SEOSiri Privacy Policy
Governing seosiri.com, developers.seosiri.com, guard.seosiri.com, and the SEOSiri Model Context Protocol (MCP) Suite
Last Updated & Effective Date: September 12, 2026
Google OAuth Branding Verification Resolution Notice
-
Privacy Policy Compliance & OIDC Data Disclosure:
Corrected the privacy policy URL to the live canonical address: https://www.seosiri.com/p/privacy-policythis-privacy-policy-has.html. The published policy contains an explicit section detailing Google OAuth user data collection, functional usage scopes (email,profile,openid), a zero-sharing/non-sale policy, and data deletion rights for the SEOSiri Model Context Protocol (MCP) Suite, including authenticated client workspace access via https://developers.seosiri.com/#user-portal. -
Publicly Accessible Application Home Page:
Verified that the application home page (https://developers.seosiri.com) is fully public, un-gated, and accessible without requiring a user login, account registration, or paywall. It displays the complete ecosystem architecture, interactive D3 network topology graph, operational tools, and developer documentation. -
Brand Name & Storefront Alignment:
Aligned the application brand name on the OAuth consent screen toSEOSiri Model Context Protocol (MCP) Suiteto match the primary headline and branding rendered on the public home page.
1. Google Data We Access and Collect
When you authenticate via Google Sign-In, our system requests basic, non-sensitive OpenID Connect (OIDC) identity scopes:
- Email Address (
emailscope): Used exclusively to identify your authenticated developer workspace, associate your assigned Cloudflare edge routing, and manage your API security license. - Basic Profile Information (
profileandopenidscopes): Used to personalize your administrative workspace and display verified identity badges in the Client Subscription Portal.
2. Purpose & Use of Google User Data
Google account information is used strictly to:
- Authenticate authorized developers accessing the SEOSiri Client Security and Subscription Portal.
- Dynamically generate personalized client configurations for Claude Desktop, Cursor AI, and Cloudflare CNAME DNS routing.
- Enforce authorized rate-limiting quotas and cryptographic license validation across our global edge nodes.
3. Zero Data Sale & Non-Sharing Commitment
We do not sell, rent, trade, or monetize your Google user data. We do not share Google user data with data brokers, advertisers, or external machine learning model training systems. Data is used solely for the functional operation of the SEOSiri Model Context Protocol (MCP) Suite.
4. Cryptographic Storage & Edge Security
All authentication exchanges are encrypted in transit via TLS 1.3. Google OIDC ID tokens are cryptographically verified using RS256 Web Crypto standards against Google’s official public keys (https://www.googleapis.com/oauth2/v3/certs). We operate a strict zero-retention policy: authentication tokens reside locally in your browser session and are never written to external tracking databases.
5. User Access Revocation & Deletion Rights
You have complete sovereignty over your data:
- Revoke Access Instantly: You can disconnect SEOSiri at any time via the official Google Account Security Permissions Portal.
- Request Permanent Data Deletion: You may request the immediate deletion of any client account records by emailing our Data Protection Officer at [email protected]. Requests are fulfilled within 48 hours.
1. Local-First Model Context Protocol (MCP) Architecture
At SEOSiri, privacy is an engineering requirement. All open-source SEOSiri Model Context Protocol servers
(including etl-pipeline-mcp, seosiri-api-guard, bioassay-mcp, biopharma-mcp, and aeo-geo-mcp)
are architected for local execution:
- Local Tool Execution: Tools run inside your local environment (Claude Desktop, Cursor AI, local terminal) or within your private VPC. We do not inspect, intercept, or record your local database queries, API credentials, or private prompts.
- Automated SHA-256 Hashing: Our data pipeline tools enforce irreversible SHA-256 cryptographic hashing on sensitive data (emails, client IP addresses) at rest before storage, ensuring local compliance with GDPR, CCPA, and HIPAA guidelines.
