Privacy Policy

Last updated: 13 August 2026

Snova is an SEO and AEO platform that helps businesses create content that ranks in Google Search and gets recommended by AI assistants. This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it.

It also describes, in Section 5, exactly how we handle data we access from Google Search Console on your behalf.

1. Who we are

Snova AB (“Snova”, “we”, “us”) is the data controller responsible for the personal data described in this policy.

We are established in Sweden, so our processing of personal data is governed by the EU General Data Protection Regulation (GDPR) and Swedish data protection law.

2. Scope of this policy

This policy covers our website at www.trysnova.com, the Snova application, and the shareable client reports we generate. It applies to visitors to our website, people who create a Snova account, and people whose details appear in a customer’s workspace.

Where a customer uses Snova to process data about their own end users, the customer is the data controller and Snova acts as a data processor on their instructions.

3. Data we collect

When you visit our website

Our hosting provider processes standard server and connection data (IP address, browser type, pages requested, timestamps) to deliver and secure the site. We also use Google Tag Manager for analytics — see Section 9.

When you create an account

  • Name, email address and password (stored only as a salted hash — we never store your password in readable form).
  • Optional profile details you choose to add, such as display name, avatar, phone number and bio.
  • Organisation and team membership, including invitations you send or accept.

When you use the product

  • The websites, domains and brand profiles you add, together with the keywords, competitors, topics and context documents you configure.
  • Content you generate or edit in Snova — articles, outlines, calendars, briefs — and the events attached to them, such as when a piece was published.
  • The text of pages already published on your website. So we can measure and improve content you wrote before using Snova, we retrieve those pages the same way a search engine would and store their text alongside the rest of your library.
  • Performance and visibility data we retrieve on your behalf from Google Search Console and third-party SEO data providers.
  • Publicly available information about other websites, including your competitors and sites that link to them, used to produce competitor analysis and link-building suggestions. This is business information about organisations, retrieved from third-party SEO data providers, and we do not seek out personal contact details.
  • Credentials you supply to connect a CMS (for example WordPress, Webflow or Framer) or Google Search Console. These are always encrypted before storage — see Section 12.
  • Prompts, chat messages and feedback you submit to our AI features.
  • Product usage and diagnostic logs used to operate, debug and improve the service.

When you pay for a subscription

Billing is handled by our payment providers. We receive subscription status, plan and invoice metadata. We never receive or store your full card number — card details are collected directly by Stripe.

When you contact us

If you email us, book a demo or use in-app support, we process the contact details and the contents of your message so we can respond.

4. How we use your data

  • To provide, operate and secure the Snova platform and your account.
  • To generate content, audits, keyword research, performance reports and AI-visibility insights that you request.
  • To produce prioritised recommendations, a growth roadmap and link-building suggestions for your site, and to draft outreach messages for you to review and send yourself. We do not send outreach on your behalf.
  • To connect and synchronise the third-party services you authorise, such as Google Search Console or your CMS.
  • To process payments, manage subscriptions and prevent abuse of usage limits.
  • To provide customer support and respond to your enquiries.
  • To send service messages (for example a report being ready) and, where you have opted in, product updates.
  • To improve reliability and product quality using aggregated and diagnostic information.
  • To comply with legal obligations, such as accounting and tax requirements.

5. Google user data (Google Search Console)

Snova offers an optional integration with Google Search Console so that your reports can show measured search performance instead of estimates. This section describes exactly how we access, use, store, share, protect and delete Google user data. Connecting Google is entirely optional and the rest of Snova works without it.

What we request

When you connect Google Search Console, we ask for the following OAuth scopes and nothing more:

  • openid and email — to identify which Google account was connected, so you can see it in your settings and reconnect the right account later.
  • https://www.googleapis.com/auth/webmasters.readonly — read-only access to your Search Console properties and their search performance data.

What we access

  • The list of Search Console properties available to the connected account, so you can select which one belongs to the site you are tracking.
  • The email address of the connected Google account.
  • Search Analytics data for the selected property: clicks, impressions, click-through rate and average position, broken down by page, search query and date.

The scope is read-only. Snova never writes to, modifies, or submits anything to your Search Console property.

How we use it

Google Search Console data is used solely to provide the features you asked for: showing how your published articles perform in Google Search, attributing clicks and impressions to individual articles, identifying the keywords your content ranks for, and producing the client reports you generate and share.

How we store and protect it

  • Your Google refresh token is encrypted with AES-256-GCM before it is written to our database. It is never stored in readable form.
  • Short-lived access tokens are requested on demand and held only in memory — they are never written to our database.
  • Retrieved performance data is cached and stored in our database so reports load quickly and historical trends remain accurate over time.
  • All data is transmitted over TLS and access is restricted to the systems and personnel that need it to operate the service.

How we share it

We do not sell Google user data and we do not share it with third parties for their own purposes. Search Console figures appear in the client reports you choose to create, and if you share a report link, the performance figures in it are visible to anyone who has that link — see Section 10.

How to disconnect and delete it

You can disconnect Google Search Console at any time from Settings → Domains in Snova, which deletes the stored refresh token and stops all further access. You can also revoke Snova’s access directly from your Google Account permissions page. On disconnection we delete the stored credential; performance data already used in reports you generated is deleted when you delete those reports or your account.

