Privacy Policy

Applies to the CollSEO application (Collabmo Digital Innovation Hub Ltda.) and to the whole service at collseo.collabmo.com.br · Last updated: September 12, 2026

Leia esta Política de Privacidade em português →

1. Who we are

CollSEO is an SEO and content platform operated by artificial intelligence agents, provided by Collabmo Digital Innovation Hub Ltda., a company registered in Brazil under CNPJ 35.594.665/0001-55, with offices at Rua Dr. Renato Paes de Barros, 618 — Itaim Bibi, São Paulo/SP, 04530-000, Brazil ("we", "us"). We are the controller of the personal data of people who create an account on the platform, and the processor of the data you send us, or authorize us to read, about your website, your business profile and your customers.

This policy explains in detail which data we access, what we use it for, where we store it, who we share it with, how long we keep it and how you delete all of it. It follows the Brazilian General Data Protection Law (Law 13.709/2018, "LGPD") and, for the Google integrations, the Google API Services User Data Policy, including the Limited Use requirements.

Data Protection Officer: Alexsandro Oliveira de Almeida — contato@collabmo.com.br.

2. Summary

  • We use your data only to operate the CollSEO features you see on screen: analyze the site, plan, write, publish and measure.
  • We do not sell data, do not transfer it to data brokers, and do not use it for advertising or credit assessment.
  • We do not use data obtained from Google APIs to develop, improve or train generalized or non-personalized AI/ML models, our own or anyone else's.
  • Access to your Google accounts is read-only, with a single exception: publishing to your Business Profile, and only when you tell us to.
  • Tokens and API keys are encrypted at rest (AES-256-GCM) and are never sent to the browser or to AI providers.
  • You can revoke access and delete your data at any time — section 12 explains how, step by step.

3. Data we collect

  • Account data: name, email address, password (stored only as a hash, never in plain text), company and team role.
  • Platform usage: access logs, actions performed (audit log), IP address, date/time and browser.
  • Your website data: public pages our crawler reads — text, titles, metadata, images and link structure — plus whatever you enter in the business profile.
  • Data from the Google accounts you connect: detailed in section 4.
  • Other integrations you configure: Bing Webmaster Tools and the YouTube Data API (keys and metrics), and your publishing CMS (Ghost, WordPress, webhook or REST API), with the credentials you provide.
  • Content produced: briefs, articles, reviews, quality scores and version history, which remain in your account.
  • Leads: if you send leads through our API, we process the data you provide (for example name, email and phone number) in order to attribute the conversion to a piece of content.
  • Support: the messages and attachments you send us.
  • Cookies and local storage: described in section 15.

We do not ask for and do not want sensitive data (racial origin, health, biometrics, religious or political beliefs, sexual life) or credit card data — billing, when applicable, happens outside the platform.

4. Data obtained from Google APIs

Connecting Google is optional and always started by you, through the "Connect Google account" button under Site → Integrations. We request only the scopes below, with incremental consent — Business Profile is requested only from customers who use local SEO. No data is read before you authorize it.

Scope / APIWhat we accessWhat we use it for
Google Identity
openid, email
The email address and account identifier of the Google Account that granted authorization.Show which account is connected on the Integrations screen, prevent duplicate connections and refresh access when the token expires.
Google Search Console
https://www.googleapis.com/auth/webmasters.readonly
The list of properties you administer and, for the ones you link: search queries, impressions, clicks, CTR, average position, pages, country, device, and indexing and sitemap status.Discover the real search demand for your site, prioritize keywords by business value, detect keyword cannibalization and ranking losses, decide what to rewrite, and measure the outcome of every published piece of content.
Google Analytics 4
https://www.googleapis.com/auth/analytics.readonly
The list of GA4 properties and, for the one you link: sessions, users, source/medium, landing pages, engagement and the conversion events you mark as relevant — always as aggregated reports.Connect organic traffic to conversions, calculate return per content piece and per keyword, and show the evolution in your dashboards and reports.
Google Business Profile
https://www.googleapis.com/auth/business.manage
Business profile data (name, categories, address, hours, attributes, photos), reviews and replies, and profile performance metrics. Requested only from users who will use local SEO — customers who only use Search Console and GA4 never grant this access.Audit profile quality, track reviews and local performance, suggest fixes and — only when you explicitly approve each action — publish posts and review replies to your profile.

