Privacy policy
Last updated: October 1, 2026
This policy covers the seo-programático product: the app at app.seo-programatico.com, the measurement code (an.js) our customers install on their sites, and the connector for AI assistants (Claude, ChatGPT). The controller is Esteban Roberto Aleart Salas, who operates seo-programático under the Pair Programming brand. Contact: the app's form (/contacto).
1. What the code measures on our customers' sites
When a customer installs our measurement code on their site, for that traffic we act as a data PROCESSOR: we measure under the site owner's instructions.
What is collected per visit: a random visitor identifier (stored in the browser, isolated per site: it never links data across different sites), sessions and events (page views, clicks with the clicked element's text, scroll depth, real interaction time, form submissions WITHOUT their content, and conversions with their value if the site defines them), technical signals (browser and version, operating system, language, timezone, screen size), the visit's origin (referrer, UTM parameters and click ids such as gclid or fbclid), the approximate location reported by the hosting at country, region and city level, and speed metrics (Web Vitals).
The IP address is never stored in plain text: it is stored encrypted (AES-256-GCM, recoverable only in a security incident) along with a hash used to detect abuse, and it is automatically deleted after 90 days by a daily purge. Location is NOT derived from that stored IP; it comes from hosting headers at visit time.
The code does not read form contents, does not collect passwords or payment data, and uses no advertising cookies.
2. If you are a visitor of a site using our measurement
The code honors the browser's privacy signals: with Global Privacy Control (GPC) or Do Not Track enabled, nothing is measured on that visit.
The controller for that site's data is its owner. You can still write to us via /contacto: we will handle your request (access, deletion) together with them and reply within 30 days.
3. Your account data (if you are a customer)
For your account we act as the CONTROLLER. We store: your email, your site's name and domain, the platform it is built with (if you tell us), the language you choose in the dashboard, your contact messages, and the sign-in links (magic links), which expire after 15 minutes. Connector sessions and tokens are stored hashed, never in plain text, and Google access is stored encrypted.
4. What you store and generate in the app
Conversion goals: name, key, the rule that defines the conversion (an event, a URL or an element of the site), its value, where it came from (the dashboard, the monthly plan or your assistant), the role of whoever created it (team or customer) and the dates of changes and archiving. If you change a goal's rule, its results are recalculated backwards too, because the rule is applied to the measurement already stored.
Tasks and calendar: title, note, date, status (pending, done or dismissed), the goal they are tied to, and who originated them (you, the team, the monthly analysis or your assistant). They are used to follow the work on your site. You can see all of them; the ones the team owns are closed only by the team.
Competition: the searches you track, the domains, URLs and titles that appear in the results, their positions and the features of the results page, with the date of each capture; plus your verdicts (whether a domain is a competitor or not) and your notes. Captures come from search results providers or are saved by your assistant with what it saw.
Site memory: notes, corrections and preferences about your site. They come from you (in the dashboard or the chat), from the team, or from earlier sessions of your assistant. They can be read from the dashboard and the chat, and we take them into account in the analysis. You can ask us to delete them, fully or partially.
5. Diagnostics and artificial intelligence
For opportunities, scoring, indexing, performance and page health we use your Search Console and Analytics metrics, our own measurement, the indexing status Google reports, a review of your site's public pages (what any visitor sees) and speed measurements.
The monthly analysis processes that data, aggregated and without visitors' personal data, with artificial intelligence models from external providers acting as processors: only to write your analysis, your plan and content drafts.
AI prompts: these are questions we build from real searches for your site and ask AI assistants, through a provider, to see whether they mention you. They are our inferences: they are not people's conversations and we do not capture anyone's chats.
6. The connector for assistants (ChatGPT, Claude)
Each connector call receives the site and the details of your question (for example a date range, a search, a goal or a filter) and returns to the assistant what you asked for: your site's metrics (Search Console, Analytics and our own measurement), goals and their results, tasks, competition, memory notes and the site's settings.
Those responses are received by the assistant you connected (for example ChatGPT or Claude) and are subject to that service's privacy policy.
Some tools write data inside SEO Programático, always at your request: creating, editing or archiving goals; saving search captures; saving verdicts and notes about competitors; and creating, completing or dismissing tasks. None of them modifies your Google account or your site.
If you disconnect the assistant, we delete its access tokens. What is already stored in your account stays.
7. What we use the data for
Only to provide the service: showing you your site's measurement (in your dashboard and your chat), producing your diagnostics, your monthly analysis and your plan, keeping the network healthy (bot classification) and supporting you. Legal basis: performing the service you request and the site owner's legitimate interest in measuring their own traffic.
We do not sell data, we do not use it for advertising, and we never link visitors across different customers' sites.
8. Who receives data
Infrastructure: Vercel (app hosting and geolocation headers), Supabase (database) and Zoho Mail (transactional email: sign-in links and notices).
Artificial intelligence model providers: they receive aggregated data about your site (metrics, searches, pages and diagnostic results) to write your analysis, your plan and content drafts.
Search results and SEO data providers: they receive searches, domains and public URLs to capture results, search volumes, backlinks and answers from AI assistants.
Google: besides reading Search Console and Analytics with your permission, we use its public speed measurement tool on your site's public pages.
The assistant you connect: it receives the results you request through the connector.
SEO Programático does not sell the data or use it for advertising.
Results sent to the assistant you connect are subject to that assistant's privacy policy.
9. How long we keep each thing
Encrypted IP and its hash: 90 days (automatic daily purge). Measurement events and sessions: while the site's account is active. Goals, tasks, competition captures, site memory, stored Google metrics, analyses and technical logs (errors and connector usage): while the account is active. Contact messages and requests: up to 24 months. Sign-in links: expire after 15 minutes.
If you delete your account, we delete your site's data within 30 days. Automatic database backups may keep deleted data for up to 7 more days; after that it is gone.
If you disconnect the assistant, we delete its tokens. If you revoke Google access, we stop reading and delete that access; metrics already stored stay in your account so you don't lose your history if you reconnect, and they are deleted with the account or when you ask.
10. Your rights and how to exercise them
You can request access, export, correction or deletion of your data (the whole account, one site, or just the memory) by writing to us via /contacto. We reply within 30 days.
You can revoke the connector's access at any time: remove it from your assistant, disconnect it from Integrations in the dashboard, or type "switch account" in the chat (it revokes the session tokens).
11. Data processing agreement for customers
If your company needs a data processing agreement (DPA) formalizing section 1 (instructions, subprocessors, assistance and deletion), write to us via /contacto and we will sign one.
12. Google data you connect (Search Console and Analytics)
If you connect your Google account, we access, in READ-ONLY mode, your Google Search Console metrics (impressions, clicks, position, queries, pages and indexing status) and your Google Analytics 4 metrics (sessions, users, page views and conversions). Search Console and Analytics are connected separately, each with its own permission. We do not modify, create or delete anything in your Google account.
We use this data ONLY to show you your dashboard and generate the SEO analysis of YOUR own site. It is transmitted in only two cases: to the assistant you connect, when you request that data through the connector, and to AI providers acting as processors to write your analysis. We do not sell it, do not use it for advertising, and do not use it to train general artificial intelligence models.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We store the aggregated data needed for your dashboard and an encrypted access for each connection. You can revoke access anytime at https://myaccount.google.com/permissions, from Integrations in the dashboard, or via /contacto: we stop reading and delete that access. Metrics already stored stay in your account so you don't lose your history if you reconnect, and they are deleted when you delete the account or ask via /contacto.
13. Changes
If this policy changes materially, we announce it in the app. The date of the last update is at the top.
See also the terms of service.