What does SeeGeo actually collect?
Three kinds of data, and it's worth separating them because they behave differently.
What you type. The domain you submit for an audit. If you create a project, also the business name, category, optional location, and any competitor names you enter. Each audit also records an approximate country and city (from our hosting provider's geolocation header — never your IP address, the same rule as the rate limit below), so we can see where interest in the tool comes from.
If you contact us about the done-for-you service. The request form asks for your name, email, and website, plus an optional phone number and message — all of it provided by you, used only to reply and scope the work. With that request we also record your approximate country and city (from our hosting provider's geolocation header — never your IP address itself, the same rule as the rate limit below) and a coarse device description ("iPhone · Safari"), so we have context for the conversation. Ask us to delete a request and we will.
When you first arrive, we note which channel introduced you: the campaign
tags on the link, if any (the utm_source, utm_medium, utm_campaign and
utm_content parameters advertisers add); otherwise the domain of the site
that sent you (for example "google.com" — the domain only, never the page
address or your search); and, if you came from an ad, the name of the ad
network's click parameter (for example "gclid" — the name only, never its
value). We keep this in a cookie for 30 days and record it with any audit you
run or request you send. It describes a channel, never anything about you. A
visit with no tags and no referring site sets nothing.
Your email address, only if you choose to sign in. Accounts are optional — everything works without one. If you do sign in, we store your email address, and if you use Google, the name and profile picture Google returns. Nothing else. There is no password to store because we don't use them.
What your browser sends automatically. Standard web-server information: IP address, user agent, referring page, and timestamps, recorded by our hosting provider. Plus Google Analytics data about which pages you view.
A one-way fingerprint of your IP address, to stop abuse. The audit is public and each run sends roughly seventeen requests to a website you choose, so it needs a limit or it becomes a tool for attacking other people's sites. To count requests per network without keeping the network's address, we convert your IP to an irreversible fingerprint (HMAC-SHA-256 with a secret we hold) and store only that, with the time. The original address is never written down, the fingerprint cannot be turned back into it, and rows older than 24 hours are deleted automatically. We do not use it to identify you, profile you, or link your visits together.
What we fetch from the site you audit. When you enter a domain, we
request that site's robots.txt, homepage, sitemap, and up to eight
additional pages, and we store the resulting report — including short
excerpts of the page content that triggered each finding. If the site you
audit contains personal information in its public pages, that text can end up
inside a stored report. To generate the report's "How an AI reads your site"
panel, an excerpt of the audited site's public homepage text (up to ~7,000
characters) is also sent to Groq, an AI inference provider, and the summary
it returns is stored as part of the report. No information about you — no
account data, cookies, or IP address — is sent with it.
What cookies does SeeGeo set?
Two, and neither is used for advertising.
| Cookie | Purpose | Lifetime |
|---|---|---|
seegeo_device |
A random identifier so your audits stay visible only to your browser. Contains no personal data and is not readable by page scripts. | 1 year |
authjs.session-token |
Set only if you sign in: keeps you signed in. Removed when you sign out. | 30 days |
_ga, _ga_* |
Google Analytics — which pages get visited, roughly where visitors come from. | up to 2 years |
The seegeo_device cookie is what makes the privacy of your reports work: it
is how we tell your audits from someone else's without asking you to sign up.
Clearing it doesn't delete your reports, but it does mean you can no longer
see them.
We don't use advertising cookies, cross-site trackers, or session recording.
Why do we hold this data?
To provide the service you asked for — running an audit, storing its report so you can return to it, and showing your own history back to you. For analytics, our interest is understanding which pages are useful, which we consider a legitimate interest under GDPR Article 6(1)(f). If you'd rather not be counted, a browser-level ad/analytics blocker prevents it entirely, and we don't work around blockers.
Who else processes it?
We keep this list short on purpose, and it is complete as of the date above.
| Processor | What they handle | Where |
|---|---|---|
| Vercel | Hosting, request logs, IP addresses | United States |
| Neon | Database storing audits and projects | United States (us-west-2) |
| Google Analytics | Site usage analytics | United States |
| G2 | Attribution of visits that arrive from our G2 profile or G2 ads (a small script from g2.com loads on each page) | United States |
| Fontshare | Serves the typeface; receives your IP as part of the request | EU/US |
| Google PageSpeed Insights | Speed measurement of an audited site, when enabled | United States |
| Google Sign-In | Verifies your identity if you choose that sign-in route | United States |
| Resend | Sends sign-in links to your email address | United States |
| Groq | Generates the report's "How an AI reads your site" summary from the audited site's public homepage text | United States |
We do not sell personal data, and we do not share it with advertisers. If we ever add a processor, this table changes before the processor does.
