Privacy Policy
Last updated · July 28, 2026
How NebulaSEO collects, uses, and protects your data. Plain English; no surprises.
NebulaSEO ("we," "our," or "us") operates the website nebulaseo.com and provides AI-powered local SEO services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By using NebulaSEO, you agree to the collection and use of information in accordance with this policy.
We collect information you provide directly to us, including your name, email address, agency name, and billing information when you register for an account. We also collect information through your Google account when you connect via Google OAuth, including your Google profile information and, with your explicit permission, access to your Google Business Profile data. We automatically collect certain technical information including IP addresses, browser type, device information, and usage data when you use our platform. When you use the NebulaSEO iOS app, we additionally collect: (a) an Apple Push Notification Service ("APNs") device token that we use solely to deliver alerts you have enabled (new Google reviews, payment failures, referral commission earned, post approvals); (b) the business address coordinates you provide for each location, which we use to render Google Maps rank grids and rank-tracking heatmaps. We do NOT collect device location or background location. (c) photos you upload to the post-automation image library, stored in our secure blob storage and used only to attach to Google Business Profile posts you publish through the app.
When you connect your Google Business Profile to NebulaSEO, we access your business listing information, posts, reviews, and profile performance insights solely to provide our SEO optimization services. When you separately connect Google Analytics, we access your Google Analytics (GA4) reporting data on a read-only basis (via the analytics.readonly scope) to display your website traffic and engagement metrics inside your dashboard and in the reports we generate for you. We never modify your Google Analytics configuration. We use Google's official APIs and comply with Google's API Services User Data Policy, including the Limited Use requirements. We do not sell your Google Business Profile or Google Analytics data to third parties, and we do not use it for advertising. You may revoke NebulaSEO's access to your Google account at any time through your Google Account settings at myaccount.google.com.
We use the information we collect to provide, maintain, and improve our services; process transactions and send related information; send technical notices and support messages; respond to your comments and questions; and send marketing communications (which you may opt out of at any time). We use your Google Business Profile data exclusively to deliver the SEO optimization features you have requested, including automated posting, review management, and rank tracking. We use your Google Analytics data exclusively to show you your own website traffic and engagement metrics in your dashboard and reports.
We do not sell, trade, or rent your personal information to third parties. We share limited information with trusted service providers who assist us in operating our platform: our payment processor (Stripe) processes subscription and invoice transactions, our AI provider (Anthropic) processes post drafts and review-response drafts, and our transactional email provider (Resend) delivers account, billing, and product notification emails. These parties are contractually bound to keep this information confidential and use it only to deliver the service they provide to us. We may also disclose your information when required by law or to protect our rights. Agency accounts that enable Stripe Connect to invoice their own clients additionally transmit client billing details (name, email, optional phone, invoice amounts and descriptions) directly to Stripe under the agency's own Stripe Connect account. NebulaSEO acts only as the platform that initiates the request; we do not store full payment card numbers, and the agency (not NebulaSEO) is the merchant of record for those client invoices.
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. All data is transmitted over HTTPS. Payment information is processed by Stripe and we do not store credit card details on our servers. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
We retain your personal information for as long as your account is active or as needed to provide you services. If you delete your account, we delete your account data immediately upon request (and in any case within 30 days), except where we are required to retain it for legal or business purposes. Billing records (invoices, billing-event ledger entries, and Stripe transaction history) are retained where required for tax, legal, or fraud-prevention purposes.
You have the right to access, update, or delete your personal information at any time through your account settings. You may also request a copy of your data or ask us to restrict processing of your data by contacting us at privacy@nebulaseo.com. If you are located in the European Union, you have additional rights under GDPR including the right to data portability and the right to lodge a complaint with a supervisory authority.
