Back to home
Legal

Privacy Policy

How we collect, use, store, and protect your data - written in plain English, not legalese.

Last updated: 2026-06-29

1. Who we are

Klimb is an agency-managed SEO command dashboard operated by GoodLives. When this policy says “we” it means GoodLives acting as data controller for your Klimb account, and data processor for the website data you connect (GA4, GSC, Apify, AI provider keys).

Data protection contact: sakshi@goodlives.in

2. What we collect

Only what the product needs to run. Specifically:

Account data

  • Email, display name, hashed password (or Google-OAuth identifier)
  • Role (super_admin / admin / member / client) and project memberships
  • Profile preferences (active project, theme)

Project data

  • Website domain, industry, target keywords you enter
  • Crawled page metadata (URL, title, H1, audit findings)
  • Optional Google Analytics 4 Property ID + Search Console Property URL (read-only OAuth service account)

Audit & analytics data

  • Apify-returned SERP rankings, AI Overview citations, backlink profile, Domain Authority, content gaps
  • GA4 page view aggregates + GSC search query aggregates - we never store individual-user analytics
  • Pillar scores, tasks, wins, CWV snapshots

AI feature data (Claude / OpenAI)

Klimb's AI features (article generation, E-E-A-T analysis, keyword and topic suggestions, research chat) run on Klimb's own Anthropic (Claude) and OpenAI accounts by default, metered as “AI credits” against your plan. When you use one of these features, the prompt and the content you ask us to process - for example page text, target keywords, article briefs, or your chat messages - are sent to Anthropic and/or OpenAI through Klimb's provider accounts to generate the output. Because we automatically fail over between providers for reliability, your content may be processed by either Anthropic or OpenAI on a given request. We do not sell your data and we do not use it to train Klimb's own models; the providers' handling of API content is governed by their own terms (linked under Sub-processors below).

Optional BYOK (bring your own key):instead of Klimb credits you may add your own Claude or OpenAI key under Settings → Integrations. If you do, that feature calls the provider on your own account, and your key is stored only in your browser (see below).

What we do NOT collect or store server-side

  • Your own (BYOK) Claude / OpenAI API keys - the optional BYOK path stores your key only in your browser and passes it through a single server request to the provider; it is never written to our disk, logs, or database. You can remove it any time from Settings, which reverts that project to Klimb credits.
  • Payment card numbers - billing is handled by Razorpay (PCI-DSS Level 1 certified). Card data is tokenized at Razorpay; we only see a non-sensitive payment token + invoice metadata.
  • Marketing cookies or third-party analytics trackers

3. Why we collect it (legal basis, GDPR)

  • Contract (Art. 6(1)(b)): account data, project data, and AI features you invoke on Klimb credits - required to operate the service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): audit findings + aggregated analytics - used to compute pillar scores and surface SEO recommendations.
  • Consent (Art. 6(1)(a)): optional integrations you connect yourself (GA4, GSC, and your own BYOK AI key) - you authorize each separately.

4. Sub-processors

The following vendors handle your data on our behalf:

  • Supabase - hosted Postgres + auth. SOC 2 Type II certified. privacy policy.
  • Vercel - Next.js hosting + edge network. SOC 2 Type II. privacy policy.
  • Apify - web scraping for SERP / backlinks / content-gap / PAA discovery. privacy policy.
  • Razorpay - payment processor for paid subscriptions; receives card details + billing address directly via the hosted checkout, returns a tokenized reference and invoice metadata to us. PCI-DSS Level 1. privacy policy.
  • Google (GA4, Search Console, PageSpeed Insights) - only when you connect a service-account key. privacy policy · DPA.
  • Anthropic (Claude) - processes the prompts + content you submit to AI features. Used by default through Klimb's own account (metered as AI credits), or on your own account if you add an optional BYOK key. privacy policy · commercial terms.
  • OpenAI - processes the prompts + content you submit to AI features. Used by default through Klimb's own account (metered as AI credits), or on your own account if you add an optional BYOK key. privacy policy · business terms.

DPA (Data Processing Agreement) available on request - email the address above.

5. Where your data lives

Primary region: Supabase cluster in the chosen region (typically Mumbai / ap-south-1 for India-based projects). Vercel edge network serves static assets globally. Google & Apify data residency follows their default regions based on your account.

When you use AI features, the prompts + content you submit are processed by Anthropic and/or OpenAI on their own infrastructure, which may be outside India and the EU (primarily the United States) - whether you use Klimb credits or your own BYOK key. We rely on those providers' data-processing terms for that transfer, and a Data Processing Agreement covering it is available on request.

6. Retention

  • Audit findings: last 30 days of detailed findings (older pruned automatically). Pillar-score snapshots retained indefinitely.
  • Task + article data: retained until you delete the project or the task.
  • Account data: retained while your account is active + 30 days after deletion for backup rollover, then hard-deleted.

7. Your rights (GDPR / DPDP)

You have the right to:

  • Access - export a full JSON copy of your account + project data (Settings → Profile → Export my data).
  • Rectification - update your profile + project fields any time from the dashboard.
  • Erasure - permanently delete your account and cascade-delete your projects (Settings → Profile → Delete my account).
  • Portability - the export is a machine-readable JSON you can re-ingest elsewhere.
  • Object - opt out of any processing you don't consent to by disconnecting the relevant integration.
  • Complain - to your local data protection authority. For India: the Ministry of Electronics & Information Technology (parent of the Data Protection Board of India established under the DPDP Act 2023; the Board's standalone portal is being set up). For EU: your national DPA.

Requests handled within 30 days. Most can be executed from the dashboard in one click.

8. Security

TLS 1.3 in transit, AES-256 at rest (Supabase-managed). Row-Level Security policies enforce multi-tenant isolation for every table. AI features run on Klimb's own provider keys by default; an optional BYOK key stays in your browser and never rests on our servers. See the security page for details.

9. Cookies

We use first-party cookies only: a session cookie (auth) and an active-project cookie (remember which project you last opened). No marketing or third-party tracking cookies.

10. Children

Klimb is not directed to users under 16. We don't knowingly collect data from children.

11. Changes

Material changes posted here with the “last updated” date bumped. If the changes affect your rights, we'll email active users.

12. Contact

Questions, complaints, or DPA requests: sakshi@goodlives.in

GoodLives
3212, DLF Phase 4, Gurugram, Haryana 122002, India