Last updated: 6 October 2026
This privacy policy explains how DATA HIT Ltd ("DATA HIT", "we", "us", "our") handles your information when you use the tools hosted at tools.datahit.co. The tools fall into two categories with different data-handling models — both are covered in this single policy. Read alongside the DATA HIT main privacy policy, which covers general website usage.
DATA HIT Ltd is a company registered in England and Wales, with its registered address at Department, 4 The Boulevard, Leeds, LS10 1PZ. For any privacy-related enquiries, please contact us at hello@datahit.co.
We currently offer the following tools at tools.datahit.co:
When you connect your Google account to one of the OAuth-based tools, we request the following read-only scopes:
Both scopes are read-only. We do not request any permissions to modify, delete, or write data to your Google accounts.
Spiral and Timing Grid each offer two ways to connect. The default is browser-only and stores nothing on our servers. The optional persistent connection stores a refresh token on our servers so the connection survives across visits and so Pro features that run on a schedule (e.g. the Monday digest) can fetch on your behalf.
Default: in-browser connection.
Optional: persistent server-side connection. When you click "Stay connected next time" beside the Connect Google button, or any time a Pro feature needs to query Google on your behalf when you are not actively at the page (e.g. the Monday digest cron), the tool initiates the OAuth 2.0 authorisation-code flow with offline access instead. This issues a refresh token that we encrypt and store server-side so we can mint short-lived access tokens for future requests. Specifics:
ga4_connections, gsc_connections).analytics.readonly for GA4, webmasters.readonly for Search Console. Read-only. Same scopes as the in-browser path.We do not use your Google user data for any purpose other than providing the visualisation and the Pro features you have enabled. Your data is never used for advertising, marketing, profiling, AI model training, or any purpose unrelated to the tool's core functionality.
To revoke access at any time, click "Disconnect" in the tool or visit your Google Account permissions page.
Search Seasonality runs partly on our servers because it looks up monthly search volume from a third-party SEO data provider. This section explains exactly what is sent where.
What you provide:
Looking up a single keyword needs no account and we do not ask for any personal information. Keyword sets need a free account.
What we process and keep:
Search Console import: on a free account, the import signs you in to Google in your browser with read-only Search Console access, and your top queries go straight from Google to the page; they are not sent to or stored by DATA HIT. On Pro with a saved Search Console connection, our server fetches the property's top queries with that connection and passes them to your browser; we do not store them. Either way, nothing is sent to our data provider until you choose to scan.
Third parties that receive your scan data:
Search Seasonality does not send your keywords to any AI or language-model provider. We never sell or share your keyword data with any party other than the processors listed above.
Sensitive keywords: because your keywords are transmitted to DataForSEO to produce the scan, please avoid using the tool to look up personal information, medical conditions, or any other information you would not feel comfortable sharing with that third party under its policy.
Like Search Seasonality, the AI Answer Monitor runs partly on our servers because it consumes data from a third-party SEO provider. This section explains exactly what is sent where. The tool has three modes with different data flows: the AI-answer exposure report, available on the free tier, and topic scans and prompt checks, which are Pro. All three require a signed-in account.
What you provide:
What is sent to the data provider: your domain and the country, in two requests to DataForSEO, which return the search terms your site ranks for and which of those carry an AI Overview. Brand terms are not sent to DataForSEO — the filter is applied on our servers to data already retrieved, which is why changing it costs nothing and returns instantly.
What we store:
The exposure report is not persisted to our database, and no report history is kept against your account.
Note on domains you do not own: the report accepts any domain, because it reads only public search-results data. If you enter a competitor's domain, that domain is sent to DataForSEO in the same way your own would be.
What you provide:
Free users cannot trigger a topic scan; they see a fixed sample (a hard-coded "best CRM" result). No data is transmitted to any third party in that sample path. This applies to the topic scan only — the free AI-answer exposure report described above does send your domain to DataForSEO.