2. Atlassian Cloud Apps (Jira, Confluence & Rovo Agents) Privacy Policy
This section governs our Atlassian Marketplace Cloud applications, including SEOSiri Model Context Protocol (MCP) Suite and SEOSiri Rovo MCP & PII Shield (built on the Atlassian Forge platform):
-
Zero Data Retention of Jira Content: When our Forge apps process Jira issue context, summary text, or Confluence documentation, data is evaluated entirely in-memory at the Cloudflare edge (
rovomcp.seosiri.com). We do not store, index, or retain customer Jira tickets, user comments, or corporate attachments on external databases. -
Atlassian Isolated Storage: Administrative configuration and policy settings are stored exclusively inside Atlassian's native
@forge/bridgestorage vault. Customer data never resides on third-party marketing or tracking platforms. -
Authorized Network Egress: Egress communications are strictly restricted to encrypted TLS 1.3 connections with our verified edge gateways (
*.seosiri.com) to execute real-time PII scrubbing and Model Context Protocol tool routing. - AI Training Prohibition: Data accessed via our Atlassian Jira and Rovo integrations is strictly excluded from third-party LLM training pipelines or commercial profiling.
- App Uninstallation & Deletion: Upon uninstallation of our apps from your Atlassian site, all tenant-associated storage records within the Forge environment are automatically deleted.
2. AI & Machine Learning Data Processing
When utilizing our web-based SEO tools, metadata generators, or image transcription features:
- Ephemeral Image Processing: Images selected for OCR or analysis are processed in real-time memory via temporary, secure connections. We do not retain or store your design assets or images on permanent storage drives.
- Encrypted API Connections: When generative AI suggestions are requested, communications with AI infrastructure providers (such as Google Cloud Vertex AI or OpenAI) occur over encrypted TLS connections with zero customer profiling.
3. Edge Reverse Proxy & Threat Defense Telemetry
For domains routed through our security proxy (guard.seosiri.com), traffic is inspected to mitigate OWASP Top 10 vulnerabilities (SQLi, XSS, BOLA/IDOR, Mass Assignment, CSRF):
- Clean Traffic Non-Retention: Legitimate, non-malicious user requests pass through edge memory without disk storage or persistent IP retention.
- Forensic Threat Logging (GDPR Recital 49): In the event of an active cyberattack, technical telemetry (source IP, network ASN, country, attack vector) is recorded under the legal basis of Legitimate Interest for Network Security (EU GDPR Article 6(1)(f), Recital 49) and California Consumer Privacy Act (CCPA) § 1798.145.
- 30-Day Auto-Purge: All security incident logs are permanently deleted after thirty (30) calendar days. Threat data is never sold or used for behavioral profiling.
4. Information We Collect on Our Website
When you visit seosiri.com, subscribe to our newsletter, or purchase enterprise licenses:
- Personal Identifiers: We may collect your email address, name, company name, and transaction identifiers when you contact our desk or purchase licenses via Payoneer.
- Technical Usage Data: We automatically receive browser types, device operating systems, referring URLs, timestamps, and diagnostic metrics to optimize site delivery and performance.
5. Cookies & Tracking Technologies
We use essential and security cookies to operate our workspaces safely:
- Session & Security Cookies: Essential cookies required for user navigation, workspace security, and CSRF protection.
- Preference Cookies: Used to remember your dashboard layout and active view choices.
- Google Analytics: We use Google Analytics to analyze aggregated, non-personally identifiable traffic patterns. You can opt out at any time by installing the Google Analytics Opt-out Browser Add-on.
6. Data Security & International Processing
We employ industry-standard administrative, technical, and physical safeguards—including Cloudflare Edge encryption, strict HSTS, and Content Security Policies (CSP)—to protect your information. Administrative operations are conducted from our facility in Bangladesh with global cloud edge acceleration across worldwide nodes.
7. Children's Privacy
Our services, developer tools, and APIs are designed strictly for professional developers and enterprise businesses. We do not knowingly collect personal data from individuals under 18 years of age.
Data Protection & Privacy Contact
If you have questions, data deletion requests, or compliance inquiries, contact our Data Protection Officer:
Email: [email protected]