Privacy Policy
Last updated: 10 September 2026
Who we are
AlmightyFormulaSEO is operated by THE EMADKO HOUSE, registered with the Corporate Affairs Commission in Nigeria as a business name (BN 9814925). We are the data controller for the personal data described on this page.
THE EMADKO HOUSE is a registered business name rather than a separate legal entity, which means the data controller is its proprietor trading as THE EMADKO HOUSE. Their full legal name and postal address are not published here, but we will give them to you on request and will not ask why you want them. Email privacy@almightyformulaseo.com and we will reply with both. We also provide them to any regulator or court that asks.
THE EMADKO HOUSE has no establishment in the United Kingdom or the European Union. We are not registered with the UK Information Commissioner's Office, and we do not claim a registration number we do not hold. Where UK or EU data protection law applies to you because we offer this service to you, we apply the rights set out on this page in full, regardless of where we are established.
For anything about your data or this policy, email privacy@almightyformulaseo.com. For general questions, hello@almightyformulaseo.com. We do not publish a postal address here, because the address behind the registration is a private one. It is filed with the Corporate Affairs Commission. If you need it, for a formal notice or a regulator's request, email privacy@almightyformulaseo.com and we will provide it.
The short version
We collect the email address you sign up with, the business details you give us, the content you create, and the credentials you choose to connect so we can publish for you. We send your topics and content to an AI provider so articles can be written, and to the platforms you connect so articles can be posted. Inside the app we record how the interface is used, with the content masked, so we can find the places people get stuck. We use no advertising or tracking cookies, and we do not sell your data. The rest of this page is the detail behind those sentences, including the parts that are less comfortable.
What we collect and why
Your account
When you sign up we collect your email address and a password. The password is hashed by our authentication provider and we never see or store the plain text of it. We also store an account identifier, the dates your account was created and confirmed, and your sign in times. You have to confirm your email address by clicking a link before the account works.
We also record the timezone your browser reports when you sign up, for example Europe/London. That exists so a schedule set to nine in the morning runs at nine in your morning rather than nine UTC. You can change it in Settings.
Your business profile
During onboarding, and at any time afterwards in Settings, you can tell us your company name, website address, a description of what your business does, who your audience is, your key products, your value proposition, your preferred writing tone, your target market and language, and the keywords you care about. You can also set a separate notification email address.
We use this so articles sound like your business rather than generic filler. It is sent to our AI provider as context whenever an article is generated. If you would rather it were not, leave those fields empty. Your articles will simply be more generic.
The website you ask us to analyse
If you give us your website address, our server fetches the public pages of that site and reads the text so we can work out what your business does and which keywords suit it. We only fetch what is publicly reachable, the same as any search engine crawler does. The extracted text is sent to our AI provider to be summarised, and the summary is saved to your business profile.
Content you create
Articles you generate or write, including the title, body, meta description, focus keyword, tags, word count, status, hero image address and publish dates. Keywords you track, with our trend and volume estimates. Your automation schedules and calendar entries. A log of actions taken in your account, such as an article being generated or published.
When we publish to a platform you connected, we store the outcome of that attempt, including the HTTP status code and the response the platform sent back. That response sometimes contains details about your site, such as a post identifier or an error message naming your account on that platform. We keep it so that when a publish fails you can see why, rather than only that it did.
Credentials you connect
To publish on your behalf we have to store the access details you give us:
- WordPress: your site address, your username, and the application password you generate for us.
- Shopify: your store address and API access token.
- Webflow: your API key.
- Custom webhook: the URL and the shared secret.
- LinkedIn: when you connect an account we receive and store an access token, a refresh token, your LinkedIn member identifier, your display name, your profile picture address and the permissions you granted. If you connect a Company Page we also store that page's identifier, name, logo, your role on it, and the list of pages you can administer, so we can show you a destination picker.
Settings also contains older fields where you can paste your own API keys for services such as Pexels, Apify, YouTube or Groq. These are optional and unused by default. Leave them blank unless we have asked you to fill one in.
We use these credentials for nothing except the actions you ask for. We do not read your site, your inbox or your LinkedIn feed.
Google Search Console, if you connect it
Connecting Search Console is optional. If you do, you sign in with Google and grant AlmightyFormulaSEO one permission: read-only access to your Search Console data. We cannot change anything in your Search Console, and we ask for nothing else in your Google account.
What we receive and store. When you connect, Google gives us an access token and a refresh token, which let us read your Search Console data without asking you to sign in again every hour. We also store the email address and account identifier of the Google account you connected, the permissions you granted, the Search Console property you choose, and your permission level on that property. We fetch the list of properties your Google account can see so you can pick one, but we keep only the one you choose.
