Privacy policy

This policy covers SEO Agent 1 Backup Runtime, operated by Mathieu Mariole, and these public information pages. It does not describe every other tool in the SEO system. Last updated 24 September 2026.

Data accessed and why

The app accesses the authorized Google account's email address to confirm the expected owner. It reads identifiers, names, parent relationships, ownership, sharing permissions and capabilities for the designated backup location and required ancestors. It reads metadata for backup files and downloads encrypted backups to confirm the remote bytes match the local archive.

The OAuth permission is drive.file: access to files created by or explicitly authorized for this app. This is not a metadata-only permission. Although the scope permits operations on app-authorized objects, the backup implementation does not modify sharing or automatically overwrite or delete files. It does not scan unrelated Drive content.

Backup data and storage

Local backups include a SQLite measurement journal, saved source captures and a manifest of hashes and backup context. These can contain business identifiers, website URLs, search queries, performance metrics, timestamps, coverage and publication records. The initial recovery archive also contained selected recovery software and nonsecret configuration.

Plaintext source data and intermediate archives remain locally accessible to the owner. The app encrypts archive content locally with age before uploading it to Google Drive. Only ciphertext is uploaded as file content; Google also receives ordinary file metadata such as filename, size and timestamps, and standard API request information. OAuth tokens, private recovery keys, browser sessions and unrelated source-material libraries are not part of the intended backup package.

Credentials and recovery

Runtime OAuth credentials are stored separately in owner-only local files and used to refresh access without sending the Google password to the app. The recovery key is separately held by the owner in LastPass. The backup uploader uses the public encryption recipient and does not need the private recovery key. The owner controls access to the vault and devices.

Sharing and use

The app uses Google user data only to provide and secure backup and recovery. It does not sell that data, use it for advertising, or send it to AI models for training. Google hosts the encrypted files. Authorized operator access and recovery take place on owner-controlled devices. LastPass holds the recovery key at the owner's direction; it does not receive backup contents from this app.

SEO Agent 1 Backup Runtime's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Retention, revocation and deletion

There is no automatic backup-pruning schedule. Local evidence and encrypted Drive backups are retained until the owner deliberately removes them. Revoking the app through Google Account connections stops future authorized access but does not delete existing local or Drive copies. The owner can delete those copies separately and manage Drive trash under Google's retention controls. Loss or deletion of the recovery key may make retained ciphertext unrecoverable.

Information-site hosting

These static pages contain no login form, analytics scripts, advertising or application cookies. The hosting provider is Vercel, which processes ordinary connection information such as IP address, requested URL and browser information to serve and protect the site. These pages do not access Google Drive or receive recovery keys.

Changes and contact

Material changes to data access or use will be described here before adoption and will require any applicable authorization. Contact the operator using the address below for privacy or deletion questions.