We use cookies and similar technologies (including browser local and session storage) in two categories. ESSENTIAL (always on, no tracking rides them): a session cookie that keeps you signed in; security and abuse-prevention storage; "_n_attr" (records which outreach link brought you to us; first-party; expires after 30 days); "nebula_ui" (remembers interface preferences such as theme; first-party; expires after about 1 year); and, for the public sales chat, a "nebula_anon_id" identifier and related engagement timestamps so we can remember your active chat if you return. MEASUREMENT (your choice, off by default): we load Google Tag Manager for analytics and advertising measurement (for example, seeing which pages or ads bring visitors), but all of its measurement and advertising signals default to DENIED until you choose "Accept" on the cookie banner. Choosing "Essentials only" keeps them denied. Your choice is stored as "nebula:consent" and you can change it any time via the "Your Privacy Choices" link in the footer, which reopens the banner. We never sell your personal information in either mode. You can also instruct your browser to refuse cookies or clear storage entirely; some portions of the platform may not function properly without the essential set.
You do not need an account to run our free local-SEO audit or to use our public sales chat, and we collect some information through those tools before any account exists. Free audit: when you run a free audit we store the email address and business you enter, along with your IP address, and use them solely to count your free audits, prevent spam and abuse, and act as a receipt key for the audit you requested. Your free-audit email is not added to any marketing list and is not sold or shared. Sales chat: when you use the public sales chat we store an anonymous chat identifier (kept in your browser and on our servers), your IP address and browser/user-agent, the messages you send, and any business, city, or contact details you choose to provide. We use this to operate the chat, run any audit you ask for, prevent abuse, and improve the assistant. The text of your chat is processed by our AI provider (Anthropic) to generate replies. If you ask to speak with a human, we create a sales lead from the contact details you provide so a person can follow up with you. Retention and deletion: anonymous sales-chat sessions are automatically pruned after about 30 days of inactivity. Free-audit and sales-lead records are kept for as long as needed to enforce our anti-abuse limits and to follow up on inquiries. You can ask us to delete the information collected through these tools at any time by emailing privacy@nebulaseo.com with the email address or business you used; this is also how you exercise your access and deletion rights for any prospect data, whether or not you ever created an account.
Our platform integrates with third-party services including Google APIs (Business Profile, Analytics, OAuth, Maps, Places, PageSpeed Insights), Stripe for payments (including Stripe Connect for agency-to-client invoicing), Anthropic for AI-powered content generation, DataForSEO for rank and competitor lookups, Apple Push Notification Service (APNs) for iOS notifications, Resend for transactional email delivery, Telnyx for voice call delivery, and Cloudflare Turnstile for bot detection on the free-audit form. These third parties have their own privacy policies, and we encourage you to review them. NebulaSEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you or your client connects a third-party account to NebulaSEO, we store an access token for that account, encrypted at rest, together with the account's name and identifier so we can show you what is connected. What we access is limited to what the integration does: for Facebook and Instagram we publish posts to the Page or account you select and read nothing else; for Jobber and Housecall Pro we receive completed-job records, including the customer name and contact details on that job, so the work can be reflected in your dashboard; for Zapier we send only the events you subscribe a Zap to. We do not read private messages, advertising accounts, or anything else these platforms could expose. You can disconnect at any time from your dashboard, or by removing NebulaSEO from the platform's own settings, and we delete the stored tokens immediately in either case. See nebulaseo.com/data-deletion for how to have the rest of the associated data removed.
