SEORav · Legal
Privacy Policy
How SKB Business Service Ltd, trading as SEORav, collects, uses, stores, and protects personal data when you use seorav.com and the SEORav platform.
- Effective
- 2026-07-09
- Last updated
- 2026-07-09
- Version
- 1.2
SEORav is operated by SKB Business Service Ltd, a company registered in England & Wales (Companies House number 13879468) with registered office at 20 Wenlock Road, London, N1 7GU, United Kingdom.
1.1 Who we are and how to contact us
| Role | Contact |
|---|---|
| Data Controller | SKB Business Service Ltd, 20 Wenlock Road, London, N1 7GU, United Kingdom |
| Data Protection Officer | Rav, dpo@seorav.com |
| General privacy enquiries | privacy@seorav.com |
| EU Representative (Article 27 GDPR) | SEORav is in the process of formalizing the appointment of an EU Representative. EU residents may contact us at privacy@seorav.com in the interim. Updated representative details will be published here when finalized. |
1.2 What personal data we collect
Account data (when you sign up)
- Name and email address
- Password (stored as a salted hash; we never see your plaintext password)
- Google or Microsoft account identifier (if you sign in with Google or Microsoft: email, name, provider account ID)
- Company / organization name
- Website URL(s) you connect to SEORav
- Billing details (processed by Stripe — see Section 1.5)
Usage data (automatically collected)
- IP address and approximate location (city/country) derived from it
- Browser type, operating system, device type
- Pages viewed, features used, time spent on pages
- Referring URL (how you got to seorav.com)
- Session recordings — interactions with the dashboard (mouse movement, clicks, scroll behavior, visible content), captured via PostHog session replay. See Section 1.4 for how these are used and how to opt out.
Customer content (when you use the platform)
- URLs of websites you connect for crawling and analysis
- Content (articles, answer pages, briefs, prompts, voice fingerprints, social posts) you generate, edit, or store
- Images we generate for your articles, stored on a public content-delivery URL
- Connection credentials for the platforms you link — CMS, social accounts, and outreach mailboxes (OAuth tokens and scoped API keys, encrypted with AES-256-GCM at rest, with a customer-isolated encryption key)
- Pages we crawl from your own site and from the competitor and prospect sites you research
- Citation tracking results (which AI engines cite which of your articles)
Data about people who are not SEORav users
If you use the Authority module to build backlinks, SEORav helps you find and contact the people who run relevant websites. To do that we collect, from the public pages of those websites:
- Publicly listed contact email addresses, and where published, the name and job title attached to them
- Publicly listed social profile links for the site or its editorial team
- The page the information was found on, so its source is always traceable
We honour robots.txt, identify our crawler by name, and do not attempt to decode addresses that a site has deliberately protected. This data is held for the account that researched it, is used only to contact that person about a link, and is deleted when you delete the prospect or your account. You are the sender of any outreach email and control this data — see Section 2.10 of the Terms of Service. If you are a recipient and want your details removed from our systems, email privacy@seorav.com and we will remove them.
Communications data
- Email correspondence with our support team
- Feedback you submit through the platform
- Opens and clicks on outreach emails you send — we store a timestamp and a counter, never the recipient’s IP address, device, or location
1.3 Why we collect it (lawful bases)
We process personal data on the following lawful bases under Article 6 of UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Providing the Services you signed up for | Contract (Art. 6(1)(b)) |
| Processing payments and billing | Contract (Art. 6(1)(b)) |
| Account security, abuse prevention, fraud detection | Legitimate interests (Art. 6(1)(f)) |
| Finding and contacting website owners on behalf of a customer running outreach | Legitimate interests (Art. 6(1)(f)) — the customer is the sender and the controller of that correspondence |
| Product analytics and session replay (improvement) | Consent (Art. 6(1)(a)) — opt-in via cookie banner |
| Marketing emails to existing customers | Soft opt-in (PECR) / Legitimate interests |
| Marketing emails to prospects | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations (tax, accounting) | Legal obligation (Art. 6(1)(c)) |
1.4 How we use AI and what we do (and don’t) send to AI providers
SEORav uses AI to help generate content, score quality, extract brand voice, and track citations. Here’s exactly what happens to your data when AI is involved:
Anthropic (Claude API)
We use Anthropic’s Claude (Sonnet 4.6 and Haiku 4.5) for article outlines, drafts, optimization, AEO scoring on certain signals, and citation gap analysis. Anthropic does not train its models on data sent through their commercial API — this is contractually committed in Anthropic’s commercial terms. Content you generate through SEORav is not used to train any AI model.
