Privacy policy
Your data, access, and choices, stated clearly.
This policy covers crawliq.online, the Swiss Knife SEO product sites, and the working application at swissknifeseo.ai. It explains our handling of account, project, Google, analytics, and support data.
Effective and last updated July 20, 2026
Plain-language summary
We use personal data to operate Crawliq and Swiss Knife SEO, deliver the features a user requests, secure the service, provide support, and improve visible product workflows. We do not sell personal data or Google user data. We do not use Google user data for advertising, credit decisions, data brokerage, or general AI model training.
Effective and last updated July 20, 2026
Reviewer reference
Google data handling at a glance
- Access
- Google sign in identity, read-only Analytics reports, and read-only Search Console performance data, only after the user approves the relevant consent screen.
- Use
- Account access, selected property discovery, visible reports, user-requested joins with crawl evidence, saved project history, and monitors the user enables.
- Storage
- Encrypted OAuth tokens and only the report data, cached values, or derived project records needed for the feature the user selected.
- Sharing
- No sale, advertising, data brokerage, credit use, or general AI model training. Limited processors act only to provide, secure, support, or improve visible product features.
- Control
- Disconnect inside the application, revoke from the Google Account connections page, delete the project, close the workspace, or contact the operator for a verified request.
1. Scope and data controller
This Privacy Policy applies to crawliq.online, swissknifeseo.com, the Swiss Knife SEO application at swissknifeseo.ai, related support, and the Crawliq crawler technology inside the product. We operate these services from Sarajevo, Bosnia and Herzegovina, and are the controller of personal data described here.
References to "Crawliq", "Swiss Knife SEO", "we", "us", and "the service" refer to this product and operator. A customer organization may be the controller of data it places in a workspace. In that case, we process that data for the customer to provide the service.
Back to contents2. Information we collect
- Account and identity data. Name, email address, profile image if supplied by an identity provider, hashed password where used, login method, workspace membership, role, plan, preferences, and account security events.
- Project and crawl data. Site addresses, ownership verification state, crawl settings, fetched public page data, links, technical findings, reports, saved filters, keywords, prompts, backlink records, monitor settings, exports, and related workflow history.
- Content you provide. Uploaded files, URLs, briefs, instructions, feedback, generated material you save, and messages or attachments sent to support.
- Technical and usage data. IP address, request time, browser and device information, requested route, response status, session activity, feature events, active time, viewport size, diagnostic records, and error or performance data.
- Billing data. Plan, invoice, transaction status, and business billing details when paid access is available. Payment card details are handled by the payment processor and are not stored on our application servers.
3. Public website data
The public reference and product sites receive ordinary web server and network security logs. These may contain an IP address, user agent, requested path, time, referring page, response status, and security rule result. We use these records to deliver pages, prevent abuse, diagnose faults, and understand aggregate site use.
The public sites offer a Google Analytics control. The Google tag loads on every visit, but until the visitor accepts it runs with storage denied: it sets no cookies and stores nothing on the device. Whether or not it is accepted, we send normalized page paths without query strings, page titles, device and browser information, and ordinary engagement events. Only acceptance permits analytics cookies. Advertising storage, advertising personalization, and Google signals remain disabled in both states.
Back to contents4. Google sign in and Google API data
Google sign in and project data connections are separate. Using Google to sign in does not automatically connect Google Analytics or Search Console. A user must start each connection, review the Google consent screen, select an account, and choose the relevant property.
| Feature | Permission or data | What the service does |
|---|---|---|
| Google sign in | openid, email, profile | Confirms identity and supplies the name, email address, and profile image associated with the selected Google Account. |
| Google Analytics 4 | analytics.readonly | Lists Analytics properties the user may access and reads selected traffic, acquisition, page, and engagement reports for the connected project. The service cannot edit Analytics properties. |
| Google Search Console | webmasters.readonly | Lists Search Console properties the user may access and reads selected query, page, country, device, clicks, impressions, click through rate, and average position data. The service cannot edit Search Console properties. |
Google credentials are never requested or stored. OAuth access and refresh tokens are stored in encrypted form. Tokens do not appear in normal pages, reports, exports, support tools, or analytics events.
Back to contents5. How we use Google user data
Google user data is used only to provide or improve user-facing features that the user requests. This includes signing in, selecting a property, displaying reports, joining selected search or analytics metrics to the user's own project evidence, suggesting project terms from selected Search Console data, monitoring requested metrics, and troubleshooting those functions.
