How Bisibility handles your data on Cloud, and what stays on your own server when you self-host.
Bisibility is open-source, self-hostable SEO observability with an optional hosted cloud service. This policy explains what data is handled when you use the hosted service, the public website, and the open-source product.
When you self-host Bisibility, your app, database, provider credentials, keyword data, rank history, and audit records stay on infrastructure you operate. Bisibility does not receive that self-hosted data unless you choose to send it to us, such as by contacting support or importing a self-hosted workspace into Cloud.
We collect the data needed to run an SEO observability workspace, authenticate users, secure the service, and respond to requests.
We use data to provide the product: sign users in, show workspaces, run rank checks, call the providers you connect, calculate keyword history, expose exports and API responses, send requested emails, and keep audit records for sensitive actions.
We also use data to protect the service, troubleshoot failures, enforce rate limits and permissions, communicate about the service, process hosted-service payments through a payment processor, and comply with legal obligations.
Where data-protection laws such as the GDPR apply, we rely on the legal bases of performing our contract with you, our legitimate interests in operating, securing, and improving the service, compliance with legal obligations, and your consent where the law requires it.
In a self-hosted deployment, Bisibility has zero subprocessors for your workspace data because the data stays on infrastructure you choose and operate. Your database, Redis or Valkey instance, Temporal worker, email provider, analytics choices, backups, and access controls are controlled by you or your organization.
For the hosted cloud service, workspace data is stored and processed in the hosted environment used to provide your workspace. If you import from self-host to Cloud, that import is an action you initiate and authorize.
Bisibility is bring-your-own-provider software. Rank checks and analytics imports use the provider accounts you connect. Provider billing and provider terms are between you and that provider; Bisibility does not resell provider data.
For self-hosted installs, any subprocessors are the services you configure. For the hosted service, we use subprocessors only as needed to operate the service, such as hosting, email delivery, payment processing, error and performance monitoring, security, and support. Resend may be used for email delivery, and Sentry for error and performance monitoring. Connected BYO providers receive the data needed for the checks or imports you request.
If you connect Google Search Console or Google Analytics 4 to a project, Bisibility accesses Google user data through Google APIs using the OAuth scopes you approve on the Google consent screen. Bisibility's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
In a self-hosted deployment, Google user data flows only to infrastructure you operate and Bisibility does not receive it. The statements below describe the hosted cloud service.
Bisibility uses cookies that are necessary for the app to work, including authentication session cookies, a short-lived signed session cache, active-project selection, theme and interface preferences, and temporary OAuth state cookies when you connect supported integrations.
The public marketing site does not currently load a marketing analytics script. If we add privacy-friendly, cookieless analytics, we will update this policy before relying on it. Self-hosted operators may add their own analytics and cookie notices for their deployments.
Account, project, keyword, provider-connection, API-key, and rank-history data is kept while the account or project exists, unless you delete it sooner or we need to keep limited records for legal, security, or dispute reasons.
Audit logs are automatically purged by the maintenance workflow after the configured retention window. The default window is 365 days, and self-hosted operators can configure it with AUDIT_RETENTION_DAYS within the supported range of 1 to 3650 days. Expired sessions and verification records are also purged by maintenance.
You can access and export rank data through CSV, JSON, XLSX, and the REST API. You can update account and workspace data in the app, rotate provider credentials, revoke API keys, and delete projects from the settings danger zone. Account deletion is available from the account danger zone.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection. For hosted-service requests, contact [email protected]. For a self-hosted deployment operated by someone else, contact that operator because they control the data.
Provider credentials are encrypted before storage and decrypted only when needed for a provider call or connection test. API keys are stored as hashes, audit logs redact sensitive fields, and role-based access control limits who can read, change, or delete project resources.
No system is perfectly secure. You are responsible for protecting your own account, API keys, provider credentials, and self-hosted infrastructure. Please report vulnerabilities to [email protected].
If you use the hosted service, your data may be processed from locations where we or our subprocessors operate, as needed to provide and secure the service. If you connect a BYO provider, that provider may process data under its own terms and transfer rules.
If you self-host, Bisibility does not transfer your workspace data. Any transfer depends on the infrastructure, providers, backups, and support processes you choose.
Bisibility is not directed to children and is intended for professional or organizational use. We do not knowingly collect personal data from children under 13 or the equivalent minimum age in their location.
We may update this policy as the product, hosted service, or legal requirements change. When changes are material, we will update the date on this page and provide reasonable notice through the service or another appropriate channel.
For privacy questions, rights requests, or data-processing questions about the hosted service, contact [email protected]. Security reports should go to [email protected].