Features Pricing Demo About Contact Documentation Log in
Get started
Home/Trust center
One page, no PDF email thread

Your data,
handled calmly.

SEO & Chill is built on a simple promise: your content flows directly between your server and the AI provider you choose. We are never in that path. This page shows exactly what data goes where, who our subprocessors are, and how the platform is secured. Everything an agency, DPO or EU buyer needs, public and linkable.

The data flow

What leaves your site: and what never does.

Goes to your AI provider

Only when you run an AI action, directly from your server, under your own API agreement:

  • The content excerpts you choose to optimize
  • Your prompts and settings (tone, length, keyword)
  • Sent with your own API key. Identical for all 10 providers

Never comes to us

SEO & Chill servers are not a proxy. We never receive:

  • Your site content, drafts or media
  • Your API keys. Encrypted in your own database
  • Your visitors’ personal data
OpenAIAnthropic ClaudeGoogle GeminiDeepSeekMistral AIGroqxAI GrokOpenRouterMoonshot KimiLocal. Ollama & LM Studio
All 10 providers, one plugin. Connect your own key and switch anytime.

The license API receives exactly four things: license key, activated domain, plugin version, activation status. Details per provider are in each provider’s own policy. You choose who you trust with your content.

Security practices

Boring by design. That’s the point.

Encrypted keys, on your server

API keys are encrypted at rest with AES-256-CBC in your own database. Decryption happens only on your server, only to call your provider.

Hardened plugin architecture

Every admin action is guarded by WordPress capability checks and nonces; database interactions use prepared statements; file integrity is verified on update.

Fail-open licensing

License checks are signed and cached. If our API is ever unreachable, your plugin keeps working for a 14+ day grace window. Your SEO never depends on our uptime.

Isolated infrastructure

Marketing, documentation and the customer portal run as separate installs. The portal. The only system with customer data. Sits behind a WAF with mandatory 2FA for all admin users.

Backups & recovery

All systems are backed up daily to off-site storage, with tested restores.

Minimal data by design

Cookieless analytics, no ad trackers, and a license API that receives a domain and a version number. Not your content.

Subprocessors

Who we work with.

SubprocessorPurposeLocationData involved
StripePayments, billing, invoicing, taxUSA / EUCard data never touches our servers
CloudflareCDN, DNS, WAF and edge cachingGlobal (EU data residency)Traffic protection for site and API
PostmarkTransactional email (receipts, licenses)USAName and email address only
KlaviyoNewsletter delivery & list managementUSA (EU-U.S. DPF certified)Email address of newsletter subscribers only
Help ScoutCustomer support conversationsUSAWhat you share in a ticket
PlausibleWebsite analyticsEUCookieless, no personal data
InstatusPublic status pageUSANo customer data

AI providers you connect yourself (OpenAI, Anthropic, Google, and the rest of the ten) are your own processors under your own agreements. Not our subprocessors. We announce subprocessor changes on this page before they take effect.

DPA included: no signature needed.

Our Data Processing Addendum is public and automatically forms part of your agreement the moment you purchase. Electronic acceptance is how Art. 28 GDPR contracts work for SaaS. For audits or client files, the public DPA together with your order confirmation is all the evidence you need.

FAQ

Questions, answered calmly.

Your content goes directly from your server to the AI provider you connected, under your own API agreement with that provider. We are never in that data path. Whether a provider trains on API traffic is governed by their terms; most major providers do not train on API data by default, but verify this in your provider’s policy.

No. Keys are stored in your own WordPress database, encrypted with AES-256-CBC, and are only ever sent to the provider they belong to. They are never transmitted to SEO & Chill servers.

The minimum needed to validate a license: your license key, the domain it’s activated on, the plugin version and activation status. No site content, no analytics, no personal data of your visitors.

There is nothing to sign. And nothing missing. The Data Processing Addendum is public and automatically forms part of the Terms for every customer, which satisfies Art. 28 GDPR. If your auditor or client asks, point them to the public DPA plus your order confirmation.

Everything the plugin created. Meta, redirects, schema settings. Lives in your WordPress database and stays there. On our side, license and billing records are retained only as long as legally required, then deleted.

Calm software. Calm compliance.

Everything on this page is one link. Send it to your DPO and get back to ranking.

Get started
14-day refund policy · Cancel anytime · No exit popups, ever