Security and data
Where your data lives,and what we do with it.
Dynamic SEO reads your site's public pages, stores what you write and answers the plugin's requests. This is the whole list, so you don't have to ask.
Where the data lives
The database is in Stockholm. The rest is listed here.
- Database and sign-in
- Supabase in the North EU region, Stockholm. Encrypted at rest, row-level security per account.
- The app
- Runs on Vercel. That is where you sign in, crawl and publish.
- Delivery API and cache
- Cloudflare Workers with a KV cache. This is what the plugin calls, and the only thing between your site and an answer.
- Queue and rate limiting
- Upstash Redis. The crawl queue and the limit on how many requests a client may make per minute.
- Operational logs
- Better Stack in Frankfurt. Technical logs with request id, account id and site id.
- Product analytics and error reports
- PostHog in Frankfurt, only after your consent. Sentry for error reports.
What the plugin sends
One request per page view. Nothing about the visitor.
When a page on your WordPress site renders, your server makes one GET request to our API. The visitor's browser never talks to us.
- What is sent
- The page's domain and path, plus three headers: the site key, the plugin version and the WordPress version. That is all.
- What is not sent
- No IP address, no user agent, no cookies, no form content. The request comes from your server, not from the visitor.
- Cache and timeout
- The answer is cached in the plugin for five minutes and on our side. The plugin waits at most eight seconds. If we don't answer, the site's original tags show.
- What we log
- Path, status code, cache hit, response time, plugin version and a hash of the calling server's IP. Deleted after 30 days. This is what the Deploy view is built from.
What we store about your site
What is public, what you write, and what you connect.
- From the crawl
- Title, description, H1, canonical, robots, hreflang, Open Graph and Twitter tags, status code and response time, whether the page is in the sitemap, the internal links, the page's headings and the text keywords are computed from. All fetched from pages anyone can open.
- How the crawler behaves
- It identifies itself as DynamicSEO-Crawler and DynamicSEO-ContentBot, respects robots.txt and Crawl-Delay, and never fetches from private or internal addresses.
- What you write
- Categories, templates, variables and the fields you publish. It is your content, and it can be exported from Settings.
- Search Console, if you connect it
- Clicks, impressions, position and queries per page, with read-only permission. The token is encrypted at rest. Disconnect and the access is revoked.
- What we never have
- The login to your CMS, your visitors' data, your customers' details. The plugin only needs the site key.
How it is protected
The same routines as every serious service, plus one for the crawler.
- Encrypted in transit
- TLS on every request, HSTS on dynamicseo.com. The database encrypts at rest.
- One account, its own rows
- Row-level security in the database. An account sees only its own sites, and another customer's data is never in the answer.
- One key per site
- The site key (sk_…) only grants reads of published content for that site. Regenerate it in the Integrate view and the old one stops working immediately.
- Strict Content Security Policy
- Without unsafe-eval. Scripts load only from the hosts we list.
- The crawler is kept out of private networks
- Every address is validated before it is fetched, including after a redirect. Private networks, link-local addresses and DNS rebinding are blocked.
- Rate limiting
- The API limits how many requests a client may make per minute, and the crawl backs off when our own database is under load.
Sub-processors
Who helps us run the service
Each one is bound by a data-processing agreement. The full list with legal basis is in the privacy policy.
Read the privacy policy- Supabase: database and sign-in, Stockholm
- Vercel: hosting of the app, US-based under Standard Contractual Clauses
- Cloudflare: delivery API, cache and DDoS protection
- Upstash: Redis for the queue and rate limiting
- Better Stack: operational logs and monitoring, Frankfurt
- PostHog: product analytics, Frankfurt, only after consent
- Sentry: error reports, US-based
- Resend: email from the contact form and the waitlist
- Google: Tag Manager and Analytics, only after consent
Remove, export, leave
You can leave at any time, and the original stays.
- Unpublish
- The site's original tags take over within a minute. Per page, per selection or everything at once, from Deploy.
- Uninstall the plugin
- The site key and the plugin's cache are deleted from WordPress. Nothing is left behind.
- Disconnect Search Console
- One click in the app. The token is revoked and the sync stops.
- Delete the account
- Email hello@dynamicseo.com and we delete the account, the sites and the crawl data. We answer within 30 days. Deletion straight from the account does not exist yet.
- Export
- All published content for a site downloads from Settings. Other data we hand over on request, in a machine-readable format.
Uptime and vulnerabilities
If something breaks, you should hear it before your customers do.
We monitor the app and the database around the clock from Better Stack. If you find a vulnerability, email hello@dynamicseo.com. We answer within one business day, and the machine-readable details are in security.txt.
Common questions