Legal

Privacy Policy

Effective 26 July 2026

Unhidden is built to provide useful SEO insights without collecting more personal data than the service needs. We do not sell personal data, use it for targeted advertising, or track people across unrelated websites.

1. Who is responsible for your data

Robin Karlberg Technologies AB, organisation number 559549-4146, Malakitgatan 6, 224 88 Lund, Sweden, is the data controller for personal data connected with the Unhidden website, accounts, subscriptions, and direct use of the service.

For visitor metrics collected through the Unhidden analytics script on a customer's website, that customer is normally the data controller and we act as its service provider. Visitors should first contact the owner of the website they visited about that processing.

2. Data we collect

Account and contact data

  • Your email address and, if you provide it, your name.
  • Your Google account identifier if you sign in with Google. We use the email address and identifier needed to create and secure your account; we do not store your Google password.
  • A password hash and salt if your account uses a password. We do not store the password itself.
  • Session records, login and recovery tokens, and your email and notification preferences.
  • Messages you send to support or otherwise send directly to us.

Websites and SEO service data

  • Websites and domains you add to your account.
  • URLs, keywords, target markets or locations, tracked keywords, and notes about changes to your website.
  • SEO reports and the public page data used to create them, such as titles, headings, readable page text, links, metadata, structured data, and aggregated comparisons with top-ranking pages.
  • Keyword and domain research requests, report history, credit usage, and other actions needed to provide and account for the service.
  • Your conversations with the built-in AI assistant. To answer questions about your website, the assistant may also use relevant reports, visitor metrics, tracked keywords, and Search Console data from your account.

The scanning tools are intended for publicly available webpages. A public page can contain personal data, so please do not submit private URLs, secrets, or personal data that is not needed for the analysis.

Optional Google Search Console data

If you connect Google Search Console, we store the authorization tokens needed to maintain the connection and read the properties you choose. We then process read-only Search Console data such as page and query names, clicks, impressions, click-through rate, country, and average position. You can stop future access by revoking Unhidden's access in your Google account. Disconnecting does not automatically remove reports or other data already created from the connection; contact us if you want that data deleted as well.

Payments and subscriptions

Payments are handled by Stripe. We store Stripe customer and subscription identifiers together with your plan, billing interval, subscription status, renewal information, and credit balance. Payment card details are entered with and stored by Stripe, not by us.

Visitor metrics collected for customers

When a customer installs our analytics script, it records only visits arriving from recognized search engines or AI assistants. For each page view it records:

  • the customer website and page path;
  • the recognized search or AI referrer;
  • a random, temporary page-view identifier;
  • visible time on the page, capped at ten minutes;
  • whether the visitor engaged by remaining for ten seconds, following a link, or scrolling through a substantial part of a long page; and
  • timestamps needed to calculate aggregate visitor and engagement metrics.

The script does not set cookies, use local storage, fingerprint the device, collect the page title or page contents, or retain the visitor's IP address in the analytics record. Like any web request, the visitor's IP address is handled transiently by the network and server receiving the request and may appear in limited infrastructure security logs. We do not use this data to identify visitors or follow them between websites.

Technical, security, and website usage data

  • For a free report, we create a salted one-way hash of the requesting IP address to enforce the weekly limit without storing the raw address in the report-limit record.
  • Error reports may contain the page URL, error details, limited diagnostic metadata, whether the device is mobile, and its operating-system family.
  • Our own website uses a self-hosted, cookieless analytics service to understand page views and product events. Ordinary server logs may also contain request time, requested URL, IP address, and user-agent data for security and reliability.

3. Where the data comes from

We receive data directly from you, from your use of the service, from public webpages you ask us to analyze, from Stripe, and—only when you connect or use the relevant feature—from Google Search Console or Google sign-in. The customer analytics script sends the limited visitor metrics described above from the customer's website.

