Skip to content

Security and privacy

How you sign in, what Serplyze can read at Google, how workspaces are kept apart, how secrets are encrypted and who processes your data.

This page describes how Serplyze protects your account and your Search Console data in practice. The binding documents are the Privacy policy, the Data processing agreement and the Terms.

Signing in

  • Email and password. A password has at least 8 and at most 128 characters. You confirm your email address before the first sign-in.
  • Continue with Google. Google must report the email address as verified. Signing in with Google asks for your identity only; it does not give Serplyze access to Search Console.
  • An account that signs in with Google can add a password under Settings → Profile → Password. You get an email when a password is added.
  • A password reset link works for one hour, and resetting the password ends all your sessions.
  • Sign-in, sign-up, password reset and code entry are rate limited. For example, an address can try a password five times a minute.

Two-step verification

You can add a second step with an authenticator app such as Google Authenticator, 1Password or Authy.

  1. Open Settings → Profile and select Set up two-step verification.
  2. Confirm your password. If you sign in with Google only, you first add a Serplyze password.
  3. Scan the QR code with your authenticator app, or enter the setup key by hand, then type the 6-digit code and select Turn on.
  4. Save the backup codes that are shown. Each one works once if you lose your phone, and they are not shown again.
  • Once it is on, the code is asked for after a password sign-in and after a Google sign-in.
  • Trust this device for 30 days on the code screen skips the code on that browser for 30 days.
  • In Settings → Profile you can create New backup codes (the old ones stop working) or Turn off two-step verification. Both ask for your password.
Limit

Two-step verification is a personal setting. A workspace owner cannot require it for every member, and there is no SMS or email code option.

Sessions

  • A session lasts 14 days and is extended while you keep using Serplyze.
  • Settings → Profile → Signed-in devices lists every browser that is signed in, with the sign-in time and IP address. Sign out ends one of them.
  • Sign out everywhere in the Danger zone ends every session, including the current one.
  • When you change your password, Sign out of my other sessions is ticked by default.

What Serplyze can do at Google

  • Connecting Search Console is a separate step from signing in. It requests Google's read-only Search Console permission (webmasters.readonly) and your email address, and nothing else.
  • Read-only means Serplyze cannot add or remove sites or users, submit sitemaps, request indexing or change any setting in your Search Console.
  • Only owners and admins of a workspace can connect or disconnect a Google account.
  • You can end the access at any time, in Serplyze or in your Google account. See Delete your data and Google access.

How workspaces are kept apart

Every row of customer data belongs to a workspace, and the database itself enforces that boundary with row-level security. Each request tells the database which workspace it is working for, and the database returns and accepts only rows of that workspace. A request that names no workspace gets no rows. The rule sits below the application code, so a mistake in a screen or an API endpoint cannot show another workspace's data.

  • The same mechanism enforces project access inside a workspace. A member who is limited to some projects, or a client, can only read the rows of those projects. See Team and access.
  • The web application, the background sync service and the sign-in system use separate database roles with only the rights each needs. The web application cannot read stored Google tokens or BigQuery keys at all.
  • Important changes such as connecting or revoking Google access, deleting a project, removing a member and creating API keys are written to an append-only audit log.

Encryption

  • All traffic uses HTTPS, and the database is encrypted at rest.
  • Google refresh tokens and BigQuery service-account keys get a second layer, envelope encryption: each secret is sealed with its own random key using AES-256-GCM, and that key is wrapped with a master key that is not stored in the database.
  • A sealed secret is bound to the record it belongs to, so a copy placed on another record cannot be decrypted.
  • These secrets are never shown in the product. Only the background sync service decrypts them, when it calls Google.
  • API keys, live CSV links, report share links and invitations are stored as SHA-256 hashes. That is why a new key or link is shown only once.
  • Passwords are stored as salted hashes.

Hosting and subprocessors

Your data is stored in the EU, in Frankfurt, Germany. These are the providers that process data on our behalf:

ProviderPurposeLocation
NeonManaged PostgreSQL database that stores account and Search Console dataEU (Frankfurt, Germany)
DigitalOceanApplication and background-sync serversEU (Frankfurt, Germany)
CloudflareDNS, TLS and network protection in front of serplyze.com; storage of encrypted database backupsGlobal network
ResendDelivery of emails: sign-in and verification links, invitations, alerts, scheduled reportsUSA
StripePayments, invoices and tax calculationUSA / EU
OpenAIUnderstanding AI chat questions; suggesting keyword groups and brand termsUSA
Sentry (Functional Software, Inc.)Error monitoring and session replays of the web app in your browserEU (Frankfurt, Germany)
GoogleSign-in with Google and the Search Console APIUSA / global

The Privacy policy and the DPA hold the authoritative list, including which data each provider receives. If this table and those pages ever differ, the legal pages apply.

Card details are entered on Stripe's page and never reach Serplyze's servers.

What is sent to AI providers

Serplyze uses the OpenAI API for three features. Clicks, impressions, CTR and positions are never sent in any of them.

FeatureSent to OpenAINot sent
Ask Serplyze (AI chat)The question you type, up to four of your earlier questions with the type of calculation chosen for them, a neutral description of the screen you are on and today's dateYour Search Console data, domain, project names, keywords and numbers. OpenAI only picks which built-in calculation answers the question; Serplyze runs it on its own servers.
AI keyword groupingThe text of the keywords to group, your brand terms and the names of your existing groupsAll metrics. Nothing is changed until you review and apply the suggestion.
Brand-term suggestions in project setupYour site's domain and up to 200 of its top search queries as textAll metrics. Suggestions are saved only if you keep them.
  • These features run only when you use them.
  • Under OpenAI's API terms, API data is not used to train its models, and Serplyze does not use your data to train AI models either.
  • Your chat questions are stored in your chat history, which only you can see.
Limit

There is no workspace setting that switches the AI features off. If you do not want text sent to OpenAI, do not use the chat, AI grouping or the brand-term suggestion.

Browser error monitoring

  • When the web app fails in your browser, a technical error report goes to Sentry: the error message, the stack trace, the page address without its query string, and the browser and device type.
  • Before a report is sent, cookies, request bodies, headers and your user identity are removed, and email addresses in messages are replaced with a placeholder.
  • For a sample of sessions, and for sessions in which an error happens, a replay of clicks and page layout is recorded with all text and all inputs masked and media blocked.

What you control

  • Give teammates their own login and the narrowest role that works. See Team and access.
  • Give API keys and live CSV links a clear name and revoke the ones you no longer use. A live CSV link is readable by anyone who has it. See REST API and Google Sheets.
  • To get a copy of your data or have it deleted, see Exports and Delete your data, or write to the privacy address in the Privacy policy.