Privacy Policy
Last updated: October 2, 2026 · Versión en español
1. Who we are
Sealmetrics (“we”, “us”, “our”) is a web analytics platform headquartered in Spain, EU. We provide cookieless analytics services to businesses (“Clients”). This privacy policy covers how we handle data in two contexts: (a) visitors to sealmetrics.com, and (b) visitors to our Clients’ websites where Sealmetrics analytics is installed.
2. Data we collect on sealmetrics.com
When you visit sealmetrics.com, we collect:
- —Information you voluntarily provide via forms (name, email, company, website URL)
- —Analytics data via our own Sealmetrics script (page views, session duration, referrer), grouped by a pseudonymised session identifier that rotates daily; nothing is stored on your device
We do not use cookies, tracking pixels, or third-party analytics tools on sealmetrics.com.
The same first-party Sealmetrics script also runs on the sign-up flow of the platform at my.sealmetrics.com (account creation, plan selection, email verification and organisation set-up) and nowhere else on the platform: once you are signed in, nothing is measured. In that flow it records the pages viewed and the steps completed (account created, plan chosen, trial started, email verified), with the chosen plan and billing interval as the only attributes. No email, name, company or user or organisation identifier is ever sent to it. It works exactly as described in section 3: no cookies, no local storage, and an ephemeral session identifier that is not kept across sessions. This is our own audience measurement, so it requires no consent (see section 4).
Signing in to the platform at my.sealmetrics.com does set three strictly necessary cookies — sm_access_token (15 minutes), sm_refresh_token (7 days) and sm_csrf (7 days). They exist only to keep your session open and protect it against cross-site request forgery. They carry no analytics, advertising or profiling purpose, are transmitted over encrypted connections only, and are deleted when you sign out. As strictly necessary cookies for a service you expressly requested, they are exempt from the consent requirement of Art. 5(3) of the ePrivacy Directive and Art. 22.2 of the Spanish LSSI, which is why you see no consent banner. You can block them in your browser settings, but you will then be unable to sign in; blocking them does not affect browsing sealmetrics.com, which sets none.
3. Data we collect on Client websites
When installed on a Client’s website, Sealmetrics collects:
- —Page URLs and referrer URLs
- —Browser type, operating system, screen resolution
- —Session behavior (page views, scroll depth, clicks, time on page)
- —Country-level geolocation derived from the visitor’s browser timezone (Intl.DateTimeFormat). For accounts with bot/agent detection enabled, an additional IP-based country lookup (via MaxMind GeoLite2 offline database) is performed only on session entry, used exclusively for bot detection signals.
On IP addresses: We do not persist IP addresses in our analytics database. The IP is used transitorily on the server for: (i) anti-abuse blocklist matching, (ii) the GeoLite2 lookup described above when applicable, and (iii) operational logging with limited retention. The IP is never available to Clients in their reports.
On session identifiers: Sealmetrics uses a short-lived session identifier computed in the visitor’s browser from general device characteristics. It is not unique to a person — many different visitors can produce the same value — so it cannot identify an individual. It is never stored on the visitor’s device, and each client site’s data is processed in isolation. Sealmetrics does not use it to correlate visits over time: each new entrance is counted as new, independent data, and no visitor history or profile is built across sessions. Since August 2026 the identifier is additionally pseudonymised on our servers with a secret key and a random daily salt that is destroyed on rotation (and excluded from backups): not even Sealmetrics can reconnect a device’s activity across two different days or across different sites.
On advertising click identifiers: when a visitor lands from an ad, the click identifier present in the landing URL (e.g. gclid, msclkid) is processed on the fly solely to determine the ad network of the click for attribution and deduplication. Its value is never stored — only the network type is retained — so it is not accessible in reports, via API or in exports.
We do not collect: persistent device identifiers, names, email addresses, or any data that could identify an individual visitor. No cookies, local storage, session storage, or IndexedDB are used.
4. Legal basis for processing
For sealmetrics.com form submissions: consent (Article 6(1)(a) GDPR) and legitimate interest in responding to inquiries (Article 6(1)(f)). For our own analytics script on sealmetrics.com and on the my.sealmetrics.com sign-up flow: our legitimate interest in measuring the audience of our own site and the effectiveness of our marketing (Article 6(1)(f)). For analytics data on Client websites: legitimate interest of the Client in understanding website usage (Article 6(1)(f)). In both cases the only pseudonymised data is the session identifier, which rotates daily and, once rotated, cannot be reconstructed, not even by us; reports are always aggregated.
