Legal

Privacy Policy

Effective October 2, 2026 · See also our Terms of Service

LogNorm helps startups grow by analysing their websites, search performance and market. That means handling some of your data, and we take that seriously: we collect what the product needs, use it to run LogNorm for you, never sell it, and give you control over what you connect.

01Who we are

LogNorm (“LogNorm”, “we”, “us”) provides a growth platform for startups at lognorm.com. This policy explains how we handle personal information when you visit our website, create an account or use the LogNorm app.

For information you put into a workspace (your websites, content and connected accounts), the workspace’s organisation decides what goes in and we process it on its behalf. For account, billing and website visitor information, we decide how it is used. Questions about either go to [email protected].

02Information we collect

  • Account details. Your name, email address, password (stored only as a salted hash) and profile picture. If you sign in with Google or GitHub, we receive your name, email address and profile picture from them.
  • Workspace content. What you and your team add: websites, keywords, competitors, AI prompts to track, Company Brain documents, briefs, drafts, moves and comments.
  • Website data. Public pages of the websites you add, and of competitors you track, which we crawl to analyse structure, content and search visibility.
  • Connected accounts. When you connect Google Search Console, a publishing destination (WordPress, Ghost, GitHub or a webhook) or your own AI provider key, we store the access tokens or keys needed to act on your behalf, encrypted with a key unique to your workspace.
  • Billing information. Your plan, invoices and payment status. Payments are processed by Dodo Payments; we never see or store full card numbers.
  • Usage and device information. Sign-in sessions (IP address, browser and device), actions taken in the app (kept as an activity log for your workspace), and how many credits each feature used.
  • Messages. What you send us by email, and delivery status for the emails we send you.

03Google user data

LogNorm can use Google in two ways. Each asks for only what it needs, and you choose whether to connect it.

  • Sign in with Google. We request your basic profile: name, email address and profile picture (the openid, email and profile scopes). We use them only to create your account and sign you in.
  • Google Search Console. With your permission, we request read-only access (webmasters.readonly) to the Search Console properties you choose. We read the list of your properties and their search performance data: queries, pages, clicks, impressions, click-through rate and average position. We cannot change anything in your Search Console account.

How we use it. Search Console data is used only to provide LogNorm’s features to your workspace: showing your search performance, finding opportunities and decaying pages, recommending and prioritising moves, grounding briefs and drafts in the queries people actually search, and measuring the results of what you publish. To produce those recommendations and drafts, relevant excerpts (for example a page’s top queries) may be sent to an AI model provider listed below, which processes them only to return a result to us.

What we never do. We do not sell Google user data, use it for advertising, share it with data brokers, or use it to train or improve generalised or non-personalised AI or machine-learning models. People at LogNorm don’t read it unless you ask us to for support, it is needed for security or abuse investigations, or the law requires it.

Your control. You can disconnect Search Console at any time in the app. Disconnecting revokes our access at Google and lets you delete the Search Console data we stored. You can also remove LogNorm’s access from your Google Account at myaccount.google.com/permissions.

LogNorm’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

04How we use information

  • To provide LogNorm. Run analyses, build your weekly plan, generate briefs and drafts, publish where you tell us to, and measure outcomes.
  • To communicate with you. Account emails (confirmation, password resets, security notices, invitations), your weekly plan digest, and billing receipts. Account and security emails can’t be switched off while you have an account; the digest can.
  • To bill you. Manage your plan, credits and invoices through our payment provider.
  • To keep LogNorm secure. Detect abuse, fraud and unauthorised access, rate-limit sign-in attempts, and keep an audit log of staff access to workspaces.
  • To support and improve LogNorm. Answer your questions and understand, in aggregate, which features are used so we can improve them.
  • To meet legal obligations. Keep records the law requires and respond to lawful requests.

We do not sell personal information, and we do not use it for advertising. Our public website (not the LogNorm app) uses Google Analytics to count visits and see which pages are read; there are no advertising trackers.

05AI processing

Many LogNorm features use AI models. To generate a result, we send the model the context it needs, such as your website’s content, your Company Brain, the keywords or topics involved and, where relevant, Search Console excerpts. Requests go through our AI providers’ business APIs (optionally via Cloudflare AI Gateway), or to your own provider when you add your own key, in which case that provider’s terms with you apply.

We don’t use your data to train AI models, and we use providers and settings that don’t use API requests to train their models. AI output can be wrong: review drafts before you publish them.

06Who processes it

We share information only with the service providers that run LogNorm for us, under contracts that limit their use of it to providing their service:

ProviderWhat forLocation
RailwayApplication hostingUnited States
NeonDatabase and file storageUnited States (AWS)
CloudflareDNS, content delivery, security, AI gatewayGlobal
Dodo PaymentsPayments, taxes and invoicing (merchant of record)Global
ResendSending emailUnited States
Amazon Web ServicesReceiving emailGlobal
OpenAI, Anthropic, GoogleAI modelsUnited States
DataForSEOSearch and keyword data for the sites and keywords you researchGlobal
GoogleSign in with Google and Search Console, when you connect themGlobal
Google AnalyticsVisit statistics for our public website (not the app)Global

When you publish, LogNorm sends content to the destination you chose (for example your WordPress site or GitHub repository). We may also disclose information if the law requires it, to protect the rights and safety of our users or LogNorm, or as part of a merger or acquisition, in which case this policy continues to apply to it.

07Cookies

The LogNorm app uses only cookies needed for the service to work:

  • Session cookie. Keeps you signed in. Expires after 30 days without use, or when you sign out.
  • ln_site. Remembers which of your websites you were working on.
  • ln_ref. Remembers a referral code from a link you followed, for 30 days, so the referrer can be credited.

We also keep small preferences, such as light or dark mode and editor layout, in your browser’s local storage. There are no advertising cookies.

Our public website (the home page, product pages, pricing, docs and blog) also sets Google Analytics cookies (_ga and _ga_*) to measure visits. The signed-in app doesn’t. You can opt out with Google’s browser add-on.

08How long we keep it

  • Account and workspace data. Kept while your account and workspace exist. When a workspace is deleted, its data is removed from our live systems straight away and from backups within 30 days.
  • Search Console data. Kept while the connection exists, or deleted on disconnect if you choose.
  • Billing records. Kept as long as tax and accounting law requires.
  • Security logs. Sign-in sessions and rate-limit records are short-lived and expire on their own.

09Your choices and rights

Depending on where you live (including under the GDPR, UK GDPR and California law), you can ask to access, correct, export or delete your personal information, and to object to or restrict how we use it. You can update your profile and delete workspaces in the app. To delete your account or make any other request, email [email protected] from your account’s address; we answer within 30 days.

If you’re in the EU or UK, you can also complain to your local data protection authority. We’d appreciate the chance to address your concern first.

10Security

Traffic to LogNorm is encrypted in transit (TLS) and data is encrypted at rest. Passwords are stored as salted hashes. Connected-account tokens, publishing credentials and your own AI keys are encrypted with AES-256-GCM using a key unique to your workspace. Staff access to workspaces is limited, and every staff session inside a workspace is recorded in an audit log. No system is perfectly secure; if a breach affects your information, we will tell you without undue delay.

11International transfers

LogNorm is hosted in the United States, and our providers may process information in other countries. Where the law requires it, transfers are covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

12Children

LogNorm is a business tool and isn’t intended for anyone under 16. We don’t knowingly collect information from children; if you think we have, contact us and we’ll delete it.

13Changes to this policy

We’ll post any changes here and update the effective date. If a change is significant, we’ll also email account owners before it takes effect.

14Contact

Email [email protected] with any question about privacy or this policy.