How this data is stored

  • Access and refresh tokens are encrypted at rest with AES-256-GCM in our database, never travel to the browser and are never sent to AI providers.
  • Imported metrics (queries, clicks, positions, sessions, conversions, reviews) are stored in the platform database, isolated per company: each account sees only its own data.
  • We keep only what the historical analysis needs — the last 90 days of Search Console and GA4 on the first import, then daily updates — and we never copy data from properties you did not link.

Writing to your accounts

Search Console and Analytics are accessed read-only (.readonly scopes): CollSEO does not change, delete or upload anything to those accounts. The only possible write is to your Business Profile, and only when you approve that specific action on screen — no agent posts to your profile on its own.

Who can see it

Only users of your own company, according to each person's role. Our staff does not browse your data: technical access happens only when you ask for support, to investigate a security incident or to comply with a legal obligation — always recorded in the audit log.

5. Limited Use of Google API data

CollSEO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:

  • We use this data solely to provide and improve the user-facing features of CollSEO that you subscribed to.
  • We do not transfer this data to third parties, except: (a) to infrastructure sub-processors strictly necessary to run the feature, under contract and on our instructions; (b) when you explicitly tell us to; (c) to comply with applicable law or a court order; (d) in a merger or acquisition, with prior notice to you and these same rules preserved.
  • We do not use this data for serving advertising of any kind — no personalized ads, no remarketing, no targeting.
  • We do not sell this data and do not transfer it to data brokers or information resellers.
  • We do not use this data for creditworthiness assessment, lending purposes or anything similar.
  • We do not use data obtained from Google APIs to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models, our own or third parties'. The models we use are third-party models consumed through APIs, and nothing we send them is used for their training at our initiative.
  • No humans read this data, except: with your explicit consent (for example a support request you open), when necessary for security purposes such as investigating abuse or an incident, to comply with applicable law, or in aggregated and anonymized form to operate and improve the service.

6. Legal bases and purposes

  • Performance of the contract: creating and maintaining your account, analyzing the site, planning and producing content, publishing when you authorize it, measuring results and issuing reports.
  • Consent: connecting your Google accounts and other integrations, and receiving non-essential communications. Can be withdrawn at any time (section 12).
  • Legitimate interest: security, fraud and abuse prevention, AI cost control and product improvement — always with the minimum data and without overriding your rights.
  • Legal obligation: retention of access logs required by the Brazilian Internet Act, and responding to authorities.

7. Artificial intelligence: what is sent to the model

To analyze, write and review, the platform sends the AI provider configured in your account (for example DeepSeek, OpenAI, Anthropic, Google or a local model) only what the task requires: excerpts of your site, the business profile, the keyword list and aggregated metrics such as impression volume and average position of a term.

We never send AI providers: passwords, Google or CMS tokens, API keys, lead data or personal data of your visitors. We also do not use the content sent to train our own models — we neither train nor fine-tune any model.

The choice of provider is yours, on the Models and keys screen: you can use the default provider, your own key (in which case the provider's terms apply directly to you) or a local model hosted on our infrastructure, in which case the text never leaves it.

8. Who we share data with

We do not sell data. We share it only with those necessary for the service to work, always as processors acting on our instructions:

  • Infrastructure and hosting: the server provider where the application, database and files run.
  • AI model providers: according to your account configuration and limited to the subset described in section 7.
  • Transactional email: to send invitations, password resets and system notices.
  • Services you connect: your publishing CMS, Bing Webmaster and YouTube — and Google itself, when reading the data you authorized.
  • Authorities: when required by law or court order.

