XypherSEOXypherSEO
Legal

Privacy Policy

What we collect, why, and what you can do about it. In plain English.

XypherSEO Privacy Policy

Effective Date: 11 July 2026

Version: 2.0

Applies to: xypherseo.com, the XypherSEO WordPress plugin, and the XypherSEO Chrome extension

The short version

We collect the minimum we need to sell you a licence, keep it working, and support you.

We do not sell your personal data. We do not share it for advertising.

If you use our AI features with your own API key, your content goes straight from your server to Anthropic or OpenAI. It never touches our servers.

Freemius handles your payment. We never see your card number.

You can email Hello@xypherseo.com to see, correct, or delete what we hold about you.

The long version is below, and it is the one that legally counts.

1. Who is responsible for your data

XypherSEO ("XypherSEO", "we", "us", "our") is the data controller (called the Data Fiduciary under Indian law, and the body corporate under the SPDI Rules) for the personal data described in this policy.

1.1 Statutory entity details

Published as required by Section 12(3)(c) of the Companies Act 2013 and Rule 4(2) of the Consumer Protection (E-Commerce) Rules 2020.

Company name: XypherSEO

Website: xypherseo.com

Support email: Hello@xypherseo.com

Address: New Delhi, India

Contact for all privacy matters: Hello@xypherseo.com

The person designated to answer questions about the processing of your personal data, under Section 5 of the Digital Personal Data Protection Act 2023 and Rule 3 of the DPDP Rules 2025, is the XypherSEO Grievance Officer. Full details in Section 11.

If you are in the EU or the UK, see Section 12 for our representative and your right to complain to a supervisory authority.

1.2 Freemius is a separate controller

Freemius, Inc. is the merchant of record for every paid XypherSEO purchase. When you buy, Freemius collects and processes your billing data as an independent controller under its own privacy policy at https://freemius.com/privacy/.

We never receive or store your full card number. We receive from Freemius: your name, your email, your licence details, your site URL, your plan, and your subscription status.

2. What we collect, and why

We have set this out as a table in prose, because the law now requires an itemised notice, not a vague paragraph. Each item tells you what we collect, why, and on what legal basis.

2.1 When you visit xypherseo.com

What: IP address, approximate location from IP, browser and version, device type, operating system, referring URL, pages viewed, time on page, and standard HTTP request data.

Why: to run the website, keep it secure, and understand which pages work.

Basis: our legitimate interest in operating a secure website (necessary cookies and server logs), and your consent (analytics and marketing cookies).

Retention: server logs 90 days. Analytics per the retention setting of the analytics provider, currently 14 months.

2.2 When you buy a licence

What: your name, email address, country, licence key, plan, subscription status, site URL, and Freemius user ID.

Why: to give you the licence you paid for, validate it, deliver updates, and support you.

Basis: performance of our contract with you.

Retention: for the life of your licence, plus the period required by tax law (seven years in India, longer in some countries).

2.3 When you activate the plugin

What: your site URL, WordPress version, PHP version, active theme, active plugin list, and admin email.

Why: to validate your licence against the number of sites you paid for, deliver the correct update, and diagnose compatibility problems.

Basis: performance of our contract.

Note: additional usage analytics are collected only if you opt in to the Freemius tracking prompt during activation. If you decline, we collect only what is needed for licence validation and updates. You can change your mind at any time in the plugin settings.

Retention: for the life of your licence, plus 12 months.

2.4 When you use the AI features with your own API key

What: the specific content you ask the AI to work on. A title. A draft. A focus keyword. An image prompt. An audit result.

Where it goes: directly from your server to Anthropic (https://api.anthropic.com) or OpenAI (https://api.openai.com), using the API key you supplied.

What we get: nothing. This content does not pass through our servers and we do not store it.

Basis: performance of our contract, and your explicit action each time.

Your responsibility: you decide what to send. Do not send personal data of other people, confidential information, or anything you do not have the right to send. Their privacy policies apply, not ours: Anthropic at https://www.anthropic.com/legal/privacy and OpenAI at https://openai.com/policies/privacy-policy.

2.5 When you use the Chrome extension

What: the URL and page content of the tab you explicitly ask the extension to analyse, and your licence key (stored locally in Chrome storage on your own machine).

What we do not do: we do not read tabs you have not asked us to analyse. We do not run in the background on every site you visit. We do not transmit page contents to our servers.

Basis: performance of our contract, and your explicit action each time.

Retention: your licence key stays on your device until you remove the extension or sign out.

2.6 When you contact support

What: your email address, your name if you give it, the content of your message, and any screenshots, logs, or files you attach.

