Privacy policy

Effective July 24, 2026

Who we are

Sightkick (sightkick.so and app.sightkick.so) is operated by Sprike LLC, 8 The Green, STE R, Dover, DE 19901, United States. Questions about this policy or your data: hello@sightkick.so.

What we collect

  • Account information — your name, email address, and profile photo, provided when you sign up (directly or via Google sign-in) and managed by our authentication provider, Clerk.
  • Workspace data you provide — your website address, business description, products and services, content preferences, and anything else you enter into the product.
  • Google Search Console data — only with your explicit permission, described in the next section.
  • Payment information — handled entirely by Stripe. We never see or store your card details; we keep only your subscription status and a Stripe customer reference.
  • Usage analytics — how our marketing site and the app are used: pages viewed, referrers, and which steps of setup you reach. Our marketing-site measurement is cookieless; our product analytics sets a first-party cookie on sightkick.so so we can tell one visit from the next. We never track you across other companies' websites, and we don't sell or share this data with advertisers.
  • Session recordings — we record how the app is used (clicks, navigation, and page content) to debug problems and improve it. Everything you type is masked before it leaves your browser, so recordings never contain passwords, API keys, or CMS credentials.

Google user data

If you connect Google Search Console, we request the read-only scope webmasters.readonly via Google OAuth. With it we access the list of sites verified in your Search Console account and the search performance of the site you connect: queries, clicks, impressions, and average positions.

We use this data solely to provide features you see in the product — your search performance dashboard and the prioritization of keywords and articles for your own website. Performance metrics are stored in our database (hosted on Convex, in the United States) so your dashboard loads fast and shows history. OAuth tokens are managed by Clerk; our servers use short-lived access tokens and never store your Google password.

We never sell Google user data, never share it with third parties except the infrastructure providers listed below, never use it for advertising, and do not use it to develop or train AI or machine learning models.

Sightkick's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google Search Console at any time in the product or revoke Sightkick's access at myaccount.google.com/permissions. On request we delete the Search Console data we have stored — email hello@sightkick.so.

How we use information

To provide and improve the service: researching keywords for your site, generating and publishing content you commission, showing your search performance, sending transactional email (sign-in codes, billing receipts), and answering support requests. We send your website content and keywords — not your personal account data — to the AI providers listed below to generate your articles.

Service providers

We share data only with the providers that run the service, each receiving the minimum it needs:

  • Clerk — authentication and OAuth token management
  • Convex — database and backend hosting
  • Vercel — web hosting
  • Stripe — payments and billing
  • Google — sign-in and Search Console (at your request)
  • Anthropic, OpenAI, and Google — AI content generation; they receive your website content and keywords, not your personal account data
  • DataForSEO — search market data; receives keywords and domains only
  • ScreenshotOne and Firecrawl — fetching and screenshotting public web pages referenced in your articles
  • DataFast — cookieless marketing-site analytics
  • PostHog — product analytics and session recordings; receives your account email and workspace name so we can tell accounts apart

Retention and deletion

We keep your data while your account is active. If your subscription lapses we retain your workspace so you can pick up where you left off if you return. You can request deletion of your account and all associated data at any time by emailing hello@sightkick.so — we complete deletion requests within 30 days.

Security

All data is encrypted in transit. Access to production systems is limited and credential-protected, and CMS publishing credentials you give us are stored encrypted.

Your rights

You can access, correct, export, or delete your personal data — email us and we'll help. Depending on where you live (for example the EU/EEA under GDPR, or California under CCPA), you may have additional statutory rights; we honor them.

Children

Sightkick is a business tool and is not directed at children under 16. We do not knowingly collect data from them.

Changes

If we make material changes to this policy we'll update the effective date above and, for significant changes, notify you by email or in the product.

Contact

Sprike LLC, 8 The Green, STE R, Dover, DE 19901, United States — hello@sightkick.so