Narsil SEO Platform — Privacy Policy
Effective date: September 2, 2026 Version: 1.0
This policy explains what personal data the Narsil SEO Platform collects, why, who it goes to, and what control you have. It covers app.narsilcreative.com and the services delivered through it.
Controller: Narsil Creative, hello@narsilcreative.com.
Where you use the Platform to audit sites for your own clients, you are the controller of your clients' data and Narsil is a processor acting on your instructions. Section 8 covers that arrangement.
1. What we collect
1.1 Account data
The only direct personal identifier we store about you is your email address, together with your organization, your role in it, and the date you joined. If you sign in with Google, we receive your email address from Google for authentication.
We do not collect your name, phone number, address, or date of birth, and the Platform has no field for them.
1.2 Billing data
Payments are processed by Stripe. Stripe collects and holds your card details. Narsil never receives, sees, or stores full payment card numbers. We store Stripe's customer and subscription identifiers so we know what plan you are on.
1.3 Website and audit data
When you add a Site, the Platform fetches and analyzes its pages, and stores what it finds: URLs, page titles, meta descriptions, headings, word counts, status codes, link structure, structured-data types, performance measurements, and the raw fetched page data.
This is website data, not personal data by design — but a website can contain personal data (an author byline, a staff page, a testimonial), and where it does, that data is stored with the rest of the page record.
1.4 Business profile and review data
Some features analyze a Google Business Profile, including its reviews. Reviews contain the reviewer's display name and the text they wrote. That is personal data about people who are not our customers, published publicly by them on Google. We process it only to produce the analysis you asked for.
1.5 Files you upload
Documents uploaded to your account are stored, along with who uploaded them and when.
1.6 Content you paste in
Several tools accept pasted input — draft copy, exported reports, question lists. Whatever you paste is stored as part of that tool run. Do not paste personal or confidential data you do not want stored.
1.7 Usage and product analytics
We use PostHog to understand how the Platform is used. Three things about that configuration are worth stating plainly, because they are unusual and deliberate:
- You are identified to PostHog by a random identifier, never by your email address. The only attributes attached are your organization identifier, your plan, and whether you are a Narsil administrator. Your email address is not sent to PostHog.
- Session replay is recorded — a reconstruction of your interactions with the interface — except on the multi-factor authentication, password-reset and password-update pages, where it is switched off entirely and cannot be re-enabled by navigation.
- Web addresses are cleaned before they leave your browser. Sign-in tokens, recovery links and similar credentials are stripped out, and identifiers in paths are collapsed, so they are never transmitted to PostHog.
Analytics are disabled entirely in development and preview environments.
1.8 Security and audit logs
We log administrative and security-relevant actions — who did what, to which organization, and when — to protect accounts and investigate problems.
1.9 Support communications
If you email us, we keep the correspondence.
2. Why we use it
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Providing the Platform | Account, website, audit, uploaded, pasted | Contract |
| Billing and collecting fees | Account, billing | Contract |
| Sending service email (crawl results, alerts, password resets) | Account | Contract |
| Securing accounts and investigating abuse | Account, security logs | Legitimate interests |
| Improving the Platform and fixing problems | Usage analytics | Legitimate interests |
| Producing anonymous, aggregated benchmarks | De-identified aggregates | Legitimate interests |
| Meeting legal obligations | As required | Legal obligation |
We do not sell personal data. We do not share it with advertisers. We do not use it to train our own AI models, and we do not permit our AI providers to train on it.
3. Who we share it with
The Platform depends on third-party services. Each receives only what its
function requires. The current list, with what each receives and where it
operates, is at docs/legal/subprocessors.md, which forms part of this policy.
In summary, data may be shared with providers for: hosting and application delivery; database, authentication and file storage; payment processing; website crawling and business-profile lookups; performance measurement; AI analysis and drafting; transactional email; background job execution; and product analytics.
We may also disclose data:
- When the law requires it — to comply with a valid legal process. Where we are legally permitted to tell you first, we will.
- To protect rights and safety — where necessary to investigate fraud, abuse, or a security incident.
- In a business transfer — if Narsil is acquired or merges, data may transfer as part of that transaction. We will notify you.
4. AI processing
Some features send data to AI providers to produce analysis, recommendations, or drafts. What is sent is scoped to the task — page content, profile data, or text you supplied.
