Seodar

Privacy

Last updated: 10 September 2026

Who is responsible for this data

Seodar is run by ORTAL, Petar Nikolić s.p., Gasilska ulica 17, 6000 Koper - Capodistria, Slovenia. Slovenian tax number SI39522016. That business is the controller of everything described on this page, and the person answering [email protected] is the person who runs it. There is no data protection officer: Seodar is too small to be required to appoint one, and saying so is more useful than leaving the question open.

What we collect

  • Your account email. Needed to sign you in, to send verification and password-reset links, and to reach you about your account. Nothing else about you is required - no name, no company, no phone number.
  • The URLs you submit and what we find at them. When you add a site or run a free scan we fetch its pages and store what the checks produced: titles, meta descriptions, headings, word counts, links and timings. This is the product; without it there is no report.
  • Ordinary server logs. Timestamp, the page requested, the status it returned, the browser's user-agent string, and the address the request arrived from - which, for everything served through our network provider, is that provider's own address and not yours. Your address does reach the application: it is used to work out the daily limit on free scans and to build a visit counter, and it is discarded in the same breath rather than written down. These logs are kept for 30 days and then deleted. Separately from them we keep a count of visits per page, per country and per referring site; that count carries no identifier and no cookie, is the same whether you answered the banner or not, and is kept for a year.
  • When you were last signed in, and the country you signed in from. Your session already tells us both; we store the time and the country - and the city, if our network provider resolves one - so we can tell an account that is being used from one that has been abandoned, and so we can recognise a sign-in from somewhere unexpected. We keep the latest value only, not a history of the addresses you have used, and the address itself is not stored in your account. It is visible to Seodar staff, not to anyone else.
  • The country a free scan was run from. A free scan needs no account, so there is nothing to attach it to but the request itself. We store two letters - the country our network provider reports - against the scan, so we can see where interest in Seodar is coming from. Not your address, not your city, no identifier and no cookie: the address is used to apply the daily limit on free scans and is held only in a counter that expires within a day.

If you connect Google Search Console

Connecting Search Console is optional and everything below applies only if you do it.

  • What we ask Google for. One permission: webmasters.readonly. It lets us read your Search Console data and nothing else. We cannot change anything in Search Console, and we cannot see Gmail, Drive, Contacts, or any other Google service.
  • What we read and store. The list of properties your Google account can access, and for the one property you choose: daily clicks, impressions, click-through rate and average position, plus the search queries and page URLs behind them. We do not receive or store anything about the people who searched.
  • What we use it for. Only to show you the search-performance screens and the analysis built on them inside Seodar. We do not sell it, we do not share it with anyone, we do not use it for advertising, and we do not use it to train AI models - ours or anybody else's.
  • How the connection is protected. Google gives us a long-lived token so we can refresh your data overnight. It is encrypted before it is written to disk, it is never written to a log, and it is used for nothing but reading the property you selected.
  • How long we keep it. Daily totals for 16 months - the same window Search Console itself keeps - and the query-and-page detail for 90 days.
  • How to stop it. Disconnect from your account page. That revokes our access at Google and deletes every row we stored for that connection. You can also revoke us directly from your Google account permissions.

Seodar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect Google Analytics

Connecting Analytics is optional and everything below applies only if you do it.

  • What we ask Google for. One permission: analytics.readonly. It lets us read your Analytics data and nothing else. We cannot change anything in Analytics, we cannot see Gmail, Drive, Contacts or any other Google service, and we cannot reach any property you do not choose.
  • What we read and store. The list of properties your Google account can access, and for the one property you choose: per day and per page, the number of sessions, engaged sessions, key events and revenue. We do not receive or store anything about the individual people behind those numbers - no user identifiers, no client ids, no session recordings, no demographics.
  • What we use it for. Only to show you the traffic screens inside Seodar and to rank what a crawl found by how much of your traffic it affects. We do not sell it, we do not share it with anyone, we do not use it for advertising, and we do not use it to train AI models - ours or anybody else's.
  • How the connection is protected. Google gives us a long-lived token so we can refresh your data overnight. It is encrypted before it is written to disk, it is never written to a log, and it is used for nothing but reading the property you selected.
  • How long we keep it. Per-page detail for 400 days; the daily totals for as long as the connection exists.
  • How to stop it. Disconnect from your account page. That revokes our access at Google and deletes every row we stored for that connection. You can also revoke us directly from your Google account permissions.

