Who runs SearchSeal
Nusantara Ventures, LLC (“we”, “us”) runs SearchSeal and is the controller of the personal information covered by this policy. It covers visits to searchseal.com and use of the SearchSeal app: what we collect, how we use and share it, how long it stays and your choices. Please also read our Terms of service.
How the service works
SearchSeal puts the questions you track about your brand to AI assistants. It saves their answers and cited sources, suggests page changes and compares results before and after. Every plan checks every tracked question daily on Google AI Overviews, ChatGPT, Gemini and Perplexity. Bright Data collects answers from the ChatGPT, Gemini and Perplexity apps and the AI Overview shown on a Google search, asking from each question’s chosen country. If an app answer cannot be collected that day, ChatGPT, Gemini and Perplexity may fall back to provider APIs through OpenRouter; Perplexity uses its own Sonar API. Only AI Overviews has no fallback, so an unavailable answer stays unchecked. When Google shows no AI Overview, we record no overview, not a missed brand. Answers are dated samples that vary between runs, locations and accounts, not rankings. Before sending data to a new provider, we update this policy. Connecting Google Search Console or Bing Webmaster Tools is optional.
Data we collect
Account details: We collect your email address and time zone. Google sign-in also shares your name and profile picture. If you sign up with an email and password, we keep a secure password hash. We record your role, goal, company and website if you provide them during setup. We also record your plan, billing status and the versions of the terms and this policy you accepted, including the time of acceptance.
Brand details: We collect the websites you add and the details you enter or confirm: brand name, domain, description, industry, markets, tracked questions and rivals you choose for comparison.
Pages on the public web: We read public pages on your site, such as its homepage or a page covered by a suggested fix. We also read public pages cited in AI answers.
Answers from AI assistants: We collect responses to your tracked questions, the brands named, the sources cited and our analysis of those responses.
Optional Google Search Console connection: Connecting Search Console lets us request read-only access (webmasters.readonly). We read your available properties and daily search performance for the property you select: queries, pages, clicks, impressions, click-through rate and average position. We also read page index status through Google’s URL Inspection tool. We store daily performance rows for each query and page, totals, index results and the email address of the connected Google account. A stored refresh token maintains the connection.
Optional Bing Webmaster Tools connection: Connecting Bing lets us request read-only access (webmaster.read). We read and store your site’s daily traffic, query and page statistics. We also store a refresh token.
Payment details: Stripe handles payments and collects your card details, billing address and optional tax ID. We keep your Stripe customer and subscription IDs, plan and billing status. Your card number is never visible to us or stored by us.
Details from the free check: We keep the domain and brand you submit and the referring page. Your IP address is used to limit abuse.
Messages and technical records: We collect the messages you send us. For security and troubleshooting, we keep records of IP addresses, browsers, pages requested and errors.
Customer email: We use your email address and the account, billing and brand information needed for each message. This includes your plan, price, renewal and trial dates, payment and cancellation status, data deletion details, scan results, visibility numbers, suggested actions, completed fixes and changes in AI answers. We record your choices about product tips and weekly reports so we can respect them. We may record whether each email was delivered, opened, clicked or bounced to keep delivery working. We also collect replies you send us.
API access tokens: For each token you create, we keep its hash and last use time. We never store the token itself.
What we use data for
- Providing SearchSeal: signing you in, running checks, displaying results and suggested fixes, and sending account emails about trial endings, failed payments, plan activation, cancellation, upcoming data deletion and completed account data deletion. Failed-payment dates count from the first failed charge of the unpaid invoice. We send a notice on day 0, put your account in read-only mode and explain how to update your card. Stripe retries for up to 14 days. If it stays unpaid, we send a reminder on day 7 and a final notice on day 12. Your plan is canceled on day 14, or on Stripe’s own later retry date. Your data is scheduled for deletion after day 30 following the first failed charge, whether or not you have ever paid, subject to the effective date and notice rules under “How long data stays”. The final notice gives both dates. When Stripe cancels your plan after the retries fail, we send a cancellation notice saying payment could not be collected and giving the cancellation and data deletion dates. Updating your card and paying before cancellation keeps your plan and data. This failed-payment sequence stops as soon as payment succeeds, and full access returns. Subscribing again before the deletion date keeps your data. We email at least 48 hours before deletion, allow the full 48 hours and check again for a live subscription immediately before deleting. Dates in our emails are shown in your time zone, for example “October 30”. These emails are needed to run your account. Stripe sends its own payment receipts.
