Privacy Policy
Last updated 2026-07-31
This policy explains what personal data Wave Node (the Service) collects, why, who it is shared with, and what you can do about it. It covers the Service itself; it does not cover sites you connect to it, which have their own policies.
1. What we collect
- Account data — your name, email address and authentication credentials, plus the workspaces you belong to and your role in each.
- Connected search data — query, page, click, impression, position and date rows for the properties you connect through Google Search Console. This is data about your site's visitors in aggregate; Search Console does not expose individual users to us, and we do not attempt to re-identify anyone from it.
- Workspace content — projects, settings, saved analyses and API key metadata you create.
- Operational records — request logs, error reports and a metered record of calls made to paid data providers on your behalf, which is what makes the Usage screen possible.
We do not sell personal data, and we do not use your connected search data to train models or to build a product for anyone other than you.
2. Why we process it
- To provide the Service — authenticate you, scope data to your workspace, and run the analyses you ask for. This is necessary to perform our contract with you.
- To meter and bill usage, including vendor spend attributable to your workspace.
- To keep the Service working and secure — diagnose faults, prevent abuse, and enforce spending caps. This is our legitimate interest in operating a reliable service.
3. Who it is shared with
We use a small number of processors, each for a stated purpose, and share only what that purpose needs:
- Clerk — authentication and identity. Holds your name, email and login credentials.
- Convex — the application database holding workspace content and settings.
- Google Search Console — the source you connect. We read from it under the authorisation you grant and can stop when you revoke it.
- Third-party SEO data providers — queried per analysis for keyword and competitor data. These receive the search terms and domains an analysis is about, not your account details.
- Analytics warehouse and hosting — infrastructure that stores aggregates and runs the Service.
This list must be kept accurate: verify it against the deployed configuration before publishing, and update it whenever a processor is added or removed.
We also disclose data where we are legally required to, and to a successor in the event of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.
4. Where it is processed
Our processors may store and process data outside your country. Where personal data leaves the UK or EEA, transfers rely on the relevant safeguards, such as adequacy decisions or standard contractual clauses.
5. How long we keep it
- Account and workspace data — for as long as the workspace exists, and deleted within 30 days of the workspace being deleted.
- Imported search data — retained while the property is connected, and deleted with the workspace. Disconnecting a property stops further imports but does not by itself delete what was already imported; ask us if you want that removed sooner.
- Operational and billing records — kept for as long as we need them for accounting and audit.
Confirm these periods against the deployed retention configuration before publishing.
6. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, and complain to a data protection regulator. Much of this you can do yourself: account details are editable in Settings, API keys are revocable there, and deleting a workspace removes its data. For anything else, contact us and we will respond within the period the law allows.
7. Security
Access is scoped per workspace and enforced server-side, not in the browser. API keys are stored hashed and shown once at creation. We use encryption in transit throughout. No system is perfectly secure, and we will notify you and any relevant regulator of a breach affecting your personal data as required by law.
8. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
9. Changes
We may update this policy. The date at the top of this page always reflects the current version, and we will notify account holders of material changes before they take effect. See also the Terms of Use.
10. Contact
Privacy questions and rights requests should go to the contact address published for your workspace's billing account.