Skip to content
Trust

Privacy Policy

What we collect, why we collect it, and the controls you have — in plain language.

Last updated 20 July 2026

Read
Collection

What We Collect.

Who we are, the categories of data we hold, and the cookies that keep you signed in — aligned with the EU GDPR and Türkiye's KVKK (Law No. 6698).

Who We Are

Octolyze (“we”, “us”) operates a cloud technical SEO audit platform. For the purposes of the GDPR and KVKK, we are the data controller for the personal data described in this policy. You can reach us at [email protected].

Data controller: Octolyze Technology Inc. · Mimar Sinan Mah. 307. Sok. No:2, Atakum / Samsun, Türkiye · Tax No: 0671007700

Data We Collect

We collect a handful of categories, and no more than we need to run the Service:

  • Account data — name, email address, hashed password, role/plan, and account preferences.
  • Audit & crawl data — Target Site URLs you submit, and the technical metadata we retrieve (status codes, titles, meta tags, headings, links, response times, sitemaps, resources). We do not intend to collect personal data from crawled pages, but public pages may contain some.
  • Usage data — actions in the app, feature usage, device/browser type, IP address, timestamps, and diagnostic logs.
  • Billing data — plan, subscription status, and limited transaction details. Card details are handled by our payment processor — we do not store full card numbers.
  • Communications — messages, support requests, and feedback you send us.
  • Cookies — session and preference identifiers (see “Cookies & Tracking” below).

Cookies & Tracking

We use a small number of cookies and similar technologies that are strictly necessary to sign you in and remember your preferences (for example, an authentication token stored in your browser). Where we use any non-essential analytics, we will ask for consent as required by law and you can manage your choices. We do not sell your data or use it for cross-site advertising.

Usage

How We Use Your Data.

The purposes we process data for, the legal bases behind them, and the extra care we take with crawled sites, connected Google accounts, and shared reports.

How We Use Data

We use the data we hold to:

  • Provide, operate, and maintain the Service (run crawls, generate scores and reports, enable sharing);
  • Authenticate you, secure accounts, and prevent fraud or abuse;
  • Process subscriptions, billing, and renewals;
  • Provide support and respond to your requests;
  • Improve, troubleshoot, and develop features (using aggregated or minimized data where possible);
  • Send service and transactional messages, and — with your consent where required — product updates;
  • Comply with legal obligations and enforce our Terms.

Legal Bases

Where the GDPR/KVKK applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, improve, and operate the Service, balanced against your rights); consent (e.g., certain cookies or marketing, which you can withdraw); and legal obligation (e.g., tax and accounting).

Data From Sites You Crawl

When you submit a Target Site, we crawl it on your instruction and store technical results in your account. With respect to any personal data contained in the pages you crawl, you act as the controller and we act as a processor on your behalf; you are responsible for having a lawful basis and the right to crawl and analyze that site. We process such data only to provide the Service to you.

You must only crawl websites you own or are authorized to analyze. Do not use Octolyze to collect personal data unlawfully.

Google Search Console & Analytics Data

Octolyze can connect to your Google Search Console and Google Analytics 4 accounts. The connection is optional, is made only when you start it yourself from the Integrations screen, and can be undone at any time. This section describes exactly what we request, retrieve, store, share and do with data received from Google APIs.

Scopes we request. Both API scopes are read-only — Octolyze cannot create, change or delete anything in your Google account:

  • Search Console (https://www.googleapis.com/auth/webmasters.readonly) — to list the properties your Google account is verified for, so you can pick the one that matches your project, and to run Search Analytics queries for that property. Why not narrower: Search Console publishes no read scope below this one. The alternative, webmasters, is broader — it adds write access to sitemaps and property settings, which Octolyze neither needs nor wants.
  • Analytics (https://www.googleapis.com/auth/analytics.readonly) — to list the GA4 properties your account can read, so you can choose one, and to run reports against the property you link. Why not narrower: this is the narrowest scope covering both calls. The Admin API is the only way to discover which properties you can read, and the Data API serves the reports. Google publishes no per-property or report-only read scope, and the alternatives (analytics.edit, analytics.manage.users) grant write access we do not need.
  • openid and email (https://www.googleapis.com/auth/userinfo.email) — requested only so the connection can be labelled with the Google address it belongs to (“connected as [email protected]”) and so two connected accounts can be told apart. They are never used to sign you in to Octolyze and never used for authorisation.

Search Console and Analytics are connected separately, and you can connect either without the other. If you connect both with the same Google account, Google carries the earlier grant forward onto the same credential, so the two integrations share one encrypted refresh token. Disconnecting removes that credential and both integrations with it.

What we retrieve from Search Console, for the property you link and the date window you choose: search queries and page URLs with their clicks, impressions and average position; the same figures by day and per page per day; the device split (desktop, mobile, tablet); the country breakdown; and the totals for the preceding equal-length period, so the dashboard can show a comparison.

