Privacy Policy

Your data, in plain language

What Assio collects, why, who it goes to, and how to see, take or delete it. Last updated 4 October 2026.

Who we are

The Assio website and app at assio.net are run by Assio (“Assio”, “we”), the data controller for the personal data described here. Reach us about anything in this policy at support@assio.net.

Our role for different data

We are the controller for your account, your workspace membership, billing and (if you accept it) analytics data. We decide why and how that data is used.

We are a processor for personal data that sits inside the sites you add and the services you connect, such as names on your public pages or data from your Search Console, GA4 or WordPress. We handle it only to give you the service, under our Data Processing Agreement, which applies to every customer automatically.

What we collect

You give us

  • Account details: your name, email address and password (stored only as a hash, never in plain text). If you sign in with Google, we receive your name, email and profile picture from Google.
  • Workspace details: workspaces, members, invitations and API keys (stored only as a hash).
  • Your sites and work: the domains you add, the project context you write, keywords you research or track, and the SEO changes Assio proposes and you approve.
  • Connections you choose to make: access tokens for Google Search Console and GA4, and a WordPress username and application password. These are kept on our servers and never sent back to your browser.
  • Billing: your plan and subscription. Stripe collects your card details directly; they never touch Assio.

We collect automatically

  • Sign-in sessions: the IP address and browser (user agent) of each signed-in session, to keep your account secure.
  • Analytics, only if you accept it: pages you view, with browser and device details. Session recording is switched off.

From the sites you add

Assio reads your site’s public pages and stores their content, audit results and rankings. It reads only what anyone could see in a browser.

Why we use it (lawful bases)

Under the GDPR we need a lawful basis for each use. Here is each one:

PurposeData usedLawful basis
Create and run your account and workspacesAccount and workspace detailsContract: needed to provide the service you signed up for
Learn your sites, run audits, research keywords, track rankings and apply approved changesYour sites and work; connections you makeContract
AI features (SAM assistant, suggested titles, descriptions and answers)Your prompts and relevant site contentContract: you ask for the feature
Billing and keeping financial recordsBilling detailsContract, and legal obligation for tax and accounting records
Keeping accounts secure and preventing abuseSession IP address and user agentLegitimate interests: protecting you and the service
Understanding which pages help people (analytics)Pages viewed, browser and device detailsConsent: off until you accept, and you can withdraw any time

We do not sell your personal data and we do not use it for advertising, including cross-site behavioural advertising.

AI features

When you use SAM or ask Assio to draft titles, descriptions or answers, your prompt and the site content needed to respond are sent to an AI model provider through Vercel AI Gateway. The output is a suggestion: nothing goes live on your site until you approve it.

Who receives it

We share personal data only with the service providers below, who process it on our instructions to run Assio. This is also the sub-processor list for our Data Processing Agreement.

ProviderWhat they do for AssioWhat they receive
VercelHosts the website and appAll data passing through the app, including request logs with IP address
SupabaseDatabaseAccount, workspace, site and billing records stored by Assio
StripePayments and subscriptionsName, email, billing details. Card details go straight to Stripe and never touch Assio
GoogleGoogle sign-in, and Search Console, GA4 and PageSpeed when you connect themSign-in identity; access tokens; public page URLs for PageSpeed
PostHogProduct analytics, only if you accept analyticsPages viewed, browser and device details, IP address
AI model provider(s), via Vercel AI GatewaySAM assistant and AI-written suggestionsYour prompts and the site content needed to answer them
Keyword and search-market data providerKeyword volumes and search-market dataKeywords and domains only, no personal data
Page-rendering serviceLoads public pages that need JavaScript to displayPublic page URLs only

We may also disclose data if the law requires it, or to a buyer if Assio is sold or merged, in which case this policy continues to protect it.

Where your data is stored

Assio is a US service. Our database runs in the United States (AWS, Northern California) and the app runs on Vercel servers in the United States. If you use Assio from outside the US, your data is transferred to and stored in the US. Where a transfer of EU, UK or Swiss personal data needs a safeguard, it is covered by the European Commission’s Standard Contractual Clauses in our providers’ data processing terms. Ask us at support@assio.net for details.

