GEO SEO SuperApp
Desktop and browser extension privacy policy
Last updated: July 10, 2026
1. Scope
On-Page ("we", "us", or "our") provides GEO SEO SuperApp, a free macOS desktop application and optional Chrome, Microsoft Edge, and Brave extension. This policy covers those clients. Use of api.on-page.ai is also governed by the separate On-Page API privacy policy.
2. Local application data
Projects, conversations, run receipts, crawler results, Search Console caches, browser-flow history, indexation observations, social drafts, and recipe outcome measurements are stored on your Mac. Credentials, OAuth tokens, browser pairing secrets, and connected-site secrets are stored in macOS Keychain rather than in application preferences or SQLite.
The SuperApp does not include advertising trackers and does not automatically upload your local workspace, crawl history, browser-flow history, Search Console cache, or recipe measurement ledger to On-Page.ai. Measurement exports are created only when you request one and can include an On-Page organization identifier for an authorized internal subscription analysis.
3. OpenAI Codex and connected providers
The app runs OpenAI Codex using the ChatGPT account or API key you choose. Prompts, attachments, selected page content, and tool inputs and outputs needed for a task are processed by OpenAI under your OpenAI account and its applicable settings and terms.
Optional MCP, data, and publishing providers receive data only when you connect them and run a task that calls their tools. This may include URLs, keywords, page content, browser observations, Search Console observations, or approved social copy. Their own privacy and retention terms apply. Non-On-Page providers remain optional.
4. Google Search Console data
When you connect Google Search Console, the desktop app requests permission to read your verified properties, performance rows, URL inspection results, and sitemaps. Sitemap submission is an optional separate permission and requires an explicit action. OAuth and service-account credentials are stored in macOS Keychain and are sent only to Google authentication and Search Console endpoints.
Search Console observations are cached locally so you can review opportunities and run SEO workflows. Query-level daily rows older than 120 days are aggregated, and dated analytics older than 16 months are deleted. When you ask Codex to analyze Search Console data, the selected observations may be included in the OpenAI request. Disconnecting revokes access on a best-effort basis, removes the local credential, and deletes that account's cached Search Console data.
5. Browser extension
The extension connects to the desktop broker on 127.0.0.1. During an approved browser task it can inspect tabs, URLs, visible text, links, interactive elements, and screenshots, and can perform visible navigation, clicks, typing, scrolling, and other requested actions. The extension does not independently send page data to a remote service.
Browser output selected by a task may be passed by the desktop app to OpenAI or another provider you connected. Cookies, saved passwords, and browser password stores are not intentionally exported. A per-profile pairing token is stored in extension local storage; its counterpart is stored in macOS Keychain. You can reset the extension profile or revoke a pairing in the app.
6. Connected sites, On-Page.ai, and social publishing
On-Page.ai receives the URLs, keywords, page data, and job details needed for scans you request. Hosted scheduled scans additionally store the schedule, budget, run state, and notification settings in your On-Page API workspace. On-Page API billing and server retention are described in the main platform privacy policy.
Connected WordPress and SSH tools can use Keychain credentials locally without returning the secret in normal tool output. If you explicitly ask the AI agent to retrieve a stored credential using the generic credential tool, that credential enters the Codex tool session and may be processed by OpenAI. Social publishing sends approved copy and media only to the exact Postiz-compatible server and accounts you select; drafts and receipts remain local.
7. Sharing, sale, and use
We do not sell SuperApp or extension data and do not use Google user data for advertising. Data is shared only with services you connect or direct the app to use, infrastructure needed to deliver On-Page API features, or when required by law. We do not use your Search Console data or page content to train our own machine learning models without explicit opt-in consent.
8. Retention and controls
- Delete local projects, drafts, runs, crawls, and exports from your Mac.
- Disconnect Google Search Console to revoke credentials and clear its local cache.
- Revoke browser pairings and optional provider connections at any time.
- Delete your On-Page API account through its account controls or support process.
Provider-side copies and retention are controlled by the provider that processed the request. Local backups may retain deleted app data according to your own macOS backup settings.
9. Security and children
We use TLS for network connections, macOS Keychain for secrets, authenticated browser pairing, scoped provider permissions, and explicit approval gates for sensitive writes. No security method is perfect. GEO SEO SuperApp is not intended for children under 16, and we do not knowingly collect their personal information.
10. Your rights and contact
Depending on your jurisdiction, you may request access, correction, export, or deletion of personal data we control. For privacy questions or requests, email privacy@on-page.ai. We may update this policy as the app changes and will revise the date above when we do.