Last updated: 13 August 2026
This policy explains how SEO Toolbox (“we”, “us”) handles your personal data when you use this site and its tools. For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary and you are the Data Principal.
Every tool here runs without an account. If you never sign in, we hold no account data about you at all — only the run record described below.
1. What we collect, and why
| Personal data | Collected when | Purpose |
|---|---|---|
| Email address, name and profile picture URL | When you register, or when you sign in with Google | To create and identify your account, and to send account email |
| Password, stored only as a scrypt hash | When you register with a password | To verify sign-in. The password itself is never stored or readable |
| Google account identifier (the "sub" claim) | When you sign in with Google | To match your Google sign-in to the same account each time |
| IP address and browser user agent | On sign-in, sign-out, failed sign-in, password reset and tool runs | Security audit trail, abuse and rate-limit control |
| Session token in an httpOnly cookie | While you are signed in | To keep you signed in. Strictly necessary, and set only while signed in |
| Tool inputs and results, and the URLs you audit | Each time you run a tool or a crawl | To show you the result and your run history |
| Analytics and session behaviour: pages viewed, referrer, device and browser, approximate location from IP, and — through Clarity — clicks, scrolling and mouse movement | Only after you accept analytics in the consent banner | To see which tools get used and where pages go wrong. Nothing is collected if you decline |
We run no advertising and set no advertising cookies. We do not sell personal data, and we do not use it to build a profile of you for advertising. Analytics is the one thing here that is not strictly necessary, and it is the one thing we ask before running — see cookies and analytics below.
A crawl or a tool run stores the URL you submitted and what the page returned. Point the crawler only at sites you own or are authorised to test, and do not put other people’s personal data into tool inputs.
2. On what basis we process it
We process your personal data on the basis of the consent you give when you create an account or run a tool, for the purposes listed above. Where the DPDP Act permits certain legitimate uses — such as data you voluntarily provide for a purpose you asked for, and the security records needed to keep the service safe — we rely on that instead.
You can withdraw consent at any time by writing to hello@punitvithlani.com, or by deleting your account. Withdrawing consent stops future processing; it does not make past lawful processing unlawful.
3. Cookies and analytics
Two cookies, and neither is for advertising:
- Session cookie — set only while you are signed in. It is strictly necessary to keep you signed in, and is httpOnly, so page scripts cannot read it.
- Consent cookie (
analytics-consent) — remembers whether you accepted or declined analytics, for 180 days, so you are not asked on every page.
If you accept, we load Google Analytics 4 and Microsoft Clarity, which set their own cookies. Clarity also records how a page is used — clicks, scrolling and mouse movement — and replays it to us as a session recording, with what you type into form fields masked by its default settings. We use both to see which tools get used and where pages break, never to identify you personally.
Until you accept, neither script is loaded at all. Decline and the page stays as it is: every tool works the same either way. You can change your mind at any time with Cookie settings in the footer of any page — withdrawing is one click, as the Act requires it to be.
4. Who else sees it
We share personal data only with the processors needed to run the service:
- Google — only if you choose “Sign in with Google”. Google tells us your email, name and profile picture; we tell Google nothing about your activity here.
- Google Analytics and Microsoft Clarity — only after you accept analytics. Both process the usage data described above on their own infrastructure, which is outside India.
- Our email provider — to deliver verification, password-reset and audit-alert email to the address on your account.
- Our hosting provider — the servers this application and its database run on.
Each acts as a Data Processor under contract, may process the data only on our instructions, and may not use it for its own purposes. We otherwise disclose personal data only where the law compels it.
5. Where it is processed
Data is stored on servers operated by our hosting provider. Some processors may process data outside India, which the DPDP Act permits except to countries the Central Government restricts by notification. Should such a restriction apply to one of our processors, we will move the processing.
6. How long we keep it
- Account data — for as long as your account exists. Delete the account and it is erased.
- Sessions — until the session expires or you sign out, after which the record is expired and cleared.
- Sign-in events — kept as a security trail for the life of the account, then erased with it.
- Tool runs, crawls and audit reports — kept so you can revisit your history, and erased with the account they belong to.
- Email verification and reset tokens — stored only as a SHA-256 hash, and expire within hours.
When personal data is no longer needed for the purpose it was collected for, and no law requires it to be kept, we erase it.
7. Your rights as a Data Principal
Sections 11 to 14 of the DPDP Act give you the following rights. To exercise any of them, write to hello@punitvithlani.com from the email address on your account.
- Access
- Ask for a summary of the personal data being processed and the processing activities it is used in.
- Correction and completion
- Ask for inaccurate or incomplete data to be corrected, completed or updated. Your name and email can also be changed from your account page.
- Erasure
- Ask for your personal data to be erased, unless it must be retained to comply with a law.
- Grievance redressal
- Raise a complaint with us and get a response. If it is not resolved, escalate to the Data Protection Board of India.
- Nomination
- Nominate another individual who may exercise these rights on your behalf if you die or become incapacitated.
- Withdraw consent
- Withdraw consent at any time, as easily as it was given. Withdrawal does not undo processing that already happened lawfully.
We respond to a rights request within 30 days. The Act also places duties on you: give authentic information, do not impersonate anyone, and do not file false or frivolous grievances.
8. Grievance redressal
Send any grievance about how your personal data is handled to our grievance contact at hello@punitvithlani.com, with “DPDP grievance” in the subject line. We acknowledge within 72 hours and aim to resolve within 30 days.
If you are not satisfied with the outcome, you may complain to the Data Protection Board of India. Exhausting our grievance process first is a precondition under the Act.
9. Children and persons with a guardian
This service is not directed at children. If you are under 18, or you have a lawfully appointed guardian, an account may be created only with verifiable consent from your parent or guardian. We do not knowingly track or behaviourally monitor children, and we never run targeted advertising — at children or anyone else. If we learn that a child’s data was collected without that consent, we erase it.
10. How it is protected
- Passwords are stored as scrypt hashes, never in a readable form.
- Email verification and reset tokens are stored only as hashes, so a leaked database cannot be used to mint a working reset link.
- Session tokens are opaque random values in httpOnly, secure, same-site cookies, so page scripts cannot read them.
- Traffic is served over HTTPS, and administrative access is limited to named accounts.
No safeguard is absolute. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal, as Section 8(6) requires.
11. Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how your personal data is used, we will tell you by email before it takes effect.
12. Contact
Data protection queries, rights requests and grievances: hello@punitvithlani.com. Please write from the address on your account so we can verify who is asking — we will not act on an account request we cannot attribute.
See also the terms and conditions. Questions about the tools themselves can go to the same address: hello@punitvithlani.com.