Privacy Policy

Last updated: July 15, 2026

Zaatar automates the SEO work of your website: it reads your search performance data, audits your pages, drafts content, and proposes fixes that you approve. Doing that requires access to data about you and your website. This policy explains what we collect, why, who we share it with, and the rights you have over it.

1. Who we are

The service at zaatar.ai (the “Service”) is operated by PLACEHOLDER_LEGAL_ENTITY_NAME, PLACEHOLDER_REGISTERED_ADDRESS, registered under PLACEHOLDER_COMPANY_REGISTRATION_RCS(“Zaatar”, “we”, “us”). Zaatar is the data controller for the personal data described in this policy. For any privacy question or request, contact support@zaatar.ai.

2. What we collect

Account data

Sign-in is through Google. When you create an account we receive your name, email address, and profile picture from your Google account. If you join or create an organization we also store your role and membership in it.

Data from services you connect

The Service works by connecting to tools you already use, with your explicit authorization on each one:

  • Google Search Console: search performance data for the properties you connect (queries, clicks, impressions, positions, indexed pages).
  • Google Analytics: if you connect it, read-only traffic and audience reports for the GA4 properties you choose, used to inform the analysis and content we produce for you.
  • GitHub: metadata and content of the repository you choose as your publishing destination, so agents can read your site and open pull requests against it.

Your website

We crawl the public pages of the website you register, the same way a search engine does, to audit and improve them.

Content produced in the Service

Audits, reports, article drafts, tasks, and pull requests generated for your projects, plus any input you write in the product (for example edits to a draft or your company profile).

Technical data

Standard server logs (IP address, browser type, timestamps, requested pages) and operational records of what the Service did on your behalf. We do not run advertising trackers.

3. Why we process it

  • To provide the Service (performance of our contract): running audits, generating content and fixes, opening pull requests you approve, sending you the emails the product depends on (for example when work is ready for your review).
  • To secure and improve the Service (legitimate interest): debugging, abuse prevention, capacity planning, and understanding which features are used.
  • To comply with the law (legal obligation): accounting, tax, and responding to lawful requests.
  • With your consent, where required: optional product communications. You can withdraw consent at any time.

4. AI processing

Zaatar’s agents use large language models to analyze your data and draft content. To do that, relevant excerpts of your project data (for example search queries, page content, or your company profile) are sent to our AI infrastructure subprocessors over encrypted connections and processed to produce the analysis or draft. We send what a task needs, not your whole account, and we never sell your data or use it for advertising.

5. Google user data

Zaatar’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google Search Console and Google Analytics data are accessed read-only, are used solely to provide the SEO and analytics features you see in the product, are never used for advertising, and are never sold. Humans at Zaatar do not read this data except with your consent, for security purposes, or where required by law.

6. Who we share it with

We share personal data only with the subprocessors that run the Service, under data processing agreements. We never sell personal data.

PurposeProviderLocation
Application and database hostingHetzner Online GmbHEuropean Union
AI model inferenceOpenRouter, Inc.United States
Transactional emailMailjet SASEuropean Union (France)
Search ranking data (SERP)DataForSEO LLCUnited States

If we ever introduce paid plans, payment details will be handled by a dedicated payment provider and disclosed here before launch. We may also disclose data where the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply to it.

7. International transfers

Some subprocessors may process data outside the European Economic Area. Where that happens, transfers are protected by an adequacy decision or by the European Commission’s Standard Contractual Clauses.

8. How long we keep it

Your data is kept for as long as your account is active. When you delete your account, deletion enters a 30-day grace period during which you can change your mind; after it, your personal data is deleted or anonymized. Server logs are kept for a limited period for security purposes, and residual copies in encrypted backups are purged on a rolling basis. Data we must keep for legal reasons (for example invoices) is retained for the legally required duration.

9. How we protect it

Data is encrypted in transit with TLS and the credentials to your connected accounts are encrypted at rest with AES-256-GCM, using an encryption key stored separately from the database. Access to your data is scoped to your organization on every request, and the permissions we request from Google and GitHub are the narrowest that support the product: read access to your search data, and repository access used to open pull requests that only you can merge.

A small, named group of our staff can open your account and see it as you see it, so that we can diagnose a problem you reported or find one before you hit it. These support sessions are limited to a fixed list of staff accounts, are read-only unless changing something is the only way to reproduce a fault, expire automatically after a short period, and are recorded: who opened the account, when, why, and anything they changed. We do not use this access for any purpose other than operating and supporting the Service.

10. Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, ask us to restrict or object to processing, and withdraw any consent you gave. Write to support@zaatar.ai and we will respond within one month. You can also lodge a complaint with your supervisory authority; in France that is the CNIL (www.cnil.fr).

11. Cookies and local storage

Our marketing website uses Simple Analytics, a privacy-focused analytics service that uses no cookies and collects no personal identifiers. The application stores your session token in your browser’s local storage so you stay signed in; it sets no advertising or cross-site tracking cookies.

12. Children

The Service is built for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 15.

13. Changes to this policy

When we change this policy in a material way, we will update the date at the top and notify you in the product or by email before the change takes effect.

14. Contact

Privacy requests: support@zaatar.ai. Anything else: support@zaatar.ai.