We do not sell Google user data. We do not use it for targeted, personalized, interest-based, or retargeted advertising. We do not use it for credit decisions, lending, data brokerage, information resale, or building unrelated databases. We do not use Google user data to train general-purpose AI models or permit a service provider to use it for independent model training.
Crawliq and Swiss Knife SEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Back to contents6. Sharing and disclosure of Google user data
We do not transfer or disclose Google user data except when needed to provide or improve the feature the user requested, protect the service, comply with law, or complete a corporate transaction with the user's legally required consent. Processors may handle the minimum data needed for hosting, secure storage, product troubleshooting, or a user-directed feature. They act under contractual restrictions and may not use the data for their own advertising, resale, profiling, or model training.
Authorized staff or contractors may view specific Google-derived data only when the user asks for support and consents to that access, when access is necessary to investigate abuse or a security incident, or when law requires it. We do not disclose OAuth tokens to support personnel through normal tools.
If a user deliberately starts an AI-assisted feature using a selected term or metric derived from Google data, the minimum selected content needed for that visible feature may be sent to the relevant provider. Google account credentials and OAuth tokens are never sent to AI providers.
Back to contents7. Google connection lifecycle
A Google connection begins only when a signed-in user chooses the relevant connection control. The browser is sent to Google's authorization screen, where Google identifies the requesting application, the selected Google Account, and the permissions requested. The user can approve or cancel. We do not see the user's Google password.
- Authorization. Google returns a short-lived authorization code after consent. The application exchanges it through Google's secure token endpoint.
- Property selection. The application lists only Analytics or Search Console properties the authorized Google identity can access. The user selects the property associated with the Crawliq project.
- Report requests. The application requests the minimum report fields and date range needed for the page or monitor the user opens. Analytics and Search Console remain separate connections.
- Display and project use. Results are displayed inside the user's organization and may be joined to that organization's crawl pages or saved monitoring history.
- Disconnection. Disconnecting stops future Google API requests for that connection and removes the active stored token. Revoking access in Google also prevents future requests.
We do not request permission to edit Analytics, Search Console, advertising accounts, email, files, calendars, contacts, or other Google products. Adding a new scope or a materially different Google use requires an updated consent flow, updated disclosure, and any review Google requires before public use.
Back to contents8. Google data retention and deletion events
Different actions affect connected Google data in different ways. This table explains the practical result.
| User action or event | Immediate result | Stored project data |
|---|---|---|
| Disconnect Analytics or Search Console | The active connection is removed and new API requests stop. | Previously saved report or derived history can remain in the project until the project or workspace is deleted, unless the user asks us to remove it sooner. |
| Revoke from Google Account | Google invalidates provider access. The application can no longer refresh the connection. | Existing project records follow the same project and workspace deletion controls. |
| Delete the connected project | The project, connection, crawl history, and related live report records are removed from the active service. | Residual encrypted backup copies age out within the normal limited backup schedule. |
| Close the workspace or account | After authority is verified, live workspace access and its connected project data are removed. | Only records required for legal, accounting, fraud prevention, or dispute purposes are retained, plus temporary rolling backups. |
| Connection expires or fails | New Google requests stop until the user reconnects. | Existing project history is not silently overwritten by an authorization failure. |
A user who wants both the connection and previously saved Google-derived project history removed should delete the relevant project or send a verified deletion request. Revoking access at Google prevents future access but does not itself instruct every third-party application to delete data already saved under the user's earlier instructions.
Back to contents9. Service providers and other recipients
We use a limited set of processors to operate the service. These include Contabo for European server infrastructure, Cloudflare for network delivery, security, and private object storage, Google Analytics for optional consented public-site measurement, PostHog for product analytics and masked-input session replay through its European endpoint, Sentry for error and performance monitoring with default personal data collection disabled, email infrastructure for service messages, and a payment processor when billing is enabled.
AI and search data providers receive only the public URL, query, prompt, or selected project content required for an action the user starts. Provider availability and the exact provider used may change. We may also disclose information to professional advisers, authorities, or a successor organization when necessary and permitted by law. We do not allow these recipients to use customer data for unrelated purposes.
Processors are selected for a defined operational purpose and receive only the category of information needed for that purpose. Infrastructure providers may process encrypted storage, network requests, logs, and backups. Monitoring providers receive bounded diagnostic or product-use events. Email providers receive the destination address and message needed to deliver an account or support communication. A provider is not permitted to build an advertising profile, resell customer data, or use Google user data for independent product development.
