Privacy Policy
How we collect, use, store, and protect your data — including data accessed through Google APIs.
Last updated: 17 June 2026
This Privacy Policy describes how DeepLode (“DeepLode,” “we,” “us,” or “our”), a product of Velirum Digital OU (the “Data Controller”), collects, uses, and safeguards information when you use the DeepLode SEO platform at app.deeplode.ioand related services (the “Service”).
1. Information we collect
Account information
When you create an account or are invited to an organization, we collect your name, email address, and authentication credentials managed through our authentication provider (Supabase). We never store your password in plain text.
Information you provide
Domains, keywords, service-line and business-profile details, and any other configuration you enter to operate the Service.
Data accessed through Google APIs
With your explicit authorization via Google OAuth, the Service accesses the following Google user data on a read-only basis:
- Google Search Console (scope
webmasters.readonly) — search analytics for properties you select: queries, pages, countries, devices, clicks, impressions, click-through rate, and average position. - Google Analytics (scope
analytics.readonly) — aggregated reporting data for the GA4 property you select: sessions, engagement, bounce rate, conversions, and related page-level metrics. We also read your Analytics account and property list (via the Analytics Admin API) solely to let you choose the correct property. - Basic profile (scope
userinfo.email) — your Google account email address, shown in the app so you know which account is connected.
Billing information
Payments are processed by Paddle, our authorized Merchant of Record. DeepLode does not receive or store your full credit card number, CVV, or bank account details. Paddle provides us with transaction identifiers, subscription status, plan details, and billing contact information (name, email, country) as required to administer your subscription. Paddle’s own privacy policy governs their handling of your payment data.
Usage and log data
We may collect standard server logs (IP address, browser type, pages visited, timestamps) for security, debugging, and platform health monitoring. This data is not linked to your Google API data.
2. How we use information
- To provide rank tracking, traffic and conversion reporting, content analysis, and AI-driven SEO diagnostics.
- To aggregate Search Console and Analytics data into the dashboards, reports, and insights that constitute the Service.
- To authenticate you and operate your organization’s account.
- To process billing and manage your subscription via Paddle.
- To send transactional emails (invitations, password resets) via AgentMail.
- To maintain, secure, and improve the Service.
What we do NOT do with your data
- We do not use Google user data for advertising of any kind.
- We do not sell or rent your personal information.
- We do not transfer Google user data to third-party advertising platforms, data brokers, or information resellers.
- We do not use Google user data to determine credit-worthiness or for lending purposes.
- We do not use Google user data to develop, train, or improve generalized artificial intelligence or machine-learning models.
- We do not allow humans to read your Google user data, except with your explicit consent, for security purposes (e.g. investigating a reported abuse), or as required by applicable law.
Google API Services — Limited Use disclosure
DeepLode’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve user-facing features prominently displayed within the DeepLode application.
- Google user data is not transferred to third parties except as necessary to operate the Service (see Sub-processors below) or as required by law.
- Google user data is not used for advertising, interest-based targeting, or retargeting.
- Google user data is not used to determine creditworthiness or for lending purposes.
- Google user data is not used to train or improve any generalized AI or machine-learning models.
- Google user data is not read by humans except with your explicit permission, for security purposes, or as required by law.
3. How we store and protect data
- Aggregated Search Console and Analytics metrics are stored in our managed Postgres database (Supabase) under row-level security scoped to your organization.
- Google OAuth tokens are stored encrypted in a private storage bucket and are never exposed to the browser or other organizations.
- Access to your data is restricted to authenticated members of your organization and to the limited DeepLode personnel who operate the Service.
- We implement industry-standard security controls including TLS in transit and encryption at rest. All infrastructure is hosted in the European Union or on Cloudflare’s globally distributed network.
4. Sub-processors
We share data only with the following infrastructure sub-processors that make the Service possible, and only to the extent necessary for their specific function:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and metric data |
| Paddle | Payment processing and subscription management | Billing contact info, subscription plan |
| Cloudflare | DNS, CDN, DDoS protection, bot protection | Network traffic (IP, request headers) |
| OpenAI | AI SEO diagnostics (Lodi agent) | Anonymized rank and traffic metrics (no personal data) |
| Groq | AI content classification and insights | Anonymized keyword and content signals |
| DataForSEO | Rank checking and search volume data | Domain names and keywords |
| Firecrawl | Website content crawling and analysis | Public page URLs of domains you connect |
| AgentMail | Transactional email delivery | Recipient email address and email content |
We do not sell personal information to any sub-processor or third party.
5. Data retention
- Account data is retained for as long as your account is active. If you request account deletion, account data is removed following a short grace period (up to 30 days) to allow for error recovery.
- Aggregated metric data (Search Console, Google Analytics, rank history) is retained on a rolling 180-day window and deleted automatically beyond that.
- Google OAuth credentials are deleted immediately when you disconnect an integration from Settings → Integrations, or when you request account deletion.
- Billing records are retained as required by applicable tax and accounting law (typically 7 years).
6. Revoking Google access
You can disconnect a Google connection at any time from Settings → Integrationsin the app, which deletes the stored OAuth credentials for that domain immediately. You may also revoke DeepLode’s access directly from your Google Account permissions page. Revoking access stops all future data syncs; previously stored aggregated metrics remain in your account until you request deletion or they expire under the 180-day retention window.
7. Your rights
Velirum Digital OU is established in Estonia (European Union) and acts as the Data Controller under the General Data Protection Regulation (GDPR). Depending on your location, you may have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate or incomplete personal data.
- Right to erasure(“right to be forgotten”) — you may request deletion of your personal data where there is no overriding legal basis for us to retain it.
- Right to restriction of processing — you may ask us to pause processing while a dispute is resolved.
- Right to data portability — you may request a machine-readable export of your personal data.
- Right to object — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent (e.g. Google OAuth), you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — you have the right to lodge a complaint with your national data protection supervisory authority. For users in Estonia, this is the Estonian Data Protection Inspectorate (AKI).
To exercise any of these rights, contact us at hello@deeplode.io. We will respond within 30 days (GDPR Article 12). We may need to verify your identity before processing the request.
8. International data transfers
DeepLode serves organizations globally. Our primary infrastructure is hosted in the European Union (Supabase). Some sub-processors (OpenAI, Groq, DataForSEO, Firecrawl, AgentMail) process data in the United States or other countries. Where personal data is transferred outside the EU/EEA, we rely on the sub-processor’s Standard Contractual Clauses (SCCs) or other appropriate safeguards to ensure an equivalent level of protection.
9. Children’s privacy
The Service is intended for business use and is not directed to individuals under 16.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by updating the “Last updated” date above and, where appropriate, by email or in-app notification.
11. Contact and Data Controller
Questions about this policy, your data, or to exercise your rights? Contact the Data Controller:
Velirum Digital OU
Narva mnt 5, Tallinn 10117, Estonia
Registry code: 16776071
hello@deeplode.io
