Privacy Policy
AdvisorSEO is an AI manager for local businesses and small agencies, operated by AdvisorPPC.
Last updated: 2026-09-19
You reach AdvisorSEO by connecting it inside an AI assistant — Claude or ChatGPT — at the connector address https://mcp.advisorseo.ai/mcp. This policy sets out exactly what data AdvisorSEO handles, why it handles it, how it is protected, how long it is kept, and what you can ask us to delete. It is written to be specific rather than reassuring. If anything here is unclear, write to support@advisorseo.ai.
1. What AdvisorSEO does
Once you have connected it, AdvisorSEO works on the websites you add, on your instructions:
- Keeps a record of each website you add, together with a short business profile — what the business does, where it works, and who it serves.
- Saves keywords and content plans for each website.
- Writes article drafts, stores them for your review, and publishes an approved article to your WordPress site.
- Audits a website you name, fetching a bounded number of its pages with a declared user agent.
- Stores the leads captured by a lead-capture snippet you install on your own website.
Every change to your own data or to your site is previewed first and happens only when you explicitly confirm it. Publishing to WordPress is draft-then-approve: nothing is posted to your site without your approval at that moment.
2. What data we handle
- Websites you add. The site URL and the business profile you give us for it.
- Keywords and content plans. The keywords and plans saved against each website.
- Article drafts and published articles. The text produced for you and the record of what was published where.
- Leads. The submissions captured by the lead-capture snippet on your own website, and the status you move each lead through.
- OAuth 2.1 tokens. Issued when you authorize the connection, and used to identify your account and its workspace on every request.
- A WordPress Application Password. Supplied by you so that approved articles can be published, and stored encrypted at rest.
- Telemetry. A small fixed set of operational fields, listed in full in section 8.
We collect only what is needed to do the work you have asked for. We do not buy data, and we do not enrich or combine your data with data from other sources.
3. Leads captured by the snippet you install
The lead-capture snippet is a small piece of code you choose to install on your own website. When a visitor submits one of your forms, the snippet intercepts that submission and posts only the form's own fields to your workspace, together with a spam-score signal and a honeypot field used to detect automated submissions.
What the snippet does not do is as important as what it does:
- It reads nothing else on the page.
- It sets no advertising cookie.
- It follows no visitor around the web and builds no visitor profile.
The contents of a lead are personal data belonging to the person who filled in your form. You are responsible for telling your own visitors what you collect and why, and for having a lawful basis to collect it.
4. Why we use your data, and the limits we accept
Your data is used for one purpose only: doing the work you ask AdvisorSEO to do on your own websites. Beyond that single purpose, we accept these limits:
- We do not sell your data — not to advertisers, not to data brokers, not to anyone, in any form.
- We do not share your data across customers. Your sites, keywords, content, leads, and tokens are never exposed to or mixed with another customer's data.
- We do not use your data to train AI or machine-learning models — neither our own nor anyone else's.
- We do no advertising profiling. We do not use your data to target you with ads or to build a marketing profile of you or of your visitors.
We disclose data only to your own WordPress site when you approve a publication, to the infrastructure providers that host the service under confidentiality obligations, and where we are compelled to by valid legal process.
5. Authorization and credentials
You authorize AdvisorSEO through OAuth 2.1 — authorization code flow with PKCE (S256) and Dynamic Client Registration. You never paste an API key or a password to connect. You sign in, choose the workspace the connection belongs to, and that choice is what the connection is bound to.
Publishing is the one place a credential of yours is held. You supply a WordPress Application Password for the site you want to publish to, and we store it encrypted at rest. You can revoke it yourself at any time from WordPress, under Users → Profile → Application Passwords; once revoked it stops working immediately and AdvisorSEO can no longer publish to that site.
You can also disconnect AdvisorSEO from the AI assistant you connected it in, which ends its access to your account.
6. Workspace isolation
Isolation is per account workspace. The workspace is chosen by a human on the consent screen, carried in a signed consent token, bound onto the OAuth client, and frozen onto every token that is then issued. Every request resolves its workspace from the caller's own token before anything is read or written, and each write re-checks that the site, the article, or the lead it is about belongs to that workspace.
The practical consequence: data never crosses workspaces. An agency's client sites stay separate from one another, and from every other customer.
7. How your data is stored and protected
- Encrypted in transit. All traffic travels over TLS.
- Encrypted at rest. Stored data, including OAuth tokens and your WordPress Application Password, is encrypted on disk.
- Scoped access. Stored credentials are reachable only by the processes that need them to serve your requests, and always within your workspace.
No system is perfectly secure. We apply standard safeguards and keep the amount of data we hold to the minimum the work requires.
8. Telemetry we store
To keep the service working we record a small, fixed set of operational fields about each capability that runs. This is the complete list.
| Field | What it is | Retention |
|---|---|---|
| Internal identifiers | Our own account and workspace identifiers, so a record can be attributed and deleted. | 30 days |
| Capability name | The name of the capability that ran, for example the one that saves keywords. | 30 days |
| Success flag | Whether the run succeeded or failed. | 30 days |
| Error category | A short category for a failure, such as a permission problem or a timeout. | 30 days |
| Latency | How long the run took, as a number. | 30 days |
| Timestamp | When the run happened. | 30 days |
Telemetry holds no request bodies, no page content, and no lead contents. After 30 days it is deleted.
9. Retention, deletion, and your rights
Your sites, business profiles, keywords, content plans, drafts, published-article records, and leads are kept while your account is active, because they are the work you asked for. Telemetry ages out after 30 days as described above. Tokens are kept only while the connection is live.
Deletion on request. Email support@advisorseo.ai and we will delete what we hold for you, except for records a law requires us to keep.
Depending on where you live, you may also have the right to access, correct, or export the personal data we hold, and to withdraw consent. Write to the same address and we will respond within a reasonable time. Data that lives on your own WordPress site, including anything we published there with your approval, stays under your control and is yours to edit or remove.
10. Changes to this policy, and contact
If we make a material change we will update the "Last updated" date above and, where appropriate, notify connected customers. Continuing to use AdvisorSEO after a change means you accept the revised policy.
Questions, data requests, and deletion requests all go to one address: