Last updated: 13 August 2026
This policy explains how SEO Toolbox (“we”, “us”) handles your personal data when you use this site and its tools. For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary and you are the Data Principal.
Every tool here runs without an account. If you never sign in, we hold no account data about you at all — only the run record described below.
1. What we collect, and why
| Personal data | Collected when | Purpose |
|---|---|---|
| Email address, name and profile picture URL | When you register, or when you sign in with Google | To create and identify your account, and to send account email |
| Password, stored only as a scrypt hash | When you register with a password | To verify sign-in. The password itself is never stored or readable |
| Google account identifier (the "sub" claim) | When you sign in with Google | To match your Google sign-in to the same account each time |
| IP address and browser user agent | On sign-in, sign-out, failed sign-in, password reset and tool runs | Security audit trail, abuse and rate-limit control |
| Session token in an httpOnly cookie | While you are signed in | To keep you signed in. It is the only cookie this site sets |
| Tool inputs and results, and the URLs you audit | Each time you run a tool or a crawl | To show you the result and your run history |
We do not run analytics, advertising, or third-party tracking scripts, and we set no advertising or analytics cookies. We do not sell personal data, and we do not use it to build a profile of you for advertising.
A crawl or a tool run stores the URL you submitted and what the page returned. Point the crawler only at sites you own or are authorised to test, and do not put other people’s personal data into tool inputs.
2. On what basis we process it
We process your personal data on the basis of the consent you give when you create an account or run a tool, for the purposes listed above. Where the DPDP Act permits certain legitimate uses — such as data you voluntarily provide for a purpose you asked for, and the security records needed to keep the service safe — we rely on that instead.
You can withdraw consent at any time by writing to hello@punitvithlani.com, or by deleting your account. Withdrawing consent stops future processing; it does not make past lawful processing unlawful.
3. Who else sees it
We share personal data only with the processors needed to run the service:
- Google — only if you choose “Sign in with Google”. Google tells us your email, name and profile picture; we tell Google nothing about your activity here.
- Our email provider — to deliver verification, password-reset and audit-alert email to the address on your account.
- Our hosting provider — the servers this application and its database run on.
Each acts as a Data Processor under contract, may process the data only on our instructions, and may not use it for its own purposes. We otherwise disclose personal data only where the law compels it.
4. Where it is processed
Data is stored on servers operated by our hosting provider. Some processors may process data outside India, which the DPDP Act permits except to countries the Central Government restricts by notification. Should such a restriction apply to one of our processors, we will move the processing.
5. How long we keep it
- Account data — for as long as your account exists. Delete the account and it is erased.
- Sessions — until the session expires or you sign out, after which the record is expired and cleared.
- Sign-in events — kept as a security trail for the life of the account, then erased with it.
- Tool runs, crawls and audit reports — kept so you can revisit your history, and erased with the account they belong to.
- Email verification and reset tokens — stored only as a SHA-256 hash, and expire within hours.
When personal data is no longer needed for the purpose it was collected for, and no law requires it to be kept, we erase it.
6. Your rights as a Data Principal
Sections 11 to 14 of the DPDP Act give you the following rights. To exercise any of them, write to hello@punitvithlani.com from the email address on your account.
- Access
- Ask for a summary of the personal data being processed and the processing activities it is used in.
- Correction and completion
- Ask for inaccurate or incomplete data to be corrected, completed or updated. Your name and email can also be changed from your account page.
- Erasure
- Ask for your personal data to be erased, unless it must be retained to comply with a law.
- Grievance redressal
- Raise a complaint with us and get a response. If it is not resolved, escalate to the Data Protection Board of India.
- Nomination
- Nominate another individual who may exercise these rights on your behalf if you die or become incapacitated.
- Withdraw consent
- Withdraw consent at any time, as easily as it was given. Withdrawal does not undo processing that already happened lawfully.
We respond to a rights request within 30 days. The Act also places duties on you: give authentic information, do not impersonate anyone, and do not file false or frivolous grievances.
7. Grievance redressal
Send any grievance about how your personal data is handled to our grievance contact at hello@punitvithlani.com, with “DPDP grievance” in the subject line. We acknowledge within 72 hours and aim to resolve within 30 days.
If you are not satisfied with the outcome, you may complain to the Data Protection Board of India. Exhausting our grievance process first is a precondition under the Act.
8. Children and persons with a guardian
This service is not directed at children. If you are under 18, or you have a lawfully appointed guardian, an account may be created only with verifiable consent from your parent or guardian. We do not knowingly track or behaviourally monitor children, and we never run targeted advertising — at children or anyone else. If we learn that a child’s data was collected without that consent, we erase it.
9. How it is protected
- Passwords are stored as scrypt hashes, never in a readable form.
- Email verification and reset tokens are stored only as hashes, so a leaked database cannot be used to mint a working reset link.
- Session tokens are opaque random values in httpOnly, secure, same-site cookies, so page scripts cannot read them.
- Traffic is served over HTTPS, and administrative access is limited to named accounts.
No safeguard is absolute. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal, as Section 8(6) requires.
10. Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how your personal data is used, we will tell you by email before it takes effect.
11. Contact
Data protection queries, rights requests and grievances: hello@punitvithlani.com. Please write from the address on your account so we can verify who is asking — we will not act on an account request we cannot attribute.
See also the terms and conditions. Questions about the tools themselves can go to the same address: hello@punitvithlani.com.