seoreport.ro
  • Home
  • Knowledge Base
  • Contact
  • RO / EN
  • Sign in
Data protection

Privacy Policy

Last updated: 23 August 2026

This policy explains what seoreport.ro processes, why it is needed, which external services take part in an analysis, and how you can control your data.

1. Controller and scope

The controller for seoreport.ro is SEO Report, with contact address București, România. Privacy requests can be sent to hello@seoreport.ro.

This policy applies to the Romanian and English versions of seoreport.ro, user accounts, SEO reports, JSON exports, and the optional Google Search Console connection.

2. Data we collect

We process only the information needed to provide, secure, and maintain the service.

  • Account data: name, email address when supplied by the provider, avatar URL, OAuth provider, provider user identifier, and account timestamps.
  • Sign-in data: Google or GitHub performs authentication. seoreport.ro does not receive your password and does not retain Google or GitHub access tokens used only for ordinary sign-in.
  • Report data: the submitted URL, report UID, language, visibility, status, timestamps, failure information, and the complete technical analysis result.
  • Technical and security data: session identifier, IP address, user agent, request and error logs, rate-limit events, and similar diagnostics needed to operate and protect the service.
  • Communication and support data: when you use “Report a problem,” we retain the message, associated SEO report, submission time, reply preference, and an email address only when you request a reply. For signed-in users, we use the profile email; signed-out visitors are asked for an email only after enabling the reply option.

3. What an SEO test does

When you submit a URL, our servers and an isolated desktop browser send requests to that URL and related HTTP/HTTPS and www/non-www variants. Redirects and same-site resources may also be requested. The destination website will therefore receive technical request information, including the IP address and user agent of the analysis infrastructure.

The report can store publicly returned page and infrastructure information. Do not submit private, authenticated, confidential, or token-bearing URLs. You must be entitled to test the address and to make any resulting report public.

  • HTTP responses, redirects, headers, compression, timing, DNS, server IP, TLS certificate, and 404 behavior.
  • Server HTML and rendered DOM content such as titles, descriptions, headings, links, image metadata, canonical and robots directives, structured data, Open Graph, and social preview metadata.
  • Cookies and consent signals observed inside the isolated audit browser, CDN/reverse-proxy indicators, ad-blocker impact, Ahrefs Domain Rating, and Google Lighthouse accessibility data when the relevant integrations are configured.

4. Optional Google Search Console data

Search Console is connected only after a separate, affirmative authorization. We request the read-only scope https://www.googleapis.com/auth/webmasters.readonly. The app reads the list of properties only to select one that covers the analyzed URL, then requests exact-page performance and URL Inspection data.

Google’s OAuth scope is technically account-wide for the Search Console properties available to the selected Google account; Google does not provide a domain-specific OAuth scope. SEO Report therefore maintains a separate internal authorization list. The first OAuth approval authorizes only the domain shown in the report inside SEO Report. Every additional domain requires a new explicit confirmation in the export dialog, even when the existing Google token can technically access it. Once a domain is confirmed, its other pages do not require another confirmation.

The exported data can include clicks, impressions, CTR, average position, queries, device breakdowns, comparison periods, indexing and canonical information, last crawl information, and derived observations for the exact analyzed URL. It is used only to create the enriched JSON export requested by the report owner.

Access and refresh tokens are encrypted at rest. Search analytics cache entries are valid for up to 6 hours and URL Inspection cache entries for up to 24 hours; cached payloads are encrypted and expired entries are removed during subsequent Search Console operations. Search Console data is not added to the public report and cannot be requested by a guest or another user.

seoreport.ro does not sell Google user data, use it for advertising, or use it to train general-purpose AI or machine-learning models. The site does not automatically send the exported JSON to an AI provider; any later upload or sharing initiated by you is under your control.

The use and transfer of information received from Google APIs by seoreport.ro adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. Purposes and legal bases

  • Performance of the service and steps requested by you: account creation, authentication, running and storing tests, displaying reports, retesting, sharing, and JSON export.
  • Consent: the optional, separately authorized Search Console connection. You may withdraw it at any time without affecting processing already performed.
  • Legitimate interests: service security, abuse and fraud prevention, rate limiting, diagnostics, reliability, and protection of users and infrastructure, balanced against your rights.
  • Legal obligations and legal claims: where retention or disclosure is required by applicable law or is necessary to establish, exercise, or defend legal rights.