5. Data storage and residency
Visitor analytics data is processed and stored exclusively in EU data centers, with no sub-processors outside the EU in that data path. In the analytics platform, the sole transfer outside the European Economic Area is service email to the account’s own users (verifications, alerts, reports) via Resend, Inc. (USA), covered by Standard Contractual Clauses and its EU-US Data Privacy Framework certification. It involves no visitor data. The full sub-processor list is Annex 3 of the DPA. The AI brand monitoring report requested on sealmetrics.com has its own recipients, listed in section 9, and so do the downloadable sector studies, in section 10.
6. Data retention
The raw technical event log is retained for 1 day and then deleted automatically; only aggregated analytics remain beyond that point. Aggregated analytics data on Client websites is retained for a maximum of 24 months (enforced automatically via database TTL), in line with the AEPD audience measurement guidance (January 2024). Aggregated hourly reports are retained for 90 days. Form submissions on sealmetrics.com are retained for 24 months unless you request earlier deletion.
7. Your rights
Under GDPR, you have the right to access, rectify, erase, port, and restrict processing of your personal data. For data you have provided via forms, contact us at privacy@sealmetrics.com. Note that analytics data collected on Client websites contains no data that identifies anyone, and once the daily identifier rotates it cannot be linked to any individual.
8. Third-party sharing
We do not sell, trade, or share personal data with third parties for advertising or marketing purposes. We may share data with service providers who assist in operating our platform, under strict data processing agreements.
9. AI brand monitoring report
The form at /ai-brand-monitoring asks nineteen AI models six questions about a company and emails the answers to whoever requested them.
Data processed. Your work email, the brand you ask about, and optionally its sector and competitors. The form does not ask for your name. The report is about organisations; it is not run on individuals.
Purposes and legal basis. (a) Generating the report and emailing it to you, because you asked for it (Article 6(1)(b) GDPR). (b) Keeping a record of the request, to prevent abuse of a free service and to answer any question about it (Article 6(1)(f)). (c) Only for those who tick the separate, optional and unticked box on the form: sending occasional reports and product news from Sealmetrics, starting with a short series of follow-up emails about the report they requested (Article 6(1)(a) GDPR and Article 21 of Spain’s LSSI). From 29 to 30 September 2026 the form did not offer the box, and nobody who requested a report on those days was included. That consent can be withdrawn at any time through the unsubscribe link in any email or by writing to privacy@sealmetrics.com.
Recipients.
- —Cloudflare, Inc. runs the anti-bot check (Turnstile) and the relay that receives the form, and keeps the full report for 30 days behind the private link in the email, so you can read it at sealmetrics.com. It receives the report itself — the brand, the models’ findings and the recommendations — never your email: the link carries a random key, and the report is deleted automatically when the 30 days are up.
- —Enroutia, the model routing platform that generates the report, receives the brand, sector and competitors, and a random reference in place of your email. It never receives your email: the link between that reference and your address stays in our own automation system, and is deleted as soon as the report is delivered, or after 72 hours at most.
- —The AI models that answer the questions receive the brand, sector and competitors only, never your email. Six of them (GPT-6 Sol and GPT-6 Astra from OpenAI, Claude Sonnet 5 and Claude Opus 5.5 from Anthropic, Gemini 3.8 Flash from Google and Sonar from Perplexity) are served from the United States.
- —Resend, Inc. (USA) delivers the report and, to those who consented, the occasional emails, covered by Standard Contractual Clauses and its EU-US Data Privacy Framework certification.
- —lemlist SAS (France), only for those who ticked the box, sends the follow-up emails about the report. It receives their email, their company domain and the brand and sector they asked about.
- —Formagrid Inc. (Airtable, USA), only for those who ticked the box, holds the list of people who asked for a report: their email, company domain, the brand, sector and competitors asked about, the language and the date. Covered by Standard Contractual Clauses.
Sharing the report. The page of the full report lets whoever has its link send it to up to five work addresses at a time, and twenty per report. We send each address one email with the link, through Resend, on the legitimate interest of delivering what the sender asked for (Article 6(1)(f) GDPR). We keep no copy of those addresses: they are not added to any list, not passed to Enroutia, lemlist or Airtable, and not written to again. The optional name of the sender is printed in that email and kept nowhere else.
