1. Who we are
The controller of personal data processed through seodispatcher.com is the operator of SEO Dispatcher. For privacy requests use abhijith1203@gmail.com. A shorter EEA/UK rights summary is on the GDPR page.
2. What we collect
Account
Identity from Clerk: email address, name, and avatar if you provide them, plus a stable user id. We store a local copy so the studio can load without calling Clerk on every request.
Workspace
Data you create in the product: linked websites, drafts, SEO audits and their findings, publish runs, IndexNow pings, and settings. If you connect GitHub or Google we store encrypted OAuth tokens and the property identifiers you pick.
Billing
Plan, billing period, and opaque Dodo customer / subscription / payment ids. We do not store full card numbers or CVCs. Dodo collects payment details as an independent payment processor.
Technical
Standard request logs on Cloudflare (IP address, user agent, path, time) used to operate, debug, and rate-limit the service. We are not running a separate advertising tracker on the marketing site.
Optional marketing list
If you previously submitted the early-access form, that email is stored on a separate wishlist table until you ask us to remove it.
3. How we use it
- to create and secure your account and show the correct plan limits;
- to draft, audit, and publish when you ask, including calls to OpenAI for those jobs;
- to read Search Console or Analytics only for properties you connect;
- to open pull requests or commits on repositories you connect;
- to take payment, run trials, and open the billing portal;
- to prevent abuse and keep the service available;
- to respond to your support or privacy requests.
We do not sell personal data. We do not use your drafts to train our own models.
4. Lawful bases (GDPR)
Where GDPR or UK GDPR applies, we rely on:
- Contract — creating an account, running the workspace, billing, and publishing you request (Art. 6(1)(b)).
- Legitimate interests — securing the service, debugging, and understanding how the product is used at an aggregate level, balanced against your rights (Art. 6(1)(f)).
- Consent — where we ask for it, including connecting GitHub or Google and optional communications. You can withdraw consent by disconnecting the integration or emailing us (Art. 6(1)(a)).
- Legal obligation — keeping records we must keep for tax or accounting, including via Dodo (Art. 6(1)(c)).
5. Processors
We use companies that process data on our instructions to run SEO Dispatcher:
- Clerk. Sign-in, account identity, and session management.
- Cloudflare. Hosting (Workers), database (D1), and delivery of the app.
- Dodo Payments. Checkout, subscriptions, invoices, and the customer billing portal.
- OpenAI. Drafting posts and the AI stages of SEO audits you start.
- GitHub. Repositories you connect so we can open pull requests or commit files you approve.
- Google. Search Console and Analytics properties you connect, used only for the actions you take in the product.
GitHub and Google also act as controllers of the accounts you already have with them. Their policies apply to those accounts.
6. International transfers
SEO Dispatcher is operated from India. Several processors (including Clerk, Cloudflare, OpenAI, GitHub, Google, and Dodo) may process data in the United States or other countries. Where GDPR requires a safeguard for those transfers we rely on the processor’s Standard Contractual Clauses, adequacy decisions, or participation in a valid framework such as the EU–US Data Privacy Framework, as they publish in their own terms.
8. Retention and deletion
Workspace rows stay until you delete them or delete your account. Account deletion from Settings removes owner-scoped data from SEO Dispatcher and attempts to delete your Clerk user for this app. Files already committed to your GitHub repository are not deleted — they are yours.
Dodo may retain payment records as required by financial law. Encrypted OAuth tokens are removed when you disconnect an integration or delete the account. Request logs on Cloudflare follow Cloudflare’s retention for Workers.
9. Your rights
Depending on where you live you may have rights to access, correct, delete, restrict, or export your personal data, to object to certain processing, and to withdraw consent. EEA, UK, and Swiss residents: see the GDPR page for how to use those rights and how to complain to a supervisory authority.
To delete the account yourself, use Settings. For any other request, email abhijith1203@gmail.com. We may need to confirm it is you before we act.
10. Security
Access to workspace data is scoped to the signed-in account. OAuth tokens are stored encrypted. No method of transmission or storage is perfectly secure; we work to reduce risk and to fix issues we learn about.
11. Children
The service is not directed at children under 16 (or 18 where our Terms require it). We do not knowingly collect their personal data. If you believe we have, email us and we will delete it.
12. Changes
We may update this policy. The “Last updated” date will change. Material changes will be posted here. Continued use after an update means you acknowledge the new policy.
13. Contact
Privacy questions and GDPR requests: abhijith1203@gmail.com.