Seodar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect Cloudflare

  • What you give us. An API token that you create and scope yourself. We store it encrypted, never log it, and use it only to read analytics for the zone you picked. Delete the connection here, or revoke the token at Cloudflare, and it stops working immediately.
  • What we read. Per day and per crawler: how many requests your site served, how many succeeded, how many were served from cache, and how long your origin took. It is traffic that never reaches an analytics tag, which is the point of having it - and it is about machines, not about people.

If you track keyword positions

The phrases you ask us to track, and the country, language and device you set for them, are sent to Serper, our search-results provider, on your behalf - that is how a position gets measured at all. The request carries a search phrase and a locale, and nothing else - no account, no identifier.Your site's address is never sent. Whether you rank is worked out here, on our own server, by reading the results that came back and looking for your domain among them. The phrases are yours to write, so if you track one that names you, that phrase is what goes. Your keyword list is not shared with other customers, and it is deleted with the site.

Cookies

Two, and only one of them is set without asking. sid is the session that keeps you signed in: strictly necessary, no identifier of its own beyond a random token. seodar_consent remembers your answer to the banner, so we stop asking - it holds one word and is set whichever way you answer, including no.

If you allow it, Google Analytics sets its own cookies to count visits. Advertising features and ad personalisation are switched off in the configuration, so the measurement is visit counts and page paths rather than a profile of you.

If you say no, Google's tag still loads and still sends a request, and it is worth being exact about what that request is and is not. It carries no cookie and no identifier, nothing is written to or read from your device, and advertising identifiers are stripped from it. What it does carry is the fact that a visit happened, which Google uses to estimate the total in aggregate. This is Google's Consent Mode, and it is how we can advertise without counting the people who asked not to be counted individually. Until 16 August 2026 nothing loaded at all until you pressed Allow; that was stricter, and it is written here rather than quietly changed.

You can change your mind at any time: Cookies in the footer brings the question back, and choosing no removes the analytics cookies on your next page load. Saying no changes nothing else about the site.

One more thing on the page a free scan produces, and only there: Google's sign-in prompt (One Tap), the small "Continue as" box that appears if you are signed in to Google. It is Google's script, it loads whether or not you answered the banner, and Google may set its own cookies for it; Google's privacy policy applies to that prompt. Nothing about you reaches us unless you press it, and closing it is the end of it.

Session recording

Only if you press Allow. If you agree to the banner, we load Microsoft Clarity, which records how a visit moves: mouse movement, clicks, scrolling and what the page looked like. We watch those recordings to find where people get stuck, and fix it.

Unlike the analytics above, this one does not load at all unless you agree. There is no reduced version of a session recorder - it either records or it is not there - so the gate is the script itself, and if you say no it is never fetched.

Inside your account it records what you did, never what you were looking at. Every page behind sign-in is marked so that Clarity blocks the text before it leaves your browser. Your sites, your scores, your findings, your email address - none of it is recorded and none of it reaches Microsoft. What is recorded is where you clicked, how far you scrolled, where the pointer went and which page you were on. That is enough to see that a button is being missed, and not enough to see anything about you.

The masking is written into the pages themselves rather than switched on in Clarity's settings, so it cannot be turned off by accident from a dashboard.

Two places are excluded outright rather than masked: the checkout, and our own internal operator console. Microsoft processes all of this as our processor. Choosing no in the banner, now or later, stops it - and if you have already been recorded, saying no stops any further recording from that click onward.

