Privacy Policy
SEO Command Center ยท Disruptors Media ยท Last updated 14 August 2026
Who we are
SEO Command Center is an SEO platform operated by Disruptors Media. Our team uses it to manage SEO work for our clients, and client users sign in to view their own results and review content before it is published.
Questions about this policy or your data: kyle@disruptorsmedia.com
What we collect
Account information. Your email address, your name if provided, your role (which determines what you can see), and the date the account was created. Sign-in is handled by Supabase Auth. If you sign in with Google we receive your email address and basic profile information. We never see or store your Google password.
Connected Google accounts. If you connect Google Search Console or Google Analytics, we request two permissions, both read-only: webmasters.readonly to read Search Console performance data, and analytics.readonly to read Google Analytics 4 reporting data โ for the properties you select. We cannot change, publish or delete anything in your Google account. The token that refreshes this access is encrypted before it is stored.
Data received from Google is used only to show your search performance in the dashboard and to inform recommendations for your own website. It is not used for advertising, not sold, and never shared with other clients.
Website and business data. Pages discovered by crawling your own public website (URLs, titles, headings, word and link counts), keyword and backlink data, the business profile you or our team fill in, generated content drafts and images, and publishing history.
Website credentials. If you connect a WordPress site for automatic publishing, the application password is encrypted before storage and used only to publish content you have approved.
Activity records. We keep an audit record of significant actions โ who approved content, who changed a setting, who connected an integration โ with the acting user's ID and email. Secrets are never written to these records.
What we do not do
- We do not use advertising or tracking cookies. Cookies keep you signed in, nothing more.
- We do not track you across other websites.
- We do not sell personal data.
- We do not use your data to train AI models.
Who we share it with
We use the following providers to run the service, each receiving only what it needs:
| Provider | Purpose |
|---|---|
| Supabase | Database, sign-in and file storage |
| Vercel | Hosting |
| Search Console and Analytics data you connect | |
| DataForSEO | Keyword and backlink data (receives domain names) |
| OpenRouter / OpenAI | Generating and reviewing content |
| Kie.ai / OpenAI | Generating images |
| Google Fonts | Page typography (your browser's IP address) |
We share personal data with no one else, except where legally required. Each client sees only their own data, enforced in the database itself with row-level security rather than only in the interface.
Where it is stored, and for how long
Data is stored with Supabase and Vercel, which may include servers in the United States. If you are in the UK or EU, your data may therefore be transferred outside your country.
We keep client data for as long as the client relationship continues and for a reasonable period afterwards for record-keeping. To be straightforward about it: the platform has no automatic deletion schedule, so data is removed when someone removes it. Deleting a client removes their associated records.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you
- correct anything that is wrong
- delete your account and personal data
- disconnect any connected Google or WordPress account
Email kyle@disruptorsmedia.com and we will respond within 30 days. You can also revoke our Google access yourself at myaccount.google.com/permissions. If you are in the UK or EU you may also complain to your local data protection authority.
Security
- Sign-in is verified on every request; closed accounts cannot regain access.
- Google tokens and website passwords are encrypted before storage.
- Client data is separated at the database level.
- Content is checked before it is published to a website.
No system is perfectly secure, but an external security review of this application was completed in August 2026 and the issues it raised were addressed.
Children
This is a business tool, not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date above. Significant changes will be communicated to account holders directly.