Privacy Policy
Last updated: June 18, 2026
1. Who we are
CommandSEO ("we", "us") is operated by Dick-Jay Bustamante, a sole proprietor (registered individual) based in Antipolo City, Philippines. For privacy questions, contact support@commandseo.app.
2. Data we collect
- Account data — name, email, and password (stored hashed).
- Connected-site data — Google Search Console / Analytics data you authorize, used to analyze your sites.
- Usage data — how you use the app (commands, credits, tasks), to operate and improve the service.
- Billing data — handled by our payment processor and merchant of record, Lemon Squeezy. We do not receive or store your full card details.
- Technical data — IP address, browser, and cookies needed to keep you signed in.
3. How we use your data
- To provide the service: analyze your sites, generate plans, and verify pages.
- To authenticate you and keep your session secure.
- To process payments and manage your subscription.
- To send service communications (e.g. account, security, and billing notices).
- To send marketing emails only if you opt in. You can opt out at any time using the unsubscribe link in those emails or by contacting us.
4. Third parties we share with
We share data only with providers needed to run CommandSEO (our "sub-processors"). The current list, with locations and safeguards, is at commandseo.app/sub-processors:
- Google (Search Console and Analytics — one connection grants both): Search Console search queries, click/impression counts, average position, and page URLs; and, for sites where a matching GA4 property is found, your GA4 property list and the report metrics (e.g. sessions, pageviews, engagement) our features request.
- Anthropic — to power AI analysis. We send the page content and site data needed to perform the analysis you request; it is used to generate your results, not to train Anthropic's models.
- DataForSEO — for SEO data lookups.
- Lemon Squeezy — payment processing.
- Hetzner — cloud infrastructure and hosting.
5. Google user data — Limited Use
Connecting your Google account grants CommandSEO both Search Console and Analytics access in one step. We access: Search Console search queries, click/impression counts, average position, and page URLs for your connected properties; and, for sites where a matching GA4 property is found, your GA4 property list and the report metrics (e.g. sessions, pageviews, engagement) our features request. We use this data only to provide and improve the user-facing features you request — analyzing your sites, generating SEO plans, and verifying pages.
We do not store this Search Console / Analytics data separately — we fetch it from Google live each time a feature needs it, and use it in that moment to generate your analysis, reports, and tasks (which are retained as described in Section 8). The only Google-specific data we store is the OAuth access/refresh tokens (encrypted — see Section 6), for as long as the connection stays active.
CommandSEO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- Use Google user data only to provide or improve the features you authorized.
- Do not transfer or sell Google user data for advertising, marketing, or any other purpose.
- Do not use Google user data to train generalized AI/ML models. Data sent to our AI provider is used only to perform the specific analysis you request, not to train models.
- Do not allow humans to read your Google user data, except: with your explicit consent (e.g. to resolve a support issue), where required by law, or where the data has been aggregated and anonymized for internal operations such as security and abuse prevention.
6. Deleting or revoking access to Google data
You stay in control of the Google data you connect:
- Disconnect in-app — removing a connected Search Console / Analytics property deletes the stored access and refresh tokens for that connection.
- Revoke at Google — you can revoke CommandSEO's access at any time from your Google Account permissions page.
- Delete your account — closing your account deletes the Google data and tokens associated with it, subject to the retention period below.
- To request deletion of your Google user data, contact support@commandseo.app.
OAuth tokens for Google connections are stored encrypted at rest and are never exposed to your browser or to other tenants.
7. Cookies
We use a small number of essential cookies (e.g. your session cookie and a CSRF token) to keep you signed in securely. We do not use advertising cookies. See our Cookie Policy for details.
8. Data retention
We keep your data for as long as your account is active, then delete it within 30 days after closure, unless law requires us to keep it longer.
9. Your rights
Under the Philippine Data Privacy Act of 2012 (and the GDPR where applicable), you may access, correct, export, or delete your data, and object to certain processing. Contact support@commandseo.app to exercise these rights. You may also complain to the National Privacy Commission (Philippines).
10. Security
We protect your data with encryption in transit, hashed passwords, tenant isolation, and OAuth tokens encrypted at rest. No system is perfectly secure; we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy; we will notify you of material changes by email and an in-app notice. Continued use means acceptance.
12. Contact
Questions? Email support@commandseo.app.