6. Limited Use of Google user data

Our Limited Use commitment

Snova’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we confirm that we do not:

  • use Google user data for serving advertising, including personalised, retargeted or interest-based advertising;
  • sell, rent or transfer Google user data to data brokers, information resellers or any other third party for their own purposes;
  • use Google user data to develop, train, retrain or improve generalised artificial intelligence or machine learning models;
  • use Google user data for determining creditworthiness or for lending purposes;
  • allow humans to read Google user data, unless we have your explicit consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.

Snova uses AI models from third-party providers to generate content. Data obtained from Google Search Console is not sent to those providers for model training, and is not used to train any model operated by Snova.

7. AI processing

Snova uses third-party large language models to research topics, draft articles and analyse how brands appear in AI assistants. When you use these features, the inputs you provide — such as your brand profile, keywords, topic briefs and prompts — are sent to the AI provider that serves the request so it can generate a response.

We use business or enterprise API tiers, under which providers act as processors on our behalf and do not use the content of API requests to train their models. As stated in Section 6, Google Search Console data is never included in AI training.

8. Service providers

We rely on the providers below to run Snova. Each processes personal data only on our instructions and under a data processing agreement.

ProviderPurposeRegion
VercelApplication hosting and content deliveryEU / US
Supabase (managed PostgreSQL)Primary application databaseEU
AnthropicAI models for research and content generationUS
OpenAIAI models and embeddingsUS
Google (Gemini)AI modelsUS
PerplexityAI models with web searchUS
Google (Search Console API)Search performance data you authoriseUS
AhrefsSEO, keyword and AI-visibility dataEU / US
DataForSEOTechnical SEO and site audit dataEU / US
FirecrawlWebsite crawling for research and auditsUS
Trigger.devBackground job processingUS
TiptapCollaborative document editingEU
ResendTransactional email deliveryEU / US
StripePayment processingEU / US
AutumnSubscription and entitlement managementUS
Google Tag ManagerWebsite analyticsUS
CalendlyDemo schedulingUS

We may update this list as our infrastructure evolves. Material changes will be reflected here.

9. Cookies and analytics

We use two categories of cookies:

  • Strictly necessary. Session and authentication cookies that keep you signed in and protect against cross-site request forgery. The service cannot function without these.
  • Analytics. We load Google Tag Manager on our public website to understand how visitors find and use it. This may set cookies and process your IP address and browsing behaviour.

You can block or delete cookies through your browser settings, and you can opt out of Google Analytics using the Google Analytics opt-out browser add-on. Blocking strictly necessary cookies will prevent you from signing in.

10. Sharing and disclosure

We do not sell your personal data. We disclose data only as follows:

  • To the service providers listed in Section 8, acting on our instructions.
  • To other members of your organisation in Snova, who can see the workspaces and content shared with them.
  • To recipients of client reports you choose to share — see the note below.
  • Where required by law, court order or a competent authority, or to establish, exercise or defend legal claims.
  • To an acquirer in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply.

A note on shared client reports

Snova lets you generate a report and share it via a secret link. That link contains a 256-bit random token and is not indexed by search engines, but it is not password protected — anyone who has the link can view the report and the performance figures it contains, including data derived from Google Search Console. Share links only with people who should see them. You can revoke a link at any time, which immediately disables access, or delete the report entirely.

12. International transfers

Some of our providers are located outside the European Economic Area, primarily in the United States. Where we transfer personal data outside the EEA, we rely on the European Commission’s Standard Contractual Clauses, on the EU-US Data Privacy Framework where the provider is certified, and on additional technical measures such as encryption in transit and at rest.

13. Data retention

DataRetention period
Account and profile dataFor as long as your account is active, then deleted within 90 days of account closure
Workspace content (articles, keywords, reports)Until you delete it, or within 90 days of account closure
Google Search Console credentialsUntil you disconnect the integration or close your account — deleted immediately on disconnection
Cached third-party SEO and performance dataRefreshed on a rolling basis; typically retained up to 24 months to support historical trends
Shared client reportsUntil you delete the report or close your account
Invoices and accounting records7 years, as required by Swedish bookkeeping law
Support correspondenceUp to 24 months after the matter is resolved

14. Security

  • All traffic is encrypted in transit using TLS.
  • Third-party credentials, including CMS logins and Google refresh tokens, are encrypted at rest with AES-256-GCM before being written to the database.
  • Passwords are stored only as salted hashes.
  • Access to production systems is restricted to personnel who need it, and application access is scoped by organisation and role.
  • We set security headers including X-Frame-Options, X-Content-Type-Options and a strict referrer policy.

No system can be guaranteed completely secure, but we work to protect your data using measures appropriate to the risk. If a breach affects your personal data and poses a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.

15. Your rights

Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out.

To exercise any of these rights, email support@trysnova.com. We will respond within one month, as required by Article 12 GDPR.

If you believe we have handled your personal data unlawfully, you may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the supervisory authority in your country of residence.

16. Children

Snova is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

17. Changes to this policy

We may update this policy as the product and our legal obligations evolve. The “last updated” date at the top always reflects the current version, and we will notify account holders of material changes by email or in the application.

18. Contact us

For any question about this policy or how we handle your data, contact us at support@trysnova.com or write to Snova AB, [STREET ADDRESS], [POSTAL CODE] [CITY], Sweden.