Skip to main content
SearchProof AI
Back to service
PRIVACY POLICY

Privacy Policy

Explains account, analysis, public-web, AI, and billing data processed by the service and user rights.

Effective date August 10, 2026Version 2.3
Terms of ServicePrivacy PolicyBilling and Refund PolicyCrawler and Data Collection Guide

Operator information

Service name
SearchProof AI
Operator
PKL Labs
Business registration number
416-48-01278
Business address
135 Daeho-ro, Osan-si, Gyeonggi-do, Republic of Korea
Support and privacy contact
support@searchproofai.com

1. Controller and contact point

PKL Labs operates SearchProof AI and acts as the data controller. Its business name, business registration number, and address are published in the operator information above. Privacy and data-rights requests are accepted and handled through the official support channel provided by the service.

The privacy function is handled by PKL Labs Customer & Privacy Support. Privacy inquiries, rights requests, and incident reports may be sent to support@searchproofai.com. Only the minimum information needed to verify the requester or representative is requested, and privacy-rights requests are handled separately from ordinary support.

2. Data processed and purposes

  • Account: name, email, one-way password hash, and email-verification status — registration, sign-in, account management, and important notices
  • Security/access: IP, user agent, request ID, login/token/audit events — sessions, abuse prevention, troubleshooting, and incident investigation
  • Analysis input: domain, country, language, search engine, time zone, queries, brand, products/services, audience, and competitors — profile setup and analysis
  • Public web/results: URLs, status, title/body/metadata/links/structured data, HTML evidence, performance values, scores, findings, and reports — audit, reproducibility, comparison, and delivery
  • AI observations: query, model/channel, response, citation URLs, mention/recommendation verdicts, errors, and latency — GEO visibility measurement and quality review
  • Billing: Paddle customer/subscription/transaction IDs, email, status, product/price IDs, amount/currency, period, and refund events — access, reconciliation, refunds, and statutory records. Paddle handles card numbers and CVC; they are not stored on service servers.
  • Support: contact email, subject, message, and handling history — support, rights requests, and disputes
  • Google sign-in: Google provider identifier (sub), email, name, email-verification status, link status, and last sign-in — social account creation, linking, and authentication
  • Contract evidence: applicable Terms and Privacy Policy versions, confirmation time, registration route, language, IP, and user agent — contract formation, notice compliance, and dispute handling

3. Collection methods, sources, and necessity

Data is entered during registration, setup, or support; generated during use; collected from public websites requested by users; or received from Paddle webhooks and connected Google, PageSpeed, AI, and other APIs. Required account, security, and billing data is necessary for the relevant feature. Optional brand, audience, and competitor data may be omitted, though accuracy or features may be limited. Personal data incidentally present on public pages is not separately extracted for person profiling or marketing lists.

4. Purposes and legal bases

Account, analysis, billing, and support processing is necessary to enter into and perform the contract; security and abuse prevention rely on legitimate interests of the operator and users; optional marketing and cross-border transfers where legally required rely on consent; tax, e-commerce records, and lawful authority requests rely on legal obligations. Legal-basis terminology varies by jurisdiction. Consent may be withdrawn without affecting prior lawful processing.

5. Retention periods

  • Guest audits and HTML evidence: records older than seven days are removed by a daily cleanup job; a short delay may occur because of backlog or deletion retries. If saved to an account, the member-analysis standard applies.
  • Account, analyses, and reports: until account deletion. After an account-deletion request, deletion begins except for statutory records; permanent deletion of an individual analysis will be announced if and when that feature is available.
  • Contract/withdrawal and payment/supply records: 5 years
  • Consumer complaint/dispute records: 3 years; advertising records: 6 months
  • Security/access/audit logs: retained for the minimum period needed for abuse prevention, troubleshooting, and security investigations, then deleted; statutory retention applies where required
  • Backups: segregated from operational data and access, then overwritten or deleted on a regular rotation

6. Processors, third parties, and international transfers

The service does not sell personal data. Operations may use hosting/database, email, error monitoring, Paddle billing, Gabia AI Hub, and selected AI model channels. Processors and recipients receive only the minimum information necessary to provide the service and are subject to contractual, access-control, retention, and deletion requirements. Payment data entered directly in Paddle Checkout is processed by Paddle under its policies and Buyer Terms. No third-party disclosure occurs except under law, separate consent, or urgent life/safety necessity.

International transfers occur over encrypted connections when the relevant feature is used, based on processing or storage necessary to perform the contract or on separate consent. Users may refuse feature-specific transfers by not using Google sign-in, Paddle billing, or external AI and may withdraw optional consent through support. For Google Ads measurement, advertising storage, advertising user data, advertising personalization, and analytics storage default to denied in the EEA, United Kingdom, and Switzerland; the tag does not run on pages containing verification or password-reset tokens. A feature for which a transfer is essential may be unavailable; available alternatives such as email registration or a free SEO audit without external AI will be explained.

