
Each local area page used to take us half a day to create and optimize.
With SEOmatic, we can create hundreds of pages in the same time, which helps our clients make the best use of their budget.
It's transformed how we deliver scalable SEO solutions.
Will Hawkins
Marketing Director, Digi-Business UK
Agents read your Search Console data, do the work, and prove what actually moved. You decide what ships.
14-Day Free Trial. $1 today, not refunded, credited to your first payment.
Last updated: September 29, 2026
SEOmatic (seomatic.ai) is operated from 1 rue Marguerin, 75014 Paris, France. For the personal data of our customers and visitors we act as data controller; for the website data our customers connect (their own or their clients' sites), we act as data processor on their instructions. For any privacy matter, contact contact@seomatic.ai.
We collect only what the service needs to work:
We use your data to run the product: reading your Search Console data to diagnose and prioritize SEO work, generating content and fixes with AI, staging changes for your approval, and publishing approved changes to your CMS. We also use it to bill you, support you, secure the service, and improve the product. A workspace can optionally run its AI text generation on Anthropic or OpenAI using its own API key - the provider then bills you directly under your own agreement with them, and your explicit confirmation of this is required and recorded.
We do not sell personal data. We do not use your data or your clients' site data to train AI models.
SEOmatic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Concretely: Search Console data is read solely to provide the SEO features you see in your dashboard and reports. It is not transferred to third parties except as necessary to provide those features, not used for advertising, and never sold. You can revoke access at any time from your Google account permissions or by disconnecting the integration in SEOmatic.
To generate content, analysis, and recommendations, relevant inputs (for example page content, search queries, and your instructions) are processed by AI model providers acting as subprocessors. We never use your data to train models of our own. Provider terms vary: Anthropic and OpenAI process API traffic under terms that exclude training on customer content, while Moonshot's API terms carry no equivalent enterprise guarantee. By default, every change an agent proposes waits for your approval before anything is published; if you switch a workspace to the Assisted or Auto mode, the changes that mode allows publish without a per-change approval, while destructive changes such as redirects and de-indexing always wait for an admin, as described at seomatic.ai/trust.
Our default writing model is operated by Moonshot AI, whose infrastructure is hosted in China. If Moonshot fails to start a request (an outage), that request may be retried once on DeepSeek, also hosted in China. Workspaces marked EU-sensitive (a per-workspace toggle in Settings → Agent → Data Residency) are routed to Anthropic instead; this routing is enforced in code, not by policy alone. The Anthropic calls run on your own Anthropic API key - Anthropic bills you directly for that usage, and enabling the toggle requires your explicit, recorded confirmation of this - so content that must not reach a China-hosted provider never does, on terms between you and Anthropic. For those workspaces there is no outage backup: if Anthropic is unavailable, the request fails rather than moving to another provider. AI-visibility scans work differently for every workspace: the scan questions go to the answer engines you select (which can include Moonshot's Kimi), and the engines' public answers are analyzed with our default model.
We share data only with the service providers that make the product work:
We keep your data while your account is active. When you delete a workspace or your account, associated data (including Search Console data and CMS credentials) is deleted from production systems within 30 days, with encrypted backups expiring on their rotation schedule of up to 90 days. Invoices are retained as long as French accounting law requires. You can request deletion at any time at contact@seomatic.ai.
If you are in the EU/EEA or UK you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. Write to contact@seomatic.ai and we will respond within 30 days. You can also download your account data yourself from Settings, then Account. You may also lodge a complaint with your supervisory authority; in France that is the CNIL (cnil.fr).
Where we act as processor for our customers' client data, we forward and support requests according to our customers' instructions.
Our infrastructure is hosted in the United States. For personal data of EU/EEA and UK users, transfers rely on Standard Contractual Clauses or an applicable adequacy framework with each subprocessor. Where the China-hosted writing model would be involved, EU-sensitive workspaces are routed to a US-based provider instead, as described in section 5.
We use first-party cookies for authentication and session state, remembering your selected organization and your cookie choice, one first-touch attribution cookie (set on your first visit, after consent where it is required) so we know which channel brought you here, referral cookies when you arrive through a referral link, and analytics as described above. Some services we load set their own cookies: Stripe on payment screens, Crisp chat, Featurebase surveys and Google Analytics on our website, hCaptcha on public forms, and Rewardful to credit affiliate referrals. We do not run third-party advertising cookies. For visitors in the EU/EEA, UK, and Switzerland, analytics cookies, the attribution cookie, Google Analytics, Rewardful and Featurebase surveys are set only after you accept the consent banner, and Crisp loads only once you accept or click the chat button; declining is one click and the site works identically. See seomatic.ai/gdpr for the plain-English summary of your rights.