Why: to answer you and fix your problem.

Basis: performance of our contract.

Retention: 24 months from the closure of the ticket. If a dispute is live or reasonably anticipated, we keep the relevant records until it is resolved, and then delete them.

2.7 When you subscribe to our emails

What: your email address, where you subscribed from, the timestamp of your opt-in, and whether you opened or clicked.

Why: to send you what you asked for.

Basis: your consent. You can withdraw it at any time using the unsubscribe link in any email, or by emailing Hello@xypherseo.com. Withdrawing is as easy as subscribing.

Retention: until you unsubscribe. After that, we keep the record of your unsubscribe indefinitely, so we can prove we honoured it and so we never email you again by mistake. That is the only thing we keep.

2.8 When you join the affiliate program

What: your name, email, payment details, tax residency, referral traffic, referred sales, and commission balance.

Why: to run the program and pay you.

Basis: performance of our contract with you as an affiliate, and compliance with tax law.

Retention: for the life of the affiliate relationship, plus the period required by tax law.

2.9 What we never collect

We do not collect your full card number. Freemius does that.

We do not collect special category data (health, race, religion, political opinions, sexual orientation, biometrics, genetics). If you send us any in a support ticket, we will delete it and ask you not to.

We do not build behavioural profiles of individual users. We do not do automated decision-making that produces legal effects for you.

We do not sell your data. We do not share it for cross-context behavioural advertising. Under California law, this means we do not "sell" or "share" your personal information as those terms are defined in the CCPA as amended.

3. Who we share it with

We share only with the categories below, and only for the purposes described. We do not sell your data to anyone, ever.

Freemius, Inc. Merchant of record, licence platform, payment processing, update delivery. Independent controller. https://freemius.com/privacy/

Anthropic and OpenAI. Only when you use AI features with your own key. Only the content you send. Only at your action.

Hosting, CDN, and infrastructure providers. To run xypherseo.com and our update servers.

Analytics providers. Currently Google Analytics 4. Only where you have consented.

Email service providers. To send transactional and (where you have consented) marketing emails.

Helpdesk and support tooling. To manage your tickets.

Affiliate platform. Only if you are an affiliate.

Professional advisers. Accountants, tax advisers, and lawyers, under confidentiality.

Authorities. Where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend a legal claim. We will tell you unless we are legally prevented from doing so.

A successor. If XypherSEO is sold or merged, your data transfers to the buyer, who must honour this policy or give you notice and a choice.

Every processor we use is bound by a written contract requiring them to protect your data, process it only on our instructions, and impose equivalent obligations on any sub-processor. That is required by GDPR Article 28 and by Rule 6 of the DPDP Rules 2025, and we do it.

4. Where your data goes

XypherSEO operates from India. Freemius is in the United States. Our AI processing partners are in the United States. Our hosting, analytics, and email providers may be in India, the EU, the UK, or the United States.

So your data may be transferred outside your own country.

4.1 If you are in the EU, EEA, or UK

We transfer your data outside the EEA and the UK only where one of the following applies:

  • the destination has an adequacy decision from the European Commission or the UK government, or
  • we have put in place the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum), together with a transfer impact assessment and supplementary measures where the assessment requires them.

We rely on Standard Contractual Clauses for our transfers to India and the United States.

We do not rely on your consent as the basis for routine transfers, because consent is not a valid basis for systematic transfers under GDPR Article 49 and the EDPB has said so. We rely on Article 46 safeguards.

You can ask us for a copy of the safeguards we use. Email Hello@xypherseo.com.

4.2 If you are in India

Transfers outside India are made in accordance with Section 16 of the DPDP Act 2023 and Rule 15 of the DPDP Rules 2025, and are subject to any restrictions the Central Government notifies.

4.3 Everywhere else

We apply the same contractual safeguards to every transfer, whether or not your local law requires it.

5. How long we keep it

We do not keep data forever, and we do not keep it "just in case".

Server logs: 90 days.

Analytics: 14 months.

Licence and account data: life of the licence, plus 12 months.

Transaction and tax records: seven years from the end of the relevant financial year, as required by Indian tax law, and longer where the tax law of your own country requires it.

Support tickets: 24 months after closure. Longer only where a dispute is live or reasonably anticipated, and only for the records relevant to it.

Marketing consent records: until you unsubscribe.

Unsubscribe records: indefinitely, so that we can prove we honoured your request and never contact you again.

Affiliate records: life of the relationship plus the tax retention period.

When a retention period ends, we delete the data or irreversibly anonymise it.

Under Rule 8 of the DPDP Rules 2025 we will notify you at least 48 hours before erasing your data where the Rule requires it.