None of these partners receives Google API data for their own purposes, and none of them may use it for advertising or model training.

9. International transfers

Part of the infrastructure and some AI and email providers are located outside Brazil. In those cases, the international transfer follows the safeguards of article 33 of the LGPD — contractual clauses with the processor, limited purpose and the minimum data necessary.

10. Security

  • All traffic is encrypted in transit with HTTPS/TLS.
  • Passwords are stored only as hashes, never in plain text.
  • Integration secrets — Google tokens, API keys and CMS credentials — are encrypted at rest with AES-256-GCM, with a key that is not kept in the database.
  • Per-company (multi-tenant) isolation and role-based access control: each person sees only what their role allows.
  • Audit log of every sensitive action, with author, timestamp and previous value.
  • Protection against internal network access by the crawler and integrations, request rate limits and dependency review.

No system is infallible. If you suspect unauthorized access, write immediately to contato@collabmo.com.br. In case of an incident with relevant risk, we notify you and the Brazilian data protection authority (ANPD) within the legal deadlines.

11. How long we keep data

  • Account data and content: for as long as the account exists.
  • Google tokens and other credentials: deleted from our database as soon as you disconnect the integration, revoke access at Google or close the account.
  • Metrics imported from Google: deleted together with the account, or earlier at your request; disconnecting stops any new reads, and the history already imported may be kept for your reports until you ask for its deletion.
  • After the account is closed: we delete or anonymize the data within 90 days, except what the law requires us to keep.
  • Access logs: 6 months, as required by the Brazilian Internet Act.
  • Lead data: for the period you define, and always deleted or returned at the end of the contract.

12. How to revoke access and delete your data

  1. Disconnect inside CollSEO: under Site → Integrations, use "Disconnect" on Search Console, GA4 or Business Profile. Reading stops immediately.
  2. Revoke at Google: at myaccount.google.com/permissions, remove CollSEO's access. This invalidates our tokens immediately on Google's side.
  3. Delete the data already imported: write to contato@collabmo.com.br asking for deletion of the Google data, or of the whole account. We confirm your identity, carry it out and reply within 15 days.
  4. Close the account: a closure request deletes account data, content, integrations and credentials within the periods in section 11.

13. Your rights

You may request confirmation of processing, access, correction, anonymization, portability, deletion, information about data sharing, and withdrawal of consent. Contact our Data Protection Officer, Alexsandro Oliveira de Almeida, at contato@collabmo.com.br. We reply within 15 days. If you are not satisfied, you may file a complaint with the ANPD.

14. Third-party data you send us

When you send leads, connect tools or authorize us to read your Business Profile data, you are the controller of that data and declare that you have a legal basis to process it. We act as processors, following your instructions, and return or delete that data at the end of the contract.

15. Cookies and local storage

  • Session cookie: the only cookie we use, required to keep you signed in. We use no advertising cookies and no third-party trackers, and there is no advertising profiling.
  • Browser preferences: we store things like the site in focus and the theme on your device.
  • "Save password on this device": if and only if you tick that option on the sign-in screen, your email and password are stored in your browser's local storage to prefill the form. Nothing beyond the normal sign-in is sent to our servers. Unticking it erases the record; do not use it on a shared computer.

16. Children

The platform is intended for companies and people over 18. We do not knowingly collect data from children or adolescents.

17. Changes to this policy

If anything changes materially — especially the data we read from Google or the purpose it is used for — we notify you by email or inside the platform before the change takes effect, and where the law requires it we ask for new consent. The date at the top shows the last revision.

18. Contact

Collabmo Digital Innovation Hub Ltda. — CNPJ 35.594.665/0001-55
contato@collabmo.com.br
Rua Dr. Renato Paes de Barros, 618 — Itaim Bibi, São Paulo/SP, 04530-000, Brazil