Privacy Policy
Last updated: 2 October 2026
1. Who we are
SEO Toolbox (seotoolbox.ai, panel.seotoolbox.ai) is run by Wolf of Blog Street, Inc., a Delaware corporation, 4501 Mission Bay Drive, Ste 3A, San Diego, CA 92109, USA ("we", "us"). For data about your account, we are the controller. For data you put into the product about your own clients, their websites and outreach contacts, you are the controller and we process it for you (section 11).
Privacy contact: privacy@seotoolbox.ai (also support@seotoolbox.ai). We have not appointed an EU or UK representative or a Data Protection Officer.
2. How SEO Toolbox works (and why it matters for your data)
SEO Toolbox has no built-in AI agent. You connect your own agent (for example Claude Code, Codex or Gemini CLI) with the stb command line or an API key you create, or you use the web panel yourself. Your agent acts as you, with your key: what it sends us and what it does with the results is decided by you and your agent's provider, not by us. Your agent provider's own privacy terms apply to what you share with it.
3. Data we collect
3.1 Account and team
- Your email address and name; a password hash (Argon2id) if you set a password; your level and settings (for example your spending limits).
- Your membership: plan, status, start and end dates, how it was granted, and the order reference from the checkout.
- Agency data you enter: clients (name, logo, notes), projects and their websites, competitor websites, staff seats and client portal users (their email and name), white-label brand details (sender name, reply-to address, logo) and custom portal domains.
- Sign-in: one-time sign-in links are stored only as a hash and expire after 24 hours. A sign-in from the command line (
stb) stores the name of the computer it came from.
3.2 API keys
An API key is shown once, when you create it. We store only a hash of it, its visible prefix, its scopes, its spending cap, when it was last used and the client that last used it (the stb version or the User-Agent your agent sends). You can revoke a key at any time in the panel; a revoked key stops working at once.
3.3 Usage and runs
- Every run of a tool: the inputs you or your agent gave it (for example keywords, domains, URLs, prompts), which key or person started it, its progress log, errors and a result summary.
- The credit ledger: every purchase, hold, charge and refund, with what each charge cost us in provider fees.
- We do not keep IP addresses in our application database. Cloudflare and our hosting provider keep short-lived network logs that include IP addresses (section 9).
3.4 Results and reports
Tool results are stored in our database, one area per tool; uploaded and generated files are stored on our own servers. Reports you build stay in your account. A report you share with a client is visible only to the portal users you invite; a share link you create works for anyone who has the link until you revoke it or it expires.
3.5 Google Search Console and Google Analytics 4
- Scopes. Search Console:
webmasters.readonly. Google Analytics:analytics.readonly. Both also ask foropenidandemailto show which Google account is connected. Both are read-only: we cannot change anything in your Google accounts. - What we store. The refresh token, encrypted (AES-256-GCM), plus the Google account email and ID and the scopes you granted. Access tokens are kept in memory only.
- Search Console data. Search performance (clicks, impressions, position by day, page, query and device) and URL Inspection results for the properties you choose, archived so tools can compare periods. Ad-hoc extracts are deleted after 7 days unless a report uses them.
- Analytics data. Your property details and the report rows a tool asked for. Report rows expire after 7 days.
- Disconnect. In the tool you can disconnect at any time: we revoke the token at Google and delete it. For Search Console, the archived data stays unless you also choose to purge it. For Analytics, report rows are deleted; the list of properties stays. You can also remove access in your Google account settings.
- BigQuery (not live yet). Dark Query Ledger reads your own Search Console bulk export in BigQuery. It adds the read-only scope
bigquery.readonlyto your Search Console connection and runs read-only queries as you, in your own Google Cloud project, billed by Google to you.
3.6 Google Business Profile (not live yet: the GBP Bridge tool exists; its Google connection and a disconnect are not built yet)
Google offers no read-only scope for Business Profile, so its consent screen asks for business.manage. The tool only reads: your locations (name, website, address, hours), daily metrics and monthly search keywords. The refresh token is stored encrypted, as for Search Console.
3.7 Outreach mail
- Outreach sends from your own mailbox. Sending from Gmail opens once Google has verified our app. Gmail asks for
gmail.send, plusopenidandemailto show which account is connected (send only; we do not read your Gmail). Microsoft asks forMail.Send,Mail.Read(to find replies to your outreach),offline_accessandUser.Read. Tokens are stored encrypted. - No message is sent without your approval. Only you, signed in to the panel, can approve a message; an API key or agent cannot. Each send needs a fresh confirmation of the exact text you saw.
- We store your mailbox address and signature, the prospects (email, name, role, the public page the address came from), every message, the approval log and replies (sender, text). Contact addresses come from the site owner's own public pages, from data you import, or from you; we do not guess addresses.
- Replies asking not to be contacted, and bounces, put the address on a do-not-contact list for your account. We read replies only in Outlook (Microsoft) mailboxes; for Gmail we have no read access, so you record those yourself.
