1. Who we are and what this covers
Projark is operated by Mission SEO.
- Contact for privacy questions — momin@missionseo.com
- Sites covered — projark.com and app.projark.com
- Who this is for — the business owners, project managers, writers, specialists and clients who use Projark, plus anyone who visits our marketing site or submits feedback.
Throughout this policy, "you" means whoever is reading it — an account holder, a workspace member, or a visitor. "Customer" means the individual account that owns a Workspace, together with the organisation they act for. The workspace owner is the person who exercises the Customer's control inside the product, and is the person whose instructions we act on for that workspace's content.
2. Information we collect
2a. Account information
When you create an account or are invited into a workspace, we collect and store:
- Your email address
- Your display name
- Your password, hashed and stored by Supabase Auth — we do not store your plaintext password and it is never written to our database
- Your Google identity, if you sign in with Google OAuth
- Account creation time and last sign-in time
Invitations. If someone invites you to a workspace or project, we receive your email address from them before you have an account, store it against the pending invitation, and email you an invite from noreply@projark.com. If you don't want to accept, email us and we'll remove the pending invitation and the address with it.
2b. Content you put into Projark
- Workspaces, client company names and websites, and projects
- Topics, tasks, comments, project notes, milestones, project chat messages and project links
- File uploads
- Per-user activity inside a project — which projects you've visited and which you've starred
- Keyword research, content strategy analyses, tracked AI-search prompts, competitor registries and rank-tracking history
- Website "context layer" profiles, which we build by crawling the website the customer designates
Some of this is created by you directly; some is generated by Projark from inputs you provide (see Section 5).
2c. Data we retrieve from services you connect
Projark can connect to third-party services on a per-project basis. Nothing is connected unless someone on your team initiates it and completes the authorisation. The available connections are Google Search Console, Google Analytics 4, Google Ads and Google Docs (OAuth); Bing Webmaster Tools (API key); HubSpot (service key); and Salesforce (OAuth).
Once connected, we retrieve and display:
- Search queries, impressions and clicks
- Sessions, conversions and landing pages
- Ad campaign performance
- CRM contacts, deals, leads, opportunities and revenue figures
- The text of a Google Doc that has been explicitly linked to a task
We request the scopes each feature needs and retrieve the data used to render the reports and features in the product. Some providers grant access at a broader scope than a single feature requires; you can review exactly what you granted, and revoke it, in the provider's own third-party access settings.
A note on other people's data. Data pulled from a connected CRM in particular usually contains personal data about individuals who have never used Projark — your clients' contacts, leads and opportunity owners. We hold that data as processor, on the workspace owner's instructions, and we cache it to render the reports in the product. It is removed when the project or workspace holding it is deleted (Section 11); we do not run a separate retention timer on it. If one of those individuals asks us about their data, we will refer them to the workspace owner, who is the controller.
2d. Feedback submissions
The feedback form in the application at app.projark.com — available there whether or not you're signed in to an account — collects your comment, up to five optional images (PNG or JPG, max 5MB each, validated by file signature), and automatically collected context about the page and session the submission came from. It is protected by Cloudflare Turnstile, a CAPTCHA service.
Submissions are stored in a private storage bucket and emailed to momin@missionseo.com. That email copy travels through our transactional email provider and then sits in a Mission SEO mailbox. It is a separate copy: it is not covered by the private-bucket storage controls in Section 10, it is not removed when a workspace or project is deleted, and it is retained until we delete it on request. Please don't put credentials or sensitive personal data in the feedback box. Email us if you want a submission removed.
2e. Billing information
Payments are processed by Stripe. Card details are entered into Stripe's Checkout and Customer Portal — they are handled entirely by Stripe and are never stored on Projark's servers.
What we do store: your Stripe customer ID, your subscription status and plan, invoices, and a credit ledger for metered AI-usage overage.
Our plans are Free ($0), Pro ($299/month) and Max ($499/month), plus metered AI-usage overage credits. A plan is per-person and applies to every workspace that person owns. If you work in someone else's workspace, that workspace runs on its owner's plan — which means the owner, not you, is the billing party for that workspace's usage.
2f. Technical and usage data
- Authentication and session data — needed to keep you signed in and enforce access rules.
