Privacy Policy
Last updated: April 2026
1. Who we are
Autopilot SEO is operated by Diamond Internet ("we", "us", "our"). If you have any questions about this policy or how we handle your data, contact us at hello [at] autopilotseo.app.
2. What data we collect
- Account data: your email address when you sign up.
- Project data: website URLs and project names you enter.
- Analysis results: SEO scores and issue data generated when you run an audit.
- Keywords: any keywords you add to track rankings.
- GitHub integration: if you connect a GitHub repo, we store an encrypted access token and the repo name. We never store your GitHub password.
- Usage data: page requests and error logs handled by our hosting provider (Netlify).
We do not collect payment card data directly — payments are handled by our payment processor.
3. How we use your data
- To provide the Autopilot SEO service and your account.
- To run SEO audits on the URLs you submit.
- To track keyword rankings on your behalf.
- To send transactional emails (password resets, account notices).
- To improve the service and fix bugs.
We do not sell your data, share it with advertisers, or use it for any purpose beyond operating this service.
4. Lawful basis for processing (GDPR)
- Contract performance: processing your account and project data to deliver the service you signed up for.
- Legitimate interests: maintaining service security and stability.
- Legal obligation: retaining records as required by applicable law.
5. Third-party services
We use the following sub-processors to operate the service:
- Supabase — database and authentication. Data stored in the EU (Ireland). Privacy policy
- Netlify — website hosting. Privacy policy
- Firecrawl — used to scrape URLs you submit for analysis. Only the URL you request is sent; no personal data is transmitted.
- DataForSEO — used to retrieve domain authority and backlink data for URLs you submit.
- Google PageSpeed Insights API — used to retrieve performance scores for URLs you submit.
- GitHub — only if you choose to connect your repo. We only access repositories you explicitly authorise.
6. Cookies
We use only essential cookies necessary for the service to function:
- Session cookie (sb-* / supabase-auth-token): keeps you signed in while using the app. Expires when you sign out or the session times out.
- Theme preference: stored in localStorage (not a cookie), remembers your dark/light mode preference.
We do not use advertising cookies, tracking pixels, or any third-party analytics cookies.
7. Data retention
We keep your data for as long as your account is active. If you delete your account, all your project data, analyses, and keywords are permanently deleted within 30 days. Anonymised, aggregated usage statistics may be retained indefinitely.
8. Your rights
Under GDPR (and equivalent legislation), you have the right to:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your account and data.
- Portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interests.
- Restrict — ask us to suspend processing of your data.
To exercise any of these rights, email us at hello [at] autopilotseo.app. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. International transfers
Some of our sub-processors (Firecrawl, DataForSEO, Google) may process data outside the UK/EU. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions.
10. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes by email or by a prominent notice in the app. The date at the top of this page shows when it was last revised.