1. Who we are
Prolition is a Search Everywhere Optimisation platform operated by PROLITION PTY LTD (ABN 21 677 968 311), a company registered in Australia. In this policy, "Prolition", "we" and "us" mean that company. "You" means the person using the platform, and where you use it on behalf of an organisation, that organisation.
You can reach us about anything in this policy at analytics@prolition.com.
2. Google user data
This section covers data Prolition accesses from your Google account. Prolition's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.1 What we access
With your permission, Prolition reads:
- Google Search Console performance data — impressions, clicks, average position, search queries and page URLs for the properties you connect. Requested scope:
webmasters.readonly. - Google Analytics 4 reporting data — aggregated reporting metrics and dimensions for the properties you connect, covering how organic sessions behave on your pages. Requested scope:
analytics.readonly. - Basic profile information — the email address and name on the Google account used to authorise the connection, so we can show you which account is connected.
We do not request write access. Prolition cannot create, modify or delete anything in your Google Search Console or Google Analytics account, and does not access Gmail, Drive, Calendar, Contacts or any other Google service.
2.2 How access is granted
Access is granted by you, through Google's own OAuth consent screen, and only for the properties you select. We store the resulting OAuth refresh token so scheduled analysis can run without you re-authorising each time. Tokens are encrypted at rest and are never shared with anyone outside the systems that run your account's analysis.
2.3 What we use it for
Google data is used for one purpose: generating search and content recommendations inside Prolition, for the account that granted the access. Specifically, we use it to:
- identify which of your existing pages underperform relative to the topics they target;
- rank content gaps by the opportunity behind them, rather than by keyword volume alone;
- show you how pages perform over time so recommendations can be revised.
We do not sell Google user data. We do not use it for advertising or ad targeting. We do not use it to train, retrain or fine-tune general-purpose artificial intelligence or machine learning models, and we do not permit our providers to do so. Google user data is not combined with data from other Prolition customers, and is never used to produce recommendations for any account other than the one that granted access.
2.4 Revoking access
You can withdraw access at any time, in either of two ways:
- inside Prolition, on the integrations settings screen, choose Disconnect for the Google property; or
- in your Google account, at myaccount.google.com/permissions, remove Prolition's access.
When you disconnect, we immediately delete the stored OAuth tokens and stop all further access. Search Console and Analytics data already ingested is removed from active systems as soon as reasonably practicable and within 30 days. Residual copies in encrypted backups expire or are overwritten within 90 days and are not used for any other purpose while awaiting deletion. To request deletion or written confirmation, email analytics@prolition.com.
3. Account and customer data
To run the platform we hold the name and email address of each user, the workspace and organisation they belong to, and authentication records such as password hashes and session identifiers. We also hold data you or your team put into the platform, including business and product information, research inputs, site structure, content plans and documents created in the service.
We process customer-supplied information to operate the service, provide support when you ask for it, and keep the platform secure and available. The terms of service explain the distinction between Your Data and intelligence generated or determined by the platform. We do not use one customer's private account or connected Google data to produce output for another customer.
4. What this website collects
This public website — prolition.com — sets no cookies, runs no analytics, embeds no third-party trackers, chat widgets or advertising pixels, and loads no fonts or scripts from third-party networks. There is nothing here to consent to.
Our hosting providers keep standard server and security logs, which may include IP address, timestamp, requested URL, referrer and user agent. These logs are used only to operate and secure the service and investigate abuse or faults, and are ordinarily retained for no more than 90 days. Relevant records may be kept longer where reasonably necessary to investigate an incident or meet a legal obligation. The logged-in application at app.prolition.com sets cookies that are strictly necessary to keep you signed in.
5. AI providers
Prolition uses third-party AI providers — Anthropic and OpenAI — to provide content planning and drafting features. To deliver those features, the relevant inputs are sent to those providers through their commercial APIs.
That transfer happens strictly to deliver the feature you have asked for. Under the API terms we operate on, these providers do not use the data submitted to train their models. Data is retained by them only for the limited periods set out in their own terms, for abuse monitoring, and is not used for any other purpose.
Where Google user data informs a recommendation, it is used as ranking and prioritisation signal within Prolition. Raw Search Console and Analytics exports are not sent to AI providers as training material, and no Google user data is used to train any model.
6. Storage, security and retention
Prolition's core application databases and file storage are hosted on Google Cloud Platform and are primarily configured in the Sydney, Australia region (australia-southeast1). Some supporting providers and globally distributed cloud services may process limited operational or security data in other locations, as described in section 7.
Data is encrypted in transit using TLS, and encrypted at rest by the storage layer. OAuth tokens and other credentials are encrypted with application-level encryption in addition to storage encryption. Access to production systems is restricted to the engineers who need it and is authenticated individually.
Customer data is isolated by workspace, with access controls designed so one customer cannot access another customer's business information, content plans or connected Google data.
Account and customer data is retained while your account is active. When you delete your account, profile information and connected Google data are removed from active systems as soon as reasonably practicable and within 30 days, except where we must retain particular records to meet a legal obligation. Encrypted backups and other recoverable copies expire or are overwritten within 90 days. Backup copies are kept beyond active deletion only for disaster recovery, are not used for ordinary business purposes, and deleted data will be removed again if a backup must be restored.
7. Who else sees your data
We never sell your data, and we do not share it for anyone else's marketing. We use a small number of service providers to run the platform, each with access only to what their function requires: our cloud hosting and database provider, our AI providers (Anthropic and OpenAI), our transactional email provider, and our error-monitoring provider.
We may disclose data if we are legally required to, for example in response to a valid order from a court or regulator. If that happens and we are permitted to tell you, we will.
8. Your rights and how to exercise them
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or ask us to stop processing it. Where you are in a jurisdiction that grants additional rights, such as the European Economic Area or the United Kingdom, we will honour those rights as they apply.
Send any of these requests to analytics@prolition.com. We will acknowledge within five business days and complete the request within 30 days, or tell you why we need longer.
If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
9. Changes and governing law
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle Google user data or personal information, we will notify account holders by email before it takes effect.
This policy is governed by the laws of the State of Victoria, Australia, and you and we submit to the non-exclusive jurisdiction of the courts of that state.