Data is encrypted in transit (TLS). CMS credentials and OAuth tokens are encrypted at rest (AES-256-GCM) and API keys are stored as SHA-256 hashes only; a small number of lower-risk secrets (webhook signing secrets, sign-in provider tokens managed by our auth library, single-use invitation and email verification links, and site tracking tokens) are protected by access controls rather than application-level encryption. Access to production systems is restricted and logged, and every staff sign-in to a customer account for support is recorded in an audit log. API keys are shown only once, at creation. Security reports go to contact@seomatic.ai; see also /.well-known/security.txt.
We publish four optional Chrome extensions: AI Citation Logger, AI Overview Inspector, Search Console Overlay, and AI Traffic Tracker. They are separate from the web app, install only if you choose, and each one is off until you explicitly turn it on. Uninstalling removes all local data.
All four share the same rule: the only thing that ever leaves your browser is information about your OWN connected domains, and it goes only to your own SEOmatic workspace. Nothing is sold, shared with third parties, transferred for advertising, or used for creditworthiness or lending. Nothing is used to train AI models. The check for whether a page belongs to you happens on your device, before any network request is made, so pages and sites that are not yours are never transmitted.
What each extension sends to your workspace:
Our optional Slack app posts the decisions your SEO agents need (changes waiting for approval, proposed campaign plans, held work, pastes and changes that measured worse) as cards in the Slack channels your organization chooses, and lets permitted teammates decide from Slack, including applying held work, undoing changes and running campaign plans. It also offers a Home tab with controls for your SEO agents, a /seomatic command, previews for SEOmatic links, an optional weekly report, and SEO Copilot answers to questions asked in a direct message to the app, by mentioning the app in a channel, in Slack's AI app panel, or with /seomatic ask. The owner of your SEOmatic organization installs it, in one Slack workspace or org-wide on Enterprise Grid.
It asks Slack for thirteen permissions: chat:write, chat:write.public, incoming-webhook, users:read, users:read.email, commands, links:read, links:write, channels:read, groups:read, app_mentions:read, im:history and assistant:write. app_mentions:read lets Slack send us messages that mention the app; im:history lets Slack send us the messages people write in a direct message with the app; assistant:write lets the app show a status line and suggested prompts in Slack's AI app panel. None of them gives access to the history of your channels, so the app never reads your channel conversations. When someone links their Slack account, Sign in with Slack asks for one user permission, openid, and nothing else (no email or profile).
What we store:
What the app reads from Slack, only when it is used:
Data from Slack is used only to run the Slack app. It is not sold, not shared with third parties except the subprocessors that run the product (section 6), not used for advertising, and not used to train AI models. Questions asked in Slack are answered by the SEO Copilot exactly like questions asked in the app, so they are processed by our AI model providers as described in section 5.
Disconnecting Slack in SEOmatic (Settings, then Integrations) revokes the token at Slack, unless the same Slack workspace is still connected to another SEOmatic organization that relies on the same token, and deletes the stored bot token and webhook URL. Removing the app from your Slack workspace, or Slack revoking its token, makes Slack notify us, and we delete the stored credentials the same way. We also disconnect and delete them when Slack reports that the token no longer works, and we delete the old ones when a new install replaces the connection. Deleting your SEOmatic organization, or your account together with the organizations you own, revokes the token at Slack first, with the same exception, before the connection is deleted. After a disconnect, nothing more is posted.
Channel problems are handled separately: if Slack reports that the default card channel was archived or deleted, or that posting there is restricted, or the channel is shared with another organization (at install or later), or the channel picked at install is one the app cannot see, we pause cards to it and delete the webhook URL for that channel, but keep the encrypted bot token while the integration stays connected, so the organization owner can pick a new channel in Settings without reinstalling.
The rest is kept while your organization exists, so that reconnecting keeps your settings and the history stays auditable: the connection record without credentials, settings, channel routes, card references and decision records. It is deleted with your organization under section 7. Questions asked in Slack, their answers and the record of which Slack thread they belong to are kept with the site, like SEO Copilot conversations in the app, and are deleted when the site is deleted, when the SEOmatic account of the person who asked is deleted, or with your organization. The activity log is deleted automatically after 180 days, or with your organization if that comes first; its entries not tied to an organization (identity links and unlinks, and installs not yet connected to one) are deleted after 30 days. Identity links are kept until they are removed or the linked SEOmatic account is deleted; each person can unlink their own Slack account in Settings, then Account, and the organization owner can see and remove the links of their team on the organization's connected Slack workspace in Settings, then Integrations.
To access, export or delete your Slack-related data sooner, or to remove an identity link, email contact@seomatic.ai. We answer within 30 days, as described in section 8.
When this policy changes materially we will update the date below and, for significant changes affecting existing customers, notify you by email. The current version always lives at seomatic.ai/privacy.