Controller and contact
The service is provided by:support@genseo.co
Data processed
Developer integrations process only the data needed to authenticate the connection and perform the operation requested by the user or their AI client. This may include:- Account, workspace, and project identifiers
- API key or OAuth authorization metadata
- Project configuration and website domain
- Keywords and keyword metrics
- Article titles, drafts, generated content, metadata, and publication status
- Publishing integration status and field mappings
- Webhook configuration
- Technical request information such as timestamps, IP addresses, client identifiers, error details, and rate-limit events
How data is used
Genseo processes this data to:- Authenticate and authorize the connection
- Enforce project and permission boundaries
- Return project, keyword, article, integration, and webhook information
- Create or update content when requested
- Generate keywords or article content when requested
- Publish approved content through a configured CMS integration
- Detect abuse, investigate errors, enforce rate limits, and maintain service security
- Provide support and improve reliability
AI clients and instructions
The plugin repository contains only public configuration and workflow instructions. It does not contain user credentials or private Genseo application data. Prompts and conversation context remain with the AI client unless the client sends specific values as arguments to a Genseo MCP tool. Genseo receives only the tool name and arguments required to perform that request.Authentication and permissions
Developer API keys are bound to one Genseo project and a defined set of scopes. Users can revoke keys in Genseo at any time. Marketplace connections that use OAuth require user approval and can be disconnected from the AI client or Genseo. Genseo does not support credentials in MCP URL query parameters.Service providers and external publishing
Genseo uses service providers for hosting, databases, authentication, monitoring, email, and product operations, as described in the main Genseo Privacy Policy. When a user explicitly publishes content, Genseo sends the required article data to the CMS provider configured by that user, such as Webflow, Shopify, WordPress, Wix, or Framer. Those providers process data under their own terms and privacy policies.Retention and deletion
- Project content and configuration are retained while the project or account remains active, unless the user deletes them earlier.
- Revoked API keys and authorization records may be retained as necessary for security, fraud prevention, and audit purposes.
- Technical logs are retained only as long as reasonably necessary for security, troubleshooting, service reliability, and legal obligations.
- Data may remain in encrypted backups for a limited period until routine backup rotation completes.
support@genseo.co.
Security
Genseo uses HTTPS for data in transit and applies access controls and project-level authorization. Users must keep API keys confidential and should grant only the scopes required for their workflow. If a credential may have been exposed, revoke it immediately and create a replacement.User rights
Depending on applicable law, users may request access, correction, deletion, restriction, portability, or objection regarding their personal data. Requests can be sent tosupport@genseo.co.
For additional information about legal bases, international transfers, cookies, subprocessors, and GDPR rights, see the Genseo Privacy Policy.