NebulaSEO offers an optional connector that lets an AI assistant you already use (for example Claude or ChatGPT) read your NebulaSEO account and create drafts in it on your behalf. It does nothing until you connect it. Connecting requires you to sign in to NebulaSEO and approve the connection on our own screen; the AI assistant never receives your NebulaSEO password. What the connector exposes is your own account data, and only for the locations on your account that have an active subscription: your business profile details, your Google reviews and review activity, your rank grid results, your Google Business Profile compliance status, your website audit and AI visibility results, your citation scan results, your posts and drafts, your photo library, and your Google Analytics (GA4) traffic figures for a location where you have connected Analytics. It cannot read another customer's account, and it cannot read a location that is not on an active subscription. An AI assistant receives only what it asks for, one request at a time, answered from the locations on your own account. Nothing is streamed to it in the background. Everything the connector writes is a draft. It can queue a Google post, a review reply, an email to your client, a proposed listing edit, or a page on a website you built with us, and each one waits in the approval queue you already use. The connector has no path that publishes to Google, sends an email, or edits a live listing, and it cannot start a rank scan, website audit, AI visibility check, or citation scan. The approval screen also offers a read-only connection, which is given no drafting tools at all. Once your assistant has the data, that data is being handled by the company that makes the assistant, under their terms and your agreement with them. We have no visibility into that relationship and it is between you and them, so connect only an assistant you are willing to show this data to. On our side, we do not sell the data the connector exposes, we do not use it for advertising, and we do not use it to train AI models. We use it to answer the request your assistant made, and for nothing else. Because the connector surfaces Google Business Profile and Google Analytics data obtained through Google OAuth, Google's Limited Use requirements apply to it. NebulaSEO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In particular, we do not transfer or use Google user data to serve advertising, we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models, and we do not allow humans to read it except where you give affirmative agreement for specific data, where it is necessary for security purposes such as investigating abuse, where required to comply with applicable law, or where the data is aggregated and anonymized for internal operations. When your assistant reads Google data through the connector, it does so at your direction, on your behalf, for the location you asked about. You disconnect the connector from your AI assistant's own settings, in the same place you added it; removing it there takes the key out of that assistant's hands. The access key an assistant holds is valid for one hour at a time and must be renewed against our servers, and a connection that goes unused for thirty days stops working on its own. We also end a connection on our side if its renewal key is presented twice, which is the signature of a copied key; that ends only the connection it happened on. The "sign out all other devices" control in your NebulaSEO settings covers browsers and phone apps and should not be relied on to end an AI connection. Revoking NebulaSEO's access to your Google account (see Section 3) additionally cuts off the parts of the connector that read live from Google, such as website traffic and your Google photo library. What we log: we do not keep a record of your connector conversations or of the individual questions your assistant asks, and we do not store a second copy of the data it reads. What we do keep is a small record of each connection itself: the name the assistant registered under, the web address its sign-in was sent to, whether it was connected read-only or with drafting, when it was created, when it was last used, whether it has been cut off, and an internal identifier for its current renewal key. We do not store the access or renewal keys themselves, only that identifier. We also store a one-way hash of each sign-in code once it has been redeemed, so the same code cannot be redeemed a second time; the code itself is never stored. The connector endpoint runs with verbose logging turned off, and what reaches our server logs is limited to error diagnostics, for example the reason a sign-in handshake was rejected, or a note that a photo library or a rendered map could not be loaded. As with every other request to nebulaseo.com, the request itself appears in our hosting provider's standard web server logs. Two further things are stored on purpose: short-lived counters that cap how many requests a connection can make in a minute and how many rank heatmap images an account can have drawn in an hour, and the rendered heatmap image itself, cached in our file storage so the same map is not drawn twice. Drafts your assistant creates are stored the way any other draft in your account is stored, and are kept until you approve or discard them.
NebulaSEO is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us at privacy@nebulaseo.com and we will take steps to delete such information.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
For App Store transparency, the NebulaSEO iOS app's data collection maps to the following Apple data categories: Contact Info (email, name), used for app functionality and account management; Financial Info (payment info routed to Stripe; we do not retain card numbers), used for purchases and account management; User Content (posts, photos, business profile data you create or upload), used for app functionality; Identifiers (user ID, device push token), used for app functionality and analytics; Usage Data (product interaction), used for analytics and app functionality; Diagnostics (crash data, performance metrics), used for app functionality. The app does NOT collect precise device location, browsing history, contacts, health & fitness, sensitive personal info, or any data we share with data brokers.
You can delete your NebulaSEO account directly from the iOS app under Settings → Manage Account → Delete Account, or by emailing privacy@nebulaseo.com. Account deletion removes your account record, your linked Business locations, your push tokens, and your Google OAuth refresh tokens. Billing records (invoices, billing-event ledger entries, and Stripe transaction history) are retained where required for tax, legal, or fraud-prevention purposes (see Section 7).
If you have any questions about this Privacy Policy, please contact us at privacy@nebulaseo.com.