitimate interests — Art. 6(1)(f): protecting the Service and its users |
| Debug, monitor and improve reliability | 3.4, 3.6 | Legitimate interests — Art. 6(1)(f): a working, reliable product |
| Aggregate, de-identified product analytics | derived from 3.4, 3.6 | Legitimate interests — Art. 6(1)(f) |
| Send service and transactional emails (billing, security, changes to terms) | 3.1 | Contract — Art. 6(1)(b) |
| Send product or marketing emails | 3.1, 3.7 | Consent — Art. 6(1)(a), withdrawable at any time; or legitimate interests for existing customers where national law permits |
| Comply with legal requests, accounting and tax duties | as required | Legal obligation — Art. 6(1)(c) |
| Establish, exercise or defend legal claims | as required | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You can ask for details of that assessment, and you can object — see clause 9.
We do not sell personal data, and we do not use your Customer Content or generated Output to train our own or any third party's AI models.
5. AI processing and automated decision-making
Generating content sends your instructions, business profile and related context to third-party AI providers (clause 6). We instruct providers not to use that data for training where their terms allow, and we select providers whose API terms exclude training on API inputs by default.
We do not carry out automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. Content generation is automated, but it produces suggestions you review and control.
6. Who we share data with
We share data only with the providers below, all of whom are bound by contract to process it only on our instructions and to protect it appropriately.
| Recipient | Purpose | Data shared | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, compute, queues, secrets | All categories, at rest and in transit | EU — Frankfurt (eu-central-1) |
| MongoDB Atlas | Database hosting | 3.1–3.5 | EU — Frankfurt |
| OpenRouter | Access to LLMs for content generation | Prompts, business profile, content context | US / model provider regions |
| fal.ai | AI image generation | Image prompts derived from your content | US |
| DataForSEO | Keyword, SERP and ranking data | Keywords, domain, country/language | US |
| Google (Sign-In, Search Console, YouTube) | Authentication, search performance, video suggestions | 3.1, 3.3, site/property identifiers | Global |
| Lemon Squeezy | Payments as merchant of record, invoicing, tax | Email, billing details you enter, subscription data | US / EU |
| Your connected CMS (e.g. WordPress) | Publishing content you approve | Generated content and images | Your own hosting |
We may also disclose data: to professional advisers under duty of confidence; to authorities where legally required, after checking the request is valid and proportionate; and to an acquirer in a merger, acquisition or asset sale, in which case we will notify you before your data becomes subject to a different privacy notice.
7. Google user data — Limited Use
Seopotion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We request the minimum scopes needed:
openidandemailfor sign-in, andhttps://www.googleapis.com/auth/webmasters.readonlyto read Search Console performance data. The Search Console scope is read-only — we cannot change anything in your Google account. - We use Google user data only to provide and improve the user-facing features you asked for.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
- We do not use Google user data for advertising, and we do not allow humans to read it, except with your explicit consent for specific messages, for security or abuse investigation, to comply with law, or on aggregated, anonymised data for internal operations.
You can revoke our access at any time by disconnecting the integration in Seopotion settings or at myaccount.google.com/permissions. When you disconnect, we delete the stored refresh token.
8. International transfers
Your data is stored in the European Union — our infrastructure and database both run in Frankfurt. Two kinds of transfer out of the EEA still happen, and we are explicit about both:
- To us, in Türkiye. We administer the Service from Istanbul, so our own staff access EU-hosted data from a country with no European Commission adequacy decision.
- To providers in the United States — the AI, SERP-data and payment providers listed in clause 6.
For both, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with supplementary technical measures including encryption in transit and at rest and least-privilege access; and, where the recipient is certified, on the EU-US Data Privacy Framework adequacy decision.
Transfers of personal data out of Türkiye are made on the bases permitted by Article 9 of the KVKK — your explicit consent, or a standard contract or undertaking notified to the Turkish Personal Data Protection Authority, as applicable to the recipient.
You may request a copy of the safeguards in place by emailing support@seopotion.co.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), where the conditions apply;
- restrict processing in certain circumstances;
- data portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, including profiling — we will stop unless we can show compelling legitimate grounds; and to object at any time and absolutely to direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- not be subject to a decision based solely on automated processing producing legal or similarly significant effects (see clause 5); and
- lodge a complaint with a supervisory authority. We are established in Türkiye and have no establishment in the European Union, so there is no single lead supervisory authority for us under the GDPR's one-stop-shop mechanism. If you are in the EU or EEA, complain to the supervisory authority of the member state of your habitual residence, your place of work, or where the alleged infringement occurred. If you are in Türkiye, apply to us first under Article 13 of the KVKK, and then to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) at kvkk.gov.tr if you are not satisfied with our response or do not receive one within 30 days.
To exercise any right, email support@seopotion.co. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free; we may charge a reasonable fee or refuse where a request is manifestly unfounded or excessive. We may ask for information to verify your identity.
Some rights can be exercised directly in the application: you can edit your business profile and content settings, disconnect integrations, and request account deletion by contacting support.
10. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted 30 days after closure |
| Workspace, website profile, content settings | For the life of the workspace, then as above |
| Generated content and content plans | For the life of the workspace, then as above |
| Integration tokens (GSC, CMS) | Until you disconnect the integration or close the account, then deleted immediately |
| Subscription and billing records | 10 years from the transaction, to meet accounting and tax obligations |
| Support correspondence | 24 months from the last message |
| Application and security logs | 90 days |
| Backups | Overwritten on a rolling 35-day cycle |
After these periods, data is deleted or irreversibly anonymised. Aggregated, de-identified statistics that cannot be linked to you may be kept indefinitely.
11. Security
We apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for all data in transit;
- encryption at rest for stored data, and AES-256-GCM encryption for OAuth refresh tokens specifically;
- authentication via Google, with short-lived signed session tokens; signing secrets stored
in AWS Systems Manager Parameter Store as encrypted
SecureStringvalues, never in code; - least-privilege access controls, with production data accessible only to personnel who need it;
- network isolation, dependency and vulnerability monitoring, and audit logging of administrative actions.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.
12. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@seopotion.co and we will delete it.
13. Changes to this notice
We may update this notice. Material changes will be announced by email or in-app notice at least 30 days before they take effect, unless a change must take effect sooner for legal reasons. The current version, with its effective date, is always at seopotion.co/privacy.
14. Contact
- Deniz Yazagan, sole trader, trading as "Seopotion"
- Address: Bengi Sokak 8/1, Erenköy, Kadıköy, Istanbul, Türkiye
- Privacy enquiries and rights requests: support@seopotion.co
- Data protection officer: none appointed — see clause 1