Privacy policy
Effective 2 October 2026
This policy is from SEOComet (“we”, “us”). It covers two things: the SEOComet web app at www.seocomet.com, and the SEOComet SEO Toolbar, our free Chrome extension. They work differently, so each has its own section.
In short: the web app stores what it needs to run your account and check your sites. The toolbar doesn’t send anything to us at all. We don’t sell data and we don’t use it for advertising. Questions go to [email protected].
The web app
What we store
- Your account: your name, email address, and a hashed password if you set one. If you sign in with Google, your Google account id as well.
- Your workspaces: workspace names, time zones, who the members are and their roles, and the email addresses you send invitations to. Also your alert rules and alert channels, which can include Slack webhook addresses, webhook addresses and their signing secrets, and email addresses.
- The sites you monitor: the addresses you add, the settings of each check, and what the checks find: status codes, response times, certificate details, URL counts and the issues raised. We keep copies of the robots.txt, ads.txt and app-ads.txt files we fetch so you can compare versions. For sitemaps we keep the counts and dates we read, not the files. We also save each site’s icon to show it in the app.
- Incidents and alerts: the incidents your checks open, who acknowledged them, and a record of each alert we sent and whether it was delivered.
- Activity log: who did what in a workspace, such as adding a site or changing a rule.
- Sessions: while you’re signed in, your session record holds your IP address and your browser’s user agent.
- Logs: the app logs errors and keeps them for 14 days. Our web server keeps standard request logs (IP address, the address requested, browser) for security and troubleshooting, and deletes them on a rolling basis.
- Billing: your Stripe customer id, your subscription’s status and plan, and the brand and last four digits of your card as Stripe reports them.
How we use it
To run the checks you set up, send the alerts you ask for, keep your account working and bill paid plans. We send account email too: address confirmation, password resets, workspace invitations and email alerts. We don’t run analytics or advertising scripts on the web app.
Fetching your sites
Our checks fetch the addresses you add to your account, and the files linked from them such as child sitemaps, with the user agent SEOCometBot. We only fetch what an account has asked us to watch.
Cookies
- A session cookie that keeps you signed in while you use the app.
- XSRF-TOKEN, which protects forms against cross-site request forgery.
- A remember-me cookie, set when you tick “Keep me signed in” or sign in with Google, so you stay signed in after closing the browser.
- Two preference cookies: appearance (light, dark or system) and whether the sidebar is open.
- seocomet_signed_in, set while you’re signed in, so these pages show “Open dashboard” instead of “Sign in”. It only says that you’re signed in, not who you are.
We don’t use advertising or tracking cookies. Cloudflare may set a cookie of its own when it needs to tell people from bots.
Who else handles your data
- Stripe takes payments. You enter card details on Stripe’s checkout and billing portal pages, so they never reach our servers.
- Resend sends our email. It receives the recipient’s address and the message.
- Google, if you choose Google sign-in. We ask Google for your name, email address and Google account id, and nothing else.
- Hetzner hosts our servers and database in the EU, in Helsinki, Finland.
- Cloudflare sits in front of www.seocomet.com for DNS and protection against attacks, so requests to the site, including your IP address, pass through it.
- Slack and your own webhook endpoints receive alerts when you set them up as channels. What happens there is up to you and those services.
How long we keep it
- Free: check history for 7 days and the activity log for 30 days.
- Pro: check history for 90 days and the activity log for 90 days.
- Agency: check history for 90 days and the activity log for 90 days.
- Records of sent alerts: 90 days, on every plan.
- Your account and workspaces: until you delete them.
Deleting your account deletes the workspaces you own, with their sites, check history, incidents and settings, and cancels their subscriptions. If someone else is a member of a workspace you own, you transfer it to them first. Stripe keeps its own payment records, as the law requires.
The SEO Toolbar
The SEOComet SEO Toolbar doesn’t collect, store or sell personal data. It has no account and no analytics. Nothing it reads is sent to SEOComet.
It reads the page in your current tab to show its SEO report. That stays in your browser. To build the report it makes these requests:
- To the site you’re checking: the page again, from inside the page, so the HTML the server sent can be compared with what you see. Like a reload, this carries that site’s own cookies.
- To the site you’re checking: its robots.txt and sitemap files. These requests carry no cookies.
- When you press a check button: the page’s images and links, which may be on other sites. These requests carry no cookies.
- When the popup opens: the page’s share images (Open Graph and X), to check their size. They may be on other sites. These requests carry no cookies.
- To Google’s Chrome UX Report API, when you press Web Vitals: the page’s address without its query string. Google’s privacy policy applies to that request.
- The popup shows thumbnails of the page’s images and share images. Your browser loads them like any image, and the image’s site may receive its own cookies.
The SEOComet logo and the “Monitor this site” link open www.seocomet.com with the checked site’s address in the link. That only happens when you click them.
The toolbar stores your settings and short-lived caches on your device: robots.txt rules for 10 minutes, check results until the tab moves to another page, and Web Vitals for up to 24 hours. Removing the extension deletes them.
Your rights
You can see and change your name and email address in your profile settings, and delete your account there. You can also ask us for a copy of your data, to correct it, to delete it, or to stop using it for a particular purpose. Write to [email protected] from the address on your account.
If you’re in the EU or the UK and think we’ve handled your data wrongly, you can complain to your data protection authority. We’d rather hear from you first.
Children
SEOComet is a tool for people who run websites. It isn’t meant for anyone under 16, and we don’t knowingly keep data about children.
Changes to this policy
When this policy changes, we’ll update the date at the top. If a change affects how we use your account data, we’ll email account holders before it takes effect. The terms of service cover the rest of how SEOComet works.
Contact
SEOComet, [email protected].