Narsil SEO Platform — Privacy Policy

Effective date: September 2, 2026 Version: 1.0

This policy explains what personal data the Narsil SEO Platform collects, why, who it goes to, and what control you have. It covers app.narsilcreative.com and the services delivered through it.

Controller: Narsil Creative, hello@narsilcreative.com.

Where you use the Platform to audit sites for your own clients, you are the controller of your clients' data and Narsil is a processor acting on your instructions. Section 8 covers that arrangement.


1. What we collect

1.1 Account data

The only direct personal identifier we store about you is your email address, together with your organization, your role in it, and the date you joined. If you sign in with Google, we receive your email address from Google for authentication.

We do not collect your name, phone number, address, or date of birth, and the Platform has no field for them.

1.2 Billing data

Payments are processed by Stripe. Stripe collects and holds your card details. Narsil never receives, sees, or stores full payment card numbers. We store Stripe's customer and subscription identifiers so we know what plan you are on.

1.3 Website and audit data

When you add a Site, the Platform fetches and analyzes its pages, and stores what it finds: URLs, page titles, meta descriptions, headings, word counts, status codes, link structure, structured-data types, performance measurements, and the raw fetched page data.

This is website data, not personal data by design — but a website can contain personal data (an author byline, a staff page, a testimonial), and where it does, that data is stored with the rest of the page record.

1.4 Business profile and review data

Some features analyze a Google Business Profile, including its reviews. Reviews contain the reviewer's display name and the text they wrote. That is personal data about people who are not our customers, published publicly by them on Google. We process it only to produce the analysis you asked for.

1.5 Files you upload

Documents uploaded to your account are stored, along with who uploaded them and when.

1.6 Content you paste in

Several tools accept pasted input — draft copy, exported reports, question lists. Whatever you paste is stored as part of that tool run. Do not paste personal or confidential data you do not want stored.

1.7 Usage and product analytics

We use PostHog to understand how the Platform is used. Three things about that configuration are worth stating plainly, because they are unusual and deliberate:

Analytics are disabled entirely in development and preview environments.

1.8 Security and audit logs

We log administrative and security-relevant actions — who did what, to which organization, and when — to protect accounts and investigate problems.

1.9 Support communications

If you email us, we keep the correspondence.


2. Why we use it

Purpose Data used Legal basis (GDPR/UK GDPR)
Providing the Platform Account, website, audit, uploaded, pasted Contract
Billing and collecting fees Account, billing Contract
Sending service email (crawl results, alerts, password resets) Account Contract
Securing accounts and investigating abuse Account, security logs Legitimate interests
Improving the Platform and fixing problems Usage analytics Legitimate interests
Producing anonymous, aggregated benchmarks De-identified aggregates Legitimate interests
Meeting legal obligations As required Legal obligation

We do not sell personal data. We do not share it with advertisers. We do not use it to train our own AI models, and we do not permit our AI providers to train on it.


3. Who we share it with

The Platform depends on third-party services. Each receives only what its function requires. The current list, with what each receives and where it operates, is at docs/legal/subprocessors.md, which forms part of this policy.

In summary, data may be shared with providers for: hosting and application delivery; database, authentication and file storage; payment processing; website crawling and business-profile lookups; performance measurement; AI analysis and drafting; transactional email; background job execution; and product analytics.

We may also disclose data:


4. AI processing

Some features send data to AI providers to produce analysis, recommendations, or drafts. What is sent is scoped to the task — page content, profile data, or text you supplied.

The AI providers we use are named in docs/legal/subprocessors.md.


5. International transfers

Our providers are primarily in the United States, and data is processed there. If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your jurisdiction. We rely on Standard Contractual Clauses or an equivalent transfer mechanism with each provider that requires one.


6. How long we keep it

Read this section carefully. The Platform is deliberately designed not to delete audit history.

Data Retention
Audit history, snapshots, crawl records, page data Kept indefinitely
Account data For the life of the account
Billing records As long as tax and accounting law requires
Uploaded files For the life of the account
Security and audit logs For the life of the account
Product analytics Per our analytics provider's retention settings

Why audit history is kept. A crawl captures a website as it was on one day. That record cannot be re-collected later, and it is the basis of every trend and comparison the Platform produces. Deleting it would destroy the history a customer paid for.

Two consequences you should understand:

This does not override your rights over personal data. Section 7 describes how to ask for erasure and what happens when you do.


7. Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, object to or restrict its processing, port it, and withdraw consent. If you are in California, you also have the right not to be discriminated against for exercising these rights.

To exercise any of them, email hello@narsilcreative.com. We will respond within the time the law allows — generally 30 days — and will not charge you except where the law permits.

How to ask for deletion, and what actually happens:

There is a Delete account section in your Settings. It takes you through what will and will not be removed, asks you to type your organization's name to confirm, and records the request.

That request does not delete anything by itself, and we would rather say so than let you believe otherwise. A person at Narsil performs the erasure by hand. We do it that way deliberately: an automatic cascade across years of audit history is the kind of thing that goes wrong once and cannot be undone.

Your subscription is separate: requesting deletion does not stop billing. Cancel your subscription in the billing portal as well, or tell us and we will do it.

You can also just email hello@narsilcreative.com. The form is a convenience, not a requirement.


8. When we are your processor

If you use the Platform to audit sites belonging to your own clients, then as to those clients' data:

A separate Data Processing Addendum is available on request. If your clients include individuals in the EEA or UK, ask for one before you begin.


9. Security

We protect data with, among other measures: encryption in transit; row-level database access controls that isolate each organization's data and are tested against forged requests; multi-factor authentication for administrative access; audit logging of administrative actions; and secrets held only in managed environment configuration.

No system is perfectly secure. If a breach affects your personal data, we will notify you and any required regulator within the timeframes the law requires.


10. Children

The Platform is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, email us and we will address it.


11. Cookies and similar technologies

We use cookies and browser storage to keep you signed in, remember preferences, and — through PostHog — measure usage as section 1.7 describes. Authentication cookies are strictly necessary; without them you cannot stay signed in.

You can block or delete cookies in your browser, but the Platform will not function properly without the necessary ones.


12. Changes to this policy

We may update this policy. For material changes we will give at least 30 days' notice by email or in-product before they take effect, and update the version and date above. Previous versions are available on request.


13. Contact

Narsil Creativehello@narsilcreative.com

If you are in the EEA or UK and believe we have not handled your data properly, you may complain to your local supervisory authority. We would rather you came to us first.