What we retrieve from Analytics, for the property you link and the date window you choose: landing pages and channel groupings with sessions, engaged sessions, new users, key events, revenue and engagement duration; the same figures by day; device category, browser and screen resolution; country, city and language; site-search terms typed into your own site’s search box; and the referring source of sessions that arrived from an AI assistant. These are aggregated reports — Octolyze never exports user-level or event-level rows.

We do not request or store demographic data. Age, gender and interest dimensions are never asked for, never received and never stored — the integration has no code path that reads them.

Where it is stored, and for how long. The figures above are stored in our own database, keyed to your Octolyze account and to the project you linked, alongside the Google account address, the scopes you granted and which property is linked. Each sync replaces the stored copy for that date window rather than adding to it, so we hold the most recent pull and not a growing archive. We keep it while your account is open and the integration is connected. It is deleted immediately when you disconnect the integration, and within 30 days when you close your account or ask us to delete it at [email protected].

How the credentials are protected. The refresh token Google issues is encrypted with AES-256-GCM before it is written, using a key held in the server’s environment and never stored in the database — so a database backup on its own yields nothing usable. Short-lived access tokens are held in memory only: never written to the database or to disk, discarded when the server restarts, and cleared the moment you disconnect.

How it is used, and who receives it. Google user data is used only to render your own dashboards, worklists and reports. We do not sell it and we do not transfer it to third parties for their own purposes. It is processed only by the infrastructure that runs Octolyze — our application servers and our PostgreSQL database, on servers we control and operated on our instructions. It is not sent to any analytics, advertising or AI provider, and it is not used to train machine-learning models. Publicly shared report links and reports sent to report members contain crawl findings only; no Search Console or Analytics figures are included in a shared or public report. No human reads your Google data except with your explicit permission, where necessary for security purposes such as investigating abuse, or where required by law.

Channel reporting shows paid channels alongside the rest, because that is how Google Analytics groups traffic. We never use any of it to build audiences or to target advertising.

Octolyze’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How to disconnect. Open Integrations in the app and choose Disconnect. This deletes the stored refresh token, the links between your projects and their Google properties, and the Search Console and Analytics figures already synced for those projects — in the same operation, so no data obtained from Google outlives the permission that allowed us to hold it. Projects linked through a different Google account are unaffected. Because the two integrations share one connection, this removes both at once. Reconnecting and re-syncing retrieves the data again from Google. You can also revoke our access directly at myaccount.google.com/permissions.

Shared Reports & Client Accounts

If you share a report via a public link or provision a Report Member account, the recipient can view the shared report. When you create a client account, we process that person’s name and email to give them access and to show you their status in your Clients (CRM). You are responsible for ensuring you may share this data with them.

Handling

Sharing, Transfers & Retention.

Who we share data with, how it crosses borders, how long we keep it, and the measures that protect it.

How We Share Data

We do not sell your personal data. We share it only with:

  • Service providers (processors) who help us run the Service — e.g., cloud hosting, database, email delivery, payment processing, and error/analytics tooling — under contracts that protect your data;
  • People you choose to share reports or accounts with;
  • Authorities where required by law, to comply with legal process, or to protect rights, safety, and the integrity of the Service;
  • A successor in a merger, acquisition, or asset sale, subject to this policy.

International Transfers

Our providers may process data in countries other than yours. Where we transfer personal data internationally, we use appropriate safeguards (such as Standard Contractual Clauses) and take steps consistent with the GDPR and KVKK to protect it.

Data Retention

We keep personal data for as long as your account is active and as needed to provide the Service. Crawl results are retained so you can compare audits over time and are removed when you delete them or close your account, subject to reasonable backup cycles. We keep certain records longer where required for legal, tax, or security purposes.

Security

We use technical and organizational measures to protect your data, including encryption in transit (HTTPS), hashed passwords (argon2id), scoped access controls, and session tokens that are never stored in plaintext. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your data and to notify you of significant incidents as required by law.

Control

Your Rights & Contact.

The rights you can exercise at any time, how we treat children's data, how we announce changes, and how to reach us.

Your Rights

Subject to applicable law (GDPR and KVKK Art. 11), you have the right to:

  • Access the personal data we hold about you and learn how it is processed;
  • Rectify inaccurate or incomplete data;
  • Erase your data (“right to be forgotten”) and delete your account;
  • Restrict or object to certain processing, and withdraw consent at any time;
  • Data portability, where applicable;
  • Lodge a complaint with a supervisory authority (in Türkiye, the KVKK Authority; in the EU, your local DPA).

To exercise your rights, email [email protected]. You can also update your profile or delete your account from within the app.

Children’s Privacy

The Service is not directed to children and is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (e.g., by email or in-app) and update the “Last updated” date above.

Contact

For any privacy question or to exercise your rights, contact us at [email protected].