LEGAL & TRUST
Privacy Policy
Last updated: 12 Sept 2026
1. What we collect
When you create a Serply account we collect your email address and a hashed password. If you connect a CMS (WordPress, Shopify, Ghost, Webflow, Wix, and HubSpot) we store the credentials you give us, encrypted, so we can publish on your behalf. When you add a site we read its public pages and store what we learn as your site brain. We also collect basic usage data such as pages visited and features used.
You do not need an account to use everything on this site, so we also hold data from people who never sign up. If you run the free AI-visibility audit we store the domain you entered, your email address if you asked for the report, and a hashed version of your IP address rather than the address itself. For other free tools we store the tool, action, submitted website domain, time and outcome, plus your email only if you request a follow-up. We do not store draft text or generated files from the browser editors. If you join the newsletter or the partner waitlist we store the email address and whatever you typed into that form.
2. Why we process it, and on what basis
We process your account data to provide the service you signed up for: authenticating your sessions, building your site brain, generating content plans and articles, publishing to your CMS, running technical audits, and tracking AI visibility. The lawful basis is performance of our contract with you.
We process requested tool follow-ups, free-audit, newsletter, and partner-waitlist data on the basis of your consent. You can withdraw it at any time by replying to any email we send you, or by writing to hello@serply.ai. We keep those records for 24 months from your last interaction, then delete them.
We process limited usage and error data on the basis of our legitimate interest in keeping Serply working and secure and understanding which tools and websites people submit. Free-tool usage records are deleted after 24 months. A submitted website does not establish who owns it or who used the tool. We do not sell your data, we do not use it to train any AI model of our own, and we do not build advertising profiles.
3. How long we keep it, and closing your account
Your data is stored on encrypted servers. CMS credentials are encrypted at rest using AES-256-GCM. All connections between your browser and Serply use TLS 1.2 or higher. We keep your account data for as long as your account is open.
You can delete your Serply account yourself, at any time, from Settings in the dashboard. Deleting it removes your account and everything attached to it: your sites, site brains, articles, content plans, audits, and visibility history. Articles already published to your CMS stay on your CMS, because they are yours.
Free-tool usage is recorded separately from your account. Email us to request removal of records associated with your email or website, within 30 days. We keep the limited billing records UK law requires us to keep, and nothing else.
4. Who else receives your data
We use 11 active service providers to deliver Serply. The categories below explain what they do and the data they receive. We do not sell your data. We are happy to provide the full, current list of sub-processors on request: email hello@serply.ai.
- AI content, visibility and connected search services · Writing and planning content, checking AI visibility, assessing site performance and supporting optional search-account connections.Receives: Public site content, brand and business context, keywords, tracked questions and site URLs; account identity and search metrics when you connect a search account.
- Search research and measurement · Researching search demand and measuring search visibility.Receives: Your domain and the keywords in your content plan.
- Public website reading · Reading your website to build your site brain.Receives: The public pages of sites you add to Serply.
- Transactional email delivery · Delivering account messages and requested reports.Receives: Your email address and the contents of the emails we send you.
- Cloud hosting and storage · Hosting the website, running the service, and storing account data and files.Receives: Account data, site content and files, API requests, IP addresses and standard web request logs, according to each provider’s role.
- Payments and subscription billing · Processing payments and managing subscriptions.Receives: Your email address and billing details; card details go directly to our payment provider and never reach Serply’s servers.
Some of these operate outside the UK and EU, mainly in the United States. Where your data is transferred internationally it is protected by appropriate safeguards such as Standard Contractual Clauses. You can request details of the applicable transfer safeguards and a copy of them by emailing us. We keep our subprocessor register and this notice up to date.
5. What we send to AI providers
Serply uses AI providers’ business APIs to generate content and measure AI visibility. The full list of providers is available through the contact above.
What goes to them: the public content of the sites you add, your brand name and business description, your target keywords, and the buyer questions you ask us to track. Every AI-visibility check works by putting your tracked questions to 4 different AI providers and recording which of them mention you, so those questions and your brand name necessarily leave our systems. Article generation sends your site context so the writing sounds like you.
What does not go to them: your password, your CMS credentials, and your billing details. If you are running Serply on behalf of a client, they are the ones whose site content this is, so tell them: you need this section to be able to answer their questions honestly.
6. Cookies and browser storage
Serply loads no analytics, no advertising, and no third-party tracking scripts, so there is nothing here to consent to and no cookie banner to click through. Your session is held in your browser’s local storage rather than in a cookie. The only cookie we set records whether you left the dashboard sidebar open. You can clear both at any time from your browser settings; clearing them signs you out.
7. Your rights
You have the right to access, correct, export, or delete your personal data, and to object to or restrict some of our processing. Two of those you can exercise yourself, right now, without asking us: from Settings in the dashboard you can download a JSON export of your account data, and you can delete your account outright.
For anything else, email hello@serply.ai and we will respond within 30 days. If you are in the UK or EU you also have the right to complain to your local data protection authority, and in the UK that is the Information Commissioner’s Office.
8. Who to contact
Serply is the data controller responsible for the personal data described in this policy. For any privacy question, or to exercise any of the rights above, contact us at hello@serply.ai.