Privacy Policy
Last updated 2026-08-27
SeoScore (seoscore.lt) audits websites for SEO, GEO, AEO, speed and security. This policy explains what data we process, why, and for how long. Every statement below matches what the software actually does.
1. Data controller
Veesla, email info@seoscore.lt. Any question about your data can go to that address.
2. What we process
2.1. Data about the scanned website
When you enter a domain, our crawler fetches its public pages the same way a search engine bot does. We store URLs, response codes, headers, textual signals (title, description, heading structure), the issues found and the resulting scores.
2.2. Account data
On registration: email address, name and a password hash (we never store the password itself and cannot recover it). We use strictly necessary session cookies. There are no advertising or tracking cookies.
2.3. Signing in with Google
If you choose “Continue with Google”, we receive three things
from Google: the account identifier (sub), the email
address and the name. The scopes are openid,
email and profile; we request nothing else
(no contacts, Drive or calendar) and have no access to it.
We use them for one purpose — recognising your account. We store the identifier because the email address on a Google account can change while the identifier cannot: without it, changing your address would lose your scan history. If an account with the same email already exists, we link Google sign-in to it instead of creating a second one.
We do not request long-lived access for sign-in: once you are signed in, we hold no further access to your Google account.
2.4. Google Search Console data
If you connect your own Google account, we request a
single scope — webmasters.readonly. It is
read-only: we cannot change anything in your Search Console account.
From it we retrieve and use:
- the list of your verified properties, so you can choose which one to connect;
- search performance data (queries, impressions, clicks, CTR, average position) for a 28-day window.
We use it for exactly three things:
- Ordering findings: an issue on a page thousands of people see ranks above an issue nobody sees.
- The “Real traffic” report section: your queries, positions, and the pages that are shown but not clicked.
- Copy suggestions: if you request AI insights, we pass the queries a page already appears for to the model, so a new title speaks the language people actually search with.
We do not sell this data, do not share it for advertising, and do not use it for any other purpose. It belongs to your scan and is visible only to you (and to anyone you hand the report link to).
3. Google API Services Limited Use
SeoScore’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Search Console data is used only to provide and improve your audit report;
- it is not transferred to third parties except as necessary to provide this service (see section 5), and only at your request;
- it is never used for advertising and never sold to data brokers;
- humans do not read it, except with your consent for support, or where required by law, for a security investigation, or to restore service.
4. How we protect it
- The
refresh tokenis encrypted in the database and never appears in reports or logs. - All traffic is HTTPS with HSTS.
- Servers are in the European Union (Lithuania).
- Database access is limited to the application and its administrator.
5. Who else receives data
Three services the audit depends on, and precisely what reaches them:
- Google PageSpeed Insights — the URL of the scanned page, to obtain a speed measurement.
- Google Sign-In — the Google account you choose confirms your identity (data flows from Google to us).
- Google Search Console — a request on behalf of the account you connected (data flows from Google to us, not back).
- OpenAI — only if you press “AI insights”: the analysed page’s text, the issues found and the Search Console queries, to obtain rewrite suggestions. Without that click, nothing leaves for OpenAI.
We do not share data with ad networks, data brokers or analytics platforms, and we never sell it.
6. Retention
- Scores, domain and findings — until you delete them; history is what answers “did it improve”.
- Detailed scan data (page lists, link graph, signals, Search Console figures) — about 60 days, then purged.
- Search Console access token — until you disconnect.
- Account — until you delete it.
7. Your rights, and how to use them
- Revoke Google sign-in: myaccount.google.com/permissions. Your account here remains; you can reach it via “forgot password”.
- Disconnect Search Console: My scans → “Disconnect”. We delete the token and revoke it on Google’s side in the same request. You can also revoke access at myaccount.google.com/permissions.
- Delete scan history: in your account, next to each domain — “Delete”. Every scan of that domain goes with it.
- Access, erasure, restriction or objection: write to info@seoscore.lt — we answer within 30 days.
- You may lodge a complaint with the Lithuanian State Data Protection Inspectorate (ada.lt).
8. Legal basis
Account and audit data are processed to perform our contract with you (GDPR 6(1)(b)); Search Console data is processed on the basis of your consent (GDPR 6(1)(a)), which you can withdraw at any time using the button described in section 7.
9. Changes
If this policy changes, the date at the top changes with it. For material changes we email you, where we have your address.