S
Seonis
Privacy policy
Last updated 3 September 2026
This describes what Seonis collects, why, and what we do with it. It is written to be
read rather than to be survived, and it describes the system as it actually works
today — where something is not built yet, it says so.
Who we are
Seonis is operated by Fleeta Limited, registered in England and Wales.
For data protection purposes we are the controller of your account data, and the processor
of the data you connect to us about your own website and its visitors.
Contact: accounts@fleeta.co.uk.
What we collect
- Account information
- Your name, email address, chosen interface language, and a hashed password. If you subscribe, our payment processor holds your card details; we never see or store them.
- Information about your website
- The domain, the pages listed in your sitemap, and the business profile you write — what you do, who you sell to, your tone of voice, your competitors. This is what the writer uses, so a thin profile produces generic articles.
- Google Search Console data, if you connect it
- Read-only. Impressions, clicks, average position and the search queries your site is shown for. We use it to report performance and to find phrases you are already shown for but rarely clicked on, which become article topics.
- Google Analytics data, if you connect it
- Read-only. Session and user counts by channel. We never receive individual visitor identifiers and do not attempt to identify your visitors.
- Content we generate for you
- Articles, keyword lists, and the quality reports behind them, including which model wrote each stage and what it cost.
- Link exchange records
- If you take part, we record every link proposed, approved, placed and verified, along with the full reasoning behind each match. You can see all of it.
- Operational logs
- Standard web server logs, including IP address, kept for troubleshooting and security.
Google user data
Seonis's use and transfer of information received from Google APIs to any other app will
adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
In plain terms, and specifically:
- We request read-only scopes only. We cannot change anything in your Search Console or Analytics, and we do not ask for permission to.
- We use the data to provide the reporting and keyword features you can see in your dashboard, and for nothing else.
- We do not sell it, and we do not use it for advertising.
- We do not use it to train machine learning models, our own or anyone else's.
- No human at Seonis reads it, except where you explicitly ask us to look at something, or where we are legally required to.
- You can disconnect at any time in Settings, which revokes our token. You can also revoke access from your Google account directly.
Who else processes your data
We use a small number of sub-processors. Article text and the business profile it is
written from are sent to model providers so the article can be written.
- OpenAI — article writing, keyword research, quality checks. Sent under their API terms, which exclude API content from training.
- Google (Gemini API) — the same tasks, on the cheaper stages. Note that a Gemini API key on Google's free tier permits Google to use the content; our production keys are on paid billing, where it does not.
- OVH — hosting, in the European Union.
- Cloudflare — domain registration and DNS.
Your Search Console and Analytics figures are not sent to model providers. They are
used to produce charts and to rank keyword opportunities, both of which happen on our own
servers.
Where your data lives
On servers in the European Union. Model providers may process content outside the EU,
including in the United States, under the transfer mechanisms in their own terms.
How long we keep it
- Account and content data: while your account is open, and for 30 days after you close it, so an accidental cancellation can be undone.
- Link exchange records: for as long as a placed link is live, plus one year, because both parties are entitled to a record of what was agreed.
- Server logs: 90 days.
- Invoices: seven years, as UK tax law requires.
Your rights
Under UK and EU data protection law you can ask for a copy of your data, ask us to correct
or delete it, object to processing, or ask us to send it elsewhere. Write to
accounts@fleeta.co.uk
and we will respond within one month. If you are unhappy with our answer you can complain to
the Information Commissioner's Office in the UK, or your national supervisory authority in
the EU.
Cookies
We set one session cookie so you stay signed in, and one cookie carrying the token that
protects forms against cross-site request forgery. Both are strictly necessary for the
service to work, so we do not ask for consent for them. We do not use advertising or
analytics cookies on this application.
Security
Traffic is encrypted in transit. Credentials for your website and your Google tokens are
encrypted at rest, and are not readable from the interface once saved. Access to production
is restricted to named administrators.
Changes
If we change this policy in a way that affects you, we will email you before it takes
effect. The date at the top of this page always reflects the current version.