- Usage and cost ledger (
usage_events) — we record AI and API operations per workspace, with their cost, so we can meter usage, bill accurately and debug problems. - Standard operational data generated by hosting and running the service, such as request and error logs held by our hosting and infrastructure providers.
3. Controller and processor — who's responsible for what
For customer content and connected-service data (2b and 2c), the Customer is the controller and Projark is the processor. The Customer, acting through the workspace owner, decides what data goes into Projark and why, and controls its removal using the project and workspace deletion tools described in Section 11. Retention is subject to the exceptions in Section 11 — invoices and usage/cost ledger events are kept after workspace deletion for accounting — and we do not offer configurable retention periods or automated deletion schedules. We don't decide to use their client data for our own purposes.
Practically: if you're a client user or a writer invited into someone else's workspace and you want data corrected or removed, the workspace owner is the right first contact. They control it; we act on their instructions.
For account data and billing data (2a and 2e), Projark is the controller. We decide why we hold your email address, sign-in times and payment records — because we need them to give you an account, secure it, and bill for it. You can come to us directly about that data.
For technical and usage data (2f), Projark is the controller. Authentication and session data, the usage and cost ledger, and operational logs are held because we need them to secure, meter, bill and debug the Service. That is also why ledger events are retained after a workspace is deleted (Section 11).
Feedback submissions (2d) are held by Projark as controller, since you're sending them to us directly.
On data processing agreements. We do not currently offer a separately signed Data Processing Agreement. This policy, together with our Terms of Service, is the document that describes and governs our processing. If your client engagement requires a signed DPA, standard contractual clauses, or a specific processing instrument, email us and we will tell you plainly what we are and are not able to sign today.
4. How we use information
- Run the service — authenticate you, show you the right workspaces and projects, enforce who can see and do what, deliver notifications and invites.
- Generate the analyses you asked for — keyword research, content strategy, competitor and AI-search analysis, rank tracking and website context profiles. This involves sending content to AI providers; see Section 5.
- Retrieve and display data from services you connected — pulling search, analytics, ads, CRM and document data into the reports and views in the product.
- Bill you — process subscriptions through Stripe, meter AI and API usage, issue invoices, and manage overage credits.
- Support you — respond to your emails and feedback submissions, and investigate problems you report.
- Keep the service secure and working — investigate abuse or unauthorised access when it is reported to us or comes to our attention, log privileged staff actions, debug errors, and maintain the platform.
We do not sell your data. We do not use customer content for advertising, and we do not run advertising or cross-site tracking on our sites.
Staff access
A small number of Mission SEO staff can access workspace content and account records where it is needed to operate the service, respond to a support request, investigate abuse or a suspected security incident, or comply with law. Staff also have internal tooling that can suspend or delete a user account (see Section 11). Admin routes are hidden from non-staff, and every privileged staff action is written to an append-only audit log. That log covers privileged administrative actions; it is not a complete record of every occasion on which a staff member views customer content while providing support or debugging. We do not browse customer content for any other reason.
5. AI processing — read this one
Projark's core features send your content to third-party AI providers. This is not incidental; it's how the product works.
Who processes it
- Anthropic (Claude)
- OpenAI (GPT)
What gets sent to them
- Keywords and keyword research inputs
- Tracked AI-search prompts
- Text scraped from the website you designated
- Competitor names and domains
- SERP result titles and URLs
- Task and topic titles and briefs
- The text of a Google Doc that has been explicitly linked to a task
Live web searches
Some AI calls use the providers' built-in web-search tools. When that happens, live web searches are issued as part of generating your result, and query text derived from your content leaves our infrastructure. The search engines and websites reached that way are selected by the AI provider, not by us.
AI output is not guaranteed to be correct
- Outputs are AI-generated and may be wrong, incomplete or misleading.
- Outputs are non-deterministic — the same input can produce different answers on different runs.
- Our AI and AEO ranking features are directional, not position-exact. Treat them as signal, not measurement.
Don't rely on AI output as a factual record without checking it, and don't present it to your clients as verified data.
Training and retention by the AI providers
Projark does not train models on your content, your clients' content, or your connected-service data. We don't have our own models. We send your content to Anthropic and OpenAI only to produce the output you requested.
