Security & data handling
Client data stays behind the API. The browser never talks to the database directly. Here’s how we keep the Flight Deck locked down.
API-only access
All reads and writes go through our authenticated API. Database and file storage are deny-by-default — the marketing site and app UI don’t hold direct data-store credentials. Live progress is polled through the API, not a client-side database listener.
What we collect to run the product
Account details (name, email), the workspaces and clients you create, site and competitor URLs you choose to analyze, and technical logs for security and debugging. We retrieve publicly accessible page content from the sites you add so we can score and audit them.
Google Analytics & Search Console
When you connect Google Analytics or Search Console, OAuth stays on-domain. Tokens are stored server-side and used only to read the analytics and search data for the properties you connect — never exposed to the browser.
AI processing
Analyses, recommendations, briefs, reports, and proposals use third-party AI providers as processors. We send the data needed to generate those outputs; we do not sell your data. Details live in the Privacy Policy.
Subprocessors (high level)
We rely on cloud infrastructure (hosting, authentication, database, storage), AI providers for generation, performance-measurement providers, and — only when you connect them — Google Analytics and Google Search Console. We may also use keyword-research and email-delivery providers to operate the service. Each processes data only to provide its function.
Encryption & access
Data is encrypted in transit. Access to production systems is restricted. Connected-account tokens stay server-side. No method of transmission or storage is 100% secure, but we design for least privilege and deny-by-default data access.
Questions
Privacy requests: privacy@marketpilotseo.com. Product or BETA questions: hello@marketpilotseo.com or contact us.
