Legal
PRIVACY POLICY
How Colma collects, uses, and protects personal information.
PRIVACY POLICY
Last updated February 16, 2026
This Privacy Notice for Colma AI, LLC (doing business as Colma AI) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at colma.ai, access our application at app.colma.ai, or visit any website of ours that links to this Privacy Notice
- Access the Services through an authorized reseller or distribution partner
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at joel@colma.ai.
SUMMARY OF KEY POINTS
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. We also process Customer Data — business, website, and SEO data you submit or connect to the Services — as described below.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we collect any information from third parties? We may receive data from third-party platforms (such as Google Search Console and Google Analytics) that you authorize us to access. We do not purchase personal information from third-party data brokers.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties, including our AI model providers and other subprocessors listed in Section 5.
How do we keep your information safe? We have appropriate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- CUSTOMER DATA — YOUR BUSINESS AND SEO DATA
- HOW DO WE PROCESS YOUR INFORMATION?
- WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
- OUR SUBPROCESSORS
- DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
- DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
- HOW DO WE HANDLE YOUR SOCIAL LOGINS AND THIRD-PARTY PLATFORM CONNECTIONS?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
The personal information we collect may include the following:
- Names
- Phone numbers
- Email addresses
- Mailing addresses
- Usernames
- Passwords
- Contact preferences
- Contact or authentication data
Sensitive Information. We do not process sensitive information.
Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice at: https://stripe.com/privacy.
Social Media Login Data. We may provide you with the option to register with us using your existing social media account details. If you choose to register in this way, we will collect certain profile information about you from the social media provider, as described in Section 8 below.
Information automatically collected
We automatically collect certain information when you visit, use, or navigate the Services. This information includes device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services.
This includes:
- Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services.
- Device Data. Information about your computer, phone, tablet, or other device you use to access the Services, including IP address, device and application identification numbers, browser type, hardware model, internet service provider, and operating system.
- Location Data. Information about your device's approximate location based on your IP address.
Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. CUSTOMER DATA — YOUR BUSINESS AND SEO DATA
In the course of using our AI-powered SEO Services, you may submit, upload, or connect data related to your business and marketing activities. This "Customer Data" includes but is not limited to:
- Website URLs and domain information
- Keywords, search queries, and SEO targets
- Website performance data, search traffic data, and analytics
- Competitor URLs and market research inputs
- Content you submit for optimization or generation
- Credentials and access tokens for connected third-party platforms (e.g., Google Search Console, Google Analytics, Google Ads)
- Any other business or marketing data you provide through the Services
How we use Customer Data. We use Customer Data solely to provide and improve the Services to you. Specifically:
- We transmit relevant portions of your Customer Data to our AI model providers to generate analyses, recommendations, and content on your behalf. See Section 7 for more details.
- We use Customer Data to power our SEO data integrations and third-party data lookups (e.g., keyword volume and competition data).
- We may use aggregated, de-identified, and anonymized Customer Data to improve and train our own models and improve the Services. We will not use your identifiable Customer Data to train third-party AI models without your consent.
Customer Data ownership. As between you and Colma AI, LLC, you retain all right, title, and interest in and to your Customer Data. We do not sell or rent your Customer Data to third parties.
Connected third-party platforms. If you connect third-party platforms to the Services (such as Google Search Console or Google Analytics), we will access data from those platforms solely to provide the Services to you. Our use of data obtained through Google APIs is subject to the Google API Services User Data Policy, including the Limited Use requirements. We access only the data necessary to deliver the requested features and do not use Google user data to serve advertising or for any other purpose not permitted by the Google API Services User Data Policy.
Data submitted by Reseller-provisioned users. If you access the Services through a Reseller, the Customer Data you submit is processed by Colma AI, LLC as described in this Privacy Policy. The Reseller does not have access to your Customer Data unless separately authorized by you.
3. HOW DO WE PROCESS YOUR INFORMATION?
We process your personal information and Customer Data for a variety of reasons, including:
- To provide the Services. We process your information and Customer Data to deliver the AI-powered SEO analyses, reports, recommendations, and content you request through the Services.
- To facilitate account creation and authentication. We process your information so you can create and log in to your account, including through our authentication provider WorkOS.
- To communicate with you. We may process your information to respond to your inquiries and send you service-related messages via our email provider Resend.
- To send administrative information to you. We may process your information to send you details about our products and services, changes to our Terms of Service, this Privacy Policy, and other similar information.
- To improve and develop the Services. We may use aggregated, de-identified data derived from your use of the Services to improve our algorithms, AI models, and product features.
- For security and fraud prevention. We process your information to identify and prevent fraud, abuse, and other harmful activities. We use BetterStack for monitoring and logging to support this.
- To comply with our legal obligations. We may process your information to comply with applicable laws, respond to legal requests, and exercise, establish, or defend our legal rights.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We may share your personal information and Customer Data in the following situations:
- AI Model Providers. We share relevant input data (including portions of Customer Data) with our AI model providers — currently Anthropic, OpenAI, Google (Gemini), and Perplexity — to generate AI-powered outputs. These providers process data pursuant to their own privacy policies and our data processing agreements with them.
- SEO and Web Data Providers. We share limited data (such as keywords and URLs) with DataForSEO to retrieve keyword metrics, search volume, and competitive data, and with Firecrawl to retrieve and process web content necessary to provide the Services.
- Payment Processors. We share payment information with Stripe to process transactions.
- Infrastructure Providers. We host the Services on Render and use Cloudflare for network security, performance, and DNS. Your data passes through and is stored on infrastructure operated by these providers.
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Legal Requirements. We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
- Vital Interests. We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person, or illegal activities.
We will not sell or rent your personal information or Customer Data to third parties for their own marketing or commercial purposes.
5. OUR SUBPROCESSORS
We use the following third-party subprocessors to provide the Services. We maintain data processing agreements with these subprocessors where required by law.
| Subprocessor | Purpose | Privacy Policy |
|---|---|---|
| Anthropic | AI model inference for SEO analysis and content generation | https://www.anthropic.com/privacy |
| OpenAI | AI model inference for SEO analysis and content generation | https://openai.com/policies/privacy-policy |
| Google (Gemini) | AI model inference for SEO analysis and content generation | https://policies.google.com/privacy |
| Perplexity | AI-powered web research and search synthesis | https://www.perplexity.ai/hub/privacy |
| DataForSEO | Keyword research, search volume, and competitive SEO data | https://dataforseo.com/privacy-policy |
| Firecrawl | Web crawling and content extraction | https://www.firecrawl.dev/privacy |
| Stripe | Payment processing | https://stripe.com/privacy |
| Render | Cloud infrastructure and application hosting | https://render.com/privacy |
| Cloudflare | Network security, performance, and DNS | https://www.cloudflare.com/privacypolicy/ |
| PostgreSQL (via Render) | Primary database for application data storage | https://render.com/privacy |
| WorkOS | Authentication, single sign-on, and user directory | https://workos.com/privacy |
| Resend | Transactional email delivery | https://resend.com/privacy |
| BetterStack | Logging, monitoring, and uptime tracking | https://betterstack.com/privacy |
| Google (APIs) | Google Search Console, Analytics, and Ads data access | https://policies.google.com/privacy |
We will update this list when we add or change material subprocessors. We encourage you to review this section periodically.
6. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.
We use the following categories of cookies:
- Strictly Necessary Cookies. Required for the Services to function. These cannot be opted out of.
- Functional Cookies. Remember your preferences and settings to improve your experience.
- Analytics Cookies. Help us understand how the Services are being used so we can improve them. We use aggregated and anonymized analytics data.
- Third-Party Cookies. Certain third-party services we use (including Cloudflare) may set their own cookies in accordance with their own privacy policies.
You can control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Services. To the extent cookie-based tracking constitutes a "sale" or "sharing" under applicable US state laws, you may opt out as described in Section 14.
7. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
Yes. Our Services are powered by artificial intelligence, machine learning, and similar technologies (collectively, "AI Products"). These tools are designed to provide automated SEO and digital marketing analysis, content generation, and workflow automation.
Use of AI Technologies
We provide the AI Products through third-party AI service providers, currently including Anthropic, OpenAI, Google (Gemini), and Perplexity. As outlined in this Privacy Notice, your input data and Customer Data will be shared with and processed by these AI service providers to enable your use of our AI Products. You must not use the AI Products in any way that violates the terms or policies of any AI service provider.
Our AI Products
Our AI Products are designed for the following functions:
- Automated SEO analysis and auditing
- Keyword research and content strategy recommendations
- AI-assisted content generation and optimization
- Competitive analysis and reporting
- Web research and content extraction
- Digital marketing workflow automation
How We Process Your Data Using AI
All personal information and Customer Data processed using our AI Products is handled in line with this Privacy Notice and our agreements with third-party AI service providers. Input data you provide is transmitted to AI service providers for inference only — we do not authorize these providers to use your identifiable data to train their own models, consistent with the data processing agreements we maintain with them.
How to Opt Out
You may limit the use of your data with our AI Products in the following ways:
- Opting out of model improvement. You may contact us at joel@colma.ai to opt out of having your aggregated, de-identified usage data used to improve our AI models. Note that this does not affect our ability to use your data to provide the Services to you.
- Disconnecting third-party accounts. You may revoke our access to any connected third-party accounts (e.g., Google Search Console) at any time through those platforms' settings or by contacting us.
