legal
Privacy policy
last updated 2026-07-24
Serpital provides SEO diagnostic and page-generation software for financial businesses. This policy describes what we collect when you use the site and the free scan, and how we handle it. Questions: hello@serpital.com.
What we collect
- The domain you submit. Running a scan stores the domain and the diagnostic evidence assembled about it. That evidence is built from publicly available information and licensed third-party SEO data (DataForSEO); it describes the domain, not you.
- A rate-limiting identifier. To keep the free scan free, we derive a hashed identifier from your IP address and use it for rate limiting. We do not store your raw IP address alongside scan results.
- A session cookie. The scan wizard sets an essential, httpOnly session cookie so your scan can find its way back to you. We do not use advertising trackers or third-party marketing cookies.
- Email, if you write to us. If you contact us about early access, we keep the correspondence.
Google Search Console data
Connecting Google Search Console is optional. If you connect it, Serpital accesses Search Console data for the property you explicitly authorize — search-analytics and index-coverage information — for one purpose: folding index-health evidence into your own diagnostic. Specifically:
- Access is read-only and scoped to the property you select.
- OAuth tokens are encrypted at rest and never shared with third parties.
- Search Console data is used only to produce your diagnostic. It is not used for advertising, not sold, and not transferred to anyone else.
- You can revoke access at any time from your Google account's security settings (myaccount.google.com/permissions); revocation takes effect immediately.
Serpital's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Scan results are retained so shared result links keep working and so repeat scans of the same domain can be re-served instead of re-billed. To have a scan result, a Search Console connection, or correspondence deleted, email hello@serpital.com from an address that can demonstrate control of the domain in question; we honor verified requests within 30 days.
Changes
We will update this page when practices change and revise the date above. Material changes to how Google user data is handled will be called out explicitly.