seodraft

Privacy policy

Last updated: September 26, 2026

seodraft is a hosted product with a remote MCP server that your AI agent (Claude, ChatGPT, Cursor, or another MCP client) connects to over OAuth. This page explains what seodraft stores about your workspace, why, and who else touches that data.

What we store

Account: your Clerk user id, which is the key for your workspace. Your email and login live in Clerk, not in a separate seodraft copy. The one exception is early access granted before signup, which is recorded as an allowlist entry keyed by the email address you were invited with.

Business profile: business name, description, audience, competitors, voice, site URL, sitemap URL, reference URLs, and your writing-style preferences.

Evidence bank: the first-hand facts you or your agent add for articles (a measured number, a named case, a mistake, a credential), each marked pending or accepted.

Topics and metrics: the search topics you save, plus any Google or AI search volume, difficulty, and intent numbers measured through your own DataForSEO account.

Drafts and briefs: article bodies, editorial briefs, SERP research briefs, and the results of the deterministic checks (the rules) run against each draft.

Your site's sitemap: an inventory of your own site's published pages, built from your sitemap.xml, used to avoid duplicate topics and to link between your own articles.

DataForSEO usage log: a record of each paid call made against your own DataForSEO account (action, cost, timestamp), so you can see what was spent.

Delivery target: the git repository, branch, file-path template, and format you configure for exporting drafts.

Credentials, encrypted: see "Your DataForSEO and GitHub credentials" below.

Activation events: internal counters for onboarding steps (agent connected, first brief written, and similar milestones): ids and timestamps, never article text.

Transactional email log: which emails we sent you (welcome, trial reminders, and similar) and delivery events our email provider reports back (bounced, opened).

Your DataForSEO and GitHub credentials

Your DataForSEO login and password, and your GitHub token, belong to you, not to seodraft. There is no seodraft-operated DataForSEO account: every paid lookup runs against your own account and is billed to your own balance. Both are stored encrypted at rest with AES-256-GCM, decrypted only at the moment a call you or your agent triggered needs them, and used for nothing else.

No MCP tool returns your DataForSEO password or your GitHub token. Tools that report on delivery or DataForSEO status return whether a credential is connected, never the credential itself.

Who else processes data

Clerk: authentication and session management.

Vercel: application hosting.

Neon: the Postgres database everything above is stored in.

DataForSEO: search volume, difficulty, and SERP data, called with your own credentials, never seodraft's.

GitHub: only if you configure a delivery target, and only with the token you provide, to commit draft files to a repository you choose.

Commet: subscription billing.

Resend: transactional email (welcome, trial reminders, and similar).

Umami: privacy-focused analytics on the public marketing pages only (this page, /pricing, /blog, and similar). It is not loaded on your workspace pages, so it never sees a post id, a draft, or your profile.

TypeSafe Jev: an optional classifier that runs only when seodraft has it enabled on the server. It answers typed questions about a topic, a draft, or a profile field (for example, whether two topics are semantic twins, or whether a piece of evidence reads as first-hand) and returns a probability. It never blocks anything itself and, with no key set, is never called.

What your AI agent sends us

seodraft only receives the arguments your agent sends with each tool call over MCP: a topic name, a draft body, a profile field, and similar. It does not read your conversation with Claude, ChatGPT, or another assistant, their memory, or your files beyond what appears in those specific tool-call arguments.

We do not sell your data or train models on it

seodraft does not sell workspace data. seodraft never calls a model to write an article: drafts come from your agent, over MCP. The only model call in the product is the optional TypeSafe Jev classifier described above, and it answers a narrow question about text you already stored; it does not train on your data.

Retention and deletion

seodraft keeps the data listed above for as long as your workspace exists. There is no automatic deletion and no self-service deletion today.

If this changes, this page will say so and carry a new date.

Contact

Questions about this policy or about your data: chorch@seodraft.app.