Your Data Privacy and Brass-SEO
You're safe — and here's why. Every part of Brass-SEO is built so your Google data stays yours, your conversations stay private, and nobody — not even us — can see what you ask.
The Short Version
If you only read one section, make it this one. Here is everything Brass-SEO can and cannot do with your data:
| What We Do | What We Cannot Do |
|---|---|
| Read your GSC search data | Modify your Google accounts or website |
| Read your GA4 analytics data | See your conversations (even our team cannot) |
| Encrypt your access tokens | Access your billing or credit card details |
| Auto-delete chats after 30 days | Use your data to train AI models |
| Let you delete everything instantly | Keep your data after you delete your account |
Read-Only Google Access
When you connect Google Search Console or Google Analytics, Brass-SEO requests the minimum permissions possible:
Google Search Console
Permission: webmasters.readonly
This lets Brass-SEO view your search performance data, check indexing status, and see which keywords bring traffic. It cannot submit URLs, remove pages, add users, or change any settings.
Google Analytics 4
Permission: analytics.readonly
This lets Brass-SEO read your traffic, landing page, and engagement data. It cannot create goals, modify reports, add tracking code, or change any configuration.
Google's consent screen shows you exactly what you're granting before you approve. You will see "View Search Console data" and "View your Google Analytics data" — nothing more.
Google-verified: Brass-SEO's OAuth application has been reviewed and approved by Google's Third Party Data Safety Team. This means Google has verified that our data access practices meet their security standards.
Read more about why we built Brass-SEO read-only on purpose and the 5 questions to ask before giving any SEO tool your Google access.
Encrypted Token Storage
When you connect your Google accounts, Brass-SEO receives an access token that allows it to read your data. These tokens are stored with AES-256-GCM encryption — the same encryption standard used by banks and government systems.
The tokens are encrypted before they reach the database. Even in the unlikely event of a database breach, the tokens would be unreadable without the separate encryption key.
You can revoke access at any time by disconnecting your Google accounts from the account settings page or by removing Brass-SEO from your Google account permissions.
Private Conversations
Every question you ask Brass-SEO and every response you receive is private to your account. This is enforced at the database level, not just the application level.
Row Level Security
Every chat table in the database has security policies that enforce ownership. Your user ID must match the record's owner before any data is returned. This applies to chats, individual messages, and conversation state.
No Admin Access to Chats
The internal admin dashboard shows subscription status, usage metrics, and connection status. It does not display message content. There is no interface for team members to view customer conversations.
Automatic Cleanup
Chat history is automatically deleted after 30 days through an automated process. This limits the data footprint and ensures old conversations do not persist indefinitely.
The only person who can read your conversations with Brass-SEO is you.
AI Does Not Train on Your Data
Brass-SEO routes AI conversations through a privacy-configured gateway. This setup means:
- •Not stored. Your conversations are not retained by the AI provider after generating a response.
- •Not trained on. Your data is not used to improve, fine-tune, or train AI models. Your SEO data and business information never become part of a training dataset.
- •Not remembered. Each conversation session is independent. The AI does not carry information from one session into another. When you start a new chat, it starts fresh.
This is a deliberate architectural choice. We selected our AI provider and gateway configuration specifically to ensure your business data stays isolated and private.
Payment Security
Brass-SEO never handles your credit card information directly. All payment processing goes through LemonSqueezy, a dedicated payment processor.
When you subscribe, you enter your payment details on LemonSqueezy's secure checkout page. Brass-SEO receives a confirmation that payment succeeded and your subscription status — nothing else. Your card number, billing address, and payment credentials never touch our servers.
You can manage your billing, update payment methods, or cancel your subscription at any time through the billing portal in your account settings.
You Control Your Data
You can remove your data from Brass-SEO at any time, in two ways:
Disconnect Google Accounts
Revoke access from your account settings or from Google's permission manager. Brass-SEO immediately loses the ability to read your Google data.
Delete Your Account
Full account deletion removes everything: your user record, stored tokens, chat history, and conversation state. This is permanent and immediate.
There is no retention period, no "we keep your data for 90 days," and no fine print. When you delete, the data is gone.
Infrastructure Security
Beyond the privacy features above, Brass-SEO is built on infrastructure designed for security:
| Layer | Protection |
|---|---|
| Authentication | Secure authentication with session management |
| Database | Row Level Security on every table containing user data |
| Encryption | AES-256-GCM for OAuth tokens at rest |
| Hosting | HTTPS, security headers, and firewall protection |
| Monitoring | Error tracking and performance monitoring (no chat content logged) |
| Rate Limiting | Per-user and per-IP rate limits on all API endpoints |
FAQ
Can Brass-SEO make changes to my website or Google accounts?
No. Brass-SEO uses read-only OAuth scopes for both Google Search Console and Google Analytics. It can view your search performance and analytics data but cannot modify your website, your Google settings, or any of your data.
Can anyone at Brass-SEO read my conversations?
No. All chat messages are protected by Row Level Security at the database level. Each user can only access their own conversations. There is no admin panel or backdoor that exposes chat content. Even the internal admin view only shows subscription status and usage metrics, never message content.
Does the AI remember my conversations or use them for training?
No. Brass-SEO routes conversations through a privacy-configured gateway. Your conversations are processed to generate a response and then discarded. They are not stored by the AI provider, not used to improve or train AI models, and not accessible to anyone outside your session.
What happens to my data if I cancel my subscription?
Your chat history is automatically deleted after 30 days through an automated cleanup process. If you want immediate removal, you can delete your account from the account settings page, which permanently removes all your data including conversations, OAuth tokens, and user records.
Does Brass-SEO store my credit card information?
No. All payment processing is handled by LemonSqueezy, a third-party payment processor. Brass-SEO never sees, stores, or has access to your credit card numbers, billing details, or payment credentials.
Related Resources
Privacy Policy
The full legal privacy policy for Brass-SEO.
Terms of Service
Usage terms, data handling, and service conditions.
Support
Contact us with any questions about data privacy.
About Our Bot
How the Brass-SEO crawler works and what it accesses.
5 Questions Before Connecting
What to check before giving any SEO tool your Google access.
Why Read-Only Access
Our design philosophy: request only the access you need.
The SEO Tool Trust Test
A framework for evaluating any tool's data practices.
Ready to Get Started?
Your data is protected at every level. Connect your Google accounts with confidence — read-only access, encrypted storage, and private conversations. Your first three days are free.
Start Your Free Trial