Snack SEO — Privacy Policy #

Effective date: 18 August 2026

Controller: Snack Prompt Corp, a Texas corporation
Address: 604 Canyon Creek Trail, Fort Worth, TX 76112, United States
Contact for all privacy matters: hello@snackseo.com
Service: Snack SEO — https://snackseo.com (application at https://app.snackseo.com)


Table of contents #

  1. Who we are and what this policy covers
  2. Our two roles: controller and processor
  3. Personal data we collect
  4. Data we access from connected Google accounts (OAuth)
  5. Google API Services User Data Policy — Limited Use disclosure
  6. Data we collect when we crawl your websites
  7. AI features and how your data is used with AI models
  8. Why we process your data and our legal bases
  9. Aggregated and de-identified data
  10. Who we share data with (sub-processors and other recipients)
  11. International transfers of data
  12. How long we keep data
  13. Security
  14. Cookies and similar technologies
  15. Marketing communications
  16. Your rights under the GDPR and UK GDPR
  17. Your rights under CCPA/CPRA and other US state laws
  18. Your rights under the LGPD (Brazil)
  19. Your rights under PIPEDA (Canada)
  20. How to exercise your rights
  21. Automated decision-making and profiling
  22. Children
  23. Third-party sites and services
  24. Changes to this policy
  25. How to contact us and how to complain

1. Who we are and what this policy covers #

Snack SEO is a multi-tenant software-as-a-service platform for search engine optimisation ("SEO") and AI-search visibility. It is operated by Snack Prompt Corp, a corporation organised under the laws of the State of Texas, United States, with its registered address at 604 Canyon Creek Trail, Fort Worth, TX 76112, United States ("Snack Prompt", "we", "us", "our").

This Privacy Policy explains how we collect, use, disclose, transfer and retain personal data when you:

This policy applies globally. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and comparable US state privacy laws, the Brazilian Lei Geral de Proteção de Dados (LGPD), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

This policy does not replace our Data Processing Agreement, which governs our processing of personal data contained in your Client Data on your behalf.


2. Our two roles: controller and processor #

Snack SEO handles two very different kinds of data, and our legal role differs for each. This distinction matters, so please read it carefully.

2.1 We are a controller for Account Data #

"Account Data" is personal data about you and your team as our customer: your name, email address, password hash, company name, job title, billing details, support correspondence, product usage telemetry, marketing preferences and similar information. We decide why and how this data is processed, so for Account Data we are the controller (a "business" under CCPA/CPRA). Sections 3, 8 and 12–25 of this policy describe that processing.

2.2 We are a processor for Client Data #

"Client Data" is the data you or your end clients put into, or authorise us to retrieve into, the Service: the domains and URLs you add; content you upload or paste; keyword lists; competitor lists; brand and prompt configurations; data we retrieve from your connected Google Search Console, Google Analytics and Google Business Profile accounts; data our crawler collects from the websites you authorise; and any personal data that happens to be contained in any of the above (for example, an author name in a page byline, or a contact email address appearing on a crawled page).

For Client Data we act as a processor (a "service provider" under CCPA/CPRA) acting on your documented instructions. You are the controller. You are responsible for having a lawful basis for the data you place in, or route through, the Service, and for giving the notices and obtaining the consents your own privacy law requires. Our Data Processing Agreement governs this relationship and forms part of our contract with you.

2.3 Where a person visits your website #

Where our crawler or your connected analytics accounts result in us handling data about visitors to your website, we handle that data solely as your processor. We do not build profiles of your website visitors, we do not sell that data, and we do not use it for our own advertising.


3. Personal data we collect #

3.1 Data you give us #

CategoryExamples
Identity and contact dataFull name, email address, company or agency name, job title, country, time zone, profile photo (if you upload one)
Account credentialsHashed password, multi-factor authentication settings, session and refresh tokens, API keys you generate
Workspace and team dataWorkspace name, team member invitations and email addresses, roles and permissions, client or project names you create
Billing dataBilling name and address, VAT/tax identifiers, plan and subscription history, invoices, the last four digits and expiry of a card and its issuing country. We do not store full payment-card numbers. Card details are collected and stored by our payment processor.
Support and communications dataEmails, in-app messages, support tickets, bug reports, screenshots and recordings you send us, survey and interview responses
Content you submitPrompts, briefs, drafts, notes, uploaded documents, feedback and anything else you type into or upload to the Service