What we process server-side (Pro scans only):
ai_mention_scans) — every completed Pro scan is also persisted to D1 alongside your user id, with the full DataForSEO payload in a raw_json column so the tool can re-render historical scans without re-paying DataForSEO. Failed scans, and scans where DataForSEO returned zero items, are not persisted (they also do not decrement your monthly quota).Third parties that receive AI Answer Monitor scan data:
We never sell or share AI Answer Monitor scan data with any party other than the processors listed above. The brand names, source URLs, and fan-out queries returned by DataForSEO and stored in our database are not your personal data — they are public third-party data about the AI engine's response patterns — but they are scoped to your account so only you can see your own scan history.
Pro: watched scans and weekly diff cron. Weekly re-runs are paused at present (since 30 September 2026): nothing is re-scanned or sent on your behalf until they resume. When you click the ★ Watch button on a completed scan, we add the (keyword, country, platform) tuple to a "watch list" (D1 ai_monitor_watches, capped at 20 entries on Solo and 50 on Agency). Every Monday at 07:00 UTC, an automated cron re-runs each watched scan and computes a diff against the previous week's results (new and dropped brand mentions, new and dropped cited sources). The diff is persisted to D1 (ai_monitor_diffs) and surfaced on your /app/welcome dashboard. These cron-driven scans draw from a separate processing budget and do not decrement your manual monthly quota. The third-party data flow for each cron-driven scan is identical to a user-triggered scan (see "Third parties" above).
Pro: AI overview (optional). Click the "Generate AI overview" button on a completed scan and we send the scan's brand / fan-out / source tables to Anthropic to produce a 2-4 sentence plain-English summary. See section 5 for the shared AI overview data flow that covers Spiral, Timing Grid, AI Answer Monitor, and SERP Seasonality Map.
Sensitive keywords: because your keyword is transmitted to DataForSEO (and, if you click Generate AI overview, to Anthropic), please avoid using the tool to look up personal information, medical conditions, or any other information you would not feel comfortable sharing with those third parties under their respective policies.
AI Answer Stability runs on our servers, because it asks third-party AI engines the same question several times.
What you provide: a question (e.g. "What is the best server-side tagging platform?"), your brand name, and optionally some competitor names.
What is sent where:
What we store: the question, the brand names you entered, and the answers, cited sources and extracted brands, in our database (Cloudflare D1), against your account. If anyone asks the same question within 24 hours, they are shown the same answers rather than new ones; your brand names and your account are never shown to them.
Sensitive questions: because your question is sent to the providers above, please don't use the tool with personal information about anyone.
The Pro tier adds account-based features on top of the three free tools. Using Pro requires an email address (for sign-in) and a payment method (for the subscription). Everything in this section applies only to users who have created a Pro account; the free tools remain anonymous and unchanged.
What we collect when you create a Pro account:
users table). Never sold, never used for marketing without explicit opt-in.pro_solo or pro_agency with one of trialing / active / past_due / canceled, kept in sync via Stripe webhooks.We do not collect your name, address, or any other contact information for the Pro tier. Stripe handles all payment details directly — we never see your card number or full billing address.
Authentication (magic links):
magic_link_tokens). The plaintext token is sent to your inbox via Resend (see "Third parties" below) and is valid for 15 minutes and one use only.dh-session (HttpOnly, Secure, SameSite=Lax, 30-day sliding TTL). The session row lives in D1 (table sessions); the cookie carries only the session id, not your email or plan tier.What we store as you use Pro features:
keywords) — the keyword + country pairs you opt to track for weekly rankings (the Track button in Search Seasonality), scoped to your user id. Up to 20 active rows on Solo and 200 on Agency. Archived rows are soft-deleted, not erased, so historical snapshots stay attributable.ai_mention_scans) — every Pro AI Answer Monitor scan you run is persisted with the keyword, country, AI engine, search scope, brand entities, fan-out queries, cited sources, and DataForSEO cost telemetry. See section 4 for the full data flow. Counts toward your monthly scan quota (50 Solo / 250 Agency, resets 1st of month UTC).ai_monitor_watches) — (keyword, country, AI engine) tuples you have pinned via the ★ Watch button. Up to 20 on Solo, 50 on Agency. The Monday 07:00 UTC cron iterates this list to re-scan and diff (see "What we do with this data" below). Soft-deleted on unpin.ai_monitor_diffs) — one row per (watched scan, week) recording the new brand mentions, dropped brand mentions, new cited sources, and dropped cited sources versus the previous week's scan. Surfaced on your /app/welcome dashboard. Hard-deleted with the parent watch on unpin