Legal
Privacy Policy
Last updated: 1 Jun 2026
1. What we collect
When you create a Serply account we collect your email address and a hashed password. If you connect a CMS (WordPress, Shopify, Ghost, Webflow, Wix, and HubSpot) we store the credentials you give us, encrypted, so we can publish on your behalf. When you add a site we read its public pages and store what we learn as your site brain. We also collect basic usage data such as pages visited and features used.
You do not need an account to use everything on this site, so we also hold data from people who never sign up. If you run the free AI-visibility audit we store the domain you entered, your email address if you asked for the report, and a hashed version of your IP address rather than the address itself. If you join the newsletter or the partner waitlist we store the email address and whatever you typed into that form.
2. Why we process it, and on what basis
We process your account data to provide the service you signed up for: authenticating your sessions, building your site brain, generating content plans and articles, publishing to your CMS, running technical audits, and tracking AI visibility. The lawful basis is performance of our contract with you.
We process free-audit, newsletter, and partner-waitlist data on the basis of your consent. You can withdraw it at any time by replying to any email we send you, or by writing to hello@serply.ai. We keep those records for 24 months from your last interaction, then delete them.
We process limited usage and error data on the basis of our legitimate interest in keeping Serply working and secure. We do not sell your data, we do not use it to train any AI model of our own, and we do not build advertising profiles.
3. How long we keep it, and closing your account
Your data is stored on encrypted servers. CMS credentials are encrypted at rest using AES-256-GCM. All connections between your browser and Serply use TLS 1.2 or higher. We keep your account data for as long as your account is open.
You can delete your Serply account yourself, at any time, from Settings in the dashboard. Deleting it removes your account and everything attached to it: your sites, site brains, articles, content plans, audits, and visibility history. Articles already published to your CMS stay on your CMS, because they are yours.
Free-audit, newsletter, and waitlist records are keyed to an email address rather than to an account, so account deletion does not reach them. Email us and we will remove those too, within 30 days. We keep the limited billing records UK law requires us to keep, and nothing else.
4. Who else receives your data
Running Serply means sending parts of your data to other companies. Here is the complete list, what each one does, and what reaches it. Each handles your data under its own data processing agreement.
- OpenAI · Article writing, content planning, and AI-visibility checks.Receives: Your site content, brand and business context, target keywords, and the questions you track.
- Anthropic · AI-visibility checks and the free audit.Receives: Your brand name, business context, and the questions you track.
- Google · Gemini for AI-visibility checks, PageSpeed Insights for the technical audit, and Search Console plus Google sign-in if you connect them.Receives: Your brand name, the questions you track, your site URLs, and, if you connect them, your Google account identity and Search Console metrics.
- Perplexity · AI-visibility checks and the free audit.Receives: Your brand name, business context, and the questions you track.
- DataForSEO · Search volume, keyword difficulty, and AI Overview data.Receives: Your domain and the keywords in your content plan.
- Firecrawl · Reading your website to build your site brain.Receives: The public pages of the sites you add to Serply.
- Resend · Sending transactional and report email.Receives: Your email address and the contents of the emails we send you.
- Supabase · Managed Postgres database and file storage.Receives: Everything in your account: it is the database Serply runs on.
- Stripe · Payments and subscription billing.Receives: Your email address and billing details. Card numbers go to Stripe directly and never reach Serply's servers.
- Railway · Hosting the Serply API and background workers.Receives: Everything your account sends to the Serply API.
- Vercel · Hosting and delivering the Serply web app.Receives: Your IP address and standard web request logs.
Some of these operate outside the UK and EU, mainly in the United States. Where your data is transferred internationally it is protected by appropriate safeguards such as Standard Contractual Clauses. If we add a processor, this list changes before the integration ships.
5. What we send to AI providers
This one deserves its own section, because it is the product. Serply sends your data to OpenAI, Anthropic, Google, and Perplexity through their business APIs, not their consumer apps.
What goes to them: the public content of the sites you add, your brand name and business description, your target keywords, and the buyer questions you ask us to track. Every AI-visibility check works by putting your tracked questions to 4 different AI providers and recording which of them mention you, so those questions and your brand name necessarily leave our systems. Article generation sends your site context so the writing sounds like you.
What does not go to them: your password, your CMS credentials, and your billing details. If you are running Serply on behalf of a client, they are the ones whose site content this is, so tell them: you need this section to be able to answer their questions honestly.
6. Cookies and browser storage
Serply loads no analytics, no advertising, and no third-party tracking scripts, so there is nothing here to consent to and no cookie banner to click through. Your session is held in your browser’s local storage rather than in a cookie. The only cookie we set records whether you left the dashboard sidebar open. You can clear both at any time from your browser settings; clearing them signs you out.
7. Your rights
You have the right to access, correct, export, or delete your personal data, and to object to or restrict some of our processing. Two of those you can exercise yourself, right now, without asking us: from Settings in the dashboard you can download a JSON export of your account data, and you can delete your account outright.
For anything else, email hello@serply.ai and we will respond within 30 days. If you are in the UK or EU you also have the right to complain to your local data protection authority, and in the UK that is the Information Commissioner’s Office.
8. Who to contact
Serply is the data controller responsible for the personal data described in this policy. For any privacy question, or to exercise any of the rights above, contact us at hello@serply.ai.