3.2 Data we collect automatically #

CategoryExamples
Device and connection dataIP address, browser type and version, operating system, device type, screen size, language, referring and exit URLs
Usage and telemetry dataPages and features viewed, buttons clicked, reports run, crawls started, credits consumed, timestamps, session duration, feature-flag state
Diagnostic dataError messages, stack traces, performance timings and breadcrumb logs captured by our error monitoring tool (Sentry). Stack traces can incidentally contain a user identifier or a URL you were viewing.
Security dataSign-in attempts, IP-based geolocation at city level, security events, audit-log entries for actions taken in your workspace

3.3 Data we receive from third parties #

3.4 Sensitive data #

We do not ask for, and the Service is not designed to hold, special-category data under Article 9 GDPR or "sensitive personal information" under the CCPA/CPRA (such as health data, biometric data, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, sex life or sexual orientation, or government identifiers). Please do not upload such data to the Service or place it in prompts. If we become aware that such data has been uploaded, we may delete it.


4. Data we access from connected Google accounts (OAuth) #

This section is important, because it is the part of the Service that touches the most sensitive data you control. Connecting a Google account is always optional, and the Service remains usable without it (with reduced functionality).

4.1 What we connect to, and why #

ConnectionOAuth scope categoryWhat we readWhy we read it
Google Search ConsoleRead-only Search Console data (webmasters.readonly) and, where you enable it, site listingVerified property list; Search Analytics rows (query, page, country, device, search appearance, clicks, impressions, CTR, average position); index-coverage and URL-inspection results; sitemap statusTo show your real organic performance, detect ranking and traffic movements, find keyword and page opportunities, diagnose indexing problems, and measure the effect of changes we recommend
Google Analytics (GA4)Read-only Analytics data (analytics.readonly)Property and data-stream list; aggregated report rows such as sessions, users, engagement, conversions and revenue, broken down by channel, source/medium, landing page, country and deviceTo connect SEO activity to sessions, conversions and revenue, and to prioritise pages by business value
Google Business ProfileBusiness Profile management/read (business.manage)Location list and location details; business categories; reviews and review replies; performance metrics such as searches, views, calls and direction requestsTo support local SEO reporting, monitor listing accuracy, and track local visibility

We request read-only scopes wherever the Google API offers one. Where an API only exposes a broader scope (as is the case for Google Business Profile), we still use it only for the read and reporting purposes described above, and we will tell you in the consent screen before you grant it.

4.2 What we explicitly do not do with Google user data #

4.3 How connected data is stored and separated #

Google user data retrieved for your workspace is stored in your tenant's records in our database and is protected by row-level access controls so that it is only accessible to authenticated members of your workspace with sufficient permissions. OAuth access and refresh tokens are stored encrypted at rest and are used only to refresh the connection and to make the read calls described above.

4.4 How long we keep it #

4.5 How to revoke access — three independent routes #

You may withdraw this permission at any time, and doing so is always effective:

  1. In Snack SEO: open Settings → Integrations, find the connection, and click Disconnect. This deletes the stored tokens and stops all further calls.
  2. In your Google Account: go to https://myaccount.google.com/permissions, find "Snack SEO", and click Remove access. This revokes our tokens at source.
  3. By email: write to hello@snackseo.com and ask us to disconnect and delete. We will action it within 7 days and confirm to you.

Revoking access stops future retrieval immediately. Data already retrieved is deleted on the timetable in section 4.4, or sooner on request.


5. Google API Services User Data Policy — Limited Use disclosure #

Snack SEO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and in the terms Google uses:

If you believe we are not complying with this commitment, please contact hello@snackseo.com.


6. Data we collect when we crawl your websites #

When you add a domain, we may crawl it to run technical SEO audits, extract content, check internal links, capture structured data and measure performance.


7. AI features and how your data is used with AI models #

Snack SEO uses large language models and AI-search engines in two distinct ways.

7.1 Generative features (content briefs, drafts, recommendations, summaries) #

When you use a generative feature, we transmit your prompt together with relevant context — which may include page content, keyword data, extracts of your connected Search Console or Analytics data, and your own instructions — to one or more AI providers: OpenAI, Anthropic, Google (Gemini), or a model routed through OpenRouter.

Please note the accuracy and originality disclaimers in section 6 of our Terms of Service: AI output can be wrong, can be similar or identical to output generated for another user, and must be reviewed by a human before you publish it.

