Effective 26 July 2026
Unhidden is built to provide useful SEO insights without collecting more personal data than the service needs. We do not sell personal data, use it for targeted advertising, or track people across unrelated websites.
Robin Karlberg Technologies AB, organisation number 559549-4146, Malakitgatan 6, 224 88 Lund, Sweden, is the data controller for personal data connected with the Unhidden website, accounts, subscriptions, and direct use of the service.
For visitor metrics collected through the Unhidden analytics script on a customer's website, that customer is normally the data controller and we act as its service provider. Visitors should first contact the owner of the website they visited about that processing.
The scanning tools are intended for publicly available webpages. A public page can contain personal data, so please do not submit private URLs, secrets, or personal data that is not needed for the analysis.
If you connect Google Search Console, we store the authorization tokens needed to maintain the connection and read the properties you choose. We then process read-only Search Console data such as page and query names, clicks, impressions, click-through rate, country, and average position. You can stop future access by revoking Unhidden's access in your Google account. Disconnecting does not automatically remove reports or other data already created from the connection; contact us if you want that data deleted as well.
Payments are handled by Stripe. We store Stripe customer and subscription identifiers together with your plan, billing interval, subscription status, renewal information, and credit balance. Payment card details are entered with and stored by Stripe, not by us.
When a customer installs our analytics script, it records only visits arriving from recognized search engines or AI assistants. For each page view it records:
The script does not set cookies, use local storage, fingerprint the device, collect the page title or page contents, or retain the visitor's IP address in the analytics record. Like any web request, the visitor's IP address is handled transiently by the network and server receiving the request and may appear in limited infrastructure security logs. We do not use this data to identify visitors or follow them between websites.
We receive data directly from you, from your use of the service, from public webpages you ask us to analyze, from Stripe, and—only when you connect or use the relevant feature—from Google Search Console or Google sign-in. The customer analytics script sends the limited visitor metrics described above from the customer's website.
We do not make decisions about people that produce legal or similarly significant effects using solely automated processing. SEO reports and AI features are automated tools, but their output is informational.
We disclose only the data needed to operate the relevant feature. Depending on what you use, recipients include:
We may also disclose data when required by law, to protect rights or security, or as part of a merger, financing, acquisition, or sale of the business with appropriate safeguards. We do not sell personal data or disclose it to data brokers or advertising networks.
We are based in Sweden, but some providers may process data outside the EU/EEA. Where data-protection law requires a transfer safeguard, we use an approved mechanism made available for that transfer, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
We keep data only for as long as needed for the purpose described above. In particular:
Deleted data may remain briefly in restricted backups until they are overwritten in the normal backup cycle. We may keep data that has been irreversibly anonymized because it can no longer identify a person.
We use only strictly necessary first-party cookies:
token keeps you signed in and lasts for up to 100 days unless you sign out or the session is invalidated.mlReq protects the magic-link sign-in flow and expires after 15 minutes.Our product analytics and customer website analytics are cookieless. Google and Stripe may set their own cookies when you visit their pages or use their embedded flows; their privacy notices govern those cookies.
Depending on the circumstances, the GDPR gives you the right to request access, correction, deletion, restriction, or portability of your personal data, and to object to processing based on legitimate interests or for direct marketing. Where processing is based on consent, you can withdraw that consent at any time without affecting earlier processing.
To exercise a right, email robin@rkt.dev. We may need to verify your identity. Some rights have exceptions—for example, we may need to retain transaction data required by accounting law.
You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or with the data-protection authority where you live or work.
We use technical and organisational safeguards designed to protect data, including access controls, secure session cookies, hashed passwords, limited retention for sensitive tokens and logs, and encrypted network connections. No online service can guarantee absolute security, so please protect your account and contact us if you suspect unauthorized access.
The service is intended for adults and organisations, not children. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact us so we can review and delete it where appropriate.
We may update this policy when the service or law changes. We will post the revised version here and change the effective date. If a change materially affects how we use account data, we will provide reasonable notice through the service or by email.
Questions about privacy can be sent to robin@rkt.dev. For account access, correction, or deletion, contact robin@rkt.dev. Our company details are available in the Impressum.