Privacy Policy
Last updated Jan 14, 2026 · US Eastern Time (Washington, D.C.)
1. Who we are
SERPforAI ("we", "us") operates the SERP and Web Reader API platform available at serpforai.dev. This policy explains what personal data we process and why.
2. Data we collect
- Account data - your email address, display name and profile image if you sign in with Google.
- Authentication data - a session token stored in your browser's local storage. Passwords reach us only as a SHA-256 hash computed in your browser; we never receive plaintext passwords.
- Usage data - API call counts, remaining credits and per-key usage totals needed to operate and bill the service.
- Analytics data - only if you accept analytics cookies. Until you do, no analytics or advertising scripts are loaded.
3. Cookies and local storage
We use two categories of browser storage:
- Strictly necessary - your session token and API key are kept in local storage (not a cookie) so the dashboard and playground can call the API directly from your browser; a short-lived Google sign-in state cookie is also required during the Google sign-in handshake. These cannot be switched off without breaking sign-in.
- Analytics and marketing - disabled by default. Your choice is stored in your browser under
serpforai_cookie_consentand is unrelated to your login session.
4. How we use your data
- To authenticate you and keep you signed in.
- To meter API usage, maintain credit balances and prevent abuse.
- To provide support and send service notices.
- To improve the product, where you have consented to analytics.
5. Query content
Search keywords and URLs you submit are processed to fulfill the request. We do not sell query content, and we do not use it to build advertising profiles.
6. Data sharing
We share data only with infrastructure providers that operate the platform on our behalf, and only to the extent required to deliver the service. We do not sell personal data.
7. Your rights
Depending on your jurisdiction (including the GDPR and CCPA) you may request access, correction, deletion or export of your personal data, and you may withdraw analytics consent at any time by clearing your browser storage. Contact privacy@serpforai.dev.
8. Security
Session tokens and API keys are stored in your browser's local storage, and the dashboard and playground call the API directly from your browser rather than through a server-side proxy - this is why your API key is visible to you on /dashboard/keys. Treat both values like passwords: never paste them into a shared machine or commit them to a public repository, and regenerate a key immediately if you believe it has leaked. Sensitive endpoints are rate limited per IP address.
9. Retention
Account and usage records are retained while your account is active and for as long as required to meet legal and accounting obligations. Deleting your account removes your profile and keys.
10. Contact
Questions about this policy: privacy@serpforai.dev.