7.2 AI-search visibility monitoring #

To measure how a brand appears in AI-generated answers, we run prompts you configure against AI search products including ChatGPT-class models, Google Gemini, Perplexity and models accessed via OpenRouter, and we record the answers, the brands mentioned and the sources cited.

7.3 No sensitive automated decisions #

We do not use AI to make decisions that produce legal or similarly significant effects concerning any individual. See section 21.


Where we act as controller (Account Data), we rely on the following legal bases under the GDPR and UK GDPR.

PurposeData usedLegal basis (GDPR/UK GDPR)
Creating and administering your account; authenticating youIdentity, contact, credentialsPerformance of a contract (Art. 6(1)(b))
Providing the Service, including running crawls, retrieving connected data, generating reports and AI outputsAccount Data; Client Data (as processor)Performance of a contract (Art. 6(1)(b)); for Client Data, your instructions under the DPA
Taking payment, invoicing, tax and accountingBilling dataPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Providing support and responding to enquiriesSupport and communications dataPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) — running a responsive business
Securing the Service, preventing fraud and abuse, enforcing our terms and rate limitsSecurity, device and usage dataLegitimate interests (Art. 6(1)(f)) — protecting our platform, our customers and third parties; legal obligation (Art. 6(1)(c))
Monitoring performance and errors, debugging, capacity planningDiagnostic and usage dataLegitimate interests (Art. 6(1)(f)) — keeping the Service working
Improving and developing the Service; building aggregate benchmarks and indicesUsage data; aggregated and de-identified data (see section 9)Legitimate interests (Art. 6(1)(f)) — improving a product our customers pay for
Service and transactional emails (receipts, security alerts, outage notices, material changes)Identity and contact dataPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Marketing emails and product announcementsIdentity, contact, marketing preferencesConsent (Art. 6(1)(a)) where required by law; otherwise legitimate interests (Art. 6(1)(f)) in marketing to existing customers about similar services, subject always to an easy opt-out
Analytics and advertising cookies on our marketing siteCookie and engagement dataConsent (Art. 6(1)(a))
Establishing, exercising or defending legal claims; complying with lawful requestsAny relevant dataLegitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests or fundamental rights. You may object to that processing — see section 16. You may request a summary of the relevant assessment at hello@snackseo.com.


9. Aggregated and de-identified data #

We may create aggregated, statistical and de-identified datasets from usage of the Service — for example, benchmark averages for click-through rate by search position, the frequency with which particular domains are cited by AI answer engines, or aggregate crawl-health statistics across our customer base.

We will not publish aggregated statistics in a form that would allow a specific customer, workspace or client site to be identified without that customer's consent.


10. Who we share data with (sub-processors and other recipients) #

We do not sell personal data, and we do not "share" personal data for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA.

10.1 Sub-processors #

We use a limited set of vendors to run the Service. Each is bound by a written contract that requires them to process data only on our instructions, to keep it confidential, and to apply appropriate technical and organisational security measures. The current list — with the service provided, the data involved, the location of processing and the transfer safeguard — is maintained at /legal/subprocessors and is incorporated into this policy by reference.

In summary, the categories are: cloud infrastructure and database hosting (Supabase, Hetzner Online GmbH); network, DNS, CDN and object storage (Cloudflare); search and SEO data providers (DataForSEO, SerpApi); Google APIs for connected properties and generative AI (Google LLC); AI model providers (OpenAI, Anthropic, OpenRouter, Perplexity); transactional email (Resend); error monitoring (Sentry); and internal operations and record-keeping (Airtable).

You can subscribe to notifications of changes to that list — see the sub-processors page.

10.2 Other recipients #


11. International transfers of data #

Snack SEO runs on infrastructure in the European Union (Hetzner Online GmbH in Nuremberg, Germany; Supabase database hosting in Frankfurt, Germany) and in the United States. Snack Prompt Corp is established in the United States. Some of our sub-processors process data in the United States and, for globally distributed services such as Cloudflare's edge network, in other countries.

This means personal data originating in the EEA, the UK, Switzerland, Brazil or Canada may be transferred to, stored in, or accessed from the United States and other countries whose data-protection laws may differ from those of your own country.

We rely on the following safeguards:

You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by emailing hello@snackseo.com.


