Legal
Last updated: July 25, 2026
This Privacy Policy explains what data SEOEdgeAI ("we", "us") collects when you use the seoedgeai.com website and dashboard, the Cloudflare Worker and edge proxy, the AI agent, and the blog engine it runs on your behalf (together, the "Service"), why, for how long, and what control you have over it. SEOEdgeAI is operated from France by Jourdelune, a private individual who publishes under that name. We have not appointed a Data Protection Officer; the single contact point for any privacy question or request is [email protected]. Where a Service you connect (your own website) belongs to you, you and SEOEdgeAI each act as an independent data controller for your own part: we control the account, dashboard and agent data described below; you control what your own site publishes and how you use the traffic and ranking data we surface to you.
There is no SEOEdgeAI password: you sign in exclusively through Google OAuth. That grants us your Google account id, name, email address and profile picture, which we store to identify your account and personalise the dashboard. The same consent screen offers read-only access to Google Search Console (the "webmasters.readonly" scope) so the agent can read your rankings, clicks, impressions and per-page position — it is a checkbox you can decline, and declining still lets you use the rest of the Service. We store the access and refresh tokens Google issues, and the exact scopes you granted, so we can call the Search Console API on your behalf later; we never see or store your Google password. You can revoke this access at any time from your Google Account's "Third-party apps & services" settings, which immediately stops us from reading anything further.
Deploying the Worker with one click (instead of pasting it yourself) requires connecting your Cloudflare account, also via OAuth. That grants a token scoped narrowly to reading your zones and reading/writing Workers scripts and routes — nothing else on your Cloudflare account. We store that access token (and a refresh token, when Cloudflare issues one) only to deploy, update or remove the Worker you asked for. You can disconnect Cloudflare at any time from the Account page in your dashboard, which deletes the stored tokens, or revoke it directly from Cloudflare's own "Authorized Applications" settings. Connecting Cloudflare is optional: you can instead paste the Worker snippet yourself, or add one nginx directive if you run your own reverse proxy.
For every site you connect we store its name, public hostname, origin URL, the internal token the Worker uses to authenticate to our proxy, your blog path, the crawler-only toggle, your four agent permission switches, and the free-text objective you give the agent. This is the configuration data the proxy and the agent need to operate your site; it exists for as long as the site is connected and is deleted, together with the deployed Worker, when you remove the site.
To do its job the agent reads your site's pages (their current titles, meta descriptions and structured data), your Search Console performance, and — if you enable analytics — your Umami visitor stats; from that it decides new titles, meta descriptions, JSON-LD, and, on the schedule and volume you choose, new blog articles and small tools ("mini-apps"), which we store and serve at the edge or through your managed WordPress subsite. Every run's transcript (the tool calls it made, what it decided, and the token cost) is stored so the "watch it work" viewer in your dashboard can replay it, and so the agent can look back at what it tried before deciding what to try next. Turning a permission off in the dashboard stops the corresponding tool from working, not just from being suggested.
Each agent run happens in an isolated, single-use sandbox. The page content, stats and instructions it needs are sent to the language model we use through OpenRouter (currently models such as DeepSeek and MiniMax); that provider processes the request and returns a result, and we do not use your data to train any model. When the agent needs to research a topic for an article, it queries our own self-hosted SearXNG metasearch instance rather than a third-party search API, so no outside search provider learns what your business is researching. Images used in articles are sourced with their licence recorded alongside them.
Search Console metrics (impressions, clicks, click-through rate and average position, per page and per day) are pulled on a schedule using the token described above and stored so the agent's before/after comparisons and your dashboard charts work without re-querying Google constantly. If you enable analytics for a site, we register it with our own self-hosted Umami instance, which records aggregate, cookieless visitor metrics for that site — pageviews, visitor counts and referrers — used to feed the agent's stats and your dashboard. Umami does not use cookies and does not build cross-site profiles of your visitors.
SEOEdgeAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: the Search Console data we receive is used only to power features you can see in your dashboard — the agent's decisions about your pages, its before/after comparisons, and your charts. We do not sell it, we do not use it for advertising or credit decisions, and we do not use it to train any AI model. No one on our side reads it except where necessary to investigate a bug or abuse, to comply with the law, or where you have explicitly asked us to look at something.
We do not set our own cookies to keep you signed in: after Google sign-in, the dashboard issues a bearer token that your browser stores in local storage, not a cookie. seoedgeai.com itself is delivered through Cloudflare, which may set a small number of strictly necessary technical/security cookies (for example bot-management) as part of serving the site — these are Cloudflare's own operational cookies, not ours, and we do not use them for tracking. We do not use advertising or cross-site tracking cookies, and our own website carries no third-party analytics script.
We never sell your data. We share it only with the providers that make the Service work, each acting on our instructions: Google (sign-in and Search Console), Cloudflare (Worker deployment and, for our own website, edge delivery), OpenRouter and the model providers it routes requests to (AI processing, described above), and OVH, our infrastructure host. We do not share your data with anyone for their own marketing.
Our own infrastructure runs in the European Union, at OVH (2 rue Kellermann, 59100 Roubaix, France). Some processors we rely on — Google, Cloudflare and OpenRouter — are based in or operate infrastructure in the United States, so a limited amount of data (the categories described above) may be transferred there. Where that happens, we rely on that provider's EU–US Data Privacy Framework certification or on the European Commission's Standard Contractual Clauses; we can provide the relevant documentation on request.
Account, site configuration, agent run history and content data are kept for as long as your account and the relevant site stay connected, because the agent's whole approach depends on remembering what it already tried. Removing a site deletes its configuration, its deployed Worker and its stored history within a reasonable period; deleting your account removes all of it, across every site, the same way. Search Console and analytics figures are kept on the same basis — they exist to power historical charts, so they are deleted together with the site rather than on their own separate timer.
You can access, correct, export or delete your data at any time. The Account page in your dashboard (open it from your profile menu) lets you see exactly what we hold — your Google connection, your Cloudflare connection, and every site you have added — and delete any of it yourself: disconnecting Cloudflare removes the stored tokens, removing a site deletes its data and tears down its deployed Cloudflare Worker, and deleting your account does all of that for every site at once and then removes your account itself. You can also exercise any right the GDPR and the French Data Protection Act of 6 January 1978 (as amended) give you — access, rectification, erasure, portability, restriction or objection — by writing to [email protected]; we will act on it within a reasonable period. You may also lodge a complaint with the CNIL (cnil.fr) or, if you are in another EU country, your own national data-protection authority.
OAuth tokens and other secrets are stored on infrastructure we control, with access restricted to operating the Service. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify affected users and, where required, the competent supervisory authority.
The Service is not directed at children and requires a Google account, which already carries its own minimum-age requirements. We do not knowingly collect data from a child below the applicable age; if you believe a child is using the Service, contact us and we will remove the data.
We may update this Privacy Policy as the Service evolves. The "Last updated" date at the top reflects the latest version; material changes will be communicated through the dashboard or by email.
Questions about this policy, or any data request, can be sent to [email protected].