Privacy policy
Effective 15 September 2026 · Grandfield Media Private Limited, Hyderabad, India
Short version: we hold your account, your plan and a record of which tools you ran. We do not hold the pages we check for you, and we never sell anything to anyone.
What we hold
Your name and email address. Your workspace name and the website you told us about. Your plan, payments and invoices. A record of each tool run — which tool, whether it succeeded, how long it took, and for tools that check a URL, the address you asked about. Support tickets and their replies. Your WordPress connections, if you make any. The technical logs needed to keep the service running and secure.
What happens to what you type
Text tools and generators — readability, slug, schema builders, previews and the rest — run entirely inside your browser. The text, the list or the file you paste never reaches us. We record only that the tool ran and how long it took, so your Usage page is honest. Those runs never count against your daily limit.
Tools that take a URL or a domain cannot work that way. To audit a page, follow a redirect, read a robots.txt or crawl a site, our servers have to fetch it. For those we store the address you entered and the result summary we show you. We do not keep a copy of the page itself.
Other services we pass things to while a tool runs
The keyword suggestion tools ask Google's public autocomplete for completions of your keyword, so that keyword reaches Google. The domain and registration tools ask the public RDAP registry about the domain you entered. Nothing else about you is sent with either.
WordPress connections
If you connect a WordPress site, we store its address, the username, and an application password encrypted with AES-256-GCM. We use it only to read and to make the changes you approve. Every change is written to a log with its previous value, which is what makes Undo possible — so that log necessarily contains the old and new text of the things you changed. Disconnect a site and the credentials are deleted.
If you set up monitoring, we keep a fingerprint of the watched page so we can tell you what changed since the last check.
Why we hold it
To run your workspace, count usage against your plan, invoice you, answer support, keep the service secure, and meet tax and accounting law. Never for advertising. Never sold, and never shared for anyone else's marketing.
Who processes it for us
Razorpay (payments), Supabase (database hosting), Vercel (application hosting), Resend (sign-in codes and receipts). Each receives only what its job needs.
Where it is stored
Your data is stored on servers in the United States. If you are in India, that is a transfer outside the country, and by using Seoitz you agree to it. Our processors are bound by their own contracts to protect it.
How long we keep it
Account and workspace data for as long as your account exists. Tool run records for twelve months, so Usage and trends work. Invoices and payment records for eight years, as Indian tax law requires. Support tickets for three years. Sign-in codes expire in minutes.
Security
Everything travels over HTTPS. Sign-in is by one-time code, so there is no password of yours for us to lose. WordPress credentials are encrypted at rest with a key held outside the database. Access to production is limited to people who need it.
Your rights
You may ask us for a copy of your data, ask us to correct it, ask us to delete it, or nominate someone to act for you if you cannot. Write to seoitz@grandfieldmedia.com and we will answer within thirty days. Deleting your account removes your workspace, your WordPress connections and their stored credentials; invoices stay for the period tax law requires.
Grievances
If something about your data is not handled the way you expected, write to our grievance officer at seoitz@grandfieldmedia.com or call +91 92479 12081, Monday to Saturday, 10 am to 6 pm IST. If you are still unsatisfied you may approach the Data Protection Board of India.
Cookies
One cookie, to keep you signed in. No tracking cookies, no advertising pixels, no third-party analytics.
Children
Seoitz is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy we update the effective date above, and we email you before anything material takes effect.