We cannot make promises on those providers' behalf. What Anthropic and OpenAI retain, for how long, whether it is reviewed by humans, and whether inputs may be used to improve their models is governed by their own terms and the plan we hold with them. We have not obtained, and do not claim, a zero-retention or no-training commitment from either provider, and we have not independently audited them. If a client engagement requires a specific commitment on this point, email us before enabling AI features.
Also relevant
DataForSEO is used to retrieve SERP and keyword data. Keywords and search parameters derived from your content are sent to DataForSEO to fulfil those requests.
6. Connected services and how credentials are handled
When you connect Google, Bing, HubSpot or Salesforce, we store the credential needed to keep the connection working — an OAuth refresh/access token, or the API/service key you supplied.
How they're protected:
- Credentials are encrypted with AES-256-GCM, using an encryption key held separately from the database credentials.
- Credential columns are locked at the database level so browser-tier clients cannot read them. They are only usable server-side.
- OAuth flows are protected against CSRF using an httpOnly state cookie plus nonce verification.
Two limitations you should know about, because they're real:
- Credentials are project-scoped, not user-scoped. Once a credential is stored for a project, the server uses it on behalf of any member of that project who views the connected reports — and also on its own, from scheduled background jobs that refresh data such as rank-tracking history while nobody is signed in. Connecting an integration effectively shares access to that data with everyone on the project.
- Credentials persist until someone disconnects the integration. If the person who connected an integration is removed from the project, their stored credential stays in place and keeps working until a current project member explicitly disconnects it. Removing someone from a project does not revoke the connection they set up.
If someone leaves your team, disconnect the integrations they connected — or revoke Projark's access from the provider's own side, for example in your Google account's third-party access settings.
Google user data and Limited Use
Projark's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
These are the Google permissions Projark can request, and what each one is used for:
-
Google Search Console —
https://www.googleapis.com/auth/webmasters.readonly
Reads search queries, impressions, clicks and average position for the site property you select, to show search performance and branded-vs-unbranded demand in your project dashboard and reports. -
Google Analytics 4 —
https://www.googleapis.com/auth/analytics.readonly
Reads sessions, conversions, conversion rate and landing-page performance by channel for the property you select, to show traffic and conversion results alongside the work in the project. -
Google Ads —
https://www.googleapis.com/auth/adwords
Reads campaign and conversion performance for the account you select, to report paid results next to organic. Note: the Google Ads API does not offer a read-only scope —adwordsis the only scope available, so that is what Projark requests. Projark issues reporting queries only, and never creates, edits, pauses or deletes campaigns, ad groups, budgets, keywords or any other Google Ads entity. -
Google Docs —
https://www.googleapis.com/auth/documents.readonly
Reads the text of a single Google Doc that a user has explicitly linked to a task, so AI-assisted output for that task is grounded in the real draft. Projark does not browse, list or open any other file in your Drive. -
Signing in —
userinfo.email,userinfo.profile
Reads your name, email address and profile picture to create and identify your Projark account and send you service email such as invitations and password resets.
Onward transfer of Google user data. The only Google user data Projark sends to a third party is the text of a Google Doc you have explicitly linked to a task, which is transmitted to our AI processors — Anthropic and OpenAI — solely to generate the output you requested (see Section 5). No Search Console, Analytics, or Google Ads data is sent to any AI provider. Projark has no AI models of its own and does not train any model on your data. As described in Section 5, we cannot make commitments on those AI providers' behalf about their own retention practices.
Revoking access. Any current member of a project can disconnect a Google account inside Projark at any time. If you no longer have access to that project, you can revoke Projark's access directly from your Google Account at myaccount.google.com/permissions, which takes effect immediately.
Projark does not sell Google user data, does not use it for advertising or ad targeting, and does not use it for any purpose other than providing and improving the user-facing features described above.
7. Crawling your website
To build the website "context layer" profile, Projark fetches pages from the website the customer designates for analysis, and reads publicly available search results.
- Our crawler sends a Chrome user-agent.
- We can also send a per-project verification header, which you can allowlist in your own Cloudflare configuration so our requests aren't blocked.
We do not crawl competitors' or other third parties' websites. Competitor analysis uses the competitor names and domains you enter, public SERP data, and data from DataForSEO. Separately, and as described in Section 5, some AI features use the providers' built-in web-search tools, which issue live searches against the open web using terms derived from your content.
