Privacy Policy
Última actualización: 2026-09-05
What personal data Semantyra collects, why, how long it is kept, and your rights.
Who we are
Semantyra is operated by Semantyra, Italy (full registered address available on request at [email protected]) ("Semantyra", "we"). For privacy questions contact [email protected].
This policy covers the semantyra.com marketing site and the Semantyra application.
Data we collect
We collect only what the service needs to function:
- Account data: name, email address, hashed password (or a Google account identifier if you sign in with Google), preferred language.
- Workspace and project data: the website URLs you add, crawl settings, and the analysis Semantyra produces from public pages of those sites.
- Usage and billing data: plan, subscription status, and provider-side identifiers from Stripe. We never see or store full card numbers.
- Technical data: IP address and request metadata in short-lived security and rate-limit logs.
How we use it
We process the data above to:
- Provide the analysis you request and keep your account secure.
- Send mandatory transactional email (verification, password reset, billing, scan completion, and alerts you enabled).
- Meter usage against your plan and take payment.
- Detect abuse and protect the service.
Third parties and sub-processors
We share data only with processors that help us run the service, under contract, for the purposes above. The current list:
- Hosting and infrastructure: Semantyra is self-hosted on dedicated hardware. The application, PostgreSQL database and Redis run in containers on that machine; no third-party application or database host is used.
- DNS and edge network: Cloudflare, for DNS and TLS termination in front of the site.
- Email delivery: Google (Gmail / Google Workspace SMTP), for transactional email only.
- Payments: Stripe and, if you choose it, PayPal - for subscription billing. Card and account details are entered on the processor and never reach us.
- AI model providers: page titles and trimmed main text from the public pages we analyse are sent to model providers to enrich the analysis - OpenRouter (which may route to OpenAI, Anthropic, Google or open models) and, for AI-visibility checks, OpenAI, Perplexity or an OpenRouter free model. We never send credentials, personal data or raw HTML - see the next section.
- Search data: Google Search Console (only if you connect it) and DataForSEO, for keyword and ranking data about the sites you added.
What we never send to AI providers
Credentials, API keys, OAuth tokens, billing data, personal data about your site visitors, and full raw HTML are never sent to model providers. Only page titles, extracted main text (trimmed), and derived items such as entities and keyphrases are sent, and only when AI enrichment is enabled.
Retention
Account and workspace data: kept while your account is active and deleted within 30 days of account deletion, except where we must retain records such as invoices to meet a legal obligation.
Security and rate-limit logs: rotated within 30 days.
Backups: purged on the backup rotation schedule (see docs/BACKUP_RESTORE.md).
Your rights
Depending on your location you may have the right to:
- Access a copy of your data (export).
- Correct inaccurate data (edit it in Settings, or ask us).
- Delete your account and associated project data.
- Object to or restrict certain processing.
- Lodge a complaint with your data protection authority.
Exercising your rights
Self-service export and deletion are on the roadmap. Until then email [email protected] and we will action verified requests within 30 days.
International transfers
The service is operated from Italy (EU). Your account and project data are stored in the EU. Some sub-processors may process limited data outside the EEA: Stripe, PayPal, Cloudflare, Google and the AI model providers. Where they do, transfers rely on the European Commission Standard Contractual Clauses (and the UK Addendum where relevant), together with the safeguards published by each provider.
Changes
We will post material changes here and, where required, notify you by email. The "last updated" date reflects the current version.
Contact
Questions about this document: [email protected].