Home → Legal

Privacy Policy

SEO Merlin is software you install on your own server, not a hosted service. That distinction shapes this entire document — almost nothing your site produces ever reaches us.

Last updated: 21 July 2026  ·  Applies to: the SEO Merlin WordPress plugin, free and premium editions

Who we are

SEO Merlin is published by:

CARPEBO SINGLE MEMBER P.C.
2nd km Xanthis–Lagous, Xanthi, Greece
Company Registration Number: 161870546000

Privacy enquiries: privacy@seomerlin.com
Support: support@seomerlin.com

In this policy, “we”, “us” and “our” mean CARPEBO SINGLE MEMBER P.C. “The plugin” means the SEO Merlin software. “Your site” means the WordPress installation where you install it.

How to read this policy

SEO Merlin is software you install on your own server. It is not a hosted service. That distinction shapes everything below, so this policy is written in two parts:

Part A — What we collect about you. This concerns you as our customer: licence validation, purchases, and support. This is the part where we act as a data controller.

Part B — What the plugin does on your site. This concerns the software running on your server: what it stores, what it sends out, and to whom. Almost none of it reaches us. You need this part because you are the controller of your own site’s data, and you may need to describe the plugin in your own privacy policy.

If you are reviewing this document to assess our use of Google API data, section 6 is written for you.

Part A · 1. Licence validation

When you activate a premium licence, the plugin contacts our licensing service to confirm the licence is valid and to track how many activations it has.

What is sent:

DataWhenWhy
Your licence keyOn activation, and periodically while you use the pluginTo confirm the licence is valid
A random site identifierWith every checkTo count activations against your licence seats. Generated on your site, not derived from your domain name
Your site’s domain nameOn activation onlyTo show you which sites a licence is active on
The plugin versionWith every checkTo serve the correct licence rules

What is not sent: your email address, your name, your content, your scan results, your API usage, or anything about your site’s visitors.

Licence checks are throttled — status is re-checked at most once a day, and results are cached on your site.

Legal basis (GDPR): performance of our contract with you (Article 6(1)(b)).

Retention: licence records are kept for the life of the licence and for as long as we are required to keep transaction records under Greek and EU law.

2. Purchases

Purchases are processed by Freemius, Inc., who act as the merchant of record. When you click a purchase link in the plugin, your browser is sent to Freemius’s checkout with your WordPress administrator name, email address, and site URL pre-filled so you do not have to type them.

Freemius handles the transaction, payment details, invoicing, and tax. We never see or store your payment card details. Freemius is an independent controller for the data it collects at checkout, under its own privacy policy.

We receive from Freemius the information we need to fulfil and support your licence: your name, email address, the product and plan purchased, and the licence key.

Legal basis: performance of contract (Article 6(1)(b)) and compliance with our legal obligations for tax and accounting (Article 6(1)(c)).

3. Support

If you email support@seomerlin.com, we receive whatever you send us — your message, your email address, and anything you choose to include, such as screenshots, log excerpts, or site details.

We use it only to answer you. We do not use support correspondence for marketing.

Legal basis: performance of contract (Article 6(1)(b)) and our legitimate interest in supporting our product (Article 6(1)(f)).

Retention: support correspondence is kept for up to three years, so that we can refer to previous conversations if you contact us again.

4. The Google sign-in service

If you connect Google Search Console or Google Analytics, the plugin uses our authentication service at connect.seomerlin.com. This exists so that you do not have to create your own Google Cloud project.

What passes through it:

  • When you connect: the address of your site’s WordPress admin page, so we can send you back there after you approve access. Nothing else about you or your site.
  • When your access expires: your Google refresh token, so a new access token can be issued.

What we do with it: the service holds your tokens for a maximum of 120 seconds, in a one-time store that is erased the moment your site collects them. Refresh requests are passed to Google and the result returned; nothing is retained. We do not store your Google account identity, and we do not request access to it — the permissions we ask Google for do not include your name, email address, or profile.

We never receive: your Search Console data, your Analytics data, your site’s content, or anything Google returns to your site.

Legal basis: performance of contract (Article 6(1)(b)).