Voyage AI (embeddings)
We use Voyage AI’s voyage-4-large model to convert your content into numerical “embeddings” used for keyword clustering, related-article matching, and semantic search over your own crawled content. Voyage processes content excerpts but does not retain or train on them.
Citation tracking
SEORav lets you check whether the major AI engines (ChatGPT, Perplexity, Claude, Gemini, Copilot, and Google’s AI Mode) cite your content for a given query. Scans run when you start one from your dashboard and on any recurring schedule you set up. Each scan is performed via Bright Data’s web infrastructure, which proxies our queries. The queries we send are generic, search-style prompts (e.g. “best CRM for startups,” “how to reduce SaaS churn”) — they are equivalent to what any user might type into the AI engine themselves. Citation responses are stored against your account so you can review them on subsequent visits.
Image generation
We generate the hero image for each article, and illustrations placed inside the article body, using Recraft. We send Recraft a prompt built from your article’s title, its section topics, and your brand colours. We do not send your article body, your account details, or any personal data. Finished images are stored on Cloudflare R2 and served from a public content-delivery URL, which means anyone with the link can view the image file. Google Gemini, Fal.ai, and Replicate are configured as standby providers and receive the same prompt text only if Recraft is unavailable.
The citation network
Where our system finds a relevant, already-published page belonging to another SEORav customer, it may cite and link to that page from an article we generate for you, and your published pages may be cited the same way. Only the published page’s public URL, its title, and an excerpt of its public text are involved — no account data, and nothing that is not already public on the web. Each site has a single setting that turns this off in both directions. See Section 2.7 of the Terms of Service.
We do not train our own models on your data
SEORav does not currently train any proprietary AI models, and we will not use customer content to train models without separate, explicit, written consent.
Session replay
We use PostHog session replay to record dashboard interactions for the purpose of debugging and product improvement. Session replays are tied to your account once you sign in. You can opt out of session replay (and all other PostHog analytics) by:
- Declining the analytics cookie category in our cookie banner, or
- Re-opening the banner at any time via the Cookie preferences link in the website footer, and withdrawing the analytics category
Text you type into form fields is masked before recording, and we do not record the contents of network requests. Session replays are stored for 30 days and then automatically deleted.
1.5 Who we share data with (sub-processors)
We use third-party service providers (“sub-processors”) to operate the Services. Each is bound by a data processing agreement that requires GDPR-compliant data handling. Our complete sub-processor list is published at seorav.com/legal/sub-processors. Key sub-processors include:
- Supabase (database, authentication, storage, edge functions, realtime) — EU (eu-west-2)
- Vercel (web app hosting and edge functions) — global edge network
- Hostinger (Python API server hosting on KVM 2 VPS) — UK datacentre
- Cloudflare (R2 storage and content delivery for generated images) — global
- Anthropic (Claude LLM API) — US-based, GDPR-compliant data processing
- Voyage AI (embeddings) — US-based
- Recraft (image generation) — US-based, prompt text only
- Stripe (payment processing and Customer Portal) — UK / US
- Serper and DataForSEO (search, keyword, and backlink data) — US-based
- Bright Data (citation polling proxy + page-fetch fallback) — global
- PostHog (product analytics + session replay) — EU instance (eu.i.posthog.com)
- Google LLC (sign-in, Google Trends, Google Analytics, and the Gmail API when you connect a Gmail mailbox for outreach) — US-based
- Microsoft Corporation (sign-in, and the Graph API when you connect an Outlook mailbox for outreach) — US / EU
We will give you 30 days’ notice via the sub-processor list page (and email if you have an active account) before adding a new sub-processor that materially affects how we process your data.
1.6 International data transfers
Some of our sub-processors are based outside the UK and EEA (notably Anthropic, Voyage AI, Recraft, Serper, DataForSEO, Bright Data, the Stripe US entity, Vercel, Cloudflare, Google, Microsoft, and PostHog’s underlying infrastructure). When data is transferred outside the UK / EEA, we ensure protection through one or both of:
- Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner’s Office
- UK International Data Transfer Agreements (IDTA) with US-based providers
You can request a copy of the transfer mechanisms in place by emailing privacy@seorav.com.