4. Why we use the data

  • To provide the service and perform our contract: authenticate accounts, run requested analyses, save reports, provide analytics and Search Console features, operate the AI assistant, manage credits, process subscriptions, and send service messages.
  • For our legitimate interests: secure the service, prevent abuse, fix errors, understand aggregate product usage, support customers, and improve reliability and features. We balance these interests against the rights of the people concerned.
  • With your choice or consent: connect optional services and send product news or offers where consent is required. You can change email preferences in account settings or use the unsubscribe link.
  • To comply with law: keep required accounting records, respond to lawful requests, and establish or defend legal claims.

We do not make decisions about people that produce legal or similarly significant effects using solely automated processing. SEO reports and AI features are automated tools, but their output is informational.

5. Who receives data

We disclose only the data needed to operate the relevant feature. Depending on what you use, recipients include:

  • Stripe for checkout, payment, invoicing, and subscription management.
  • Google for Google sign-in and, at your request, read-only Search Console access.
  • Resend for login links, password resets, weekly digests, and other service or opted-in emails.
  • OpenAI to generate AI report analysis and assistant responses. This can include your prompt, public page content and metrics, and the relevant account data the assistant needs to answer your question.
  • SerpApi and DataForSEO for search results, keywords, domains, market selections, and related SEO metrics.
  • Oxylabs, when a proxy is needed to retrieve a public page for analysis. It receives the requested public URL and the technical data needed to make that request.
  • Infrastructure, database, security, and professional advisers that help us host, protect, support, and administer the service under appropriate confidentiality obligations.

We may also disclose data when required by law, to protect rights or security, or as part of a merger, financing, acquisition, or sale of the business with appropriate safeguards. We do not sell personal data or disclose it to data brokers or advertising networks.

6. International transfers

We are based in Sweden, but some providers may process data outside the EU/EEA. Where data-protection law requires a transfer safeguard, we use an approved mechanism made available for that transfer, such as an adequacy decision or the European Commission's Standard Contractual Clauses.

7. How long we keep data

We keep data only for as long as needed for the purpose described above. In particular:

  • Account data, saved reports, chats, tracked keywords, site notes, and customer analytics are generally kept while the account or relevant feature remains in use, until you delete an available item, or until you ask us to delete the account.
  • Search Console response caches expire after about six hours. Cached search results and crawled public pages expire after up to seven days. Keyword and domain research caches expire after up to 30 days.
  • Client error reports expire after 30 days. Short-lived authentication and abuse-prevention records generally expire within 15 minutes to seven days.
  • Billing, transaction, security, support, and legal records are kept for the period required by law or reasonably needed to resolve disputes, enforce agreements, and protect the service.

Deleted data may remain briefly in restricted backups until they are overwritten in the normal backup cycle. We may keep data that has been irreversibly anonymized because it can no longer identify a person.

8. Cookies and similar technologies

We use only strictly necessary first-party cookies:

  • token keeps you signed in and lasts for up to 100 days unless you sign out or the session is invalidated.
  • mlReq protects the magic-link sign-in flow and expires after 15 minutes.

Our product analytics and customer website analytics are cookieless. Google and Stripe may set their own cookies when you visit their pages or use their embedded flows; their privacy notices govern those cookies.

9. Your rights

Depending on the circumstances, the GDPR gives you the right to request access, correction, deletion, restriction, or portability of your personal data, and to object to processing based on legitimate interests or for direct marketing. Where processing is based on consent, you can withdraw that consent at any time without affecting earlier processing.

To exercise a right, email robin@rkt.dev. We may need to verify your identity. Some rights have exceptions—for example, we may need to retain transaction data required by accounting law.

You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or with the data-protection authority where you live or work.

10. Security

We use technical and organisational safeguards designed to protect data, including access controls, secure session cookies, hashed passwords, limited retention for sensitive tokens and logs, and encrypted network connections. No online service can guarantee absolute security, so please protect your account and contact us if you suspect unauthorized access.

11. Children

The service is intended for adults and organisations, not children. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact us so we can review and delete it where appropriate.

12. Changes to this policy

We may update this policy when the service or law changes. We will post the revised version here and change the effective date. If a change materially affects how we use account data, we will provide reasonable notice through the service or by email.

13. Contact

Questions about privacy can be sent to robin@rkt.dev. For account access, correction, or deletion, contact robin@rkt.dev. Our company details are available in the Impressum.