Legal
Privacy Policy
SAGEOBOT website and app
Last updated: July 27, 2026
The German-language Datenschutzerklärung is the legally binding version of this policy. In case of any discrepancy between the two versions, the German version prevails.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Alexander Zakharov (sole proprietor)
Turmweg 31
20148 Hamburg
Germany
Email: hello@sageobot.com
VAT ID: DE455314355 (§ 27a UStG)
“SAGEOBOT” is the product/brand name used by the individual named above; there is no separate company registration (sole proprietorship) and no separate managing director. The provider is reachable exclusively by email; no phone line is offered, which satisfies the fast electronic contact requirement of § 5 DDG. A data protection officer is not required (sole proprietor, no large-scale or systematic processing of special categories of personal data under Art. 9 GDPR).
Scope of this policy
This Privacy Policy covers the SAGEOBOT website (sageobot.com), the public diagnostic tool, and the authenticated web application (together, the “Service”). SAGEOBOT is a taxonomy-constrained, AI-assisted SEO content platform for business customers (B2B). It explains which personal data SAGEOBOT processes, for what purposes, on what legal basis, to whom it may be disclosed, and how long it is retained.
The Service is directed at business operators within the meaning of § 14 BGB. Should a consumer (§ 13 BGB) exceptionally become a contracting party in an individual case, applicable consumer-protection rules apply in addition, as a safeguard rather than an expectation.
Processing activities
For each processing activity below: purpose, categories of data, legal basis (Art. 6 GDPR), recipients, and retention period.
Account and authentication
Purpose: registration, sign-in, access control (roles, site assignment), evidence of Terms/ Privacy Policy acceptance.
Data: email address, Firebase user ID, authentication provider (including Google sign-in), role, assigned site IDs, timestamp and version of accepted Terms of Use and acknowledged Privacy Policy.
Legal basis: Art. 6(1)(b) GDPR (contract performance); additionally Art. 6(1)(f) GDPR (legitimate interest in security and access control).
Recipients: Google/Firebase (Firebase Authentication).
Retention: for the duration of the contractual relationship plus statutory retention periods.
Service delivery / content platform
Purpose: website/company profile, SEO strategy, AI-assisted article generation and review, quality gating, CMS publishing, indexing, performance and analytics reporting, AI-visibility reporting.
Data: site/domain data, target market, CMS configuration, Google Search Console settings, article drafts, headlines, publishing preferences, uploaded assets, prompts, source material, editorial feedback; integration credentials (OAuth tokens, API keys, webhook URLs); where Google Search Console is connected: the connected Google account email, property permissions, query/page performance data, sitemaps, URL inspection data.
Legal basis: Art. 6(1)(b) GDPR (contract performance); Art. 6(1)(f) GDPR (legitimate interest in operating and securing the Service).
Recipients: OpenAI (content generation), Google/Firebase (storage, GSC), Hetzner (hosting), Bing Webmaster Tools, DataForSEO, OpenPageRank.
Retention: while the site/account is active, unless deleted earlier.
Public diagnostic tool (access-code protected)
Purpose: free SEO/AEO analysis of a submitted website before registration.
Data: access-code hash, submitted email address, target URL, target market/language, public website content of the target URL, generated report, report token hash, delivery status, pseudonymized IP hash, user agent, timestamps, Terms/Privacy Policy acceptance. If you separately opt in to product updates, we store that request pending until double opt-in confirmation.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure requested by the data subject); Art. 6(1)(f) GDPR (abuse prevention); for optional product updates: Art. 6(1)(a) GDPR (consent, double opt-in).
Recipients: Resend (report email delivery), Google PageSpeed (performance measurement).
Retention: only for as long as needed to deliver the report and prevent abuse; the diagnostic submission is deleted no later than 180 days. The IP hash is already pseudonymized.
Billing
Purpose: subscription management, payment processing, invoicing, automated tax calculation.
Data: email address, name, billing address, VAT ID, subscription/entitlement status; payment data is processed exclusively by Stripe (Stripe-hosted checkout).
Legal basis: Art. 6(1)(b) GDPR (contract performance); Art. 6(1)(c) GDPR (commercial/tax retention obligations).
Recipients: Stripe Payments Europe, Ltd. / Stripe, Inc.
Retention: invoices and accounting records for 8 years (§ 147(3) AO / § 257(4) HGB); books, inventories, and annual financial statements for 10 years; other business correspondence for 6 years.
Transactional email
Purpose: delivery of diagnostic report links and double opt-in confirmations.