12. How long we keep data #

DataRetention
Account and workspace recordsFor the life of the account, and 90 days after account closure, then deleted or anonymised
Client Data in an active workspaceUntil you delete it, or as configured in your workspace retention settings
Client Data after workspace or account deletionDeleted from live systems within 30 days; purged from encrypted backups within a further 60 days
Google user data (Search Console, Analytics, Business Profile)Life of the connection plus 90 days; OAuth tokens deleted within 7 days of disconnection (section 4.4)
Crawl artefacts (HTML snapshots, rendered text, screenshots)12 months by default, or as configured in your plan
AI prompts and outputsStored in your workspace until you delete them; provider-side abuse-monitoring copies deleted per that provider's policy (typically ≤30 days)
Invoices, payment records and tax documents7 years, to meet US and EU accounting and tax obligations
Support tickets and correspondence3 years from last contact
Security, audit and access logs12 months
Error monitoring and diagnostic events90 days
Marketing contacts and consent recordsUntil you unsubscribe or object, plus 3 years for proof of consent
Aggregated and de-identified dataIndefinitely (no longer personal data — see section 9)

Where we are required to retain data to comply with a legal obligation, resolve a dispute or enforce our agreements, we will retain the minimum necessary for that purpose and isolate it from active processing.


13. Security #

We implement technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security, and we do not warrant that the Service will be free from unauthorised access. You are responsible for protecting your own credentials, for using multi-factor authentication, and for removing team members' access promptly when they leave.

Report a suspected vulnerability or compromise to hello@snackseo.com.


14. Cookies and similar technologies #

We use cookies and similar technologies for the following purposes:

Where required by the ePrivacy Directive, the UK PECR or comparable law, we set non-essential cookies only after you consent through our cookie banner. You can change or withdraw your choices at any time via the "Cookie settings" link in the footer of https://snackseo.com. Most browsers also let you block or delete cookies; blocking strictly necessary cookies will prevent you from signing in.

We honour the Global Privacy Control (GPC) signal, which we treat as a valid opt-out of "sale" and "sharing" for the browser that sends it.

We do not use cookies inside the authenticated application at https://app.snackseo.com for advertising purposes.


15. Marketing communications #

We send two kinds of email:

We do not sell or rent your email address to anyone.


16. Your rights under the GDPR and UK GDPR #

If you are in the EEA, the United Kingdom or Switzerland, you have the following rights in relation to personal data for which we are the controller:

Where we act as processor for Client Data, please direct your request to the customer that controls that data (the workspace owner). If you contact us directly, we will forward your request to them and assist them in responding, but we cannot act on Client Data without their instruction.

We do not charge for responding to a request unless it is manifestly unfounded or excessive, and we will respond within one month, extendable by two further months for complex requests (we will tell you if we need the extension).


17. Your rights under CCPA/CPRA and other US state laws #

This section applies to residents of California and, as applicable, of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others).

17.1 Categories collected, sources, purposes and disclosures #

In the preceding 12 months we have collected the following categories of personal information as defined by the CCPA:

CCPA categoryCollected?SourceBusiness purposeDisclosed to
Identifiers (name, email, IP, account ID)YesYou; authentication providersAccount, support, security, billingSub-processors (hosting, email, monitoring, payments)
Customer records (billing name, address, partial card data)YesYou; payment processorBilling, tax, fraud preventionPayment processor, accountants
Commercial information (plan, purchases, usage of paid features)YesYou; the ServiceBilling, support, product analyticsSub-processors
Internet or network activity (usage, telemetry, diagnostics)YesAutomatic collectionOperating, securing and improving the ServiceHosting, analytics, error monitoring
Geolocation (coarse, IP-derived city level)YesAutomatic collectionSecurity, fraud prevention, localisationHosting, security tooling
Professional or employment information (job title, company)YesYouSupport, account management, marketingCRM/operations tooling
Inferences (segment, likely use case)YesDerived from the aboveProduct improvement, marketingInternal only
Sensitive personal informationNot intentionally collected — see section 3.4———
Biometric, health, education, audio/visual (other than support recordings you send us)No———

17.2 No sale, no sharing #

We do not sell personal information and we have not sold personal information in the preceding 12 months. We do not "share" personal information for cross-context behavioural advertising, other than, on our public marketing site only and only where you consent through the cookie banner, the use of advertising cookies, which some laws treat as "sharing". You can opt out through the cookie banner, the "Do Not Sell or Share My Personal Information" link in our footer, or by sending a Global Privacy Control signal.

We do not knowingly sell or share the personal information of consumers under 16 years of age.

