Privacy Policy

Last updated: 4 de setembro de 2026

This policy explains what Bora collects, why, and what we do with it. It covers the Bora web application at boraseo.com and the services it connects to on your behalf.

Who we are

Bora is an autonomous SEO content service. For any question about this policy or your data, write to [email protected].

What we collect

Account data: your email address and a hashed password. We never store your password in readable form.

Site data: the domain you add, its language, target country, and the brand details you enter during setup.

Connection credentials: API keys and tokens for the platforms you choose to connect, such as WordPress, Ghost, Webflow, Notion or HubSpot. These are stored so we can publish on your behalf and are never shown to anyone else.

Content we generate for you: article drafts, titles, keywords, cover images and their metadata.

Activity records: a log of what the system did for your site, such as when an article was generated or delivered.

Payment data: if you subscribe, our payment provider handles the card. We keep only the card brand, its last four digits and the expiry date, so you can see which card is on file. We never receive or store the full card number.

Google user data

If you connect Google Search Console or Google Analytics, you grant Bora read-only access. This section describes exactly what happens with that access.

Scopes requested: webmasters.readonly for Search Console and analytics.readonly for Analytics. Both are read-only. Bora cannot change, publish or delete anything in your Google account.

What we read: clicks, impressions, click-through rate, average position, top queries and top pages from Search Console; users, sessions, page views, engagement, top pages and traffic channels from Analytics.

What we store: the OAuth tokens needed to keep the connection alive, the email address of the authorising account, and the property you selected. Report data itself is not stored - it is fetched from Google each time you open the page and shown to you directly.

What we use it for: showing you these reports inside your own Bora panel, and nothing else.

What we never do: we do not sell this data, do not use it for advertising, do not use it to train any model, and do not share it with third parties.

Deletion: when you disconnect the integration, we revoke the token with Google and delete the stored authorisation. Deleting the site or your account removes it as well.

Bora's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Services we send data to

OpenAI: to generate articles we send the topic, keywords, brand description and writing instructions for your site. We do not send your account credentials, your Google data or your customers' personal data.

Google: only the read requests described above, made with your own authorisation.

Payment provider: your billing details, handled directly by them.

The platforms you connect: the finished article and its cover image, sent to the CMS you chose.

Cookies and analytics

Bora sets two cookies of its own: one keeps you signed in, the other remembers your interface language. Neither is used for advertising.

We also use Google Analytics to see how people find and move through this website - which pages are visited, from where, and on what kind of device. It sets its own cookies and sends this data to Google. We use it to improve the site, not to identify you personally, and we do not use it for advertising or link it to your account activity inside the panel.

You can block it with any browser setting or extension that stops analytics scripts; the site works exactly the same either way.

How long we keep it

We keep your data while your account is open. When you delete a site, its content, credentials and activity records go with it. When you close your account, everything is removed. You can ask us to delete your data at any time.

Security

All traffic runs over encrypted connections. Passwords are hashed. Connection credentials and Google tokens are stored on the server and are never sent to the browser. Access to the production system is limited to key-based authentication.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond.

Changes

If this policy changes in a way that affects you, we will update the date at the top and tell you before the change takes effect.

Política de privacidade · Bora