- Disconnecting a mailbox revokes the Google token, or deletes the Microsoft token (remove the app in your Microsoft account to revoke it there). Messages and replies already stored are kept with your account.
3.8 Payments (not live yet: the private beta is free)
Payments are taken by Stripe. We never see or store your full card number. We store the Stripe customer, subscription and payment ids, amounts, dates, and refund or dispute status.
3.9 Cancellation (not live yet)
When you cancel, we ask for a reason and optional detail. We keep it with the account's recent runs and reports to find and fix what failed you.
3.10 Aggregated statistics and public data
We may create aggregated, de-identified statistics from use of the service and use them to run and improve SEO Toolbox, for research, and to publish industry studies. A statistic combines at least 10 accounts and 50 sites; no member, client, site, person or business-identifying search query can be identified in it, and no raw data leaves our platform. Google user data is used only as Google's Limited Use rules allow. One member's specific results are never shown to another member, and we never sell these statistics.
Members contribute to these statistics by default and can opt out in Account settings. Contributors get network benchmarks built only from them: click-through rate by position against the median of their niche, the typical lift by type of fix, and normal ranking volatility. A member who opts out stops contributing and stops getting benchmarks; their own tools keep working. The benchmarks, and the opt-out setting with them, are coming after the private beta; until then you can opt out by writing to privacy@seotoolbox.ai.
Public data our providers return for runs (search results, keyword and backlink data) is stored and reused to run the service. It holds no member identifiers.
Google user data
SEO Toolbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use data from your Google accounts only to provide and improve the SEO Toolbox features you see; we do not sell it, do not use it for advertising, do not use it to train AI models, and do not let anyone read it except to support you at your request, for security, or where the law requires. Where a tool sends part of this data to an AI provider (section 9) to produce a result for you, that provider processes it under API terms that forbid it from training on your data. You can disconnect any Google account at any time (section 3.5) or at myaccount.google.com/permissions; disconnecting revokes our access and deletes the token.
4. Cookies and similar storage
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
stb_session | panel | Keeps you signed in (Secure, HttpOnly, SameSite=Lax). Strictly necessary. | 30 days, deleted on log out |
stb.signed-in, stb.context (local storage), stb.gsc-client (session storage) | panel | Remember that you are signed in and which client and project you picked. Strictly necessary. | Until you log out or clear your browser |
wd_vid | seotoolbox.ai | Wolf Den, our own analytics: a visitor id to count visits and to link a sign-up or purchase to the ad that brought it. For visitors in the EU/UK, set only after you accept in the consent banner. | 395 days |
wd_ok | seotoolbox.ai | Remembers that you accepted in the consent banner. Without it Wolf Den treats you as opted out. Declining sets no cookie (the choice is kept in your browser's local storage). | 395 days, deleted when you decline |
The sales site loads fonts from Google Fonts, which receives your IP address and browser details. We use no third-party advertising cookies and no third-party analytics script.
5. Advertising measurement (Meta) (not live yet)
We buy ads on Facebook and Instagram. To measure them, Wolf Den sends Meta (Conversions API) a sign-up event and a purchase event with hashed identifiers: a hash of your email address, the Wolf Den visitor id, and the Facebook click id (fbclid) if you came from an ad. For visitors in the EU and UK, this happens only if you consented in the consent banner. You can withdraw consent at any time from the cookie settings, also linked at the foot of every page.
6. Why we use your data (legal bases)
- To provide the service (contract): your account, runs, results, reports, connections, credits, payments and support.
- To keep it safe and fair (legitimate interest): spending limits, abuse and fraud checks, error logs.
- To improve the product (legitimate interest): cancellation reasons and failed runs become fixes; aggregated statistics (section 3.10).
- Advertising measurement: consent in the EU, EEA, UK and Switzerland; elsewhere our legitimate interest, with opt-out via Cookie settings or Global Privacy Control.
- Legal duties: tax and accounting records of payments.
We do not sell your data. We do not use your data, or data from your Google accounts, to train AI models.
7. Emails we send
Sign-in links, your welcome email, invitations to staff seats and client portals (portal invitations go out under your agency's own name and reply-to address), and service messages about billing and your account, including monthly statements once billing opens. We send marketing email only to members who opt in.
8. How long we keep data
| Data | Kept |
|---|---|
| Account, team, runs, results, reports, ledger | While your account is active. After a membership ends you keep read-only access for 12 months; then we email you 30 days before we delete the account and its data. You can ask us to delete sooner at any time. |
| Sign-in links | 24 hours |
| Sessions | 30 days |
| Search Console ad-hoc extracts, Analytics report rows | 7 days |
| Some tools' raw working data (for example rank and drift snapshots, fetched pages, redirect checks) | 90 days or less, as each tool's documentation states |
| Report snapshots | The newest 24 per report |
| Database backups | 14 days, on our own servers |
| Payment records | 7 years |
9. Who we share data with (sub-processors)
We send each provider only what the task needs.
