Who we are
The Assio website and app at assio.net are run by Assio (“Assio”, “we”), the data controller for the personal data described here. Reach us about anything in this policy at support@assio.net.
Our role for different data
We are the controller for your account, your workspace membership, billing and (if you accept it) analytics data. We decide why and how that data is used.
We are a processor for personal data that sits inside the sites you add and the services you connect, such as names on your public pages or data from your Search Console, GA4 or WordPress. We handle it only to give you the service, under our Data Processing Agreement, which applies to every customer automatically.
What we collect
You give us
- Account details: your name, email address and password (stored only as a hash, never in plain text). If you sign in with Google, we receive your name, email and profile picture from Google.
- Workspace details: workspaces, members, invitations and API keys (stored only as a hash).
- Your sites and work: the domains you add, the project context you write, keywords you research or track, and the SEO changes Assio proposes and you approve.
- Connections you choose to make: access tokens for Google Search Console and GA4, and a WordPress username and application password. These are kept on our servers and never sent back to your browser.
- Billing: your plan and subscription. Stripe collects your card details directly; they never touch Assio.
We collect automatically
- Sign-in sessions: the IP address and browser (user agent) of each signed-in session, to keep your account secure.
- Analytics, only if you accept it: pages you view, with browser and device details. Session recording is switched off.
From the sites you add
Assio reads your site’s public pages and stores their content, audit results and rankings. It reads only what anyone could see in a browser.
Why we use it (lawful bases)
Under the GDPR we need a lawful basis for each use. Here is each one:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and run your account and workspaces | Account and workspace details | Contract: needed to provide the service you signed up for |
| Learn your sites, run audits, research keywords, track rankings and apply approved changes | Your sites and work; connections you make | Contract |
| AI features (SAM assistant, suggested titles, descriptions and answers) | Your prompts and relevant site content | Contract: you ask for the feature |
| Billing and keeping financial records | Billing details | Contract, and legal obligation for tax and accounting records |
| Keeping accounts secure and preventing abuse | Session IP address and user agent | Legitimate interests: protecting you and the service |
| Understanding which pages help people (analytics) | Pages viewed, browser and device details | Consent: off until you accept, and you can withdraw any time |
We do not sell your personal data and we do not use it for advertising, including cross-site behavioural advertising.
AI features
When you use SAM or ask Assio to draft titles, descriptions or answers, your prompt and the site content needed to respond are sent to an AI model provider through Vercel AI Gateway. The output is a suggestion: nothing goes live on your site until you approve it.
Who receives it
We share personal data only with the service providers below, who process it on our instructions to run Assio. This is also the sub-processor list for our Data Processing Agreement.
| Provider | What they do for Assio | What they receive |
|---|---|---|
| Vercel | Hosts the website and app | All data passing through the app, including request logs with IP address |
| Supabase | Database | Account, workspace, site and billing records stored by Assio |
| Stripe | Payments and subscriptions | Name, email, billing details. Card details go straight to Stripe and never touch Assio |
| Google sign-in, and Search Console, GA4 and PageSpeed when you connect them | Sign-in identity; access tokens; public page URLs for PageSpeed | |
| PostHog | Product analytics, only if you accept analytics | Pages viewed, browser and device details, IP address |
| AI model provider(s), via Vercel AI Gateway | SAM assistant and AI-written suggestions | Your prompts and the site content needed to answer them |
| Keyword and search-market data provider | Keyword volumes and search-market data | Keywords and domains only, no personal data |
| Page-rendering service | Loads public pages that need JavaScript to display | Public page URLs only |
We may also disclose data if the law requires it, or to a buyer if Assio is sold or merged, in which case this policy continues to protect it.
Where your data is stored
Assio is a US service. Our database runs in the United States (AWS, Northern California) and the app runs on Vercel servers in the United States. If you use Assio from outside the US, your data is transferred to and stored in the US. Where a transfer of EU, UK or Swiss personal data needs a safeguard, it is covered by the European Commission’s Standard Contractual Clauses in our providers’ data processing terms. Ask us at support@assio.net for details.
