Privacy Policy
Last updated: July 11, 2026
This Privacy Policy explains what data Korvix ("Korvix", "we") collects, why, and how we protect it. It reflects how the product actually works.
1. Data we collect
- Account data: your name/business name, email, and hashed password. Passwords are stored using bcrypt and are never stored or logged in plaintext.
- Website & crawl data: pages, titles, metadata, links, and content of the sites you connect, so Korvix can analyze and improve them.
- Search data: when you connect Google Search Console, we ingest your clicks, impressions, and average position (read-only) to measure results.
- Integration credentials: the access tokens needed to act on your connected services (see Security).
- Billing data: handled by our payment processor, Stripe. We do not store full card numbers.
- Product/usage data: basic logs and events needed to operate, secure, and improve the service.
2. How we use it
We use your data to crawl and analyze your site, propose and (with your permission) execute changes, measure outcomes with before/after search data, provide support, process payments, and secure the service. We do not sell your personal data.
3. Google user data
When you connect Google Search Console, you grant Korvix read-only access to your Google account using the openid, email, and https://www.googleapis.com/auth/webmasters.readonly scopes. Here is exactly how we handle that data:
- What we access: the email address of the Google account you connect (to show which account is linked) and your Google Search Console data — the properties your account can see and their Search Analytics metrics (clicks, impressions, average position, and the associated search queries and pages). Access is read-only; Korvix never creates, edits, or deletes anything in your Google account.
- How we use it: solely to display your own search performance inside Korvix and to measure the before-and-after impact of the SEO changes Korvix recommends or makes for you. We do not use Google user data for advertising, and we do not use it to train generalized AI/ML models.
- How we store it: we store a single Google OAuth refresh token, encrypted at rest with AES-256-GCM and scoped to your organization; secrets are never returned to the browser. Search Console metrics are retained only as needed to power your reports and are deleted when you disconnect the integration or delete your account.
- How we share it: we do not sell Google user data, and we do not share your raw Google data with other customers or any third party, except sub-processors strictly necessary to operate the service (see Third parties) and where required by law. Any cross-customer insights use only aggregated, de-identified statistics.
Korvix's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How Korvix learns across customers
Korvix measures the outcome of every change it makes so it can report what worked. Where Korvix uses those results to inform future recommendations, any cross-customer signal is built from aggregated, de-identified outcome statistics only, subject to minimum-sample and distinct-customer thresholds designed so that no individual customer's data can be reconstructed from a shared insight. Your raw site, search, and store data are never shared with other customers.
5. Security
Integration credentials (Shopify access tokens, Google refresh tokens) are encrypted at rest using AES-256-GCM. Secrets are redacted from API responses and are never returned to the browser. Access is scoped per organization; requests for another organization's data are rejected. We use TLS in transit and follow least-privilege practices.
6. Third parties (sub-processors)
We share data with service providers strictly to operate Korvix, including: Stripe (payments), Shopify and Google Search Console (the integrations you connect), our hosting and database provider, and, where enabled, an email provider for transactional messages and error/monitoring tooling. Each processes data only to provide their service. See our Data Processing Addendum for details.
7. Data retention and deletion
We retain your data while your account is active. You can delete a site or your account at any time; on deletion we remove your associated data (disconnecting an integration preserves content already published to your store). You may request an export or deletion by contacting us.
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these, contact us at the address below.
9. Changes
We will update this policy and the "Last updated" date when our practices change, and notify account holders of material changes.
10. Contact
Privacy questions or requests: support@korvixseo.com.