Back to Kitto

Legal

Privacy Policy

Last updated September 7, 2026 · Questions: [email protected]

This policy explains what Kitto collects, why, who processes it and how to remove it. The data controller is Artem Ivantsov, an individual based in Georgia. Contact: [email protected].

1. What we collect

DataWhere it comes fromWhy
Account: email, name, password hash or Google sign-in IDYou, at sign-upLog you in, send service emails
Search Console data: queries, pages, impressions, clicks, positions, per dayGoogle Search Console API, read-only, for the properties you connectBuild the opportunity map, plan content, report results
Google OAuth token for Search ConsoleGoogle, when you connectFetch the data above daily; stored encrypted
Site content: page URLs, titles, headings, text and internal linksOur crawler, reading your public pagesUnderstand what your site already covers; internal linking
CMS connection: site URL, application password or API tokenYou, when you set up publishingPublish and update articles on your site; stored encrypted
Billing: plan, invoices, last four digits of the card, countryour payment provider, acting as Merchant of RecordShow your subscription status. We never receive full card numbers
Usage and technical: pages you open in the app, IP address, browser, error reportsYour browser and our serversSecurity, debugging, keeping the service working
Support messagesYou, by emailAnswer you

We do not collect data about your visitors. We read your Search Console reports and your public pages, not your site’s analytics or user accounts.

2. Legal basis

We process data to perform the contract with you (account, Search Console data, site content, publishing, billing), to comply with legal obligations (invoices and tax records kept by our payment provider), and for our legitimate interest in keeping the service secure and working (technical logs, abuse prevention such as one introductory period per site). We do not use your data for advertising and do not sell it.

3. Who processes your data

We use a small number of providers. Each receives only what its job needs, under a contract that limits use to our instructions.

ProviderWhat it receivesPurpose
Google (Search Console API, sign-in)OAuth requests for your connected propertiesSource of your search data
our payment provider, acting as Merchant of RecordEmail, country, payment details you enter at checkoutPayments, invoices, taxes, refunds
OpenAI (API)Titles and text of your public pagesEmbeddings for internal linking and topic matching
DeepSeek (API)Briefs built from your site content and aggregated search queriesDrafting and checking articles
DataForSEOSearch queries, without any account dataPublic search results used by the quality gate
SentryError reports, which may include your account ID and IP addressFinding and fixing bugs
Hosting provider (cloud servers and database)Everything above, at restRunning the service

AI providers are used through their business APIs, whose terms prohibit using our inputs to train their models. We send them content and query data, never your credentials, tokens or payment details. Providers may be located outside your country; transfers rely on standard contractual clauses or equivalent safeguards.

4. Google user data and Limited Use

Kitto requests the read-only Search Console scope (webmasters.readonly) and nothing else. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

  • Search Console data is used only to provide Kitto’s features to you, the owner of the connected property.
  • It is not sold, not used for advertising, and not shared with other customers or with anyone except the processors above, and only for those purposes.
  • Humans at Kitto do not read your data except with your permission, for security, or to comply with the law.
  • You can disconnect at any time in Kitto or at myaccount.google.com/permissions. We delete the token immediately and the imported data as described in section 6.

5. Security

Google tokens and CMS credentials are encrypted at the field level with a key that is not stored in the database. Connections use TLS. Access to production systems is limited to the operator. Payment card data is handled entirely by our payment provider, which is PCI-DSS compliant. If a breach affects your data, we notify you without undue delay and, where required, the supervisory authority.

6. How long we keep data

  • Account and site data: while your account exists. When you close it, we delete Search Console data, crawled content, tokens and CMS credentials within 30 days; backups roll off within a further 30 days.
  • Disconnected property: the token is deleted immediately; its imported data within 30 days.
  • Invoices and billing records: kept by our payment provider for the period required by tax law.
  • Technical logs and error reports: 90 days.
  • Abuse-prevention records (a hash of the property and email, used to enforce one introductory period per site): 24 months.

7. Your rights

Wherever you live, you can ask us to access, correct, export or delete your personal data, to restrict or object to processing, and to withdraw consent where processing is based on it. Write to [email protected]; we respond within 30 days. If you are in the EU, EEA, UK or Switzerland, you can also complain to your local data protection authority. Closing your account in Settings deletes your data without needing to email us.

8. Cookies

The app uses strictly necessary cookies only: a session cookie to keep you logged in and a security cookie during the Google connection flow. The public website sets no analytics or advertising cookies. Because no optional cookies are used, there is no cookie banner.

9. Children

Kitto is for site owners and businesses and is not directed at anyone under 18. We do not knowingly collect data from children.

10. Changes

We update this policy when our processors or practices change. Material changes are emailed to account holders at least 14 days before they take effect; the date at the top shows the current version. Terms of use are in the Terms of Service.

11. Contact

Artem Ivantsov, an individual based in Georgia. Privacy questions: [email protected]. Everything else: [email protected].