Legal

Privacy Policy

Last updated August 2, 2026. Plain language, describing what Ascent actually does with your data.

What this covers

  • This policy covers Ascent (the "Service"), operated to provide autonomous SEO, AEO, and GEO content generation and publishing for a customer's own website.
  • It does not cover the content of pages the Service publishes to a customer's site, or that customer's own privacy policy toward their visitors.

Information we collect

  • Account information: your name and email address, provided directly or through Google or GitHub sign-in.
  • Site and business information you provide during onboarding: your website URL, business name, phone, address, service area, industry, and services offered. Used to research keywords and write pages that describe your business accurately.
  • Publishing credentials for the platform you connect: a WordPress application password, or a GitHub personal access token and repository name. These are encrypted (AES-256-GCM) before being stored and are only decrypted at the moment a page is published.
  • OAuth tokens from Google (sign-in, and optionally Search Console read access) and GitHub (sign-in, and repository publish access), stored encrypted the same way.
  • Billing information when you subscribe: Stripe processes payment details directly. We store your Stripe customer ID and subscription status, never your card number.
  • Usage data the Service generates on your behalf: keywords researched, pages drafted and published, audit scores, and run history for your site.

How we use it

  • To research your market, generate pages, and publish them to your connected site on the schedule you choose.
  • To authenticate you and keep your account secure.
  • To show you what the agent has done and is planning to do, in the dashboard.
  • To process billing through Stripe and keep your subscription status current.
  • To read Search Console performance data for your own site, only if you explicitly connect it — this is read-only and scoped to your account.
  • We do not sell personal information, and we do not use your business data to train AI models beyond what a third-party provider (see below) does to generate a single response to a single request.

Third parties we send data to

  • Google — for sign-in, and if you connect it, read-only Search Console data for your own site.
  • GitHub — for sign-in, and to publish pages to a repository you explicitly connect.
  • Google Gemini — receives your business details and target keywords to draft page content. This is a live API call per page; content is not used by us to train models.
  • Stripe — processes subscription payments. We never receive or store your card number.
  • WordPress (your own site) — if you connect a WordPress site, published pages are sent directly to your site's REST API using the application password you provide.
  • We do not share your data with data brokers or advertising networks.

Google user data

  • Signing in with Google gives Ascent your name, email address and profile picture, used only to create and authenticate your account.
  • Connecting Search Console is optional and separate from signing in. It requests one scope, https://www.googleapis.com/auth/webmasters.readonly, which is read-only: it cannot change, publish to, or delete anything in your Search Console account.
  • What we access with it: impressions, clicks, average position and the queries your own verified properties rank for. What we do with it: show your rankings in your dashboard, and let the agent prioritise keywords where you already have traction. Nothing else.
  • How it is stored: the refresh token is encrypted (AES-256-GCM) at rest and decrypted in memory only when fetching your data. Performance data is stored against your account and is readable only by your account.
  • Who it is shared with: nobody. Search Console data is never sold, never shared with advertisers or data brokers, never used for advertising, and never sent to an AI model — including the Gemini calls that draft your pages.
  • How to revoke it: disconnect Search Console from your dashboard at any time, which deletes our stored token, or revoke access directly at myaccount.google.com/permissions.
  • Ascent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies

  • We set one cookie: a signed, httpOnly session cookie that keeps you logged in. It cannot be read by scripts in your browser.
  • We do not use advertising, tracking, or third-party analytics cookies, and there is nothing here to opt out of because there is no cross-site tracking to disable.
  • Theme and which website you are viewing are stored in your browser's local storage, not sent to us.

How long we keep it

  • Account, site and page data is kept while your account is open, so the agent can build on its own history rather than restarting each cycle.
  • Publishing credentials and OAuth tokens are deleted when you disconnect the service they belong to.
  • On account deletion we remove your account, site configuration, credentials and generated page records within 30 days. Pages already published to your own site are yours and are unaffected.
  • Billing records are retained as long as tax and accounting law requires, which is separate from account deletion.

How we store and protect it

  • Publishing credentials and OAuth refresh tokens are encrypted at rest (AES-256-GCM) and only decrypted in memory at the moment they are used.
  • Passwords for email accounts are hashed (scrypt), never stored in plain text.
  • Sessions are authenticated with a signed, httpOnly cookie; it cannot be read or modified by scripts running in your browser.
  • Access to your site's data is scoped to your account at the database level — no cross-account access exists in the product.

Your choices

  • You can disconnect WordPress, GitHub or Search Console at any time from Settings in your dashboard. For Search Console this revokes the token at Google as well as deleting it here.
  • You can delete your account and everything stored with it from Settings in your dashboard. It is immediate and cannot be undone; your subscription is cancelled at the same time. Pages already published to your live site are yours and are not affected.
  • You can cancel your subscription at any time; published pages remain on your site.

Changes to this policy

  • We will update this page if how Ascent handles data changes, and update the date below when we do.

Contact

  • Questions about this policy, requests to access or delete your data, and privacy complaints: toolascent@gmail.com. A person reads it.