Serpulix — Privacy Policy

Last updated: July 28, 2026

This Privacy Policy describes how Serpulix (“we”, “us”) collects, uses, and protects information when you use the Serpulix platform and related apps and integrations (the “Service”). Integration-specific notices (for example, our Shopify App Privacy Policy) apply in addition to this policy. Your use of the Service is governed by our Terms of Service.

1. Information we collect

  • Account data — name, email, and credentials of the users and agencies that sign in to Serpulix.
  • Content data — the topics, articles, pages, images, and SEO metadata you create and manage in Serpulix.
  • Connected-integration data — when you connect a third-party service (such as Google Search Console, Google Analytics, Google Business Profile, Google Tag Manager, WordPress, or Shopify), we store the access/refresh tokens and the data needed to provide the feature you enabled (for example, analytics metrics, indexing status, or publishing targets). Tokens and credentials are stored encrypted.
  • Usage data — logs and diagnostic information needed to operate, secure, and improve the Service.

2. How we use information

  • To provide and operate the Service and the features you enable.
  • To generate, optimize, and publish SEO content on the destinations you connect.
  • To display analytics, indexing, and performance data you have authorized us to access.
  • To secure the Service, prevent abuse, and provide support.

3. AI processing

Serpulix uses third-party AI providers (such as Anthropic and OpenAI) to generate and optimize content from the prompts and context you provide. We send those providers only the data needed to produce the requested output, and we do not use your private content to train third-party models beyond what those providers’ terms permit.

4. Google user data and Limited Use

When you connect a Google account, we request only the scopes needed for the features you enable:

  • Search Console (webmasters.readonly) — read search performance, indexing, and coverage data for the properties you select.
  • Indexing API (indexing) — submit URLs of your own sites for (re)crawling.
  • Analytics (analytics.readonly) — read GA4 metrics for the properties you select.
  • Business Profile (business.manage) — read the locations and performance metrics of the profiles you select.
  • Tag Manager (tagmanager.readonly) — read your accounts and containers so you can pick one.
  • Google Ads (adwords) — read campaign, keyword, and spend data for the accounts you select.
  • Basic profile (userinfo.email) — identify which Google account is connected.

Serpulix’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we use Google user data only to provide and improve the user-facing features you enabled in Serpulix. We do not use it for advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition. Humans do not read Google user data except with your explicit consent, to resolve a support issue you raised, for security purposes, or where required by law. Google user data is not used to train generalized AI/ML models. You can revoke our access at any time by disconnecting the integration in Serpulix or via your Google account permissions; disconnecting deletes the stored tokens for that connection.

5. Sharing and sub-processors

We do not sell your information. We share data only with service providers (sub-processors) that help us run the Service — including cloud hosting (Amazon Web Services), the AI providers above, and the third-party platforms you explicitly connect — and only to the extent needed to provide the Service. We may disclose information where required by law.

6. Security

Third-party tokens and credentials are encrypted at rest (AES-256-GCM). Access is restricted to the user’s own agency and verified on every request. We apply reasonable technical and organizational measures to protect your data.

7. Data retention and deletion

We retain your data for as long as your account is active or as needed to provide the Service. Disconnecting an integration deletes the associated tokens; uninstalling an app (for example, the Shopify app) deletes the credentials stored for that connection. To request deletion of your account or associated data, contact us at the address below.

8. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.

9. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service. We do not use the signed-in application for third-party advertising tracking.

10. Changes

We may update this policy; material changes will be reflected by the “Last updated” date above.

11. Contact

Serpulix
35 Murphy Circle, Florham Park, NJ 07932, USA
Email: admin@serpulix.com