  • Amazon Web Services Korea (South Korea): service and database hosting. Account, access/security, analysis, public-web evidence, results, and billing identifiers are processed during use and retained under account-deletion and statutory-retention rules.
  • Spaceship/SpaceMail (United States): registration, security, report, and support email delivery. Email address, name, subject/body, and one-time links are processed when sent. SearchProof AI keeps support/dispute records for up to three years; provider technical logs follow its contract and policy.
  • Google LLC and affiliated facilities (including the United States): Google sign-in sends provider ID, email, name, and verification status; PageSpeed sends the public target URL; Google Ads conversion measurement may send the page URL, referrer, browser and device information, advertising click identifiers, and conversion interactions over HTTPS. Purposes are identity verification, public-page performance measurement, and advertising conversion measurement. Google’s own retention follows its applicable policies.
  • The Paddle seller entity shown on the transaction confirmation and its processors (including the UK, United States, EU, and Canada): checkout data, email, customer/subscription/transaction/refund IDs, product, amount/currency, and status are processed at checkout and by webhook. Paddle’s card data and own records follow the Buyer Terms and Privacy Notice applicable to the transaction; SearchProof AI keeps e-commerce records for up to five years.
  • Gabia AI Hub (South Korea) and selected model providers such as OpenAI, Google, Perplexity, Anthropic, and xAI (primarily United States): deep analysis or setup enhancement sends queries, domain, brand/service/competitor descriptions, and limited public-web context by HTTPS API to generate AI observations and summaries. SearchProof AI retains responses and model/error records until the analysis is deleted; temporary retention by gateway/model providers depends on the selected model and then-current contract and policy.

7. AI inputs and automated decisions

When deep analysis or setup enhancement is enabled, queries, brand/service descriptions, competitor domains, and limited public-web context may be sent through Gabia AI Hub to selected models. Do not submit passwords, payment data, sensitive data, or private customer information. Inputs are minimized, and responses, errors, and model details may be stored in analysis records. AI results inform recommendations and priorities and are not used for solely automated decisions producing legal or similarly significant effects.

Without separate opt-in consent, the operator does not use user inputs or private results to train its own general-purpose foundation model or sell a data product. A model provider’s retention or training use of inputs and outputs follows the enterprise API contract and policy applicable to the selected model. Inaccurate or inappropriate output, suspected personal data, or an objection to automated processing may be reported to support@searchproofai.com; relevant source, model, and transfer records will be reviewed and available deletion, correction, or re-run options explained.

8. Cookies, browser storage, and automatic collection

Browser localStorage may contain access/refresh tokens, account email, selected language, recent domain, active scan ID, and a draft analysis configuration including domain, brand, product, audience, and competitors. sessionStorage may contain a recent checkout intent, selected product/price, and creation time. These support sign-in, draft recovery, and checkout return. Signing out removes authentication tokens, but drafts and the recent domain may remain; account deletion cannot automatically erase storage on a device, so users on shared devices should clear browser data. Blocking or deletion may sign the user out or limit recovery. Google Ads conversion measurement uses the Google tag (AW-17578495277). Page URL, referrer, browser and device information, advertising click identifiers, and conversion interactions may be sent to Google. In the EEA, United Kingdom, and Switzerland, Consent Mode v2 defaults advertising storage, advertising user data, advertising personalization, and analytics storage to denied; the tag does not run on pages containing verification or password-reset tokens.

9. User rights and how to exercise them

Subject to applicable law, users may request access, copies/portability, correction, deletion, restriction/objection, withdrawal of consent, and review. Use JSON export and account deletion in the account screen or the official privacy channel. Identity and authority are verified minimally, and responses are provided without undue delay within legal deadlines. If statutory retention, others’ rights, security, or manifestly excessive/repetitive requests justify limits, the reason and appeal route will be explained.

The in-account JSON export is a workspace summary of the account, profiles, analyses, and reports; it is not a complete statutory access copy of all security, audit, billing, or social-link records. Requests for other personal data, copies, sources, or processing history may be sent to support@searchproofai.com.

10. Deletion, security, and incident response

When purposes or periods end, database records and stored HTML are deleted so recovery is impracticable; statutory records are segregated and blocked from unrelated use. Controls include one-way password hashing, token expiry/rotation, role-based access, login throttling, transport encryption, audit logs, secret separation, backups, vulnerability checks, and SSRF/redirect defenses. Incidents trigger containment, investigation, recovery, evidence preservation, and notices to authorities and individuals where legally required.

11. Children, remedies, and policy changes

The service is for businesses and professionals and is not directed to children under 14. Known child data will be deleted after any required guardian verification. Users may seek help from the operator’s official channel and competent privacy or dispute authorities. Material changes to data, processors, transfers, retention, or rights will be announced comparably before effect; required consent will be obtained and prior versions retained.

Ordinary policy changes are normally announced seven days in advance; materially adverse changes to purposes, data, processors, transfers, retention, or rights are announced 30 days in advance with a comparison and effective date. Processing that requires consent is offered separately, and silence or continued use is not treated as consent.

Related standards and external policies

Linked documents may be updated by their operators, and mandatory law prevails over this document.

  • Korean Personal Information Protection Act, Article 30
  • Paddle Privacy Notice
  • PIPA Article 28-8 (international transfers)
  • PIPC Privacy Policy Guidance
  • Google Privacy Policy
SearchProof AI
Terms of ServicePrivacy PolicyBilling and Refund PolicyCrawler and Data Collection Guide

© 2026 PKL Labs. All rights reserved.

SearchProof AI operator · Business Registration No. 416-48-01278 · 135 Daeho-ro, Osan-si, Gyeonggi-do, Republic of Korea · support@searchproofai.com