How long we keep it

  • Account, workspace and site data: kept while your account exists. Deleting your account deletes your user record and every workspace where you are the only member, including all of its sites and data. Workspaces you share with others stay with the remaining members. A workspace with an active subscription must cancel billing before it can be deleted.
  • Sign-in sessions: removed when they expire or you sign out.
  • Billing records: deleting your account does not delete your Stripe customer record or invoices; they are kept as long as tax and accounting law requires. Email support@assio.net to have them erased where the law allows.
  • Backups: deleted data can stay in database backups until they rotate out on our database provider’s schedule.
  • Analytics: kept in PostHog under its retention settings; withdrawing consent stops new collection.

Cookies and similar storage

Assio uses only what it needs to work, plus optional analytics that stays off unless you accept it.

NamePurposeType
better-auth.session_token (and related sign-in cookies)Keeps you signed in and protects sign-inStrictly necessary
sidebar_stateRemembers whether the app sidebar is openStrictly necessary
theme (browser storage)Remembers light or dark modeStrictly necessary
assio.consent (browser storage)Remembers your analytics choiceStrictly necessary
ph_* (PostHog cookie and browser storage)Counts page viewsOptional analytics, only after you accept

If your browser sends a Global Privacy Control signal, we treat it as a “no” to analytics and don’t ask.

Your rights (GDPR)

If you are in the UK, European Economic Area or Switzerland, you have the right to:

  • Access your personal data and get a copy.
  • Rectify data that is wrong or incomplete.
  • Erase your data (“right to be forgotten”).
  • Portability: receive your data in a machine-readable format.
  • Restrict how we use your data.
  • Object to uses based on legitimate interests.
  • Withdraw consent at any time, without affecting what happened before.
  • Complain to your local data protection supervisory authority. We’d appreciate the chance to sort it out with you first.

How to use your rights

  • In the app: go to Settings → Account to update your details, use Download my data for a JSON copy, or Delete account to erase your account (see How long we keep it for what deletion covers).
  • By email: write to support@assio.net for anything else, including restriction, objection, or data held inside a workspace you don’t own.

We may ask you to confirm your identity, usually by replying from your account email. We answer within one month, and tell you if we need longer for a complex request. Using your rights is free.

US state privacy rights (CCPA/CPRA)

This section applies if you live in California or another US state with a similar privacy law. In the last 12 months we collected the categories below, only for the business purposes listed.

CategoryExamplesBusiness purpose
IdentifiersName, email address, account ID, IP addressProviding your account, security
Commercial informationPlan and subscription historyBilling
Internet or network activitySession browser details; pages viewed (only with analytics consent)Security, improving the product
Sensitive personal informationYour account login (email and hashed password)Signing you in, nothing else
Customer contentSites you add, their public pages, project context you writeProviding the service you asked for

Sources: you; your browser or device; services you connect (Google, WordPress); and the public pages of the sites you add. Recipients and retention are described in Who receives it and How long we keep it.

No sale, no sharing. We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the last 12 months. We do not knowingly sell or share the data of anyone under 16.

Your rights

  • Know and access what we collect, use and disclose, and get a copy.
  • Delete personal information we collected from you.
  • Correct inaccurate personal information.
  • Opt out of sale or sharing. We don’t sell or share, so there is nothing to opt out of, but you can still use Your privacy choices to turn analytics off.
  • Limit use of sensitive personal information. We use your login only to sign you in, which is already the limit the law allows.
  • Non-discrimination. Using these rights never changes your price or service.

How to make a request

Use Settings → Account to download or delete your data, or email support@assio.net. We verify requests by matching them to your account email, and respond within 45 days (extendable once by another 45 when needed, with notice).

Authorized agents may make a request for you with your signed permission. We may ask you to confirm your identity with us directly.

Global Privacy Control. We honour the GPC browser signal as an opt-out: analytics stays off and we don’t ask.

Automated decisions

Assio scores pages and suggests changes automatically, but makes no decisions about you that have legal or similarly significant effects.

Children

Assio is a business tool and is not meant for anyone under 16. We don’t knowingly collect their data; if you think we have, email support@assio.net and we will delete it.

Security

Data travels over encrypted connections (TLS) and is encrypted at rest by our hosting and database providers. Passwords and API keys are stored only as hashes, connection secrets stay on our servers, and workspace data is visible only to that workspace’s members. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authorities as the law requires.

Changes to this policy

We update this page when our practices change and show the date at the top. Please check back from time to time. Last updated 4 October 2026.