5. What we do not do

We want to be specific, because “we respect your privacy” means nothing on its own:

  • The plugin contains no telemetry. It does not report your installation to us, does not send usage statistics, does not report errors to us, and makes no analytics or tracking requests. This is verifiable in the source code.
  • We do not load anything from external servers into the plugin’s interface. Fonts and assets are bundled with the plugin. No content delivery network sees your administrators.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • We do not profile you or make automated decisions about you.

Part B · 6. Google Search Console and Analytics

This section is written to be complete about our use of Google API data.

Permissions requested

The plugin requests exactly two permissions, both read-only:

PermissionPurpose
webmasters.readonlyRead Search Console performance data
analytics.readonlyRead Analytics reports

We do not request access to your Google identity. No openid, email, or profile permission is requested, and we therefore never learn who you are on Google.

What is retrieved

From Search Console: the list of properties you have verified, and search performance rows — search queries, page URLs, clicks, impressions, click-through rate, and average position.

From Analytics: the list of properties on your account, and page-level engagement reports — page paths and titles, sessions, engaged sessions, bounce rate, engagement rate, and average session duration.

No user-level, demographic, audience, or advertising dimension is requested from either service.

How that data is used

Google data powers visible features and nothing else:

  • Scanner checks that flag pages with poor click-through rates, declining rankings, indexing problems, high bounce rates, or low engagement.
  • The Keywords screen, which shows your Search Console queries.
  • The Analytics screen, which shows your engagement figures.
  • Optionally importing search queries you select into the plugin’s rank tracker.
  • Connection status on the dashboard, and a summary section in the PDF report.

Where it is stored

On your server only, in the plugin’s own database tables. Access tokens and refresh tokens are stored encrypted in your WordPress options table.

Does Google data leave your server?

Never automatically. There is no background process that transmits Google data anywhere.

Three actions you can take will send some of it onward, each requiring a deliberate click:

  1. “AI rewrite” on the Keywords screen sends the search query text you clicked, along with the page’s title and an excerpt, to Anthropic — under your own API key — to generate a meta description. Only the query text is sent; clicks, impressions and positions are not.
  2. Importing search queries into rank tracking copies the queries you select into the plugin’s tracker. Those queries are then checked against DataForSEO — under your own credentials — on a recurring basis. Only the query text, and location and language codes, are sent. No Search Console metrics accompany them.
  3. Generating the PDF report’s summary includes aggregate issue descriptions, such as “12 pages have over 100 impressions but less than 3% click-through rate”, in a prompt to Anthropic under your own key. Individual queries and pages are not included.

The plugin’s automatic AI process — which classifies your site’s type and industry once a week — reads only your site’s own content and never reads Google data.

Disconnecting

Disconnecting Google in the plugin’s settings deletes the stored tokens immediately. You can also revoke access at myaccount.google.com/permissions. Uninstalling the plugin removes the tokens along with all its other settings.

Limited use

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Other services the plugin can contact

SEO Merlin uses a “bring your own key” model. You supply your own credentials for the services below, so you contract with them directly and you see exactly what you spend. If you do not enter a key, the plugin does not contact that service.

ServiceWhat it receivesWhen
AnthropicPage titles, content excerpts, product details, author display names, and — where you use those features — uploaded images and PDFsWhen you use an AI feature, and weekly for site classification
DataForSEOKeywords, your domain, competitor domains you enter, location and language codesWhen you use keyword, backlink or competitor features, and on a schedule for rank tracking
SE RankingYour domain, your brand name, competitor domains, keywordsWhen you use AI-visibility or research features
IndexNowYour site’s own URLsOnly if you enable it — it is off by default
Google PageSpeedYour site’s homepage addressDuring scans. No credentials are used; this is a public API

Your credentials are stored encrypted on your site and are sent only to the service they belong to.

What these services do with the data is governed by your agreement with them, not ours. Their retention and training policies apply to your account. We recommend reviewing them: Anthropic · DataForSEO · SE Ranking

Content you send to an AI service may contain personal data if your published pages do — author names, quotations, or anything else your content includes. The plugin does not filter this. Consider it when choosing which pages to run AI features on.

8. What the plugin stores on your site

All of this stays on your server.