or account closure.snapshots) — every Monday at 06:00 UTC a cron job submits your tracked keywords to DataForSEO via their asynchronous postback API. The top-10 result list returned by DataForSEO is stored against the keyword id along with the capture timestamp. Snapshots are retained for the lifetime of the keyword and are deleted when the parent keyword is hard-deleted at account closure.saved_dashboards, with Search Seasonality digest records in seasonality_digest_events) — a set's name, country and keyword list, and which of its keywords the Monday email has already mentioned (keyword, country, month). Kept until you delete the set or close your account.saved_dashboards) — when you click "Save current view" on a Pro preview, we persist the control settings (metrics, filters, date range, colour scale, etc.) as a JSON blob scoped to your user id and the tool. Up to 5 per tool on Solo, 50 per tool on Agency. Soft-deleted on archive.annotations) — short notes you log against a calendar date (or date range) that surface across all three tools. Label and optional body text are stored verbatim against your user id. Unlimited on both Solo and Agency. Soft-deleted on archive.weekly_digest_sends) — one row per user per week recording whether the Monday-morning digest was sent, skipped, or failed, plus the Resend message id of the email. Used for idempotency (so a cron retry can't double-send) and for the "Most recent digest" line on your dashboard.anomalies) — when the Monday cron detects an analytics value that deviates significantly from its year-over-year baseline on the Seasonal Spiral, we record the date, metric, GA4 property id, and summary statistics (the actual value, expected value, sample standard deviation, and z-score). We do not store your raw analytics data; detection re-fetches from Google on every cron run. Rows are scoped to your user id and soft-deleted when you dismiss them. The scope of GA4 access used for detection is analytics.readonly — same as the persistent connection described in section 2.billing_events) — every Stripe webhook we receive is recorded by provider event id for dedupe + audit. The payload is the raw Stripe event; we don't enrich it with anything we don't already have on your record.gsc_connections) — if you opt to enable the persistent Search Console connection on Spiral / Grid, or Search Console import in Search Seasonality, we store the OAuth refresh token issued by Google when you authorise our app. The refresh token lets us query Google's Search Console API on your behalf (e.g. for the Monday digest cron). We do not store the access token (it lives in memory for the duration of one API request). The scope granted is webmasters.readonly only.ga4_connections) — same shape as the Search Console connection above, but for GA4. Stored when you opt into the persistent connection on Spiral / Grid via "Stay connected next time". The scope granted is analytics.readonly only. Revocation works the same way: click "Disconnect" in the tool or visit your Google account permissions page; revocation soft-deletes the row and we no longer receive access.ga4_monitors, ga4_monitor_events, ga4_monitor_series, ga4_alerts) — only if you turn on tracking checks. We use your persistent GA4 connection to run automated, read-only checks once a day, at around 09:00 in your property's time zone (retried hourly if Google is unavailable). When sessions look like they have collapsed, we also make a real-time check of how many users are active right now. We store: the property you chose, with its name and time zone; the names of the events you choose to watch; daily totals for those events (counts, and how many were credited to the Direct, Unassigned and (not set) channels); daily session counts by platform (web, iOS, Android); and the alerts we raise, with the figures behind them and any feedback you give. We do not store page-level, user-level or raw event data. Daily totals are kept for 90 days on a rolling basis. Alert emails go to your account email address via Resend and always include a link to turn them off. Explanations in alerts are written from fixed templates: your analytics data is not sent to any AI provider for this feature, and we will update this policy before that changes. Turning tracking checks off, or switching to another property, deletes the stored totals and alerts for that property. The scope used is analytics.readonly.What we do with this data:
/app/welcome with your tracked keywords, watched AI scans, weekly AI mention diffs, saved views, recent annotations, and most recent digest status.AI overview (on-demand Pro feature). The Spiral, Timing Grid and AI Answer Monitor offer a "Generate AI overview" button that produces a 2-4 sentence plain-English summary of the visible chart. The data we send to Anthropic differs per tool:
In each case the request goes to Anthropic via the Claude API; the response is sanitised (only <strong> tags allowed) and rendered inline. Generated overviews are cached in Cloudflare Workers KV for 24 hours, keyed by a hash of the full input payload, so re-clicking Generate on identical chart state returns the cached output without a fresh API call. We never send your email, user id, or any other account identifier to Anthropic. Per Anthropic's published policy, API requests are not used to train their models by default.