Back to contents10. Cookies, browser storage, and product analytics
The signed-in application uses a secure session cookie to maintain login state and a CSRF cookie to prevent forged requests. Theme preference, the public-site analytics choice, and a random per-tab analytics session identifier may use browser storage. These are not advertising identifiers.
Google Analytics is optional on the public sites and application. The Google tag loads on every visit, but until acceptance it runs with storage denied: it sets no cookies, stores nothing on the device, and cannot recognize a visitor from one visit to the next. After acceptance, Google Analytics may set measurement cookies and receive normalized paths, page titles, standard browser and device characteristics, engagement metrics, and a coarse geographic estimate that Google infers from the connection. Query strings, form values, prompts, API keys, and OAuth tokens are excluded from the configured page location. Advertising storage, advertising personalization, and Google signals remain disabled in both states. We use this measurement for one purpose, understanding in aggregate how people find and use the site so we can improve it. We do not sell it, trade it, or use it for advertising, remarketing, or audience building. Google Analytics is a Google product, so these measurements are sent to Google and processed by Google on our behalf as our processor; Google is the only third party that receives them.
For signed-in non-staff users, product analytics may record normalized application routes, page views, meaningful control clicks, form submission actions, active time, viewport size, and a privacy-masked replay of interface activity. Form inputs are masked. We do not intentionally place prompts, API keys, OAuth tokens, form values, or full URLs with query strings in analytics events. Analytics and replay access is restricted and used to diagnose or improve visible product workflows. Sentry receives error and performance diagnostics, with default personal information transmission disabled.
Analytics is used to answer operational questions such as whether users can find a report, whether a control fails, or where a workflow becomes confusing. It is not used to follow users across unrelated websites, select advertisements, or infer sensitive interests. Visitors can reject Analytics or reopen Privacy choices to change the selection, and a recorded choice is kept for six months before we ask again. Browser privacy settings, script blocking, and local storage clearing may also limit this collection without removing the essential session and security controls needed to sign in.
Back to contents11. Purposes and legal bases
- Contract. To create and operate the account, crawl an authorized site, display reports, run monitors, deliver exports, manage a plan, and answer service requests.
- Legitimate interests. To secure the service, prevent fraud and abuse, diagnose errors, maintain reliability, understand product use, and improve visible workflows without overriding user rights.
- Consent. To connect optional Google or other provider data and for any optional processing that applicable law requires the user to choose.
- Legal obligation. To retain or disclose limited records where tax, accounting, court, regulatory, or security law requires it.
We do not use personal data for solely automated decisions that produce legal or similarly significant effects.
Where more than one legal basis could apply, we use the basis that best matches the specific processing. For example, the user initiates an optional Google connection through consent, while secure token storage and request logging are also necessary to perform and protect the requested service. A user may withdraw consent for the optional connection without closing the underlying account.
Back to contents12. Security safeguards
We use role and organization scoped access controls, encrypted transport, encrypted OAuth and provider tokens at rest, secure session cookies, production security headers, private object storage with expiring signed access, guarded network requests, backups, logging, and monitoring. Customer records are resolved through the active workspace before they are displayed or changed.
Google OAuth tokens are encrypted with a dedicated application encryption key that is separate from the database records containing the encrypted values. Tokens are excluded from ordinary pages, customer exports, logs, analytics events, and routine administration lists. Private report artifacts use short-lived signed access rather than permanent public URLs.
No online service can promise absolute security. Users must protect passwords and recovery methods, keep workspace membership current, and avoid sending secrets by email. If a personal data incident requires notice under applicable law, we will notify affected users and authorities as required.
Back to contents13. General retention, disconnection, and deletion
- Account and workspace data. Kept while the account is active and as needed to provide saved history, reports, monitors, and plan administration. Deleting a site removes its crawl and report data from the live workspace. Closing an account removes the workspace from the live service after ownership is verified.
- Google tokens. Kept only while the related connection remains active. Disconnecting removes the stored connection and stops new API requests. Users can also revoke access from the Google Account connections page.
- Google report data. Read on request and stored or cached only where needed for the selected report, history, monitor, or project feature. Saved Google-derived project data is removed when the related project or workspace is deleted, subject to short-lived backups and legal obligations.
- Logs and diagnostics. Kept only as long as needed for security, fault investigation, service operation, and applicable legal requirements.
- Support and billing records. Kept while the request or commercial relationship remains relevant and longer where accounting or legal rules require it.
