Privacy Policy
Last updated: August 15, 2026 · Türkçe sürüm: /gizlilik
Summary
- We access your Search Console data read-only and never modify it.
- We never sell your data, use it for advertising, or share it with third parties.
- Your data is never used in other customers' analyses or to train AI models.
- Google access tokens are stored encrypted (AES-256-GCM).
- You can disconnect Google access or delete your account at any time.
1. Google User Data
SEO Kokpit requests the webmasters.readonly scope to read your Google Search Console data (queries, clicks, impressions, positions, site list). This scope is read-only: we cannot change, add or remove anything in your Search Console account. We use this data solely to show your performance in your dashboard, to detect SEO opportunities and issues, and to generate reports and content recommendations for you.
2. Limited Use Disclosure
SEO Kokpit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google user data to provide user-facing features of SEO Kokpit; we do not transfer it to third parties except as necessary to provide the service, comply with law, or as part of a merger/acquisition with prior notice; we do not use it for advertising; and we do not allow humans to read it except with your consent, for security purposes, or to comply with law. Google user data is not used to train generalized AI or machine-learning models.
3. What We Store
Account information (email, name), encrypted OAuth tokens, Search Console query summaries needed for your dashboards, content items you create, and subscription/billing status. Payment card data is processed by iyzico and never touches our servers.
4. AI Processing
Content generation uses Anthropic's Claude API. Only the minimum context needed for your request (keyword, brief, your brand settings) is sent for processing; outputs are stored in your account. Your data is not used to train models.
5. Data Retention and Deletion
You can revoke Google access anytime from Settings (or from your Google Account permissions page) — revoked tokens are invalidated and marked deleted. When you delete your account, your personal data and stored Google data are deleted from our systems within 30 days. To request deletion, use the dashboard or email us.
6. Security
Tokens are encrypted at rest with AES-256-GCM; the encryption key lives only in the application environment, not in the database. Access is protected by row-level security; all traffic uses TLS.
7. Contact
Data controller: ADVİSERLAB YAZILIM PAZARLAMA LİMİTED ŞİRKETİ, Şehit Muhtar Mah. Mis Sk. No: 24 İç Kapı No: 28, Beyoğlu / İstanbul. hello@adviserlab.co. Turkish data protection (KVKK) disclosure: /kvkk.