Who else processes it

Running Seodar means a few specialist providers handle some of this on our behalf. They are named here rather than described, together with what actually reaches each one.

ProviderWhat reaches itWhere, and on what basis
Hetzner Online GmbHThe server itself, and therefore everything described on this page while it is stored.Germany. Inside the EEA, so no transfer out of it.
Cloudflare, Inc.Sits in front of the site. Sees request metadata in transit - address, timestamp, the page asked for.United States, under the European Commission's standard contractual clauses.
Plus Five Five, Inc. (Resend)Your email address and the contents of the messages we send you.United States, under the European Commission's standard contractual clauses.
StripeIn use. Your billing details and the payment itself. We never see or store a card number.United States, under the European Commission's standard contractual clauses.
DataForSEO OÜKeyword and backlink data, and the AI visibility checks. It receives a bare domain name - no path, no page, no page content - or the keyword phrases and prompts you entered. See What the AI features send below.Estonia. Inside the EEA, so no transfer out of it.
Anthropic PBCThe two AI writing features, and only when you press the button. See What the AI features send below for exactly what each one carries.United States, under the European Commission's standard contractual clauses (module two, controller to processor).
Google Ireland LimitedAnalytics and the advertising tag, on the public pages only. Under Cookies above: with your consent, the visit and the analytics cookies that count it; without it, the bare fact that a visit happened, carrying no cookie and no identifier. Ad personalisation and Google Signals are switched off in the configuration either way, so no advertising profile is built from this whichever answer you give. Nothing from inside your account, ever.Ireland. Inside the EEA; Google's own onward transfer to the United States runs on the European Commission's standard contractual clauses.
SerperIn use if you track keywords. A search phrase and the country, language and device set for it. Not your site's address, not your account - whether you rank is worked out on our own server from the results it returns.United Kingdom, which the European Commission has found to provide an adequate level of protection, so no further safeguard is required.
Microsoft Ireland Operations LimitedSession recording, on the public pages only and only if you agreed to the banner. See Session recording above for what it never sees.Ireland. Inside the EEA, so no transfer out of it - Clarity customers in the EU contract with the Irish entity, and Microsoft's own onward transfer to its United States affiliate runs on standard contractual clauses between them, which is its arrangement to make, not ours.

Each acts only on our instructions under its own data-processing terms, and none of them is permitted to use your data for its own purposes. Where a provider engages others of its own, that is disclosed in its terms; it stays answerable to us for what they do, and we stay answerable to you.

What the AI features send

All of it is optional, and none of it runs on its own. The crawler, all 195 checks, rank tracking, Search Console, Analytics and Bing work without a single AI call. The AI features are part of the paid plans only; on a free account the button is visible but refuses before anything is fetched or sent. Every AI action is one you press, each costs credits, and what comes back is a suggestion - Seodar never writes anything to your site.

There are three of them and they send very different things, so they are described separately rather than as one paragraph.

  • Rewriting a title and meta description- to Anthropic. It receives that one page: its address, the language the page declares, its current title, meta description and first heading, and the first 3,000 characters of its visible text. It does not receive your email address, anything about your account, any other page of yours, or any other customer's data.
  • Summarising a report - to Anthropic. It receives your site's address, the health score, how many pages were crawled, how many findings there were at each severity, and the fifteen most significant findings as check identifiers with counts. No page content and no page addresses - the model is told the name of a check and how often it fired, and writes the summary from that.
  • AI visibility- to DataForSEO. It receives the prompt you wrote and which assistant to run it against. DataForSEO puts that prompt to OpenAI, Google and Anthropic models on our behalf; our agreement is with DataForSEO, and we have no contract with those model providers. Nothing from your site's content is sent - but the prompt is free text you write, so whatever you type is what goes.

How long the AI provider keeps it. Anthropic retains what we send and what it returns for 30 days, and may access it for safety and security purposes. A zero-retention arrangement exists and we have not enabled it, so this is the position today rather than the best position available.

Training. We do not use any of this to train AI models, ours or anybody else's. Separately, and as their own obligation rather than a control we operate, both providers exclude what is sent through their APIs from training under their own terms - Anthropic's commercial terms and DataForSEO's privacy policy.

What the keyword and backlink data costs you in privacy

Two features ask an outside data provider about your site rather than crawling it ourselves, and it is worth being exact about what leaves.

  • Backlinks and competitor research send DataForSEO a bare domain name - lowercased, with the scheme, any www., any path and any port removed. Not a page address, not page content, not your email, and no identifier of your account.
  • Keyword research and volumes send the keyword phrases themselves, with the country and language you chose. Phrases are sent in batches rather than one call each, which means fewer requests carrying the same words, not more.
  • Rank tracking sends each tracked phrase to Serper, with the country, language and device set for it.

No provider is told who asked. None of these requests carries an account identifier, a site identifier, a customer reference or a callback address. The provider sees a domain or a phrase; which of our customers it belonged to stays on our server, where we record it to bill the credits and show you the result.

Why we are allowed to do this

The GDPR asks for a lawful basis per purpose rather than one for the whole company, so here they are, one line each.

  • Running your account - signing you in, crawling the sites you add, storing findings, sending the mail the product owes you: performance of the contract you entered when you created the account.
  • Taking payment - the same contract, and for the invoice records themselves a legal obligation under Slovenian accounting law, which sets how long they must be kept regardless of what else is deleted.
  • Server logs, rate limits and stopping abuse - our legitimate interest in keeping the service up and not paying for somebody else's scraping. Balanced by keeping almost nothing: no visitor address is written down, and the logs go after 30 days.
  • Counting visits - legitimate interest in knowing which pages are read. The counter cannot identify anyone: the identifier it uses is a one-way hash that changes every day and cannot be linked across two of them.
  • Session recording - consent. It loads only after you press Allow, and not at all if you do not.
  • Analytics and advertising cookies - consent. Nothing is written to or read from your device until you allow it.
  • The cookieless signal that fires when you say no - legitimate interest in measuring totals. This one is not consent, and pretending otherwise would contradict Cookies above, which says plainly what changed on 16 August 2026: a request still leaves the page, carrying no cookie and no identifier and writing nothing to your device, so that Google can estimate a total without counting you individually. Because nothing is stored on your device it is a question about measurement rather than about cookies. You may object to it, as you may to the other legitimate interests on this list.
  • The AI features and the outside data providers - performance of the contract: they are features of the paid plans, each one started by you pressing a button.

Where the basis is a legitimate interest you may object to it, and where it is consent you may withdraw it at any time without giving a reason - the banner reopens from the footer of every page.

How long we keep it

Account data and crawls for as long as the account exists. Free anonymous scans are deleted after 30 days; an email you gave us for one is kept until you ask us to remove it. Deleting a site deletes its crawls, pages and findings. Search Console data follows the windows in the section above, and disconnecting deletes it immediately.

Invoices are kept longer than anything else here: ten years. Slovenian VAT law requires a taxable person to keep them until the end of the tenth year following the year they relate to. That is a legal obligation rather than a choice of ours, and it is one of the few things your right to erasure cannot reach - the law that requires the record is the same law that overrides the request to delete it.

Your rights

Two of them do not need us at all. Export on your account page hands back everything we hold on your account as one file, and delete your account is on the same page - it asks for your password, then removes your sites, crawls, findings, keywords and every connection, and it cannot be undone. For a correction, or anything the buttons do not cover, write to [email protected] and we will do it. If you are in the EU or the UK you also have the right to complain to your data protection authority.

Crawling other people's sites

Only submit URLs you are entitled to have scanned. SeodarBot obeys robots.txt and is capped and rate-limited, and /bot explains how to block it.