| Provider | Purpose | Data sent |
|---|---|---|
| Hetzner Online GmbH, Germany | Hosting of our two servers: the API, panel, database and files; the workers | All data in sections 3.1–3.10 |
| Cloudflare | DNS, network, TLS, the sales site, custom domains for client portals | All traffic passes through it (including IP addresses); portal hostnames |
| Stripe (not live yet) | Payments, refunds | Your email, company name and VAT ID if you give one, payment details (entered on Stripe), amounts |
| Google (Google Workspace) | Sending our emails; our mailboxes, including privacy@ and support@ | Recipient email and name, email text, sign-in links; what you write to us |
| DataForSEO | Search results, keyword, backlink and AI Overview data | Keywords, domains, URLs, locations from your runs |
| Serper | Google search results | Keywords and queries |
| Anthropic | Language model used by several tools (summaries, report narration, topic and intent analysis, outreach drafts) | Run inputs and the data the tool works on, which can include your Search Console queries and pages, page text and outreach notes |
| Microsoft (Azure OpenAI) | Classifying backlinks in Backlink Audit | Text and URLs of the pages that link to the audited site |
| OpenAI, Google (Gemini), Perplexity | AI Visibility: asking AI engines your prompts and reading their answers | The prompts you choose or that the tool writes from your Search Console queries |
| Google (Search Console, Analytics, BigQuery, Business Profile, Gmail) | Your own Google data; sending outreach from Gmail | Your OAuth tokens; outreach messages and recipients |
| Microsoft (Graph) | Sending outreach from Outlook and reading replies | Your OAuth token; outreach messages and recipients |
| Firecrawl, Scrapfly, Steel, Driver; Webshare and DataImpulse (proxies) | Fetching public web pages that our own crawler cannot reach (Backlink Audit) | URLs of public pages |
| Google Fonts | Fonts on the sales site | Visitor IP and browser details |
| Wolf Den (not live yet) | Our own visit and conversion analytics | Visitor id, pages visited, sign-up and purchase events |
| Meta Platforms (not live yet) | Measuring our Facebook and Instagram ads | Hashed email, visitor id, fbclid; EU/UK only with consent |
Every AI provider in this table processes your data under API terms that do not allow it to train on that data; AI Visibility uses Google Gemini's paid tier. We update this list before adding a sub-processor and email members 14 days before.
Text embeddings used by several tools are computed by models running on our own servers; that data does not leave them. Our crawler (SEOToolboxBot) also fetches public pages directly.
We are in the United States, and so are most of our providers. For personal data from the EU, EEA, UK and Switzerland, we rely on the EU Standard Contractual Clauses (and the UK Addendum) in our Data Processing Agreement, and on the same clauses or the EU-US Data Privacy Framework in our contracts with sub-processors.
We also share data when the law requires it, or with a buyer of the business or an affiliate that takes over the service, who would be bound by this policy.
10. Who at SEO Toolbox can see your data
Our administrators can see your account, membership, balance, ledger and the list of your runs (tool, status, errors), to support you and run billing. They cannot sign in as you. Staff seats and client portal users you invite see what you give them access to.
11. Data about your clients and other people (we act as your processor)
When you add clients, their websites, their Google or Microsoft data, portal users or outreach contacts, you are the controller (or a processor for your client) and we process that data only on your instructions, to provide SEO Toolbox. Our Data Processing Agreement applies to that data and forms part of your agreement with us. It contains the EU Standard Contractual Clauses (Module 2) and the UK Addendum for transfers to us in the United States, and lists our sub-processors (section 9). You confirm you have the right to use the data you load, and that your use of outreach follows the laws that apply to you (for example CAN-SPAM, GDPR, PECR and CASL).
12. Your rights
- Access and export. Every run's results can be exported as CSV, JSON or XLSX from the API or
stb, and as CSV from the panel (some tools also offer XLSX there). (An export of the whole account is not live yet.) Ask us for a copy of everything else. - Correction. Change your name and settings in the panel, or ask us.
- Deletion. You can delete clients, projects, reports, schedules, files and connections yourself. To delete your whole account, write to
privacy@seotoolbox.aifrom your account email; we delete it within 30 days, and backups roll off within 14 days after that. During the private beta there is no self-serve account deletion yet: an administrator deletes the account on request, within the same 30 days. Disconnecting a Google or Microsoft account revokes our token at once. We keep only the payment and tax records the law requires. - Objection, restriction, portability, withdrawing consent: write to
privacy@seotoolbox.ai; we answer within one month. You may complain to your data protection authority; EU: the authority of your country; UK: the ICO (ico.org.uk).
13. Security
Traffic is encrypted (TLS). Passwords, API keys, sign-in links and session tokens are stored only as hashes. Google and Microsoft tokens are encrypted at rest. Each tool's data lives in its own database schema with its own permissions.
14. Children
SEO Toolbox is a business service for people aged 18 and over. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
15. Changes
We will post changes here and email members about material changes 30 days before they apply.
Wolf of Blog Street, Inc., 4501 Mission Bay Drive, Ste 3A, San Diego, CA 92109, USA · privacy@seotoolbox.ai