Where is data stored, and for how long?
On servers in the United States. If you are in the EEA or UK, that is an international transfer, made under the relevant standard contractual clauses our providers maintain.
Audits and projects are kept until you ask us to delete them. Rate-limit fingerprints are deleted after 24 hours. Server logs follow our hosting provider's retention, typically around 30 days. Analytics data follows Google's retention settings, currently 14 months.
Sign-in links expire after 24 hours and work once. Sessions expire after 30 days of inactivity.
What are your rights?
If you're in the EEA or UK, you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. If you're in California, you have equivalent rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
In practice, the simplest requests are these:
- Delete my account and everything in it. If you have an account, the account page does this yourself, immediately — every audit, every tracked project and its scan history, and the sign-in itself. No email needed.
- Delete my audits. Email us the report URLs, or the domain you audited, and we'll remove them.
- Stop analytics. Use a blocker, or your browser's Do Not Track / Global Privacy Control signal.
- Everything you hold on me. Email us; we'll respond within 30 days.
If you have an account, email us from the address you signed in with and we can find everything tied to it. If you don't, we may not be able to connect a request to a record without the report URL or domain — a consequence of collecting so little, not an evasion.
Deleting your account deletes the audits and projects attached to it.
What about the websites we audit?
When you submit a domain, we fetch its publicly available pages as an ordinary
web client, identifying ourselves as SeeGeoAudit. We respect a reasonable
request rate and do not attempt to bypass logins, paywalls, or bot protection.
You should only audit sites you own or have permission to analyse. That is a condition of using SeeGeo — see the terms.
If you operate a site and want SeeGeo not to fetch it, blocking SeeGeoAudit
in your robots.txt is sufficient, and we'll honour it.
Is data used to train AI models?
We don't train AI models on your data, and no personal data is sent to any AI provider.
The audit's scores and findings are produced with no AI at all — deterministic parsing and scoring, so the same site always gets the same score. One part of the report is AI-generated and labeled as such: the "How an AI reads your site" panel, produced by sending an excerpt of the audited site's public homepage text to Groq (see the processor table). Groq processes it to generate the summary; per its API terms it does not use API inputs to train models.
Our separate visibility tracking feature does send your chosen prompts (for example, "best bakery in Portland") to AI providers in order to record how they answer. Those prompts are written by you and contain no personal data unless you put it there. That feature is not active on any account today.
Children
SeeGeo is a business tool and is not directed at children under 16. We don't knowingly collect their data.
Changes to this policy
If we change how data is handled, we'll update this page and move the date at the top. Material changes will be noted here rather than made quietly.
- 2026-08-14: disclosed the done-for-you request form — what it asks for, and that requests record an approximate country, city, and coarse device type (never the IP address).
- 2026-08-14: disclosed the hashed-IP rate limit, and the free-audit limit above which an account is required.
- 2026-08-13: disclosed the "How an AI reads your site" panel — audit reports now include an AI-generated summary produced by sending the audited site's public homepage text to Groq. Audit scoring remains fully deterministic and AI-free.
How to contact us
Email info@see-geo.com for anything on this page, including deletion requests.
Frequently asked questions
Does SeeGeo sell my data? No. We don't sell personal data, share it with advertisers, or use it for cross-site advertising. The only third parties involved are the infrastructure providers listed above, each acting as a processor on our behalf.
Do I need an account to use SeeGeo? Not at first. The first few audits run without signing up, and a functional cookie keeps them visible only to your browser. After that we ask for an email address, because an unlimited anonymous tool that fires requests at other people's websites is one we cannot keep running responsibly. An account is an upgrade: it keeps your reports when cookies are cleared and makes them reachable from another device. If you sign in later, work already done on that browser is attached to your account rather than lost.
What do you store if I create an account? Your email address, plus the name and profile picture Google returns if you use Google sign-in. No password, because we don't use them — sign-in is by one-time link or Google. Deleting your account deletes the audits and projects attached to it.
Can other people see the audits I run? Not unless you choose to share one. Reports are private to the browser that created them, and knowing the URL is not enough to open one. Sharing creates a public link that you can revoke at any time.
How do I delete my data? Email info@see-geo.com with the report URL or the domain you audited, and we'll delete the record. We'll confirm within 30 days.
Does SeeGeo use my content to train AI? No. We don't train models on anyone's data. The audit's scores are entirely deterministic and involve no AI. The one AI-generated part of a report — the labeled "How an AI reads your site" panel — is produced by sending the audited site's public homepage text to Groq, which states it does not train on API inputs.
What happens to the site I audit — do you store its content? We store the report, which includes short excerpts of the page content that triggered each finding, so the evidence remains inspectable. We don't keep a full copy of the site.