6. Recipients and external services

We do not sell personal data. Authorized administrators may access accounts and reports when necessary to operate, support, secure, or investigate abuse of the service. Data may also be processed by hosting, database, backup, CDN/reverse-proxy, and security suppliers acting for the service, or disclosed to authorities when legally required.

Depending on the selected feature and configuration, a target URL, domain, server IP, or authorized data may be sent to the following services:

  • Google: account authentication; PageSpeed Insights/Lighthouse receives the tested URL; Search Console receives authorized exact-URL queries only after separate consent.
  • GitHub: account authentication.
  • Ahrefs: the analyzed domain for Domain Rating.
  • The analyzed website and its resource providers: requests required to load and inspect the submitted page.
  • jsDelivr and infrastructure/CDN providers, including Cloudflare where active: browser and connection data needed to deliver public assets and protect the service.

7. International data transfers

Some external providers operate outside Romania or the European Economic Area. Where personal data is transferred internationally, the transfer is handled under the provider’s applicable data-protection terms and a lawful transfer mechanism, such as an adequacy decision or standard contractual clauses, where required.

8. Retention

  • Account data and saved reports remain while the account exists, unless earlier deletion is required or requested. Deleting the profile removes the account and associated OAuth identifiers, reports, results, Search Console tokens, internal domain authorizations, and Search Console cache from the application database.
  • Ordinary server sessions normally expire after 120 minutes of inactivity. A remember-sign-in cookie may persist longer until logout, expiry, or browser removal.
  • Search Console tokens and internal domain authorizations remain until you disconnect Search Console or delete the profile. Cache validity is described in section 4.
  • Operational and security logs are kept only for the period reasonably necessary for diagnostics, abuse prevention, infrastructure security, and legal obligations.
  • Problem reports are retained with the associated SEO report for as long as needed for investigation and support. Deleting the associated report or profile also removes its linked problem reports from the application database.
  • JSON files downloaded to your device and copies shared with third parties are controlled by you and are not deleted when application data is removed.

9. Cookies used by seoreport.ro

seoreport.ro uses strictly necessary session, CSRF-security, language/navigation, and remember-sign-in mechanisms required for authentication, request security, and continuity. We do not currently use advertising cookies or first-party analytics cookies. Because these mechanisms are necessary to provide the requested service, disabling them may prevent sign-in or form submission.

Cookies listed inside an SEO report belong to the analyzed website. They are observed in an isolated audit browser on our infrastructure and are not written to your own browser by seoreport.ro.

10. Private and public reports

Every report is private by default and is available only to its owner and authorized service administrators. If you choose “Make public,” anyone with the UID link can view and export the standard report, and search engines may index it. Public pages may be copied, cached, or reshared by third parties beyond our control.

Private Google Search Console data is never included in a public report. Only the authenticated owner can request an export enriched with Search Console data.

11. Security

We use HTTPS, access controls, private-by-default reports, encrypted Search Console tokens and cache payloads, CSRF protection, rate limits, restricted administration, and infrastructure safeguards. No Internet service can guarantee absolute security; please contact hello@seoreport.ro if you suspect unauthorized access.

12. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time. You may also complain to the Romanian supervisory authority, ANSPDCP, or the competent authority where you live or work.

Send a request to hello@seoreport.ro. We may ask for information needed to verify your identity and will respond within the legally applicable period.

13. Deletion and revoking external access

You can delete your profile and all associated application data from the dashboard. You can remove Search Console access from the export dialog; this attempts to revoke the Google token and deletes the encrypted tokens and cache held by seoreport.ro.

You can also review or revoke provider-side access at Google Account connections and GitHub Applications settings. If you intend to delete the profile, disconnect Search Console first or revoke it in your Google Account to ensure the provider-side authorization is removed as well.

14. Children

The service is not directed to children under 16, and we do not knowingly seek their personal data. A parent or guardian who believes a child supplied data can contact hello@seoreport.ro.

15. Changes and contact

We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated appropriately, and a new authorization will be requested before Google user data is used for a materially different purpose. The current version and date are always published here.

For privacy questions or requests, contact hello@seoreport.ro. The general contractual conditions are available in the Terms and conditions.

seoreport.ro

Technical SEO signals, browser data, and Search Console context organized into one AI-ready JSON report.

hello@seoreport.ro
Product Home Knowledge Base Sign in Contact
Legal Privacy Policy Terms and conditions Usage rules
Language Română English

© 2026 seoreport.ro. All rights reserved.

URL → SEO data → JSON → AI