Data: recipient email address, report link.
Legal basis: Art. 6(1)(b) GDPR (contract performance/pre-contractual measure); for marketing confirmations: Art. 6(1)(a) GDPR (consent).
Recipients: Resend.
Retention: for as long as needed to deliver the email and evidence consent.
Product analytics (PostHog)
Purpose: product usage analytics to improve the Service.
Data: page views, device/browser metadata, session ID, product events; after sign-in, also Firebase user ID and email address. Session replay, autocapture, page-leave tracking, and dead-click tracking are disabled by default.
Legal basis: Art. 6(1)(a) GDPR (consent via the cookie consent banner). You can withdraw consent at any time in the cookie settings without affecting your ability to use SAGEOBOT.
Recipients: PostHog (EU instance, eu.i.posthog.com).
Retention: product analytics events are stored for the lifetime of the customer account and deleted upon account deletion or at any time on request; personal data is not kept longer than needed for product analytics. Session recordings (session replays) are disabled and not collected.
Your analytics consent choice and PostHog identity are shared across sageobot.com and app.sageobot.com, so one decision governs both and you are not asked twice. If you sign in to the SAGEOBOT app after browsing sageobot.com with analytics consent granted, we may associate that prior anonymous browsing activity with your account. Server-side billing events (such as subscription creation, plan changes, or payment status) are only sent to PostHog when analytics consent is recorded on your account.
Server logs / hosting
Purpose: operation, security, error diagnosis, abuse prevention.
Data: IP address, timestamps, requested paths, HTTP status codes, device/browser metadata, audit logs, API logs, error diagnostics.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and operation).
Recipients: Hetzner Online GmbH, Nuremberg data center (infrastructure).
Retention: short-term, rolling retention; server logs are deleted no later than 180 days; no archiving beyond the operational/security purpose.
AI processing (OpenAI)
Purpose: AI-assisted article/headline generation and quality review.
Data:prompts, and website/business content the customer provides or that is extracted from the customer’s public website. This content may include personal data of third parties (for example, named employees or testimonial authors) — see “Data from other sources” below.
Legal basis:Art. 6(1)(b) GDPR (contract performance); where customer content includes personal data of third parties, SAGEOBOT processes it as a processor on behalf of the customer under Art. 28 GDPR — see “Processing on behalf of customers” below.
Recipients: OpenAI, L.L.C. (USA).
Retention: while the site/content is active, unless deleted earlier.
SAGEOBOT uses OpenAI exclusively for text and content generation. Image generation currently also uses OpenAI; the platform additionally supports Google (Gemini) as an explicitly configured per-site option for image generation only, currently not in use for any customer. If activated, the sub-processor list will be updated beforehand. Earlier marketing copy that additionally named OpenRouter or DeepSeek was inaccurate and has been corrected.
SEO data services
Purpose: SERP/keyword data, competitor analysis, AI-visibility measurement, Search Console synchronization, performance measurement, domain authority scoring.
Data: keywords, domains, search queries (generally no direct customer personal data); for Google Search Console: the connected Google account email and performance data; for PageSpeed: the target URL; for Bing Webmaster Tools: the website URL and API key; for OpenPageRank: only the domain (no personal data).
Legal basis: Art. 6(1)(b) GDPR (contract performance); Art. 6(1)(f) GDPR (legitimate interest in reporting/optimization).
Recipients: DataForSEO, Google (PageSpeed, Search Console), Microsoft (Bing Webmaster Tools), OpenPageRank.
Retention: while the site/account is active, unless deleted earlier.
Data from other sources
As part of website analysis (“SiteBrief”), SAGEOBOT automatically collects publicly accessible content from the website the customer submits (for example, service descriptions, customer testimonials, tone-of-voice examples, page overviews). This public content may include personal data of third parties, such as named employees or testimonial authors. SAGEOBOT processes this data on behalf of and under the instructions of the customer for the purpose of content creation. Responsibility for the lawfulness of publishing this content (including any necessary third-party consents) lies with the customer as the controller for its own website.
Recipients and processors
SAGEOBOT uses various service providers (processors, or in individual cases independent controllers), including for AI processing, payment processing, transactional email, hosting, and SEO data services. The complete, continuously updated list of providers — with purpose, data categories, location, and transfer basis for each — is maintained in the Sub-processor List, which is incorporated by reference into this policy and also forms Annex 2 to the data processing agreement (see “Processing on behalf of customers” below).