How long we keep it
- Account, workspace and site data: kept while your account exists. Deleting your account deletes your user record and every workspace where you are the only member, including all of its sites and data. Workspaces you share with others stay with the remaining members. A workspace with an active subscription must cancel billing before it can be deleted.
- Sign-in sessions: removed when they expire or you sign out.
- Billing records: deleting your account does not delete your Stripe customer record or invoices; they are kept as long as tax and accounting law requires. Email support@assio.net to have them erased where the law allows.
- Backups: deleted data can stay in database backups until they rotate out on our database provider’s schedule.
- Analytics: kept in PostHog under its retention settings; withdrawing consent stops new collection.
Your rights (GDPR)
If you are in the UK, European Economic Area or Switzerland, you have the right to:
- Access your personal data and get a copy.
- Rectify data that is wrong or incomplete.
- Erase your data (“right to be forgotten”).
- Portability: receive your data in a machine-readable format.
- Restrict how we use your data.
- Object to uses based on legitimate interests.
- Withdraw consent at any time, without affecting what happened before.
- Complain to your local data protection supervisory authority. We’d appreciate the chance to sort it out with you first.
How to use your rights
- In the app: go to Settings → Account to update your details, use Download my data for a JSON copy, or Delete account to erase your account (see How long we keep it for what deletion covers).
- By email: write to support@assio.net for anything else, including restriction, objection, or data held inside a workspace you don’t own.
We may ask you to confirm your identity, usually by replying from your account email. We answer within one month, and tell you if we need longer for a complex request. Using your rights is free.
US state privacy rights (CCPA/CPRA)
This section applies if you live in California or another US state with a similar privacy law. In the last 12 months we collected the categories below, only for the business purposes listed.
| Category | Examples | Business purpose |
|---|---|---|
| Identifiers | Name, email address, account ID, IP address | Providing your account, security |
| Commercial information | Plan and subscription history | Billing |
| Internet or network activity | Session browser details; pages viewed (only with analytics consent) | Security, improving the product |
| Sensitive personal information | Your account login (email and hashed password) | Signing you in, nothing else |
| Customer content | Sites you add, their public pages, project context you write | Providing the service you asked for |
Sources: you; your browser or device; services you connect (Google, WordPress); and the public pages of the sites you add. Recipients and retention are described in Who receives it and How long we keep it.
No sale, no sharing. We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the last 12 months. We do not knowingly sell or share the data of anyone under 16.
Your rights
- Know and access what we collect, use and disclose, and get a copy.
- Delete personal information we collected from you.
- Correct inaccurate personal information.
- Opt out of sale or sharing. We don’t sell or share, so there is nothing to opt out of, but you can still use Your privacy choices to turn analytics off.
- Limit use of sensitive personal information. We use your login only to sign you in, which is already the limit the law allows.
- Non-discrimination. Using these rights never changes your price or service.
How to make a request
Use Settings → Account to download or delete your data, or email support@assio.net. We verify requests by matching them to your account email, and respond within 45 days (extendable once by another 45 when needed, with notice).
Authorized agents may make a request for you with your signed permission. We may ask you to confirm your identity with us directly.
Global Privacy Control. We honour the GPC browser signal as an opt-out: analytics stays off and we don’t ask.
Automated decisions
Assio scores pages and suggests changes automatically, but makes no decisions about you that have legal or similarly significant effects.
Children
Assio is a business tool and is not meant for anyone under 16. We don’t knowingly collect their data; if you think we have, email support@assio.net and we will delete it.
Security
Data travels over encrypted connections (TLS) and is encrypted at rest by our hosting and database providers. Passwords and API keys are stored only as hashes, connection secrets stay on our servers, and workspace data is visible only to that workspace’s members. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authorities as the law requires.
Changes to this policy
We update this page when our practices change and show the date at the top. Please check back from time to time. Last updated 4 October 2026.