This Privacy Policy explains how Serpitis collects, uses, discloses, stores, and protects personal information when you visit our website, create an account, use our web application, connect third party services, contact us, or otherwise interact with Serpitis.
1. Who We Are
Serpitis is operated by Serpitis ("Serpitis," "we," "us," or "our"). For privacy questions or rights requests, contact privacy@serpitis.com.
2. Scope
This Privacy Policy applies to our website, account registration, sign in, workspace management, product usage, connected service integrations, support interactions, billing flows, and related operational communications.
This Privacy Policy does not govern third party websites, services, or platforms that you access outside Serpitis. Those services have their own terms and privacy policies.
3. Information We Collect
We may collect the following categories of information.
A. Account and authentication information
- name, email address, password hash, and email verification status;
- basic profile information returned by an identity provider if you sign in using Google or another supported sign in method;
- workspace membership, team role, invitation, and access control status.
B. Workspace and Service data
- dashboard, widget, folder, workflow, report, and site audit configurations;
- AI prompts, generated output, summaries, and related usage context;
- workspace profile fields you choose to submit, such as company or workspace name, logo, website, timezone, industry, team size, contact details, address details, goals, referral source, and brand terms;
C. Connected account data and permissions
When you connect Google services, Serpitis currently requests and processes only the permissions needed for the feature you activate. At the time of this update, those permissions are:
https://www.googleapis.com/auth/webmasters.readonlyto access connected Google Search Console properties and related read only Search Console data;https://www.googleapis.com/auth/analytics.readonlyto access connected Google Analytics 4 property metadata and related read only analytics reporting data;https://www.googleapis.com/auth/gmail.sendto send report or workflow emails from the Gmail account you connect.
We do not request Gmail read access in the current Gmail integration. We may also store OAuth tokens, token metadata, mailbox identity details, property identifiers, or site identifiers needed to keep integrations connected and functioning.
D. Billing and transaction information
- selected plan tier, billing interval, subscription status, renewal dates, and cancellation state;
- invoice records, payment amounts, currency, processor reference IDs, billing country, and refund or cancellation history;
- limited payment method metadata made available to us by the processor, such as card brand or last four digits.
Payment credentials, such as full card numbers, are usually collected directly by a designated payment processor rather than by Serpitis.
E. Support and communication data
- messages you send to us, support requests, feedback, and attached material;
- transactional email history such as verification, password reset, invitation, billing, and product notification emails;
- technical, workspace, or billing context needed to resolve a support issue.
F. Technical and usage information
- IP address, approximate geolocation derived from IP, browser type, device information, and operating system;
- timestamps, request metadata, application logs, error events, and feature usage records;
- cookies, session identifiers, local storage, and similar browser side state.
4. How We Use Information
We may use personal information to:
- create, authenticate, secure, and manage accounts and workspaces;
- operate the Service and provide requested dashboards, reports, audits, exports, and AI assisted features;
- connect and maintain third party integrations that you enable;
- send transactional emails, workflow driven report emails, invitations, password resets, and product notices;
- run hosted checkout, subscription renewals, invoices, billing confirmations, and refund or cancellation review processes;
- monitor usage limits, detect abuse, prevent fraud, troubleshoot errors, and maintain security;
- improve reliability, product performance, and support workflows;
- comply with law, enforce our agreements, and protect rights, safety, and the Service.
6. AI Processing
When you use AI assisted features, prompts and related Service context may be sent to third party AI providers or routing providers engaged by Serpitis so that outputs can be generated.
AI outputs, prompts, or related metadata may be stored in your workspace history, report content, usage logs, or support records. You should avoid submitting highly sensitive information to AI features unless you have determined that doing so is appropriate for your own legal and compliance obligations.
7. Data Retention
We retain personal information for as long as reasonably necessary to provide the Service, maintain your account or workspace, comply with legal and accounting obligations, detect abuse, resolve disputes, and enforce agreements.
- account and workspace records are typically retained while the account remains active and for a reasonable period afterward;
- connection tokens and related integration metadata may be retained until you disconnect the integration, the credentials expire, or we otherwise determine they are no longer needed;
- billing, invoice, charge, refund, and tax related records may be retained for longer periods where needed for accounting, legal, fraud prevention, or audit purposes;
- some operational logs and activity records may be retained only for limited periods, which can vary by plan, workspace configuration, or technical need.
8. Security
We use technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or disclosure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. International Data Transfers
Your information may be processed and stored in countries other than the country where you live. Those countries may have data protection rules that differ from your local laws. Where required, we take steps designed to protect transferred personal information.
10. Your Rights and Choices
Depending on your location and the circumstances, you may have rights to access, correct, delete, restrict, object to, or request portability of certain personal information, and to withdraw consent where processing depends on consent.
You may also have practical in product choices, such as updating workspace details, disconnecting supported integrations, or canceling billing if you are the workspace owner.
To submit a privacy request, contact privacy@serpitis.com. We may ask for reasonable verification before acting on a request, and some rights may be limited where exceptions apply under applicable law.
12. Third Party Services
The Service may link to or rely on third party websites, APIs, and hosted experiences. We are not responsible for the privacy practices of third parties, and you should review their policies separately.
13. Children's Privacy
Serpitis is not directed to children, and we do not knowingly collect personal information from children under the age required by applicable law to consent to data processing. If you believe a child has provided personal information to us, contact us so we can review the situation.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, product, or operational changes. If we make material changes, we may notify you through the Service, by email, or by updating the "Last updated" date above.
15. Contact Us
Privacy questions, requests, or concerns may be sent to:
Serpitis