Privacy policy
Last updated 9 September 2026
Who we are
DAW.IT – Dawid Witulski, sole proprietorship registered in Poland, ul. Grottgera 13A/9, 64-920 Piła, Poland, tax ID (NIP) 7642697963, is the controller of the personal data described here. Write to [email protected] about anything on this page.
What Seoduh does with data, in one paragraph
Seoduh reads the analytics accounts you connect, keeps the numbers so it can compare periods, and joins them with the changes you make to your site. Every connection is read-only. Seoduh never publishes, edits or deletes anything in your accounts or on your site.
What we collect
Your account
You sign in with your Google account, through Firebase Authentication. It is the same account that holds your Search Console access, so connecting your data is one step rather than two. From that sign-in we store your email address, your display name and profile picture if Google returns them, and the Firebase user id. We also store which workspaces you belong to and your role in them. Signing in gives us your identity only; reading Search Console needs the separate permission described below, which you grant explicitly.
Your sites
The name, canonical URL, domain and timezone of each site you add, plus the settings you choose: sections, digest preferences, alert rules, notes you write on the timeline and items on your to-do list.
Data from the sources you connect
Nothing is fetched until you connect a source, and each connection can be removed at any time in Settings. What we request:
| Source | Access | What we read |
|---|---|---|
| Google Search Console | webmasters.readonly |
Impressions, clicks, click rate, position by date, query, page and country; URL inspection results; sitemaps |
| Google Analytics 4 | analytics.readonly |
Sessions and engagement for organic and assistant traffic |
| Bing Webmaster Tools | webmaster.read |
Bing clicks, impressions, index and crawl status |
| Cloudflare | API token you create | Zone analytics: crawler activity, HTTP status counts, cache behaviour per path |
| Microsoft Clarity | Data-export token you create | Aggregated behaviour per page: rage clicks, dead clicks, quickbacks, scroll depth |
| GitHub | Repository you point us at | Releases and their notes, so they land on your timeline without you writing them down |
Seoduh also reads things that are public: your sitemap, your robots.txt, the Chrome UX Report for your pages, and Google's published announcements about search updates.
What we derive and keep
Report snapshots, a cache of provider responses, daily indexing and crawl history, page issues, sitemap URLs and their status over time, alerts we raised, and a record of the digests we sent. This is what makes week-on-week comparison possible.
Payment
Checkout and billing run through Dodo Payments, our payments processor. Card details go to them and never reach us. We store the customer id, subscription id, plan and status they send back, plus the billing email you gave them.
Technical logs
Our servers run on Cloudflare, which records standard request logs including IP address and user agent for security and debugging, kept according to Cloudflare's retention schedule for our plan and then deleted.
How credentials are protected
OAuth refresh grants and the API tokens you paste are encrypted with AES-256-GCM before they are written to the database, with a key held as a server secret. They are decrypted only to call the provider on your behalf. The scopes above are read-only, so even a compromised grant cannot change anything in your accounts.
Why we are allowed to process it
- To provide the service you asked for — performance of our contract with you. This covers your account, your sites and everything fetched from the sources you connected.
- To take payment — performance of the contract and our legal duty to keep invoices.
- To keep the service safe and working — our legitimate interest in preventing abuse, debugging failures and monitoring quotas.
- To email you product news — your consent, withdrawn with one click. Service email such as alerts and the weekly digest is part of the product, and you control it in Settings.
Who else sees it
We do not sell data and we do not share it for advertising. It reaches these processors because the product needs them:
- Cloudflare — hosting, database and edge network
- Google — Firebase Authentication for sign-in, the Search Console and Analytics APIs you connect, and Google Analytics 4 measuring the marketing site and the app
- Microsoft — Bing Webmaster Tools and Clarity, when connected, and Clarity session measurement on the marketing site and the app
- GitHub — when you connect a repository
- Dodo Payments — payment processing and subscription management
- Resend — sending alerts and the weekly digest, which means your email address and the contents of those messages pass through them
We may also disclose data where the law requires it, and to a buyer if the business is sold, in which case this policy travels with it.
Where it is processed
Cloudflare runs the service across its global network, so processing may happen outside the European Economic Area. Where no adequacy decision covers the destination, transfers rely on the EU standard contractual clauses in our agreements with each processor.
How long we keep it
- Account and site settings — while your account exists.
- Search Console history — the first connection backfills up to 16 months, and from then on Seoduh keeps the daily history so old periods stay comparable.
- Cached provider responses — short-lived, refreshed at the next daily boundary.
- Invoices — five years from the end of the calendar year in which the invoice was issued, as Polish tax law requires.
- After you delete your account — your workspace, sites, connections and derived history are deleted within 30 days, and backups roll off within 90 days.
Your rights
You can ask for a copy of your data, correct it, delete it, take it elsewhere in a portable form, object to processing based on legitimate interests, or withdraw consent. Email [email protected] and we will answer within a month. You can also complain to your data protection authority; ours is the President of the Personal Data Protection Office (UODO) in Poland.
Cookies
The marketing site and the app measure usage with Google Analytics 4 and Microsoft Clarity so we can see which pages are read and where visitors struggle — but only after you accept the banner that asks on your first visit. Until then nothing from either service loads. Both set their own cookies and receive your IP address, device and usage data once enabled; Google and Microsoft process it under their own policies. The app additionally stores your sign-in session in your browser so you stay logged in. There are no advertising cookies anywhere in the product. You can change your mind at any time with the Cookie settings link in either footer, which forgets the choice and asks again; a content blocker works too, and the sites keep working either way.
Children
Seoduh is a tool for running websites and is not intended for anyone under 16.
Changes
When this policy changes we update the date at the top, and for anything material we email account owners before it takes effect.