Production data is hosted server-side by Hetzner Online GmbH in the Nuremberg data center (Germany). The primary data store (Firestore) resides in the Firestore Europe multi-region (location eur3), replicated across Google data centers in St. Ghislain, Belgium and Eemshaven, Netherlands; data therefore rests within the EU. OpenAI processes data under standard contractual clauses (no EU-US Data Privacy Framework participation); Stripe, Resend, Google, and Microsoft process data under the EU-US Data Privacy Framework; PostHog is EU-hosted with no third-country transfer. These transfer mechanisms and Data Privacy Framework certification statuses were last verified on July 27, 2026.
Telegramis used for internal operational notifications. When a customer is created, the internal operations channel receives a purely internal operational notification containing only the customer’s website domain and plan/tier information — no names and no contact data (for example, no email address). The legal basis is the provider’s legitimate interest in fast internal notification of new customers (Art. 6(1)(f) GDPR). The operator is Telegram FZ-LLC (United Arab Emirates) or Telegram Messenger Inc. (British Virgin Islands), a third country without an EU Commission adequacy decision and without executable standard contractual clauses. To the extent a website domain can, in an individual case, be related to an identifiable person, this discloses a third-country transfer risk within the meaning of Art. 49 GDPR. Separately, each customer site may have its own, customer-configured Telegram channel for client notifications, which processes only that customer’s own data and is subject to the same third-country risk; it is otherwise unaffected by the disclosure above.
Processing on behalf of customers
Where a customer has SAGEOBOT process personal data of third parties (for example, data from the customer’s own website, customer lists, or testimonials), SAGEOBOT acts as a processor within the meaning of Art. 28 GDPR, and the customer remains the controller for that data. The details of this processing (instructions, technical and organizational measures, sub-processor list, deletion after contract termination) are set out in a separate data processing agreement (DPA) that forms part of the customer contract.
Your rights under GDPR
Where GDPR applies, you have the following rights:
- Access (Art. 15 GDPR) to the data we process about you.
- Rectification of inaccurate or incomplete data (Art. 16 GDPR).
- Erasure, the “right to be forgotten” (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
To exercise these rights, an email to hello@sageobot.com is sufficient.
Withdrawal of consent
Where processing is based on consent (for example, PostHog product analytics or the marketing email opt-in), you can withdraw it at any time with effect for the future — for analytics cookies via the cookie settings in the app, for marketing emails via the unsubscribe link in every email, or informally by email to hello@sageobot.com. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to lodge a complaint with a supervisory authority
Data subjects have the right, without prejudice to any other administrative or judicial remedy, to lodge a complaint with a data protection supervisory authority, in particular in the member state of their habitual residence, place of work, or place of the alleged infringement. The supervisory authority responsible for the controller is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Ludwig-Erhard-Str. 22, 7. OG, 20459 Hamburg
Phone: 040/428 54-4040
Email: mailbox@datenschutz.hamburg.de
Web: https://datenschutz-hamburg.de
Cookies and consent
The Service uses an essential authentication cookie as well as other technically necessary storage (language preference, theme, sign-in state). Product analytics cookies (PostHog) are only set after explicit consent via the cookie consent banner. Consent can be withdrawn at any time via the cookie settings without affecting your ability to use SAGEOBOT. For signed-in users, we keep a server-timestamped record of the consent decision (version, acceptance/rejection/withdrawal).
The essential consent cookie, and the PostHog analytics cookie once consent is granted, are scoped to the sageobot.com domain so they are readable and writable from both sageobot.com and app.sageobot.com. This lets your cookie choice and, once you accept analytics, your PostHog identity carry over between the marketing site and the app without a second prompt. On other hosts (for example local development or preview deployments) these cookies stay scoped to that single host only.
The legal basis for storing and accessing information on your device (for example, cookies or local storage) is § 25(1) TDDDG, or § 25(2) No. 2 TDDDG for storage that is strictly necessary; the legal basis for the subsequent data processing is Art. 6(1)(a) GDPR.
No special-category data and no automated decision-making
The Service is not intended for processing special categories of personal data (Art. 9 GDPR) or data of minors; the Terms of Use prohibit customers from uploading such data, as well as payment card data. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them: AI-assisted SEO content creation has no legal or comparably significant effect on third parties (for example, the customer’s own end customers), as it produces marketing content without decision-making character toward those persons.
Changes to this policy
This Privacy Policy may be updated to reflect product, provider, or legal changes. The “Last updated” date at the top of this page shows the most recent revision.