Skip to content
Sealmetrics
Legal

Privacy Policy

Last updated: September 15, 2026 · Versión en español

1. Who we are

Sealmetrics (“we”, “us”, “our”) is a web analytics platform headquartered in Spain, EU. We provide cookieless analytics services to businesses (“Clients”). This privacy policy covers how we handle data in two contexts: (a) visitors to sealmetrics.com, and (b) visitors to our Clients’ websites where Sealmetrics analytics is installed.

2. Data we collect on sealmetrics.com

When you visit sealmetrics.com, we collect:

  • Information you voluntarily provide via forms (name, email, company, website URL)
  • Anonymous analytics data via our own Sealmetrics script (page views, session duration, referrer — no PII)

We do not use cookies, tracking pixels, or third-party analytics tools on sealmetrics.com.

The same first-party Sealmetrics script also runs on the sign-up flow of the platform at my.sealmetrics.com (account creation, plan selection, email verification and organisation set-up) and nowhere else on the platform: once you are signed in, nothing is measured. In that flow it records the pages viewed and the steps completed (account created, plan chosen, trial started, email verified), with the chosen plan and billing interval as the only attributes. No email, name, company or user or organisation identifier is ever sent to it. It works exactly as described in section 3: no cookies, no local storage, and an ephemeral session identifier that is not kept across sessions. This is our own audience measurement, so it requires no consent (see section 4).

Signing in to the platform at my.sealmetrics.com does set three strictly necessary cookies — sm_access_token (15 minutes), sm_refresh_token (7 days) and sm_csrf (7 days). They exist only to keep your session open and protect it against cross-site request forgery. They carry no analytics, advertising or profiling purpose, are transmitted over encrypted connections only, and are deleted when you sign out. As strictly necessary cookies for a service you expressly requested, they are exempt from the consent requirement of Art. 5(3) of the ePrivacy Directive and Art. 22.2 of the Spanish LSSI, which is why you see no consent banner. You can block them in your browser settings, but you will then be unable to sign in; blocking them does not affect browsing sealmetrics.com, which sets none.

3. Data we collect on Client websites

When installed on a Client’s website, Sealmetrics collects:

  • Page URLs and referrer URLs
  • Browser type, operating system, screen resolution
  • Session behavior (page views, scroll depth, clicks, time on page)
  • Country-level geolocation derived from the visitor’s browser timezone (Intl.DateTimeFormat). For accounts with bot/agent detection enabled, an additional IP-based country lookup (via MaxMind GeoLite2 offline database) is performed only on session entry, used exclusively for bot detection signals.

On IP addresses: We do not persist IP addresses in our analytics database. The IP is used transitorily on the server for: (i) anti-abuse blocklist matching, (ii) the GeoLite2 lookup described above when applicable, and (iii) operational logging with limited retention. The IP is never available to Clients in their reports.

On session identifiers: Sealmetrics uses a short-lived session identifier computed in the visitor’s browser from general device characteristics. It is not unique to a person — many different visitors can produce the same value — so it cannot identify an individual. It is never stored on the visitor’s device, and each client site’s data is processed in isolation. Sealmetrics does not use it to correlate visits over time: each new entrance is counted as new, independent data, and no visitor history or profile is built across sessions. Since August 2026 the identifier is additionally pseudonymised on our servers with a secret key and a random daily salt that is destroyed on rotation (and excluded from backups): not even Sealmetrics can reconnect a device’s activity across two different days or across different sites.

On advertising click identifiers: when a visitor lands from an ad, the click identifier present in the landing URL (e.g. gclid, msclkid) is processed on the fly solely to determine the ad network of the click for attribution and deduplication. Its value is never stored — only the network type is retained — so it is not accessible in reports, via API or in exports.

We do not collect: device fingerprints, names, email addresses, or any data that could identify an individual visitor. No cookies, local storage, session storage, or IndexedDB are used.

4. Legal basis for processing

For sealmetrics.com form submissions: consent (Article 6(1)(a) GDPR) and legitimate interest in responding to inquiries (Article 6(1)(f)). For our own analytics script on sealmetrics.com and on the my.sealmetrics.com sign-up flow: our legitimate interest in measuring the audience of our own site and the effectiveness of our marketing (Article 6(1)(f)), as no personal data is processed. For analytics data on Client websites: legitimate interest of the Client in understanding website usage (Article 6(1)(f)), as no personal data is processed.

5. Data storage and residency

Visitor analytics data is processed and stored exclusively in EU data centers, with no sub-processors outside the EU in that data path. In the analytics platform, the sole transfer outside the European Economic Area is service email to the account’s own users (verifications, alerts, reports) via Resend, Inc. (USA), covered by Standard Contractual Clauses and its EU-US Data Privacy Framework certification. It involves no visitor data. The full sub-processor list is Annex 3 of the DPA. The AI brand monitoring report requested on sealmetrics.com has its own recipients, listed in section 9.

