Information We Collect
We collect information that you provide, information generated when you use Scorivra, and information received from services you choose to connect.
- Account and authentication information: identifiers used to operate your account and session, including the email address associated with your account.
- Sites and business information: websites, domains, business profiles, locations, keywords, prompts, and other assets that you register, configure, or ask Scorivra to analyze.
- Service and diagnostic data: audit results, measurements, reports, feature usage, job status, errors, and other data needed to provide and troubleshoot the Service.
- Technical data: server and security logs and information ordinarily included in web requests, such as IP address, browser and device type, operating system, request time, and referring URL.
- Payment and subscription data: plan, subscription status, transaction and provider identifiers, billing email and name, and related records. Payment card details are collected and processed by Lemon Squeezy through its hosted checkout; Scorivra does not directly store full payment card numbers.
- Google connection data: Google account subject identifier and email, granted scopes, encrypted OAuth refresh credentials, the GA4 properties and Search Console sites you select, and read-only performance data retrieved for those selected assets.
Scorivra also uses cookies or similar browser storage that are necessary for authentication, security, preferences, and the short-lived Google OAuth connection flow.
Google API Data
Scorivra requests only the following Google OAuth scopes for its Google performance integration:
openidemail(Google may represent this permission asuserinfo.email)https://www.googleapis.com/auth/analytics.readonlyhttps://www.googleapis.com/auth/webmasters.readonly
Access to Google Analytics 4 and Google Search Console is read-only. We use Google API data to display and analyze GA4 and Search Console performance, track changes in site performance, and provide dashboards and reports.
Scorivra does not modify Google Analytics data or Google Search Console data. We do not sell Google user data, use it for advertising targeting, or use it beyond what is necessary to provide and improve the user-facing features you request.
Scorivra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How We Use Information
We use information to authenticate users; operate accounts and subscriptions; register and analyze sites; provide AI Visibility, Google Maps Rankings, Site Audit, performance analytics, dashboards, reports, and data exports; synchronize connected data; communicate service and report information; monitor reliability and security; prevent abuse; enforce our terms; and comply with applicable law.
We may aggregate or de-identify information for service analytics and benchmarking where the result does not reasonably identify you or your registered site. Scorivra's public benchmark does not publish individual domains.
Data Storage and Security
Scorivra uses HTTPS in transit, authentication and authorization checks, and access controls intended to limit service data to authorized users and service processes. Google OAuth refresh tokens are encrypted before database storage using authenticated encryption. Short-lived Google access tokens are used to make requested API calls and are not stored as persistent account credentials by Scorivra.
No method of transmission or storage is completely secure. We use safeguards appropriate to the Service and process data only to the extent needed for the purposes described in this Policy, but we cannot guarantee absolute security.
Data Retention
We retain account, subscription, registered-site, measurement, audit, and report data while needed to provide the Service, maintain legitimate business and security records, resolve disputes, and comply with legal obligations. Retention depends on the type of data, account status, selected plan, feature history, and applicable legal requirements; we do not apply a single fixed retention period to every category.
Google OAuth connection credentials are retained while the connection is active. When the last site using a Google connection is disconnected, Scorivra requests revocation of the Google token and deletes the stored OAuth connection credential. Previously synchronized GA4 or Search Console metrics may remain as service data for the registered site until the site or related data is deleted, a valid deletion request is completed, or continued retention is required by law.
When data is no longer needed, we delete, de-identify, or securely isolate it as appropriate. Limited records may remain in backups or logs until those systems are cycled or when retention is required for security, fraud prevention, billing, dispute resolution, or legal compliance.
Google Account Disconnection
You can disconnect a site's Google integration from the Scorivra dashboard. Disconnecting removes that site's active connection. If no other site uses the same Google connection, Scorivra requests token revocation from Google and deletes the stored OAuth connection and refresh-token credential.
You can also revoke Scorivra's access in your Google Account permissions. Revocation stops future API access but does not by itself erase service data previously synchronized into Scorivra. You may separately delete a registered site or request deletion as described under User Rights.
Service Providers and Third Parties
Scorivra uses the following providers where needed to operate the Service:
- Clerk for account authentication and session management.
- Supabase PostgreSQL for application data storage and scheduled database operations.
- Vercel for application hosting and server runtime infrastructure.
- Lemon Squeezy as the hosted checkout, payment processor, subscription platform, and Merchant of Record. Lemon Squeezy receives payment and billing details under its own privacy terms. Scorivra receives limited transaction and subscription records and does not directly store full card numbers.
- Google for the optional OAuth, Google Analytics 4, and Google Search Console integrations you authorize.
- DataForSEO for search, AI visibility, Google Maps, business, and related measurement operations. Queries, keywords, locations, site or business identifiers, and measurement inputs may be sent when those features are run.
- Resend for delivery of service emails such as monthly reports when email delivery is enabled.
These providers process information on our behalf or under their own terms, depending on the service. Their processing may occur in countries other than your own.
Data Sharing
We do not sell personal information or Google user data. We share information only with service providers that help operate requested features; at your direction, such as when you connect a service or export data; to protect users, Scorivra, or the public; to investigate abuse or security incidents; to comply with law or a valid legal process; or as part of a merger, financing, reorganization, or transfer of the Service, subject to appropriate protections.
We do not share Google user data for personalized or targeted advertising.
User Rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information. You may update certain account and site information in the Service, delete registered sites, and disconnect Google integrations from the dashboard. You may also revoke access through your Google Account.
For a request that cannot be completed through the Service, use the contact method described below. We may need to verify your identity and authority before acting. Some information may be retained where required or permitted by law.
Children's Privacy
Scorivra is a business-oriented service and is not directed to children. A person who cannot lawfully consent to the processing described in this Policy may use the Service only with authorization from a parent, guardian, or other person permitted by applicable law. If you believe a child has provided personal information without appropriate authorization, contact us so we can review and take appropriate action.
Changes to This Privacy Policy
We may update this Policy to reflect changes to the Service, providers, or legal requirements. We will post the revised version at this URL and update the effective date. Where required by law or appropriate for a material change, we will provide additional notice.
Contact
For privacy questions or requests, contact Scorivra through the official support or contact method made available within the Service or on https://scorivra.com. Scorivra does not publish a dedicated privacy email, business address, or telephone number in the Service as of the effective date of this Policy.