0. Summary of Data Collection, Handling, Storage, and Sharing
In accordance with Google's Developer Program Policy and the User Data FAQ, the following summary provides immediate transparency regarding all data handled by the extension and its backend:
| Topic | Specific Practices of SEO Tool - Website SEO Checker |
|---|---|
| User Data Collection |
We collect:
|
| User Data Handling |
Information is handled strictly to:
|
| User Data Storage & Retention |
|
| User Data Sharing |
We strictly DO NOT sell, rent, lease, or monetize personal user data. We share data only with:
|
1. User Data Collection
We strictly adhere to the data minimization principle. We collect only information that is directly necessary to execute website SEO audits, authenticate user sessions, and maintain user audit histories.
1.1 Personal and Account Identification Information
When you choose to sign in to unlock comprehensive in-depth reports, we collect:
- Personal Data Google Account Profile: When you authenticate via Google Sign-In, we receive your Google unique account identifier (`sub` ID), full name, verified email address, and profile picture avatar URL through Google's official UserInfo API endpoints.
- Personal Data Mobile Phone Number: Following Google Sign-In, users are prompted to provide their mobile phone number. This number is collected directly from user input for account registration verification, profile completeness, and duplicate account prevention.
1.2 Webpage Content & Browsing Activity Analyzed
When you trigger an audit or browse an active website with the extension enabled:
- Audit Data Audited Webpage URL & Domain: The URL of the webpage you choose to audit (e.g. `https://example.com/page`).
- Audit Data On-Page Technical SEO Elements: Page title tag, meta description, meta robots directives, canonical tags, character encoding (`charset`), HTTP vs HTTPS status, and favicon declarations.
- Audit Data Content Architecture & Hierarchy: Heading structure (H1 through H6 count and text hierarchy) and word count.
- Audit Data Media Assets: Image tags (`
`), image alt attributes, aspect ratios, responsive `srcset` markup, and image formats (WebP, AVIF, SVG, PNG).
- Audit Data Social & Structured Data: OpenGraph meta tags (og:title, og:description, og:image), Twitter/X Card tags, and Schema.org JSON-LD structured data blocks.
- Audit Data Performance & Core Web Vitals Indicators: Client-measured DOM node counts, render-blocking scripts, resource reference counts (CSS, JS, fonts), and lab estimates for Largest Contentful Paint (LCP), Interaction to Next Paint (INP), and Cumulative Layout Shift (CLS).
1.3 Technical, Device & Connection Data
When the extension communicates with our backend API at https://seo-checker.unikainfocom.in:
- IP Address: Logged automatically by server web logs and reverse proxy for cybersecurity, rate-limiting, and geographic abuse prevention.
- Operating System & Platform: Detected platform metadata (e.g., Windows 10/11, macOS, Linux) and client identifier (`device_name`) used to maintain session compatibility.
- Session State: Login status flag (`is_logged = 1`) and login timestamp (`last_login_at`) to manage multi-device sessions and active logins.
1.4 Local Storage Data
The extension uses Chrome's `storage.local` API to store local preferences, your current active session user object, and cached diagnostic reports so you can access previous audit results instantly without redundant network queries.
2. User Data Handling and Purpose of Processing
We handle and process user data solely to provide, support, and secure the specific features of SEO Tool - Website SEO Checker:
| Data Type | Handling & Processing Activity | Specific Purpose |
|---|---|---|
| Audited URL & Page HTML Markup | Injected analysis scripts parse the DOM locally in your browser to evaluate 60+ SEO rules. A summary report is generated. | To diagnose technical SEO problems, calculate category scores (0–100), and display actionable remediation recommendations. |
| Google Account (Name, Email, Avatar) | Received securely from Google OAuth2 endpoints upon your authorization. Verified and saved to user profile. | To authenticate your identity, provide secure login, create your account, and personalize your dashboard experience. |
| Mobile Phone Number | Submitted voluntarily via the registration modal in the dashboard. Stored in the encrypted user profile database. | To complete user registration, verify user accounts, prevent malicious automated account farming, and offer customer support. |
| Audit History Records | Saved to the backend database when an authenticated user generates an audit. | To allow users to view, compare, export, or delete their historical website audit reports over time. |
| Device & IP Information | Processed by backend security middleware during API requests. | To enforce brute-force rate limits, prevent DDoS attacks, safeguard backend APIs, and ensure service reliability. |
2.1 Strict Single-Purpose Handling
The data collected is used exclusively for the single purpose of providing website SEO diagnostics and user account management. We never repurpose, cross-reference, or monetize this information.
3. User Data Storage and Retention
We implement industry-standard physical, technical, and administrative safeguards to protect your data across all storage environments:
3.1 Storage Locations
- Local Browser Storage: Local extension settings, authorization state, and temporary audit caches are stored on your local computer using the Chrome Storage API (`chrome.storage.local`). This data never leaves your device unless you sign in and sync your session.
- Backend Cloud Database: Authenticated user account data (Google ID, name, email, avatar, mobile number), session tokens, and saved audit histories are stored in a secured MySQL relational database hosted on dedicated cloud servers provided by Hetzner Online GmbH in secure data centers located in Germany/Finland.