- Sending optional product tips: a first-results summary after your first scan; a note two days after signup, if you have a plan, with the setup steps you have not done yet (connecting Google Search Console, tracking more questions, connecting an AI agent); and, if you signed up but have not chosen a plan, reminders one and three days after signup that your setup is saved. Each is sent at most once and only within a week of its triggering event.
- Sending an optional weekly report for each brand on Mondays, with its visibility numbers, top actions, completed fixes and changes in AI answers.
- Sending optional change alerts, at most once a day, when a rival overtakes your brand in AI answers, your brand drops out of an answer, or a fix starts working. Alerts follow your weekly report choice, and the same change is not repeated within 14 days.
- Showing a read-only report you choose to share. When you create a share link for a brand, anyone with the link can see that brand's visibility numbers, the rivals named most, each tracked question marked as named or not named per AI tool, and fixes that worked, until you turn the link off. Shared reports never include answer text, cited sources, Search Console or Bing data, or your account details, and they're marked so search engines don't list them.
- Keeping email delivery working using per-email delivery, open, click and bounce records, and applying your unsubscribe choices.
- Charging for your plan through Stripe.
- Protecting SearchSeal, preventing abuse and resolving problems.
- Improving SearchSeal with aggregated information that does not identify you.
We do not sell personal information or use your data for advertising.
Grounds for processing
Our contract with you is the basis for processing account, brand and billing information. Our legitimate interest in a safe service covers security records and abuse prevention. We keep billing records to meet legal obligations. We process Search Console and Bing data only with your authorisation; disconnecting withdraws it. Business customers can email support@searchseal.com to request a data processing agreement.
We process the information needed to send account emails to perform our contract with you. We rely on our legitimate interest in helping customers use SearchSeal to send optional product tips, weekly reports and alerts. You can opt out of any of them with one click. We rely on our legitimate interest in keeping email delivery working to process delivery, open, click and bounce records. Unsubscribing from tips or reports does not stop account emails.
Use of Google data
- Search Console data is used only to display your own search performance, suggest questions to track, and rank and check fixes for your site.
- SearchSeal itself never sends Search Console queries to AI models. A built-in template suggests questions from them. Only questions you confirm are tracked, then sent to your plan’s AI assistants. If you connect your own AI assistant or tool via API or MCP with an access token you create, we return your Search Console queries, pages, clicks, impressions, positions and resulting search fixes when it asks. Its provider handles data under its own terms. Revoking the token stops access immediately.
- We do not sell Google user data or use it for advertising. We transfer it only to the service providers listed below, as needed to operate SearchSeal.
- People at SearchSeal read your Google data only when you ask us to read it for support, when needed for security or an abuse investigation, or when required by law.
- Disconnect Search Console whenever you wish in Integrations. We immediately delete its refresh token and stop imports. Data already imported stays with the brand until you delete the brand or account, or request earlier deletion. To revoke access through your Google Account, visit myaccount.google.com/permissions.
Service providers and disclosure
We share information only with providers that help run SearchSeal. Each receives only what it needs:
- Supabase provides our database and sign-in. It stores all account and product data in Singapore.
- Cloudflare hosts and delivers the site and app, receiving requests to both.
- Stripe handles payments using the billing details you submit to it.
- Google handles sign-in and Search Console, receiving your sign-in and authorised requests. The app loads brand and rival icons through Google’s favicon service. That service receives your IP address and the domains displayed.
- Microsoft receives your authorised requests through Bing Webmaster Tools.
- Bright Data (Bright Data Ltd., Israel) receives only the tracked question text exactly as you wrote it, which may include brand and rival names, and its country. It submits each question to the apps listed above as if from that country and returns the answer and its sources. We never send it account, billing or Search Console data.
- OpenRouter (OpenRouter, Inc., United States) routes ChatGPT, Gemini and Perplexity API fallback requests to OpenAI, Microsoft Azure, Google or Perplexity (Perplexity AI, Inc., United States). We also use OpenAI models through OpenRouter to detect tone and named brands, draft suggested fixes, help with setup and run the free website check. These internal tasks use only OpenAI and Microsoft Azure, which do not train on prompts. We send question text, brand and rival names, plus answer text and short excerpts from public pages for internal tasks. We never send account, billing or Search Console data. OpenRouter and the routed providers’ business terms prohibit training on this data.
- Resend is our email delivery provider and processes email on our behalf as a processor or subprocessor, as applicable. It receives your email address and message content to send account emails, product tips, weekly reports and alerts. Delivery, open, click and bounce events may be recorded per email to keep delivery working.
