toseo.todayHome

Last updated October 6, 2026

Privacy policy

toseo.today turns a website's SEO data into daily to-do lists. This page explains what data the app uses, where it is kept, and how to remove it. In short: we only read your data to build your task lists and Insights, we don't sell it or use it for advertising, and you can disconnect at any time.

Google data (Search Console and Analytics)

When you choose "Sign in with Google", you allow toseo.today to:

  • See your Search Console data (webmasters.readonly): the properties you can access, and the searches, clicks, impressions and positions for the property you add as a project.
  • See your Google Analytics data (analytics.readonly): the GA4 properties you can access, and organic landing-page engagement, key events and revenue for the property you add.
  • See your email address, to show which Google account is connected.

Access is read-only: toseo.today can't change anything in your Google accounts.

How we use it:

  • The data is used only to show you Insights (pages losing traffic, searches you could win) and to rank your SEO tasks by the traffic they could bring.
  • It is fetched when you open the app, processed on our server, and kept in the server's memory for up to one hour so pages load quickly. The data itself isn't stored in a database. If you add an insight to your plan, the task it creates (which can mention a search and its clicks) is saved with your team's progress, as described below.
  • It isn't sold, used for advertising, or used to train AI models. The only company it goes to is Anthropic, and only the search terms and page addresses described under "Link-building ideas" below. Nobody at toseo.today reads it unless you ask us to help with a problem.
  • To keep you signed in, Google gives us a refresh token. It is encrypted and kept in a cookie on your device (toseo_vault), not on our servers, for up to 400 days unless you disconnect.

toseo.today's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Ahrefs data and API keys

If you connect Ahrefs, your API key is encrypted and kept in the same cookie on your device. It is used only on our server to read your Site Audit projects, issues and affected pages. Audit results are cached until a newer crawl is available, so we don't use more of your Ahrefs API units than needed.

Link-building ideas (Claude by Anthropic)

The off-page Tactics and Digital PR tabs are written by Claude, Anthropic's AI model, with web search. To tailor them, toseo.today sends Anthropic's API the project's domain and brand names and, when Search Console is connected, its 15 top non-branded searches and 10 most visited page addresses (no click counts or other figures). This happens when a project first opens these tabs and then once a week. Anthropic processes the request to write the ideas; under its commercial terms, API data isn't used to train its models. The resulting tactics and ideas are saved in team storage so your team sees the same list.

Crawl files you import

Crawl exports (Screaming Frog, Sitebulb, Ahrefs or other CSV files) are read in your browser. Only the results are kept: the issues found and, for each issue, up to 50 affected pages with their address, title, meta description, heading, status code, links and traffic figures from the file, plus a list of up to 1,000 affected addresses with their status code and traffic. With team storage (below) they are saved there so your team sees the same tasks; otherwise they stay in your browser's local storage.

Your projects and progress

Projects (site name, Search Console property, GA4 property ID, Ahrefs project ID, brand terms) and progress (tasks done or moved, the workload, issues moved to Ignore, planned and dismissed insights, outreach statuses) are saved in toseo.today's team storage, a database hosted by Upstash (Redis), so everyone on your team works from the same lists. On a deployment without team storage they are saved in your browser instead (projects in the encrypted cookie, progress in local storage). Google sign-ins and Ahrefs keys are never put in team storage.

Cookies

The project you have selected is remembered in a cookie (toseo_project). During Google sign-in, a short-lived cookie (toseo_oauth_state, 10 minutes) protects the sign-in from forgery. We don't use advertising or tracking cookies.

Hosting

toseo.today runs on Vercel, which keeps standard request logs (such as IP address, page requested and time) to operate and secure the service. Requests to Google and Ahrefs are made from Vercel's servers. Team storage is hosted by Upstash.

Removing your data

  • Disconnect Google or Remove key (Ahrefs) on the Connect page. Disconnecting Google also asks Google to revoke toseo.today's access. You can also revoke it yourself at myaccount.google.com/permissions.
  • Remove a project on the Connect page, which also deletes its progress, imported crawl and link-building ideas from team storage (or from your browser).
  • Clearing this site's cookies and site data in your browser removes everything toseo.today keeps on your device.
  • To have everything about your team deleted from team storage, email us (below).

Children

toseo.today is a tool for website owners and isn't meant for children under 16.

Changes and contact

If this policy changes, we'll update the date at the top of this page. Questions or requests: hello@toseo.today.

© 2026 toseo.today
PrivacyTermsDemo