6. Your rights

You have rights over your data. Which ones depend on where you live, but we apply the following to everyone, everywhere, because it is simpler and fairer:

The right to know what we hold about you and why.

The right to get a copy of it.

The right to have it corrected if it is wrong.

The right to have it deleted.

The right to restrict what we do with it.

The right to object to processing based on our legitimate interests.

The right to withdraw your consent at any time, as easily as you gave it.

The right to take your data elsewhere in a usable format.

The right to complain to a regulator (see Sections 11 and 12).

The right not to be discriminated against for exercising any of these rights. We will not degrade your service, raise your price, or deny you features because you asked us for your data.

6.1 How to use them

Email Hello@xypherseo.com from the email address on your account. Tell us what you want. That is it.

We will respond within 30 days. If your request is complex we may take longer, and we will tell you why before the 30 days are up.

We may ask you to verify your identity before we act, because handing your data to someone pretending to be you would be worse than not handing it to you at all.

6.2 When we may refuse

We may refuse or partly refuse where:

  • we cannot verify your identity
  • the request is manifestly unfounded or excessive (for example, the same request repeated ten times)
  • complying would breach a legal obligation we have, or the rights of another person
  • we need the data to establish, exercise, or defend a legal claim

If we refuse, we will tell you why, and we will tell you how to complain about our refusal.

We will not charge you a fee, except for a manifestly unfounded or excessive request, and even then only a reasonable administrative fee where the law permits it.

6.3 Nominating someone else

If you are in India, you may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, under Section 14 of the DPDP Act 2023. Email us to do this.

7. Security

We use HTTPS everywhere, access controls, encrypted storage with reputable infrastructure providers, and the principle of least privilege.

We keep security logs for one year, as required by Rule 6 of the DPDP Rules 2025.

We require every processor we use to maintain equivalent safeguards, in writing.

No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can promise is that we take reasonable technical and organisational measures, and that we will tell you promptly if something goes wrong. See Section 8.

8. If there is a data breach

If a breach affects your personal data, we will:

Tell you, without undue delay, in plain language: what happened, what data was involved, what the likely consequences are, what we are doing about it, what you can do to protect yourself, and who to contact.

Tell the regulator: the Data Protection Board of India, within the timelines in Rule 7 of the DPDP Rules 2025, and a detailed report within 72 hours. Where GDPR applies, the relevant supervisory authority within 72 hours under Article 33.

We will not hide it, delay it, or minimise it. Failing to report a breach in India carries a penalty of up to 200 crore rupees, and it is also just wrong.

9. Children

XypherSEO is a professional tool for website owners. It is not for children.

You must be 18 or over to create an account or buy a licence. We ask you to confirm this at checkout.

We do not knowingly process the personal data of anyone under 18.

We do not track, monitor, profile, or serve behavioural advertising to children, ever. This is a prohibition under Rule 10 of the DPDP Rules 2025 and we apply it globally.

If you believe a child has given us data, email Hello@xypherseo.com and we will delete it.

10. Cookies

See the separate XypherSEO Cookie Policy.

In short: we do not set any non-essential cookie before you consent. Rejecting is as easy as accepting. You can change your mind any time using the Cookie preferences link in our footer.

11. If you are in India

India currently has two data protection regimes running side by side, and we comply with both.

The SPDI Rules 2011, made under Section 43A of the Information Technology Act 2000, are in force today. The DPDP Act 2023 and the DPDP Rules 2025 will replace them when their substantive provisions commence on 13 May 2027. Until then, both apply, and this section addresses both.

11.1 Compliance with the SPDI Rules 2011 (in force now)

Rule 4 of the SPDI Rules requires us to publish a privacy policy stating the types of information collected, the purpose of collection and use, our disclosure practices, and our security practices. Sections 2, 3, 4, and 7 of this policy do exactly that.

Sensitive personal data or information (SPDI) is defined narrowly under Rule 3 to mean passwords, financial information (bank accounts, cards), physical, physiological, or mental health condition, sexual orientation, medical records and history, and biometric information.

We do not collect health data, sexual orientation, medical records, or biometrics. We do not collect or store your financial information: Freemius handles all payment data and we never see your card number.

Where we hold a password for your account, we treat it as SPDI. We store it hashed, never in plain text, and we never disclose it.

Under Rule 6, we do not publish SPDI and we do not disclose it to any third party without your prior permission, except under a lawful contract or where compelled by law.

Under Rule 8, we maintain a documented information security programme with managerial, technical, operational, and physical controls proportionate to the information we hold.

Under Rule 5, we collect only what is necessary for a lawful purpose connected with our functions, we use it only for the purpose it was collected, and we do not retain it longer than required.