Retention. The request record is kept for up to 24 months, like any other form submission. The link between the report reference and your email is deleted on delivery, or after 72 hours at most. The full report behind the private link is deleted after 30 days. If you consented to occasional emails, your address stays on that list, and in the Airtable list, until you unsubscribe or withdraw consent.
Quick AI visibility check. The check at /what-ai-says asks for no email and no name. It asks the same nineteen models what a brand is and what they would recommend to someone looking for what it sells, and gives a score from 0 to 100. It only processes what you type, a brand and what it sells, which describe an organisation, not a person. To prevent abuse of a free service that costs us every check, Cloudflare, Inc. runs an anti-bot check (Turnstile) that processes your IP address and technical data about your browser, and operates the relay that receives the check (legitimate interest, Art. 6(1)(f) GDPR). Sealmetrics does not keep that technical data. Enroutia receives the brand, what it sells and the language, never your IP address. The models receive only the brand and what it sells, and six of them are served from the United States. Each result is public at its own address and is deleted after 30 days. For the first seven days it is also shown to anyone who looks up that brand. If you represent a brand and want its result removed, write to privacy@sealmetrics.com.
10. Downloadable sector studies
On some pages we publish studies of what AI models say about a sector, such asthe one on Mallorca hotels(in Spanish). The full report of each study is requested with your email address, and we send it to you by email.
Data processed.Your email address and the study you ask for. The form does not ask for your name. We note whether the address belongs to a free email provider, to tell apart the requests that come from companies.
Purposes and legal basis.(a) Sending you the study, because you asked for it (Article 6(1)(b) GDPR). (b) Keeping a record of the request, to prevent abuse of a free service and to answer any question about it (Article 6(1)(f)). (c) Sending you occasional studies and product news, only if you tick the separate, optional box on the form (Article 6(1)(a) GDPR and Article 21 of Spain’s LSSI). Without that box we send you no commercial communications. Not ticking it does not affect the study, and you can withdraw that consent at any time through the unsubscribe link in any email or by writing to privacy@sealmetrics.com.
Recipients.
- —Cloudflare, Inc. runs the anti-bot check (Turnstile) and the relay that receives the form.
- —Resend, Inc. (USA) delivers the study and, if you consented, the occasional emails, covered by Standard Contractual Clauses and its EU-US Data Privacy Framework certification. Resend fetches the study PDF from sealmetrics.com; it contains no data about you.
- —Neither Enroutia nor the AI models receive anything: the study is done before you ask for it.
Retention. The request record is kept for up to 24 months, like any other form submission. If you consented to occasional emails, your address stays on that list until you unsubscribe or withdraw consent.
11. Looker Studio connector and Google user data
The Sealmetrics connector for Looker Studio is a Google Apps Script that lets Clients load their Sealmetrics analytics into their own Looker Studio reports. It requests a single Google permission, script.external_request, which it uses only to call the Sealmetrics API (my.sealmetrics.com).
Data accessed. The connector does not read your Google Account data: not your name, email address, contacts, Drive, Sheets or any other Google service. It only handles what you enter in Looker Studio (your Sealmetrics API key, the site and the report type you select) and the date range and fields each chart requests.
How it is used. That information is used exclusively to authenticate against the Sealmetrics API and return the analytics you asked for to your own report. It is not used for advertising, profiling or training AI/ML models, and it is never sold.
Sharing. It is sent only to the Sealmetrics API, operated by Sealmetrics S.L. in the EU. It is not shared with, transferred or disclosed to any third party.
Protection.
- —All requests travel encrypted over HTTPS (TLS).
- —API keys are stored on our side only as a SHA-256 hash, can be limited to read-only scopes and specific sites, and can be revoked at any time in Settings > API Keys.
- —The connector requests no Google permission other than script.external_request.
Retention and deletion. Sealmetrics stores no data from your Google Account. To keep reports fast, the connector caches API responses in Google’s Apps Script cache for at most 15 minutes, after which they expire automatically. Your connector settings stay in your Looker Studio data source until you delete it. You can remove the connector’s access at any time at myaccount.google.com/permissions and revoke the API key in Sealmetrics.
Limited Use. Sealmetrics’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Contact
For privacy-related questions or to exercise your rights, contact us at privacy@sealmetrics.com.
Data controller: Sealmetrics S.L. (VAT ESB70933239), Carrer de Tirso de Molina 36, 08940 Cornellà de Llobregat, Barcelona, Spain. We are not required to appoint a Data Protection Officer; privacy matters are handled at the contact above. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).