8. Subprocessors
These are the third parties that process data on our behalf. This is the complete list as of the "Last updated" date at the top of this policy; see Section 15 for how we notify you when it changes.
Always in use:
- Supabase — database, authentication, file storage and realtime infrastructure.
- Sevalla — hosting for the application and the marketing site.
- Resend — transactional email (invites, password resets, notifications, and delivery of feedback-form submissions), sent from noreply@projark.com.
- Cloudflare — Turnstile CAPTCHA on the feedback form.
- Trigger.dev — background job workers.
- Anthropic — AI processing.
- OpenAI — AI processing.
- DataForSEO — SERP and keyword data.
- Stripe — payment processing.
Only when you connect them:
- Google — Search Console, Analytics 4, Ads and Docs data.
- Microsoft (Bing Webmaster Tools) — search data.
- HubSpot — CRM data.
- Salesforce — CRM data.
One caveat on completeness. Where an AI feature uses a provider's built-in web-search tool (Section 5), Anthropic or OpenAI issue live searches and retrieve public pages as part of producing your result. The search engines and websites reached that way are selected by the AI provider, not by us, and we have no contract with them. The list above is complete for the providers Projark itself engages.
9. Cookies and local storage
We use a small number of cookies, all functional. The cookies we set are:
- Authentication cookies — httpOnly, scoped to app.projark.com. These keep you signed in. Without them the app doesn't work.
- OAuth state cookies — short-lived (10-minute TTL), used for CSRF protection while you're completing a third-party connection flow.
- Preference cookies — remember interface choices such as a dashboard's selected date range and delta display mode.
- Cloudflare Turnstile — when the feedback form is shown in the application at app.projark.com (including to logged-out visitors there), Cloudflare's CAPTCHA script runs in your browser to check you're not a bot, and may set its own short-lived storage. It is used for that check only, is set by Cloudflare rather than by us, and is governed by Cloudflare's own notice.
We also use browser localStorage for UI preferences: chart colours, column choices, and grid-vs-list view. That data stays in your browser.
Apart from the Turnstile CAPTCHA above, there are no advertising cookies, no cross-site tracking cookies, and no third-party analytics tag on the marketing site. We don't track you across other websites, and we don't sell or share data with ad networks.
10. Security
Here's what we actually do. No certifications are claimed.
- Row-level security enforced on every database table, so access rules are applied at the data layer rather than only in application code.
- AES-256-GCM encryption of all stored third-party credentials, with an encryption key held separately from the database service key.
- Column-level permission revokes on credential columns, so browser-tier clients cannot read them at all.
- OAuth CSRF protection via an httpOnly state cookie plus nonce verification.
- Server-side capability checks re-validated on every privileged action — the browser is never trusted to decide what you're allowed to do.
- Invite privilege ceiling — you cannot grant anyone a role or capability higher than your own.
- File upload validation — uploads are checked by magic bytes (not just file extension), size-capped, and stored in private buckets.
- Admin routes masked as 404 to anyone who isn't staff.
- Append-only audit log of privileged staff actions.
- Passwords hashed by Supabase Auth. Card details handled entirely by Stripe.
If we have a security incident. If we become aware of unauthorised access to personal data or customer content, we will notify affected workspace owners by email at the address on the account, without undue delay, describing what we know, what data was involved, and what we are doing about it. We notify the workspace owner rather than each member, because they are the controller for that workspace's content.
No system is perfectly secure. If you believe your account or workspace has been compromised, email momin@missionseo.com immediately.
11. Data retention and deletion
We've written this section precisely, including the parts that are manual rather than automated.
What you can delete yourself
- A workspace owner can delete their own workspace from within the app, using a type-to-confirm step. This cascades and removes workspace memberships, clients, projects, topics, tasks, comments and associated file storage. It does not delete the accounts of the people who were members — those accounts continue to exist independently.
- A project can be deleted, cascading its data and associated file storage.
Records attached to a deleted project — notes, milestones, chat messages, links, keyword research, content strategy analyses, AI-search prompts, competitor registries, rank-tracking history, website context profiles, and per-user visit and star records — go with the project they belong to. We have not documented deletion behaviour category-by-category beyond this; if you need written confirmation that a specific category has been removed for a client engagement, email us and we'll check and tell you what we find.
What survives workspace deletion
- Invoices — retained, with the workspace reference removed, for accounting.
- Usage and cost ledger events — retained for accounting.
- User accounts — deleting a workspace does not delete anyone's individual account or their account data (email, display name, sign-in times).
- Audit log entries recording privileged staff actions, and feedback submissions, which are held outside workspace storage and are not touched by workspace deletion.
- Copies already transmitted to third-party providers — content sent to AI or data providers, and email delivered through our transactional email provider, is outside our control and cannot be recalled by us.
Deleting an individual user account
There is no self-serve "delete my account and all my data" button yet. To have an account deleted, email momin@missionseo.com and we'll handle it manually.
Note the constraint: our staff tooling blocks deletion of a user account if that user owns a workspace or has authored content (comments, topics, tasks). In that situation the account is suspended instead of deleted — the account can no longer be used, but the authored content remains so the workspace's history stays intact. If you want that content gone too, the workspace owner needs to delete the relevant projects or the workspace, or tell us what to remove.
What we don't have
To be straight with you: we do not operate automated data-retention schedules, automated erasure timers, or a self-serve privacy portal. Retention outside the cases above is manual and request-based. If you need specific retention commitments for a client engagement, email us and we'll talk about what's actually possible.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data.
How to exercise them
Email momin@missionseo.com. Tell us which account or workspace you're asking about and what you want done. We'll ask you to verify you control the account before we act on it, and we'll handle the request manually. There is no self-serve export; portability requests are fulfilled manually, in whatever format we can reasonably produce.
Which rights apply to which data
- Your account data and billing data — we're the controller, so come to us directly. Note that invoices and usage/cost ledger records are retained for accounting and tax purposes even after a workspace or account is deleted (Section 11), so a deletion request will not remove them.
- Feedback you submitted — we're the controller. Come to us directly.
- Content inside a workspace, and data from connected services — we're the processor and the Customer, acting through the workspace owner, is the controller. If you're a client user, a writer, or anyone else invited into someone else's workspace, contact that workspace's owner first. If they instruct us, we'll act on it. If you contact us directly about workspace content, we'll normally refer you to the workspace owner rather than acting unilaterally on their data.
A third-party connection can be withdrawn at any time by any current member of the project, by disconnecting the integration there. If you no longer have access to the project — for example because you were removed from it — you cannot disconnect it yourself: ask a remaining project member or the workspace owner to disconnect it, and/or revoke Projark's access from the provider's own settings (see Section 6).
13. International transfers
Projark and its subprocessors (Section 8) operate infrastructure and process data in various countries. That means your data — including account data, customer content, and content sent for AI processing — may be processed outside the country where you or your clients are located.
We choose established providers and rely on the protections in their own terms and infrastructure. We do not currently offer standard contractual clauses, transfer impact assessments, or other bespoke transfer mechanisms, and we do not claim any adequacy determination. If you need specific detail about where a particular subprocessor processes data for your engagement, email us and we'll tell you what we know.
14. Children
Projark is a business tool. It is not directed at children and is not intended for anyone under 16. We don't knowingly collect personal data from children.
If you believe a child has provided us with personal data, email momin@missionseo.com. We will remove it, subject to the constraints described in Section 11: an account that owns a workspace or has authored content is suspended rather than deleted, and content inside a workspace has to be deleted by the workspace owner or on their instruction.
15. Changes to this policy
We'll update this policy when the product changes — new subprocessors, new data flows, new features that handle data differently.
- The "Last updated" date at the top always reflects the current version.
- For material changes — a new category of data, a new subprocessor handling customer content, or a meaningful change in how we use data — we'll notify workspace owners by email at the address on their account, and/or show a notice in the app.
- Continuing to use Projark after a change takes effect means the updated policy applies to you.
16. Governing law
This policy forms part of our Terms of Service and is governed by the law identified in Section 17 of those Terms. Where this policy and the Terms conflict on a privacy matter, this policy controls.
17. Contact
For anything in this policy — questions, data requests, security concerns, or complaints:
- Email — momin@missionseo.com
- Operator — Mission SEO
- Product — Projark, at projark.com and app.projark.com
If you're a client user or team member invited into someone else's workspace, your fastest route for anything about that workspace's content is the workspace owner. For everything else, email us directly.