You may review, correct, or amend any information you have given us, at any time, by emailing Hello@xypherseo.com. You may withdraw your consent at any time, and if you do, we may be unable to continue providing the service for which the information was collected.

11.2 Your rights under the DPDP Act 2023

When the DPDP Act commences you will have, and we already give you today, the right to:

  • access a summary of the personal data we process about you and how we process it
  • have your personal data corrected, completed, or updated
  • have your personal data erased
  • grievance redressal
  • nominate another individual to exercise your rights in the event of your death or incapacity

Use them by emailing Hello@xypherseo.com. Section 6 of this policy tells you how.

11.3 Grievance Officer

Designation: Grievance Officer

Support email: Hello@xypherseo.com

Address: New Delhi, India

We acknowledge every grievance within 48 hours and resolve it within one month, as required by Rule 4(4) of the Consumer Protection (E-Commerce) Rules 2020. You receive a ticket number for every grievance.

Under Rule 14 of the DPDP Rules 2025, we resolve data protection grievances within 90 days.

11.4 Nodal contact person

Appointed under Rule 4(1)(a) of the Consumer Protection (E-Commerce) Rules 2020, resident in India.

Support email: Hello@xypherseo.com

Address: New Delhi, India

11.5 Escalating beyond us

If you are not satisfied with how we handled your grievance:

For data protection matters, you may complain to the Data Protection Board of India.

For consumer matters, you may file before the District, State, or National Consumer Disputes Redressal Commission having jurisdiction where you reside or work.

For a claim of negligent handling of sensitive personal data under Section 43A of the IT Act, you may approach the adjudicating officer appointed under Section 46 of the IT Act.

11.6 Compensation under Section 43A

Section 43A of the IT Act provides that a body corporate which is negligent in implementing and maintaining reasonable security practices while handling sensitive personal data, thereby causing wrongful loss or wrongful gain, is liable to pay compensation to the affected person.

We take that seriously. It is one of the reasons we do not store your card data, do not store plain-text passwords, and do not collect sensitive categories we do not need.

12. If you are in the EU, the EEA, or the UK

12.1 Your legal bases, restated

We rely on: performance of a contract (licence, support, updates), consent (marketing, analytics cookies, non-essential processing), legitimate interests (security, fraud prevention, product improvement, direct marketing to existing customers where lawful), and legal obligation (tax, accounting, responding to lawful requests).

Where we rely on legitimate interests, we have carried out a balancing assessment, and you can ask us for a summary of it.

12.2 Your right to object

You have an absolute right to object to direct marketing. We will stop immediately, with no questions asked.

You have a qualified right to object to processing based on legitimate interests. Tell us and we will stop unless we can demonstrate compelling legitimate grounds that override your interests.

12.3 Your right to complain

You can complain to your national supervisory authority. You do not have to complain to us first, although we would prefer you did, because we would rather fix it.

A list of EU supervisory authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en

In the UK, the Information Commissioner's Office at https://ico.org.uk

12.4 Article 27 representative

Until a representative is appointed, you may contact us directly at Hello@xypherseo.com and we will respond as if the representative had been contacted.

13. If you are in California

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising these rights.

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not collect sensitive personal information as that term is defined in the CCPA. So there is nothing to opt out of, but you may still exercise every other right listed above by emailing Hello@xypherseo.com.

We have not disclosed personal information for a business purpose to any category of third party other than those listed in Section 3 of this policy in the preceding 12 months.

You may designate an authorised agent to act for you.

14. If you are elsewhere

If you are in Brazil, we comply with the LGPD and you have the rights in Article 18.

If you are in Canada, we comply with PIPEDA and you may complain to the Office of the Privacy Commissioner.

If you are in Australia, we comply with the Australian Privacy Principles and you may complain to the Office of the Australian Information Commissioner.

If you are in South Korea, Japan, Singapore, South Africa, Switzerland, or anywhere else with a data protection law, we apply the rights in Section 6 to you, and you may complain to your national authority.

Section 6 gives everyone in the world the same core set of rights, so wherever you are, you are covered.

15. Changes to this policy

If we make a minor change, we post it here.

If we make a material change (a new purpose, a new category of recipient, a new international transfer, or anything that reduces your rights), we will email you at least 30 days before it takes effect, at the address on your account, and you may object or withdraw consent before it does.

We will not quietly rewrite this policy and rely on you not noticing.

16. Contact

All privacy questions, requests, and complaints: Hello@xypherseo.com

Grievance Officer (India): as set out in Section 11.2

We answer every one.

Last reviewed: 11 July 2026