- Requests go through Narsil's provider accounts under commercial terms.
- Providers are not permitted to train models on this data.
- AI output can be wrong. It is a recommendation for you to review, not a finding of fact.
The AI providers we use are named in docs/legal/subprocessors.md.
5. International transfers
Our providers are primarily in the United States, and data is processed there. If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your jurisdiction. We rely on Standard Contractual Clauses or an equivalent transfer mechanism with each provider that requires one.
6. How long we keep it
Read this section carefully. The Platform is deliberately designed not to delete audit history.
| Data | Retention |
|---|---|
| Audit history, snapshots, crawl records, page data | Kept indefinitely |
| Account data | For the life of the account |
| Billing records | As long as tax and accounting law requires |
| Uploaded files | For the life of the account |
| Security and audit logs | For the life of the account |
| Product analytics | Per our analytics provider's retention settings |
Why audit history is kept. A crawl captures a website as it was on one day. That record cannot be re-collected later, and it is the basis of every trend and comparison the Platform produces. Deleting it would destroy the history a customer paid for.
Two consequences you should understand:
- Where your plan limits how far back you can see page-level detail, that detail is hidden, not deleted. Upgrading reveals it again. We will not describe hidden data as deleted.
- Removing a Site, or ending your subscription, does not erase the audit history already collected. It stops future collection. An ended subscription leaves your account readable rather than closed, so you keep seeing what you paid for.
This does not override your rights over personal data. Section 7 describes how to ask for erasure and what happens when you do.
7. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, object to or restrict its processing, port it, and withdraw consent. If you are in California, you also have the right not to be discriminated against for exercising these rights.
To exercise any of them, email hello@narsilcreative.com. We will respond within the time the law allows — generally 30 days — and will not charge you except where the law permits.
How to ask for deletion, and what actually happens:
There is a Delete account section in your Settings. It takes you through what will and will not be removed, asks you to type your organization's name to confirm, and records the request.
That request does not delete anything by itself, and we would rather say so than let you believe otherwise. A person at Narsil performs the erasure by hand. We do it that way deliberately: an automatic cascade across years of audit history is the kind of thing that goes wrong once and cannot be undone.
- We will remove your account and the data we hold for it.
- We must keep billing and tax records for the periods the law requires, and we will tell you which.
- If you are an agency, your clients' data is not yours to erase on their behalf; those clients hold their own rights.
- We will email you to confirm precisely what was removed and what was kept, rather than telling you vaguely that it is done.
- You can cancel the request any time before we action it.
- The request itself is retained — it is our record that a legal obligation was received and answered.
Your subscription is separate: requesting deletion does not stop billing. Cancel your subscription in the billing portal as well, or tell us and we will do it.
You can also just email hello@narsilcreative.com. The form is a convenience, not a requirement.
8. When we are your processor
If you use the Platform to audit sites belonging to your own clients, then as to those clients' data:
- you decide what is collected and why, and are the controller;
- we process it on your instructions, as a processor;
- you are responsible for having a lawful basis, for the authorization the Subscription Agreement §5.3 requires, and for telling your clients what you are doing;
- we will process it only to provide the Platform, keep it confidential, apply appropriate security, and assist you with data-subject requests as far as the Platform allows — including the limitation in section 7.
A separate Data Processing Addendum is available on request. If your clients include individuals in the EEA or UK, ask for one before you begin.
9. Security
We protect data with, among other measures: encryption in transit; row-level database access controls that isolate each organization's data and are tested against forged requests; multi-factor authentication for administrative access; audit logging of administrative actions; and secrets held only in managed environment configuration.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any required regulator within the timeframes the law requires.
10. Children
The Platform is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, email us and we will address it.
11. Cookies and similar technologies
We use cookies and browser storage to keep you signed in, remember preferences, and — through PostHog — measure usage as section 1.7 describes. Authentication cookies are strictly necessary; without them you cannot stay signed in.
You can block or delete cookies in your browser, but the Platform will not function properly without the necessary ones.
12. Changes to this policy
We may update this policy. For material changes we will give at least 30 days' notice by email or in-product before they take effect, and update the version and date above. Previous versions are available on request.
13. Contact
Narsil Creative — hello@narsilcreative.com
If you are in the EEA or UK and believe we have not handled your data properly, you may complain to your local supervisory authority. We would rather you came to us first.