Trust
Privacy policy
What we collect, why, how long we keep it, and the rights you have. Plain language, no dark patterns.
Last updated · Questions: support@seoforaiagents.com
Who we are
SEO for AI Agents is a product operated by Valiant Autonomy LLC, doing business as Own The Climb, a Maryland company (the controller of your personal data for the purposes of this policy). You can reach us about anything in this policy at support@seoforaiagents.com. This policy explains what we collect, why, and what you can do about it. We keep it short and specific on purpose.
What we collect
We collect only what the product needs to work:
- Audit inputs. The URLs and, for the local tool, the business name and address you submit. We fetch the public pages at those URLs to analyze them, and we send brand and buyer questions to AI engines to measure how they answer.
- Audit results. The scores, findings, and crawled page metadata produced by an audit, stored so you can return to the report.
- Contact details. The email address you provide to unlock a full report, subscribe, or create an account, plus your organization name and preferences if you sign up.
- Authentication data. If you create an account, the identifiers from your magic-link or OAuth sign-in. We do not store passwords by default.
- Billing data. If you subscribe, Stripe collects your card or payment details; we never see or store card numbers. We keep your Stripe customer and subscription identifiers, plan, and billing status.
- Connected accounts. If you connect Google Search Console, we store an access token, encrypted at rest, and use it only to read your search performance data for your reports. You can disconnect at any time.
- Support email. Messages you send to our support address, and our replies. An automated assistant reads them and drafts or sends answers to routine questions; anything it cannot answer goes to a person.
- Usage and reliability data. Our own first-party product events (for example, audit started and completed), which record the event, the page path, and internal ids, not your email or IP address. Error events used to keep the service working, with personal data scrubbed before storage. We do not use a third-party analytics, session-replay, or error-tracking service; this is built in-house.
- Abuse-prevention data. Your IP address and a hashed fingerprint of basic browser headers, used as short-lived keys for rate limits and free-tier caps.
We do not ask for, and do not want, special-category personal data. Please do not submit it.
Why we use it
We use your data for these purposes and no others:
- To run the audit you requested and show you the report.
- To send the emails you asked for: your report, lifecycle messages, and digests you opt into.
- To operate and secure your account and enforce usage limits.
- To keep the service reliable, detect abuse, and fix errors.
- To improve the product in aggregate. We do not sell your data, and we do not use your audit content to train AI models.
Legal bases (for EEA and UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to run audits and provide your account), legitimate interests (to secure the service, prevent abuse, and improve the product in aggregate), consent (for marketing email, which you can withdraw at any time), and legal obligation (where we must retain or disclose data by law).
How long we keep it
- Account data: while your account is active. Deleting your account in settings removes your organization data, audits, captured emails, and support threads right away; a deletion request by email is completed within 30 days.
- Audit results: for the life of the associated account. Anonymous public audits are kept until deleted on request or until the account for the email that ran them is deleted; they do not expire automatically today.
- Marketing email addresses: until you unsubscribe or ask us to delete them.
- Billing records: Stripe keeps its own payment and invoice records as tax and financial law requires, even after you delete your account.
- Error events: kept for debugging with personal data scrubbed, and unlinked from you when your account is deleted. Rate-limit counters are purged after 3 days.
Our full retention detail is also described on our security page.
Your rights
You can ask us to access, correct, export, or delete your personal data, and you can object to or restrict certain processing. You can also delete your account yourself in your account settings. You can unsubscribe from marketing email at any time using the link in any message. To exercise any right, email support@seoforaiagents.com and we will respond promptly. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
Children
The service is intended for businesses and professionals and is only for people 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we make a material change to this policy we will update the date at the top and, where appropriate, notify account holders by email. Continued use of the service after a change means you accept the updated policy. Questions go to support@seoforaiagents.com.
Changes on 2026-10-07: the full sub-processor list, billing, connected-account, support, and abuse-prevention data, accurate retention for anonymous audits and error events, the Turnstile disclosure, and an 18+ age floor.