Skip to main content
Security and data

Where your data lives,and what we do with it.

Dynamic SEO reads your site's public pages, stores what you write and answers the plugin's requests. This is the whole list, so you don't have to ask.

Where the data lives

The database is in Stockholm. The rest is listed here.

Database and sign-in
Supabase in the North EU region, Stockholm. Encrypted at rest, row-level security per account.
The app
Runs on Vercel. That is where you sign in, crawl and publish.
Delivery API and cache
Cloudflare Workers with a KV cache. This is what the plugin calls, and the only thing between your site and an answer.
Queue and rate limiting
Upstash Redis. The crawl queue and the limit on how many requests a client may make per minute.
Operational logs
Better Stack in Frankfurt. Technical logs with request id, account id and site id.
Product analytics and error reports
PostHog in Frankfurt, only after your consent. Sentry for error reports.
What the plugin sends

One request per page view. Nothing about the visitor.

When a page on your WordPress site renders, your server makes one GET request to our API. The visitor's browser never talks to us.

What is sent
The page's domain and path, plus three headers: the site key, the plugin version and the WordPress version. That is all.
What is not sent
No IP address, no user agent, no cookies, no form content. The request comes from your server, not from the visitor.
Cache and timeout
The answer is cached in the plugin for five minutes and on our side. The plugin waits at most eight seconds. If we don't answer, the site's original tags show.
What we log
Path, status code, cache hit, response time, plugin version and a hash of the calling server's IP. Deleted after 30 days. This is what the Deploy view is built from.
What we store about your site

What is public, what you write, and what you connect.

From the crawl
Title, description, H1, canonical, robots, hreflang, Open Graph and Twitter tags, status code and response time, whether the page is in the sitemap, the internal links, the page's headings and the text keywords are computed from. All fetched from pages anyone can open.
How the crawler behaves
It identifies itself as DynamicSEO-Crawler and DynamicSEO-ContentBot, respects robots.txt and Crawl-Delay, and never fetches from private or internal addresses.
What you write
Categories, templates, variables and the fields you publish. It is your content, and it can be exported from Settings.
Search Console, if you connect it
Clicks, impressions, position and queries per page, with read-only permission. The token is encrypted at rest. Disconnect and the access is revoked.
What we never have
The login to your CMS, your visitors' data, your customers' details. The plugin only needs the site key.
How it is protected

The same routines as every serious service, plus one for the crawler.

Encrypted in transit
TLS on every request, HSTS on dynamicseo.com. The database encrypts at rest.
One account, its own rows
Row-level security in the database. An account sees only its own sites, and another customer's data is never in the answer.
One key per site
The site key (sk_…) only grants reads of published content for that site. Regenerate it in the Integrate view and the old one stops working immediately.
Strict Content Security Policy
Without unsafe-eval. Scripts load only from the hosts we list.
The crawler is kept out of private networks
Every address is validated before it is fetched, including after a redirect. Private networks, link-local addresses and DNS rebinding are blocked.
Rate limiting
The API limits how many requests a client may make per minute, and the crawl backs off when our own database is under load.
Sub-processors

Who helps us run the service

Each one is bound by a data-processing agreement. The full list with legal basis is in the privacy policy.

Read the privacy policy
  • Supabase: database and sign-in, Stockholm
  • Vercel: hosting of the app, US-based under Standard Contractual Clauses
  • Cloudflare: delivery API, cache and DDoS protection
  • Upstash: Redis for the queue and rate limiting
  • Better Stack: operational logs and monitoring, Frankfurt
  • PostHog: product analytics, Frankfurt, only after consent
  • Sentry: error reports, US-based
  • Resend: email from the contact form and the waitlist
  • Google: Tag Manager and Analytics, only after consent
Remove, export, leave

You can leave at any time, and the original stays.

Unpublish
The site's original tags take over within a minute. Per page, per selection or everything at once, from Deploy.
Uninstall the plugin
The site key and the plugin's cache are deleted from WordPress. Nothing is left behind.
Disconnect Search Console
One click in the app. The token is revoked and the sync stops.
Delete the account
Email hello@dynamicseo.com and we delete the account, the sites and the crawl data. We answer within 30 days. Deletion straight from the account does not exist yet.
Export
All published content for a site downloads from Settings. Other data we hand over on request, in a machine-readable format.
Uptime and vulnerabilities

If something breaks, you should hear it before your customers do.

We monitor the app and the database around the clock from Better Stack. If you find a vulnerability, email hello@dynamicseo.com. We answer within one business day, and the machine-readable details are in security.txt.

Common questions

What people ask before connecting a client site