1.7 How long we keep your data
| Data type | Retention period |
|---|---|
| Account data (email, name, profile) | For the duration of your account; deleted within 30 days of account closure |
| Customer content (articles, voice profiles) | For the duration of your account; deleted within 30 days of cancellation |
| Crawled page snapshots | 90 days rolling |
| Citation responses (raw) | 180 days rolling |
| AI usage / cost telemetry | 365 days |
| Session recordings (PostHog) | 30 days |
| Stripe webhook event log | 90 days, then purged |
| Billing records (subscriptions, invoices) | 7 years (UK tax law requirement) |
| Webhook delivery audit log | 90 days rolling |
| Encrypted CMS, social, and mailbox credentials | Until you disconnect the connection or delete your account |
| Generated images on the public content-delivery URL | For the duration of your account; removed when the article or account is deleted |
| Prospect contact details and outreach history | Until you delete the prospect, or within 30 days of account closure |
| Support correspondence | 3 years |
1.8 Your rights under UK and EU GDPR
- Right of access. You can request a copy of the personal data we hold about you. You can also self-serve by exporting articles as Markdown from your dashboard; for a complete data export, email us.
- Right to rectification. You can correct inaccurate data through your account settings or by emailing us.
- Right to erasure (“right to be forgotten”). Cancel your subscription to start a 30-day grace period, after which all your data is hard-deleted. Some financial records are retained 7 years per UK tax law.
- Right to restrict processing. Pausing your subscription via the Stripe Customer Portal stops AI processing while leaving your data intact.
- Right to data portability. Markdown export covers article content. JSON export of metadata is available on request.
- Right to object. You can object to processing based on legitimate interests, including marketing.
- Right to withdraw consent. Where we rely on consent (analytics, marketing emails), you can withdraw it through the cookie banner, account settings, or by emailing us.
- Right to lodge a complaint. You can complain to the UK Information Commissioner’s Office (ico.org.uk) or your local EU data protection authority.
To exercise any of these rights, email privacy@seorav.com. We will respond within 30 days.
1.9 Cookies and similar technologies
We use cookies and similar technologies on seorav.com. Detailed information about which cookies we use, their purpose, and how to manage them is in our Cookie Policy.
1.10 Security
We protect your data using:
- Encryption in transit: TLS 1.3 for all connections
- Encryption at rest: All Supabase Postgres data and Storage objects encrypted at rest
- CMS credentials: Stored using AES-256-GCM authenticated encryption with customer-isolated encryption keys — no shared encryption keys between customers
- Authentication: OAuth 2.0 or scoped API tokens for all third-party integrations (we never store your CMS passwords)
- Credential isolation: Connection credentials are decrypted only inside our API server and are never sent to your browser
- Multi-tenant isolation: Postgres Row-Level Security (RLS) policies prevent cross-customer data access; RLS coverage is reviewed and hardened on every schema change as part of our standard migration process.
- Access control: Role-based access controls within our team, principle of least privilege
- Monitoring: Server-side error logging and regular dependency vulnerability scans
- Incident response: Documented breach response plan with 72-hour assessment process
If we discover a personal data breach that is likely to result in a risk to data subjects’ rights and freedoms, we will notify the UK Information Commissioner’s Office within 72 hours of becoming aware, in accordance with Article 33 UK GDPR. Affected users will be notified without undue delay where required by Article 34.
1.11 Children’s data
SEORav is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe we have, please contact us at privacy@seorav.com and we will delete it.
1.12 Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when changes were made. For material changes, we will email registered users at least 30 days before the changes take effect.
1.13 California residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect, use, disclose, and sell
- The right to delete your personal information (with some exceptions)
- The right to opt out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your CCPA rights
To exercise these rights, email privacy@seorav.com.
1.14 Contact
| Channel | Address |
|---|---|
| privacy@seorav.com · dpo@seorav.com | |
| Post | Data Protection Officer, SKB Business Service Ltd, 20 Wenlock Road, London, N1 7GU, United Kingdom |
| Regulatory complaints | Information Commissioner’s Office (ICO) — ico.org.uk · 0303 123 1113 |