We do not use your Pro account data for advertising, profiling, AI model training, or any purpose unrelated to operating the tools.
Third parties that receive Pro account data:
We never sell or share Pro account data with any party other than the processors listed above. We never combine your Pro data with any other identifier.
Closing your Pro account: to permanently delete your Pro account and all associated data (tracked keywords, SERP snapshots, AI Answer Monitor scans, watched AI scans, weekly AI mention diffs, saved views, annotations, anomaly alerts, sessions, digest history, billing event log entries scoped to your record), email hello@datahit.co from the address registered on the account. We will cancel any active subscription via Stripe and hard-delete your D1 rows. You can also self-serve cancel the subscription at any time from your dashboard via the Stripe billing portal — that ends future billing but leaves your account data in place until you also email us to request deletion.
We use Plausible Analytics, a privacy-focused analytics service, to collect anonymous usage statistics about our tools pages. Plausible does not use cookies, does not collect personal data, and is fully compliant with GDPR, CCPA, and PECR. No Google user data, scan data, keyword data, or Pro account data is shared with Plausible. The only data collected relates to page views and lightweight custom events (e.g. that a scan was triggered, that a Pro annotation was created — never the keyword text or annotation content itself).
The free tools at tools.datahit.co set no tracking cookies. We use the following browser localStorage items, all of which are purely UI preferences with no identifying value and no third-party visibility:
dh-theme — your light/dark theme preference.dh-spiral-annotation-hint-dismissed — set to 1 after you dismiss the one-time "right-click any cell to annotate" hint on the Seasonal Spiral tool (Pro feature). Suppresses the hint on subsequent visits.Pro accounts use one HTTP cookie — dh-session, HMAC-signed, HttpOnly, Secure, SameSite=Lax, 30-day sliding expiry. The cookie carries only the session id; identity is resolved server-side. The cookie is not set unless you sign in. Signing out (from the dashboard or via the sidebar) deletes both the cookie and the server-side session row.
For information about cookies used on the main DATA HIT website, see our main privacy policy.
Free tools:
Pro accounts:
To request earlier deletion of a specific cached scan, share slug, or entire Pro account, email hello@datahit.co.
All communication between your browser, our Workers, and any third party we transmit data to is encrypted using HTTPS/TLS. Our Worker runs on Cloudflare's edge with strict secret-management for the API credentials used to call DataForSEO, Anthropic, Stripe, Resend, and (for OAuth tools) Google. The OAuth client IDs for our connected tools are restricted to authorised JavaScript origins, preventing use from unauthorised domains. Session cookies are signed with a server-side HMAC key so a tampered cookie cannot impersonate a Pro user; Stripe webhooks are verified with Stripe's HMAC-SHA256 signature scheme before any database write.
Under UK GDPR and the Data Protection Act 2018, you have the right to:
Free tools: Seasonal Spiral, Timing Grid and Search Seasonality (for a single keyword) require no account, and their cached data is short-lived and not tied to your identity, so most of these rights are fulfilled by design for those tools. The AI Answer Monitor is the exception: it requires a signed-in account even on the free tier, so the account rights described above apply to it in full. To revoke OAuth access, use the tool's disconnect button or your Google Account permissions page. To purge a cached SERP scan or share slug, email hello@datahit.co.
Pro accounts: you can review the bulk of what we hold about you directly from the dashboard at /app/welcome (tracked keywords, saved views, annotations, recent digest activity). To request a full export of your account data, to correct anything inaccurate, or to delete the account entirely, email hello@datahit.co from the address registered on the account.
If you have any concerns about how your data is handled, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
We may update this privacy policy from time to time. Any changes will be reflected by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our tools after changes are posted constitutes your acceptance of the updated policy.
If you have any questions about this privacy policy or how your data is handled, please contact us: