Privacy policy
Last updated: August 18, 2026
This policy covers the seo-programático product: the app at app.seo-programatico.com, the measurement code (an.js) our customers install on their sites, and the MCP connector for assistants (Claude, ChatGPT). The controller is Pair Programming (the legal entity behind seo-programático). Contact: the app's form (/contacto).
1. What the code measures on our customers' sites
When a customer installs our measurement code on their site, for that traffic we act as a data PROCESSOR: we measure under the site owner's instructions.
What is collected per visit: a random visitor identifier (stored in the browser, isolated per site: it never links data across different sites), sessions and events (page views, clicks with the clicked element's text, scroll depth, real interaction time, form submissions WITHOUT their content, and conversions with their value if the site defines them), technical signals (browser and version, operating system, language, timezone, screen size), the visit's origin (referrer, UTM parameters and click ids such as gclid or fbclid), the approximate location reported by the hosting at country, region and city level, and speed metrics (Web Vitals).
The IP address is never stored in plain text: it is stored encrypted (AES-256-GCM, recoverable only in a security incident) along with a hash used to detect abuse, and it is automatically deleted after 90 days by a daily purge. Location is NOT derived from that stored IP; it comes from hosting headers at visit time.
The code does not read form contents, does not collect passwords or payment data, and uses no advertising cookies.
2. If you are a visitor of a site using our measurement
The code honors the browser's privacy signals: with Global Privacy Control (GPC) or Do Not Track enabled, nothing is measured on that visit.
The controller for that site's data is its owner. You can still write to us via /contacto: we will handle your request (access, deletion) together with them and reply within 30 days.
3. Your account data (if you are a customer)
For your account we act as the CONTROLLER. We store: your email, your site's name and domain, the platform it is built with (if you tell us), your contact messages, and the sign-in links (magic links), which expire after 15 minutes. Connector sessions and tokens are stored hashed, never in plain text.
Your site's memory (the notes and learnings you choose to save from the chat) is yours: you can list it from the chat and request its total or partial deletion at any time.
4. What we use the data for
Only to provide the service: showing you your site's measurement (in your panel and your chat), keeping the network healthy (bot classification) and supporting you. Legal basis: performing the service you request and the site owner's legitimate interest in measuring their own traffic.
We do not sell data, we do not use it for advertising, and we never link visitors across different customers' sites.
5. Who processes data on our behalf
Infrastructure subprocessors: Vercel (app hosting and geolocation headers), Supabase (database) and Zoho Mail (transactional email: sign-in links and notices). No data is shared with third parties for their own purposes.
6. How long we keep each thing
Encrypted IP and its hash: 90 days (automatic daily purge). Measurement events and sessions: while the site's account is active. Contact messages and requests: up to 24 months. If you delete your account, your site's data is deleted within 30 days.
7. Your rights and how to exercise them
You can request access, export, correction or deletion of your data (the whole account, one site, or just the memory) by writing to us via /contacto. We reply within 30 days.
You can revoke the connector's access at any time: remove it from your assistant, or type "switch account" in the chat (it revokes the session tokens).
8. Data processing agreement for customers
If your company needs a data processing agreement (DPA) formalizing section 1 (instructions, subprocessors, assistance and deletion), write to us via /contacto and we will sign one.
9. Google data you connect (Search Console and Analytics)
If you connect your Google account, we access, in READ-ONLY mode, your Google Search Console metrics (impressions, clicks, position, queries, pages and indexing status) and your Google Analytics 4 metrics (sessions, users, page views and conversions). We do not modify, create or delete anything in your Google account.
We use this data ONLY to show you your dashboard and generate the SEO analysis of YOUR own site. We do not sell it, do not transfer it to third parties, and do not use it for advertising or to train general artificial intelligence models.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We store only the aggregated data needed for your dashboard and an encrypted access token to read your metrics. You can revoke access anytime at https://myaccount.google.com/permissions or via /contacto, and we delete the token and associated data.
10. Changes
If this policy changes materially, we announce it in the app. The date of the last update is at the top.
See also the terms of service.