Personal notes come from a SearchSeal team address at searchseal.com, records from SearchSeal <hello@searchseal.com>, and weekly reports and alerts from SearchSeal Reports <reports@searchseal.com>. We may use mail.searchseal.com as a sending subdomain. Replies reach a person.
We may also share information to meet legal requirements or protect rights and safety. Information may pass to another business in a merger or sale of the business, with the same protections.
How long data stays
- We keep account and brand data, AI answers, fixes and before-and-after results until you delete the brand or account, or until automatic deletion after your plan ends. When your plan ends, we keep your brands, scan results, saved fixes and before/after proof for 30 days, then delete them. This applies to every account, whether or not it has ever paid. For voluntary cancellation, including a free trial, the plan ends when access ends at the end of the paid period or trial. For failed payments, deletion is scheduled for after day 30 following the first failed charge of the unpaid invoice. Updating your card and paying before the plan is canceled keeps your plan and data. Subscribing again before the deletion date keeps your data. We email at least 48 hours before deletion and never delete without sending that notice and allowing the full 48 hours. A late notice moves deletion later. Immediately before deleting, we check again that there is no live subscription. This data-deletion rule applies only to plans that end on or after the version 3.3 effective date, the day customer email is switched on. Data from plans that ended earlier is not affected by this rule.
- Deleting a brand immediately stops its checks and data imports. The brand is archived for 30 days, during which you can restore it. After that, it is permanently deleted.
- Search Console and Bing data stay until you delete the brand or account, unless you request deletion sooner.
- We keep refresh tokens until you disconnect. API token hashes stay until account deletion. Revoking an API token stops it working immediately.
- Deleting your account in Settings immediately removes your brands and profile. Your sign-in record, consisting of your email address and sign-in method, remains until you request its deletion at support@searchseal.com.
- We email a confirmation after your account data is deleted.
- We keep a record of which email was sent to which account and when, together with its delivery events, such as delivered, opened, clicked or bounced. These records stay with your account and follow its normal deletion cycle: they are deleted when your account data is deleted, either when you delete your account or through automatic deletion after a plan ends under the rule described above.
- Resend, our email delivery provider, keeps email data — content, metadata, delivery status and events, and logs — for 30 days on every plan below Enterprise. Enterprise plans allow flexible retention.
- We retain IP addresses used for abuse limits for up to 31 days.
- We retain billing records for the period required by tax and accounting law.
- Technical records and backups are removed on their normal deletion cycle.
How we protect data
Our infrastructure providers encrypt data in transit and at rest. Only our servers can read the database tables holding connection tokens. Absolute security cannot be guaranteed: no system is completely secure.
Choices and data rights
Product tips, weekly reports and alerts include one-click unsubscribe links, including the List-Unsubscribe option in email apps that support it. You can stop product tips, weekly reports and alerts for one brand, or weekly reports and alerts for all your brands. Unsubscribing from tips or reports does not stop account emails about your trial, plan, payments, cancellation or data deletion. Those emails are needed to run your account and cannot be unsubscribed from. Contact support@searchseal.com if you need help.
At any time, you can edit your account or brands, disconnect integrations, delete a brand or delete your account in Settings. Your rights depend on where you live. Under laws including the EU and UK GDPR and Indonesia’s Personal Data Protection Law (Law 27/2022), you may be entitled to access, correct, delete or obtain a copy of your data, object to or restrict some processing, and complain to a data protection authority. Contact support@searchseal.com to exercise these rights or request a copy. We may need to check your identity. We respond within 30 days.
Processing across borders
Nusantara Ventures, LLC is a Delaware company operated from Indonesia. We use a database in Singapore and hosting on Cloudflare’s global network. Our providers process data in the United States (OpenRouter and the routed providers), Israel (Bright Data) and other locations. Where legally required, we use safeguards such as our providers’ European Commission standard contractual clauses.
Cookies and browser storage
We use cookies only to keep you signed in. Browser storage holds your preferences, such as light or dark mode and fonts, and unfinished setup. SearchSeal loads no third-party analytics, advertising or session-recording tools.
Age requirement
SearchSeal serves businesses and is not for anyone under 18.
Policy updates
Updates appear on this page with a new version and date. Before material changes take effect, we notify you by email or in the app.
Get in touch
Write to: support@searchseal.com
Postal address:
Nusantara Ventures, LLC
1401 Pennsylvania Ave STE 105 #1776
Wilmington, DE 19806, United States