Scope
This policy applies to SearchSignal's public website, product application, account and token-management surfaces, MCP service, HTTP API, and related support interactions. It does not govern third-party AI clients, hosting providers, analytics products, payment processors, search-data providers, or websites analyzed through the service.
Information you provide
Depending on the production implementation, SearchSignal may process account identifiers, authentication details, project domains, URLs, saved research, token metadata, support messages, billing records, and configuration choices. Secret tokens should be stored in protected form and displayed only as required for creation, rotation, and administration.
Information generated through use
The service may create technical logs, request metadata, audit results, keyword and competitor research, rankings, backlink context, Search Console-derived data, content briefs, tool-call records, usage limits, error events, and security signals. Logs should avoid recording full credentials or unnecessary customer content.
How information is used
Information may be used to provide and secure the service, authenticate requests, authorize project access, generate requested analysis, enforce limits, improve reliability, troubleshoot problems, communicate about the account, process billing, prevent abuse, and comply with legal obligations.
Service providers and integrations
SearchSignal may rely on infrastructure, authentication, analytics, billing, email, search-data, backlink, and AI service providers. Customers may also connect third-party clients such as coding agents or chat systems. Each third party has its own terms and privacy practices, and customers should review them before connecting sensitive projects.
Retention and deletion
Production retention periods should be defined by data type and operational need. Account data, project data, audit history, usage logs, billing records, and security events may require different schedules. Provide a documented process for account closure, project removal, token revocation, and legally required retention.
Security
Use reasonable administrative, technical, and organizational safeguards appropriate to the service, including transport encryption, access controls, secret handling, authorization checks, logging controls, dependency management, and incident response. No online service can guarantee absolute security.
Choices and rights
Users may be able to update account information, remove projects, disconnect integrations, rotate or revoke tokens, change communication preferences, and request access, correction, export, or deletion where applicable. The final policy should explain the verified request process and jurisdiction-specific rights.
Contact and changes
Publish the production support and privacy contact before launch. Material policy changes should be dated and, when appropriate, communicated through the application or account email.