6. Data retention

The raw technical event log is retained for 1 day and then deleted automatically; only aggregated analytics remain beyond that point. Aggregated analytics data on Client websites is retained for a maximum of 24 months (enforced automatically via database TTL), in line with the AEPD audience measurement guidance (January 2024). Aggregated hourly reports are retained for 90 days. Form submissions on sealmetrics.com are retained for 24 months unless you request earlier deletion.

7. Your rights

Under GDPR, you have the right to access, rectify, erase, port, and restrict processing of your personal data. For data you have provided via forms, contact us at privacy@sealmetrics.com. Note that analytics data collected on Client websites is anonymous and cannot be linked to any individual.

8. Third-party sharing

We do not sell, trade, or share personal data with third parties for advertising or marketing purposes. We may share data with service providers who assist in operating our platform, under strict data processing agreements.

9. AI brand monitoring report

The form at /ai-brand-monitoring asks fifteen AI models six questions about a company and emails the answers to whoever requested them.

Data processed. Your work email, the brand you ask about, and optionally its sector and competitors. The form does not ask for your name. The report is about organisations; it is not run on individuals.

Purposes and legal basis. (a) Generating the report and emailing it to you, because you asked for it (Article 6(1)(b) GDPR). (b) Keeping a record of the request, to prevent abuse of a free service and to answer any question about it (Article 6(1)(f)). (c) Sending you occasional reports and product news, only if you tick the separate, optional box on the form (Article 6(1)(a) GDPR and Article 21 of Spain’s LSSI). Not ticking it does not affect the report, and you can withdraw that consent at any time through the unsubscribe link in any email or by writing to privacy@sealmetrics.com.

Recipients.

  • Cloudflare, Inc. runs the anti-bot check (Turnstile) and the relay that receives the form.
  • Enroutia, the model routing platform that generates the report, receives the brand, sector and competitors, and a random reference in place of your email. It never receives your email: the link between that reference and your address stays in our own automation system, and is deleted as soon as the report is delivered, or after 72 hours at most.
  • The AI models that answer the questions receive the brand, sector and competitors only, never your email. Three of them (GPT-5.6 from OpenAI, and Claude Sonnet 5 and Claude Opus 5 from Anthropic) are served from the United States.
  • Resend, Inc. (USA) delivers the report and, if you consented, the occasional emails, covered by Standard Contractual Clauses and its EU-US Data Privacy Framework certification.

Retention. The request record is kept for up to 24 months, like any other form submission. The link between the report reference and your email is deleted on delivery, or after 72 hours at most. If you consented to occasional emails, your address stays on that list until you unsubscribe or withdraw consent.

10. Looker Studio connector and Google user data

The Sealmetrics connector for Looker Studio is a Google Apps Script that lets Clients load their Sealmetrics analytics into their own Looker Studio reports. It requests a single Google permission, script.external_request, which it uses only to call the Sealmetrics API (my.sealmetrics.com).

Data accessed. The connector does not read your Google Account data: not your name, email address, contacts, Drive, Sheets or any other Google service. It only handles what you enter in Looker Studio (your Sealmetrics API key, the site and the report type you select) and the date range and fields each chart requests.

How it is used. That information is used exclusively to authenticate against the Sealmetrics API and return the analytics you asked for to your own report. It is not used for advertising, profiling or training AI/ML models, and it is never sold.

Sharing. It is sent only to the Sealmetrics API, operated by Sealmetrics S.L. in the EU. It is not shared with, transferred or disclosed to any third party.

Protection.

  • All requests travel encrypted over HTTPS (TLS).
  • API keys are stored on our side only as a SHA-256 hash, can be limited to read-only scopes and specific sites, and can be revoked at any time in Settings > API Keys.
  • The connector requests no Google permission other than script.external_request.

Retention and deletion. Sealmetrics stores no data from your Google Account. To keep reports fast, the connector caches API responses in Google’s Apps Script cache for at most 15 minutes, after which they expire automatically. Your connector settings stay in your Looker Studio data source until you delete it. You can remove the connector’s access at any time at myaccount.google.com/permissions and revoke the API key in Sealmetrics.

Limited Use. Sealmetrics’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11. Contact

For privacy-related questions or to exercise your rights, contact us at privacy@sealmetrics.com.

Data controller: Sealmetrics S.L. (VAT ESB70933239), Carrer de Tirso de Molina 36, 08940 Cornellà de Llobregat, Barcelona, Spain. We are not required to appoint a Data Protection Officer; privacy matters are handled at the contact above. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).