What we read, what we keep, and what we never keep.
This page describes what the product actually does with data, taken from how the code behaves rather than from a template. Where we have not yet fixed a detail, it says to be confirmed.
Who we are
Search Overflow operates this website and the audit service, and is based in India. Questions about this page go to overflowsearch@gmail.com.
The free audit on this site
When you enter a website address, our server fetches that site’s robots.txt file and its homepage, runs the checks in memory, and returns the result to your browser. We identify ourselves in the request as Search OverflowAI-Preview so the site owner can see who fetched the page.
We do not save the address you entered, the pages we fetched, or the result. There is no database write in that path. If you close the tab, the result is gone.
- Our web server keeps standard access logs (IP address, time, path requested) for operating the service. Retention period: to be confirmed.
- If you choose to give us your email address to receive the report or to book a walkthrough, we store the details you typed and, if you asked for it, a summary of that audit, so we can reply. We do not add you to a marketing list without a separate opt-in, and every marketing email carries an unsubscribe link that we honour.
Your browser
This site sets no analytics or advertising trackers and loads no third-party scripts. Fonts are served from our own domain.
- Local storage holds your display currency choice and which panels you have collapsed. Nothing in it identifies you.
- When you sign in as a customer, a same-origin session cookie keeps you signed in. It is not shared with any other site.
If you are a customer
Customer accounts use passwordless sign-in: a one-time code sent to your email, or sign-in with Google. We never hold a password for you.
Everything in your workspace is stored in MongoDB Atlas, our system of record: your workspace and users, the crawls of the sites you point us at, findings, claims and their sources, campaign drafts, activity logs and the audit trail. Data hosting region: to be confirmed.
- Credentials you connect, such as Google Search Console or GA4, are encrypted with AES-256-GCM under a key derived for your workspace alone. No endpoint returns a credential in plain text. Reads show a name, a four-character preview and when it was set.
- To find related content across your crawl we compute embeddings with Google Gemini and store the vectors in Pinecone, in a namespace that belongs to your workspace only. This means text from pages you audit is sent to Google for embedding.
- For AI visibility tracking, the prompts you configure are sent to the engines you select (ChatGPT, Gemini, Perplexity, Claude, Copilot, Grok), and their answers are stored so that the rate we report can be re-checked. The engines see the prompt text, not your account details.
- Each workspace is isolated at the database layer. A record that belongs to another workspace is treated as if it does not exist.
Who else sees data
- MongoDB Atlas (database hosting), Pinecone (vector storage), Google (Gemini embeddings and, if you use it, Google sign-in and Search Console or GA4 connections).
- The AI engines listed above, only for the prompts you ask us to track.
- No data broker, advertising network or analytics vendor. We do not sell or rent personal data.
Your rights and how long we keep things
You can ask to see, correct or delete personal data we hold about you by emailing overflowsearch@gmail.com. If you are a customer, deleting your workspace removes its crawls, findings and connected credentials. Retention periods for logs and for closed accounts: to be confirmed.
Changes
When this page changes, the date at the top changes with it, and the reason is noted in the changelog. We will not quietly widen what we collect.