WhatPersonal data?Retention
Scan results and detected issuesPage URLs, titles, excerpts, and Google metrics where applicableUntil you delete them or uninstall
Fix history and content snapshotsThe state of your content before each change, and which administrator made itUntil you delete them or uninstall
Log of requests to missing pagesThe requested address, the referring page, and the browser’s user-agent string. No IP addresses are recordedAutomatically deleted 90 days after the address was last requested
Rank tracking keywords and historyKeywords you trackUntil you delete them
API usage and cost recordsToken counts and costs — never prompt or response contentUntil uninstall
CredentialsYour API keys, Google tokens, and licence key, encryptedUntil you remove them or uninstall
Generated PDF reportsWhatever the report containsUntil you delete them

Data about your visitors

The only visitor data the plugin records is in the missing-page log: the address requested, the referring page, and the user-agent string. This exists so you can find broken links and spot automated attacks. No IP addresses are stored. Entries are deleted automatically 90 days after the address was last requested.

If your site is subject to the GDPR, this is data you process as controller. You may wish to mention it in your own privacy policy. The plugin adds suggested wording to WordPress’s own privacy policy tool to help.

9. Your rights over data on your site

The plugin registers with WordPress’s built-in privacy tools, so Tools → Export Personal Data and Tools → Erase Personal Data work for the data it holds:

  • Export returns fix-history entries attributed to that user, queued AI tasks they started, and their address if it is set as the alert recipient.
  • Erase removes the attribution from those records rather than deleting the records themselves, because the plugin needs them to detect when a fix stops working. The alert address is deleted.

The missing-page log is not included in either, because it holds no identifier that can be matched to an email address — no IP addresses, no accounts. Its safeguard is the automatic 90-day deletion described above.

10. Uninstalling

Deleting the plugin through WordPress removes: all of its database tables, all of its settings including every stored credential, its scheduled tasks, its must-use plugin files, its backup and report folders, and the public files it created at your site’s root.

What deliberately remains: content the plugin wrote into your posts — table-of-contents blocks, “last updated” lines, author bylines, structured data, image alt text, and SEO fields. That is your published content now, and removing it would destroy work you may want to keep. Delete or edit it in your own editor if you prefer.

Part C · 11. Your rights under the GDPR

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you;
  • rectify it if it is inaccurate;
  • erase it, where we have no overriding legal obligation to keep it;
  • restrict or object to our processing of it;
  • portability — receive it in a machine-readable form;
  • withdraw consent, where we rely on consent;
  • lodge a complaint with a supervisory authority. In Greece, this is the Hellenic Data Protection Authority.

To exercise any of these, email privacy@seomerlin.com. We will respond within one month.

Because we hold very little about you — a licence record, a purchase record from Freemius, and any support correspondence — most requests are straightforward. Data on your own site is under your control, not ours; see sections 6 to 10.

12. Your rights under California law

If you are a California resident, you have the right to know what personal information we collect and why, to request deletion, to correct inaccurate information, and to be free from discrimination for exercising these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

The categories we collect are identifiers (name, email address, licence key, site domain) and commercial information (your purchase and licence). We collect them to provide and support the product, as described in sections 1 to 5.

To exercise these rights, email privacy@seomerlin.com.

13. International transfers

We are established in Greece and our records are held within the European Economic Area.

Two of our infrastructure providers operate globally: our licensing service and Google sign-in service run on Cloudflare Workers, which process requests at the location nearest to you. Purchases are processed by Freemius, Inc., which is established in the United States. Where personal data is transferred outside the EEA, it is protected by the European Commission’s Standard Contractual Clauses.

14. Children

SEO Merlin is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

15. Changes to this policy

We will update this page when our practices change, and revise the date at the top. Material changes affecting customers will be announced by email or in the plugin.

16. Contact

CARPEBO SINGLE MEMBER P.C.
2nd km Xanthis–Lagous, Xanthi, Greece
Company Registration Number: 161870546000

Privacy: privacy@seomerlin.com
Support: support@seomerlin.com

Questions about any of this?

Privacy enquiries go to a real person, not a form. We answer within a month, usually much sooner.