3.2 Data Retention Schedule
| Data Category | Storage Location | Retention Period |
|---|---|---|
| Account Profile (Name, Email, Mobile, Avatar) | Hetzner Backend Database | Retained as long as your account is active. Permanently deleted upon user request or within 30 days of account deletion. |
| Audit History Records | Hetzner Backend Database | Retained until individually deleted by the user via the "Delete" or "Clear History" buttons, or upon account closure. |
| Local Audit Cache & Preferences | Client Device (`chrome.storage.local`) | Retained until manually cleared in extension settings or until the extension is uninstalled from Chrome. |
| Server Access & Security Logs | Hetzner Web Server Logs | Automatically rotated and permanently purged on a rolling 90-day cycle. |
3.3 Security & Encryption
All communications between the Chrome Extension and our backend APIs (https://seo-checker.unikainfocom.in) are enforced over encrypted HTTPS using modern TLS 1.2 and TLS 1.3 with robust cipher suites. Database records are protected behind strict firewall configurations, private networking, and token-based bearer authentication.
5. Prominent In-Product Disclosure & User Consent
In accordance with Chrome Web Store User Data FAQ policy on Prominent Disclosure:
- Before Google Authentication: Before connecting your Google Account, the extension displays an in-product modal explaining that Google Sign-In collects your name, email address, profile picture, and Google identifier to create and authenticate your account, complete with a direct clickable link to this Privacy Policy.
- Before Mobile Number Submission: The registration dialog clearly indicates that your mobile number will be securely stored to verify your account and enable full diagnostic reports, accompanied by a direct link to this Privacy Policy.
- Persistent Policy Access: A direct link to this Privacy Policy is permanently embedded in both the Chrome popup footer (`popup.html`) and the full audit dashboard footer (`dashboard.html`).
By clicking "Sign Up with Google", submitting your phone number, or initiating an audit, you provide affirmative consent to the collection and handling of data as described herein.
6. User Choices, Rights, and Data Deletion
We believe in giving you full ownership and control over your data. You have the following rights:
- Right to Access: You can view all saved audit reports and profile information directly inside the extension's "History" and "Profile" tabs.
- Right to Rectification: You can update or correct your profile details by contacting our support team.
- Right to Delete Individual Audits: You can immediately delete any single audit report from your account by clicking the trash/delete icon in the "Audit History" tab.
- Right to Clear All Audit History: You can wipe your entire audit history at any time using the "Clear History" button in the dashboard.
- Right to Full Account & Phone Number Deletion: You can request the permanent deletion of your complete account profile, including your name, email, Google identifier, mobile number, and all associated audit data, by emailing our privacy team at:
[email protected] (Subject: "Data Deletion Request - Ultimate SEO Checker") - Turnaround Guarantee: Verified deletion requests are reviewed and permanently processed within 30 calendar days.
7. Chrome Extension Permissions Justification
The extension declares only the minimum necessary permissions in its manifest.json to perform its core SEO audit functions:
| Permission | Specific Justification & Technical Use |
|---|---|
activeTab |
Used to access the URL and DOM of the currently focused browser tab when the user clicks the extension icon to run an SEO audit. |
scripting |
Used to inject the packaged, offline SEO diagnostic analyzer script (`seo-engine.js`) into the active webpage to inspect headings, meta tags, and structured data. |
storage |
Used to store user preferences, authenticated session credentials, and local audit caches on the user's machine. |
unlimitedStorage |
Ensures that extensive SEO audit reports, heading outlines, and schema blocks can be saved locally without exceeding standard 5MB browser storage quotas. |
tabs |
Used to detect tab updates (when a webpage finishes loading) to recalculate the real-time SEO health score and update the extension badge indicator. |
identity |
Enables standard OAuth 2.0 authentication via Google Sign-In without requesting or storing user Google passwords. |
host_permissions: ["<all_urls>"] |
Enables the extension to audit any live website that the user navigates to and requests an audit for (e.g., client websites, e-commerce stores, news portals). |
8. Data Security & Storage Safeguards
We employ robust technical and organizational security protocols:
- Transport Layer Security: All API requests use HTTPS with modern TLS encryption to prevent eavesdropping and man-in-the-middle attacks.
- Access Controls: Server administration access is restricted to authorized engineers via SSH keys and IP whitelisting.
- Brute-Force & Bot Mitigation: Rate-limiting guards protect API endpoints from brute-force attempts and denial-of-service traffic.
- No Password Storage: Authentication uses tokenized OAuth2 delegations. We never solicit or store your Google password.
9. Chrome Web Store Limited Use Certification
SEO Tool - Website SEO Checker complies fully with the Chrome Web Store User Data Policy, including the Limited Use requirements:
- We only use data to provide and improve user-facing features that are prominent in the extension's user interface.
- We do not transfer user data to third parties, except as strictly necessary to provide the core service (OAuth authentication and server hosting) or to comply with applicable laws.
- We do not use or transfer user data for personalized advertising or retargeting campaigns.
- We do not use or transfer user data to determine creditworthiness or for lending decisions.
- Human beings do not read user audit data unless the user provides affirmative consent for technical troubleshooting, or when required for security investigations or legal obligations.
10. Children's Privacy
The Service is intended for website administrators, developers, digital marketers, and general adult audiences. We do not knowingly solicit or collect personal information from children under the age of 13 (or under 16 in the European Union). If you believe a minor has provided personal information to us, please notify us immediately at [email protected], and we will delete the data promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our service features, server infrastructure, or applicable regulatory guidelines. When changes are made, we will update the "Last Updated" date at the top of this document. Continued use of the extension after any modifications constitutes acceptance of the updated policy.
12. Contact Us & Grievance Redressal
Unika Infocom Pvt. Ltd.
If you have questions about this Privacy Policy, wish to exercise your data access or deletion rights, or have concerns regarding data privacy, please contact our Data Protection Officer:
Email: [email protected]
Corporate Website: https://www.unikainfocom.in/
Customer Support Portal: https://www.unikainfocom.in/enquiry/
Backend API & Extension Service: https://www.unikainfocom.in/privacy-policy/ultimate-seo-checker/