- Backups. Deleted live data may remain in encrypted rolling backups for a limited recovery period and ages out within a few weeks under the normal backup schedule. Backups are not used as an active data source.
We review retention by purpose rather than keeping every record for one universal period. When the purpose ends, we delete, deidentify, or restrict the record unless a legal or security reason requires limited retention. Restricted records are not returned to normal product use.
Back to contents14. International data transfers
Core application hosting and product analytics are configured in Europe. Some providers or their support operations may process information in other countries, including the United States. Where data-protection law requires it, transfers rely on an adequacy decision, standard contractual clauses, contractual processor obligations, or another lawful safeguard.
A user's Google Account and the connected Google property may already be administered or hosted in another region under the customer's agreement with Google. Our transfer safeguards apply to the processing we control after Google supplies authorized data to the service.
Back to contents15. Your rights and controls
Depending on location, a user may have rights to access, correct, delete, restrict, or object to processing, receive a portable copy, withdraw consent, and complain to a data-protection authority. Withdrawing consent does not affect processing completed before withdrawal.
Users can edit projects and settings, export crawl data, disconnect integrations, revoke Google access, leave a workspace where allowed, or request account closure. To make a privacy request, email info@swissknifeseo.com from the account address and describe the request. We may ask for reasonable identity or authority verification. Never email a password, OAuth token, API key, recovery code, or payment card number.
We will acknowledge a verified request, explain any additional information needed, and respond within the period required by applicable law. If we cannot complete all or part of a request, we will explain the applicable reason where the law allows. Account exports can provide project data, but another person's confidential information, security records, and legally protected material may be limited or removed.
Back to contents16. Customer organizations and data-subject requests
When a business customer decides which sites, users, files, or other personal data to place in its workspace, that customer normally acts as the controller for that material and we act as its processor. The customer must provide notices, obtain permissions, respect objections, and avoid placing unnecessary personal data in the service.
If a person contacts us about data controlled by a customer organization, we may direct the request to that organization and support its verified response. We will not give one workspace member another person's account data merely because they belong to the same company. Workspace roles and proof of authority still apply.
Back to contents17. Service communications, external links, and provider notices
We send transactional messages needed for account security, invitations, password recovery, requested reports, enabled monitors, billing, legal notices, and support. A user can turn off optional reports or digests where the application provides a control, but cannot opt out of messages needed to secure or administer an active account.
The public sites and application link to Google, service providers, documentation, and other external websites. Their privacy practices are controlled by their operators. Following an external link does not give that operator access to a Crawliq workspace unless the user separately authorizes a connection or sends information to it.
Back to contents18. Children and business data
The service is intended for business and professional use and is not directed to anyone under 16. We do not knowingly collect personal data from children. If a parent or guardian believes a child supplied data, contact us so we can review and remove it.
Customers must have a lawful basis and necessary permission for personal data they place in a workspace. Crawling or uploading personal data from a third-party site does not transfer responsibility for that source data to us.
Back to contents19. Policy interpretation and changes
This policy is intended to describe actual product behavior in clear language. Examples explain typical processing but do not expand the permissions requested from Google or create a right to use data for a purpose not disclosed here. If an in-product notice for a specific feature gives more restrictive instructions, the more restrictive notice applies to that feature.
We may update this policy when the service, providers, or legal requirements change. The date at the top will change, and material changes affecting account holders will be communicated through the service or by email where appropriate. The published version applies from its stated effective date. We will not apply a materially broader Google data use before updating the disclosure, consent flow, and any provider review required for that use.
Back to contents20. Operator identity, privacy contact, and complaints
We operate Crawliq and Swiss Knife SEO from Sarajevo, Bosnia and Herzegovina. Privacy questions, rights requests, Google data questions, and complaints can be sent to info@swissknifeseo.com. Operator correspondence may also be sent to sanikaric@ymail.com.
Include the account email, affected workspace or site, and the specific action requested. Do not include credentials or full confidential reports. We may ask the workspace owner or account holder to confirm authority before disclosing or deleting data. Postal correspondence may be addressed to us in Sarajevo, Bosnia and Herzegovina.
Users in the European Economic Area or United Kingdom may also complain to the supervisory authority in their place of residence or work. Contacting us first can help resolve an account-specific issue, but it does not remove the right to contact an authority.
Back to contentsPrivacy questions and requests
Contact the service operator directly
Email us for access, correction, deletion, Google connection, or data-handling questions. Never send a password, token, recovery code, or payment card number.