17.3 Your rights #

We will verify your request by matching the information you provide against our records; for account holders this normally means responding from the email address on the account. You may use an authorised agent, who must provide written proof of authorisation, and we may still ask you to verify your own identity.

Where we act as a service provider for Client Data, we will refer your request to the business that controls that data.


18. Your rights under the LGPD (Brazil) #

If you are in Brazil, Law No. 13,709/2018 (LGPD) gives you the rights to: confirm that processing exists; access your data; correct incomplete, inaccurate or out-of-date data; anonymise, block or delete unnecessary or excessive data or data processed unlawfully; port your data to another provider; delete data processed with consent; obtain information about the public and private entities with which we have shared your data; be informed about the possibility of refusing consent and the consequences of doing so; revoke consent; and object to processing carried out on a legal basis other than consent where it does not comply with the law.

Our legal bases under Article 7 LGPD mirror those in section 8 (principally execution of a contract, legitimate interests, compliance with a legal obligation and, for marketing and non-essential cookies, consent). Requests: hello@snackseo.com. You may also complain to the Autoridade Nacional de Proteção de Dados (ANPD).


19. Your rights under PIPEDA (Canada) #

If you are in Canada, PIPEDA and applicable provincial legislation (including Quebec's Law 25) give you the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent (subject to legal and contractual restrictions and reasonable notice). We identify the purposes for which we collect personal information at or before collection, limit collection to what is necessary for those purposes, and remain accountable for personal information transferred to third parties for processing.

We use service providers outside Canada, including in the United States and the European Union. While personal information is in another jurisdiction, it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. Requests and questions: hello@snackseo.com. You may also complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec if you are in Quebec.


20. How to exercise your rights #

Email hello@snackseo.com with the subject line "Privacy Request" and tell us:

  1. which right you wish to exercise;
  2. the email address associated with your account (or, if you have no account, enough detail for us to locate any data we hold about you); and
  3. the country or state you are in, so we can apply the right legal standard.

Account holders can also access, export and delete much of their data directly in the Service under Settings → Account & Data.

We will acknowledge your request promptly and respond within the time limit that applies to you: one month under the GDPR/UK GDPR (extendable by two months for complex requests), 45 days under the CCPA/CPRA (extendable by a further 45 days), 15 days under the LGPD for confirmation of processing and access, and 30 days under PIPEDA (extendable with notice).


21. Automated decision-making and profiling #

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

The Service does produce automated outputs — priority scores, opportunity rankings, forecasts, AI-generated recommendations and drafts. These are decision-support tools for your marketing work, not decisions about individuals. They should always be reviewed by a person before you act on them. We may use automated fraud and abuse signals to flag accounts for review, but any suspension or termination decision that materially affects you involves human review, and you may contest it by emailing hello@snackseo.com.


22. Children #

The Service is a business tool. It is not directed to children, and we do not knowingly collect personal data from anyone under 16 years of age. You must be at least 18 to enter into a paid subscription. If you believe a child has provided us with personal data, email hello@snackseo.com and we will delete it.


23. Third-party sites and services #

The Service links to and integrates with third-party products, including Google properties, search engines and AI providers. Once data is transmitted to a third-party service at your direction, that service's own terms and privacy policy govern its handling of the data, and we have no control over it. We are not responsible for the privacy or security practices of third-party services, and we encourage you to read their policies before connecting them. Disconnecting an integration in Snack SEO stops our access, but does not delete anything already held by that third party.


24. Changes to this policy #

We may update this policy to reflect changes in the Service, our sub-processors, or the law. The version in force is always published at https://snackseo.com/legal/privacy-policy with the effective date at the top.

Continuing to use the Service after a change takes effect means you accept the updated policy. If you do not accept it, you may close your account and, where you have prepaid for an unused period, request a pro-rata refund for that period.


25. How to contact us and how to complain #

Snack Prompt Corp
604 Canyon Creek Trail
Fort Worth, TX 76112
United States
Email: hello@snackseo.com (privacy requests, data protection questions, security reports, and all other legal matters)

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy matters are handled by our management, reachable at the address above.

Right to complain. If you are unhappy with how we have handled your personal data, please contact us first — we would like the chance to fix it. You also have the right to complain to a supervisory authority:


Snack SEO is a product of Snack Prompt Corp. See also our Terms of Service, Data Processing Agreement, Sub-processors and Acceptable Use Policy.