PirateSERP policies
Privacy Policy
What information PirateSERP handles, how connected tools use it, and how to exercise your privacy choices.
Last updated:
1. Scope and responsibility
This policy describes how PirateSERP handles personal information in its SaaS application, public pages, account services, and affiliate program. PirateSERP is responsible for the account and operational information described here. Third-party sites and services you connect have their own privacy policies.
If you submit personal information about clients or other people, you are responsible for having authority and a lawful basis to do so. Contact us before using the service for regulated sensitive information or if your organization requires a separate data-processing agreement.
2. Information we collect
- Accounts and communications: email, account identifiers, authentication and verification records, optional display name, bio and social links, and information you send us for support.
- Workspace content: project domains, URLs, keywords, website and business information, research, audit and ranking results, connected analytics data, prompts, drafts, generated output, and content you save or publish.
- Connected credentials: API keys, service-account credentials, Google account refresh tokens you authorize for Web Analytics, their provider labels, and related configuration. These credentials can grant access to your third-party accounts.
- Billing: Stripe customer and subscription identifiers, invoice and payment records, amounts, currency, status, dates, and refund or dispute information. Stripe collects payment details directly; we do not store full card numbers or card security codes.
- Affiliates and access grants: referral codes and account associations, application and approval status, accepted program version, commission and adjustment records, payment contact or provider reference, payout records, and LTD invitation and redemption records.
- Activity and security: page paths, referral source, timestamps, browser and operating-system information, device and visit identifiers, sign-in and session records, approximate city/country derived from IP, and diagnostic or administrative logs. Our servers receive IP addresses when you connect. Activity may be associated with your signed-in account.
We obtain information from you, your browser and activity, the services you connect or request data from, and payment and email providers. Research tools also process public website and business information relevant to your requests.
3. Why we use information
We use information to create and secure accounts; run your projects, integrations, and scheduled tools; save and display results; process billing and refunds; administer referrals and payouts; deliver service messages; provide support; understand usage and troubleshoot problems; prevent abuse; and comply with legal obligations.
Where European or UK data-protection law applies, our legal basis depends on the activity: providing a requested service under a contract, legitimate interests such as security and service administration, legal obligations, or consent where required. You may contact us to object to processing based on legitimate interests or withdraw consent without affecting prior lawful processing.
4. AI, integrations, and service providers
Using a connected feature sends the information necessary for that request to the relevant provider. For example, prompts and selected content may go to OpenRouter and the model provider it routes to, or Google Gemini; Web Analytics questions send your question and selected aggregate report metrics to OpenRouter and its model provider; search and keyword requests may go to DataForSEO; and authorized property, query, or business information may go to Google Search Console, GA4, Maps, or Bing Webmaster Tools. The actual provider depends on the tool and configuration you choose.
Saved provider secrets are encrypted at rest and decrypted by the server when needed for authorized requests. Encryption does not prevent the destination provider from processing the request. Provider retention, model-training practices, and account settings differ; review those settings before submitting confidential material. We do not promise that every selected AI provider excludes inputs from training.
We also use infrastructure, storage, payment, and email services to operate PirateSERP. Stripe processes billing. Our Listmonk newsletter system and configured email delivery service process addresses, list membership, message content, and delivery records for customer, newsletter, affiliate, and LTD communications. Authorized staff receive access appropriate to their role, including restricted newsletter access where assigned.
We may disclose information when legally required, to respond to lawful requests, to protect rights and safety, or in a business transfer subject to appropriate privacy protections. We do not sell personal information or share it for cross-context behavioral advertising.
5. Public information and referrals
Your chosen display name and contribution counts may appear on the public Top Contributors leaderboard. Published author profiles may include your bio and social links. Content you publish through public features can be read and copied by others. The public visitor globe displays grouped city/country visit counts, not individual account names.
When you supply a referral code, we associate the referral with your account to determine eligibility and commissions. This referral flow does not set an affiliate tracking cookie. Affiliates can see their referral count, commission history, and payout history; the affiliate dashboard does not list referred customers’ email addresses or saved project content.
7. Customer emails and newsletters
Account verification adds your address to our customer email list so we can administer customer communications. Newsletter signup is available separately. We send account verification, password reset, billing or service information, and applicable affiliate or LTD messages to support the service.
You can unsubscribe from marketing using the message’s unsubscribe link or by contacting us. Necessary account, security, billing, and program-administration messages may still be sent. Unsubscribing from email does not cancel a paid subscription or delete your account.
8. Retention and deletion
We retain account and workspace data while needed to provide the service, and retain other records according to their operational, security, accounting, and legal purposes. Retention depends on the record, the account relationship, outstanding payments or disputes, and applicable obligations; we do not promise one fixed deletion period for every category.
Subscription cancellation stops renewal but does not immediately erase your account or research. Contact us to request access, export assistance, or deletion. Some records, including financial ledgers, payment references, affiliate adjustments, access-grant history, and evidence needed for security or disputes, may remain when necessary even after an account is deleted. Backups and provider-held records may follow separate retention cycles.
You can remove saved API keys in Account Settings and disconnect a Google account in Web Analytics. Disconnecting removes the local Google authorization and attempts provider revocation; you can also review or revoke access in your Google account. To invalidate an API key or service-account credential itself and stop use outside PirateSERP, revoke it with its provider.
9. Your choices and privacy rights
Depending on your location and which laws apply, you may have rights to know or access information, obtain a portable copy, correct inaccurate information, request deletion, restrict processing, object to certain processing, or withdraw consent. California residents may also have rights concerning sale or sharing and certain uses of sensitive personal information. We use account credentials to provide and secure the requested service, not to infer sensitive characteristics.
Email privacy@pirateserp.com to make a request. Include your account email and what you would like us to do, but not passwords, API keys, or full payment details. We may verify your identity or an authorized agent’s authority before releasing or changing information. We respond within the time required by applicable law and explain any relevant exception. We do not discriminate for exercising protected rights.
You may also complain to the relevant data-protection authority. You can edit supported profile fields in Account Settings; contact us about information that cannot be changed there.
10. Security and international processing
We use access controls, authentication, encrypted saved provider credentials, and other safeguards designed to protect information. No service or transmission method is completely secure. Notify us if you suspect an account or credential compromise.
PirateSERP and its providers may process information in the United States and other countries whose privacy laws differ from your own. Where legally required, transfers must use an applicable safeguard or other lawful transfer basis. Contact us for information about safeguards relevant to your use; this policy is not itself a separate data-processing or international-transfer agreement.
11. Children and policy changes
PirateSERP is a professional tool and is not directed to children under 13. We do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and take appropriate action.
We update this policy as our service and practices change, show the revision date, and provide additional notice or seek consent where required by law.
Contact us
Contact PirateSERP at privacy@pirateserp.com. You can also reach us at casey@pirateserp.com.