- Account deletion. You may request deletion of your account and associated data at any time. See Section 17 for more information.
Note that opting out of certain AI processing may limit or prevent your access to core features of the Services.
8. HOW DO WE HANDLE YOUR SOCIAL LOGINS AND THIRD-PARTY PLATFORM CONNECTIONS?
Authentication and Social Logins
Our Services offer you the ability to register and log in using third-party account details (such as your Google or GitHub account). Authentication is handled through WorkOS. Where you choose to log in via a third-party account, we will receive certain profile information about you from that provider, which we use only for the purposes described in this Privacy Notice.
Third-Party Platform Connections
Our Services allow you to connect third-party marketing and analytics platforms, including:
- Google Search Console
- Google Analytics
- Google Ads
- Other marketing platforms as made available through the Services
When you connect a third-party platform, you authorize us to access and use data from that platform solely to provide the Services to you. Our use of data obtained through Google APIs is subject to the Google API Services User Data Policy, including the Limited Use requirements: we will not use Google user data for any purpose other than to provide and improve the specific features of the Services you requested. We do not use Google user data to serve advertising.
You can revoke our access to any connected platform at any time through that platform's security settings or by contacting us at joel@colma.ai. We will delete any data obtained from the platform upon revocation, except where we are required to retain it by law.
9. HOW LONG DO WE KEEP YOUR INFORMATION?
We will only keep your personal information and Customer Data for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. In general:
- Account data is retained for as long as you have an active account with us.
- Customer Data is retained for as long as your account is active and for thirty (30) days following termination to allow for data export, after which it will be deleted from our active systems.
- Log and monitoring data retained by BetterStack is kept for a limited period consistent with operational and security needs.
- Backup data may be retained for a longer period consistent with our backup and disaster recovery practices, but will be isolated from active processing.
- Aggregated, de-identified data derived from your use of the Services may be retained indefinitely as it cannot reasonably be used to identify you.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
10. HOW DO WE KEEP YOUR INFORMATION SAFE?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process, including:
- Encryption of data in transit (TLS), enforced via Cloudflare
- Encryption of data at rest within our Render-hosted infrastructure
- Access controls limiting employee access to Customer Data to those who need it to provide the Services
- Authentication and access management via WorkOS
- Continuous monitoring and alerting via BetterStack
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
11. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at joel@colma.ai.
12. WHAT ARE YOUR PRIVACY RIGHTS?
Depending on your country, province, or state of residence, you may have the right to:
- Review, change, or terminate your account at any time
- Withdraw consent to the processing of your personal information
- Opt out of marketing and promotional communications at any time
Account Information. If you would at any time like to review or change the information in your account or terminate your account, please contact us using the contact information provided below.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. We will retain Customer Data for thirty (30) days following termination to allow for data export, after which it will be deleted.
If you have questions or comments about your privacy rights, you may email us at joel@colma.ai.
13. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information.
Categories of Personal Information We Collect
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email, IP address, account name | YES |
| B. Personal information (CA Customer Records) | Name, contact information | YES |
| C. Protected classification characteristics | Gender, age, race, ethnicity | NO |
| D. Commercial information | Purchase history, payment information | NO |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet or network activity | Interactions with our Services | YES (limited to our Services) |
| G. Geolocation data | Device location | NO (IP-based approximate location only) |
| H. Audio, electronic, sensory information | Voice/video recordings | NO |
| I. Professional or employment-related information | Business contact details, job title | YES (if provided) |
| J. Education information | Student records | NO |
| K. Inferences | Profiles drawn from collected data | NO |
| L. Sensitive personal information | N/A | NO |
| M. Customer Data | Keywords, URLs, website analytics, SEO data submitted through the Services | YES |
Your Rights
You have the right to:
- Know whether or not we are processing your personal data
- Access your personal data
- Correct inaccuracies in your personal data
- Request deletion of your personal data
- Obtain a copy of the personal data you previously shared with us
- Non-discrimination for exercising your rights
- Opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling
How to Exercise Your Rights
To exercise these rights, you can contact us by emailing personal-info-request@colma.ai or joel@colma.ai, or by contacting us at the address provided below.
California "Shine The Light" Law
California Civil Code Section 1798.83 permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.
15. DO WE MAKE UPDATES TO THIS NOTICE?
Yes, we will update this notice as necessary to stay compliant with relevant laws and to reflect changes to our data practices. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
16. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at joel@colma.ai or contact us by post at:
Colma AI, LLC 305 Scott Street San Francisco, CA 94117 United States
17. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information.
To request to review, update, or delete your personal information or Customer Data, please contact us at: personal-info-request@colma.ai.
You may request an export of your Customer Data at any time by contacting joel@colma.ai. We will provide your data in a commonly used, machine-readable format within thirty (30) days of your request.