What we do not store yet. Today we do not download or keep any of your Search Console performance data - no clicks, impressions, search queries or rankings. When we add that, we will update this section and ask you to agree before we begin.
How we use it. Only to show your own Search Console information to you, in your AlmightyFormulaSEO dashboard, for the property you chose. Nothing else.
Where it is kept and who can see it. It is stored in our database, in the European Union, in a table that your browser, other customers and our own admin screens cannot read - only our server functions can use the tokens. Your browser only ever sees whether you are connected, which property you chose and the email of the connected account. It is encrypted in transit, and our database provider encrypts it at rest. Nobody at AlmightyFormulaSEO looks at it, except when you ask us to help with a problem and agree to us looking, when it is needed to investigate a security issue or abuse, or when the law requires it.
What we never do with it.
- We never sell it, or share it with advertisers, data brokers or anyone else.
- We never use it for advertising, or to judge anyone's creditworthiness.
- We never send it to our AI provider or to any other AI service, and we never use it to train, fine-tune or improve any AI or machine-learning model, ours or anyone else's. An automated test runs before we release any change, and it fails if any part of AlmightyFormulaSEO that talks to an AI model could read your Google data.
Disconnecting and deletion. You can disconnect at any time in Settings. Disconnecting revokes our access at Google and deletes the tokens and connection details we hold, straight away. Deleting your account deletes them too. You can also remove our access yourself from your Google account at myaccount.google.com/permissions.
AlmightyFormulaSEO's use of information received from Google APIs adheres to the Google API Services User Data Policy, and we follow its stricter Limited Use requirements voluntarily, even though the read-only Search Console permission is not one they are required for. Google's own handling of your data is covered by the Google Privacy Policy.
Images you upload
Uploads are kept in a folder named after your account, so no other customer can overwrite or replace your files.
Public posts we find for you
The listening feed searches public content matching your keywords across Reddit, Quora and YouTube. For each result we store the title, the full text of the post, a short extract, the link, engagement numbers such as upvotes or comment counts, and the public display name of whoever posted it.
That is information those people chose to make public on those platforms, and we retrieve only what those platforms publish. It is still personal data about them, so please read Content about other people below before building articles on it.
We also keep a shared cache of results by keyword, so two customers searching the same keyword do not trigger two identical searches. That cache is not linked to any account.
The YouTube part of the listening feed uses YouTube API Services. We send YouTube your keywords and nothing else, and we never access your own YouTube or Google account through it. What YouTube returns is subject to the YouTube Terms of Service, and Google's handling of your requests is covered by the Google Privacy Policy. Everything we retrieve from YouTube, meaning comments, video titles and descriptions, and the display names of the people who posted them, is deleted within 30 days of being retrieved, as YouTube's developer policies require.
Usage and technical data
We count how many scans you run each month against your allowance, and keep a record of each scan run and each onboarding job so we can show you progress and diagnose failures. We also count the articles you generate each month, and for every request we send to our AI provider we record how many tokens it used and what we estimate it cost, so we can see what the service costs to run and set fair limits. That record holds counts and costs, not the text of your articles.
Our web servers keep standard access logs containing your IP address, the time of the request, what was requested and your browser's user agent string. These are used for security, abuse investigation and fixing faults.
How you use the app
Inside the signed-in app we use Microsoft Clarity to record how the interface is used - where people click, how far they scroll, and where they get stuck. It is there for one reason: the screens where you connect your CMS are the hardest part of this product, and we would rather see where they fail than guess.
We run it with content masking on, so a recording shows the shape of the page and what you interacted with, not what the page said or what you typed. Anything entered into a text box or a drop-down is masked by Clarity in every mode and is never sent - that includes every API key, token and password you type into a connection form. We have also turned Clarity's cookies off, so it does not store an identifier on your device or follow you between visits.
It runs only on the signed-in application. It is not on this page, the blog, or any other public part of the site. If you would rather not be recorded at all, email us and we will exclude your account.
What we do not collect
Stated explicitly, because most policies are vague here:
- No marketing or advertising analytics. There is no Google Analytics, no Plausible, no PostHog and no advertising pixel anywhere in this product, and nothing on our public pages at all. The one thing we do run is the masked in-app session recording described above, and it exists to fix the product rather than to profile you.
- No advertising or tracking cookies. The only third party inside the app is Microsoft Clarity, configured not to set cookies.
- No payment card details. We do not take payments at all at the moment. If that changes, cards will be handled by a payment processor and card numbers will never reach our servers.
- We do not sell, rent or share your personal data for anyone else's marketing.
- We do not use your content to train AI models of our own.
Cookies and browser storage
We use no cookies for tracking or advertising. Microsoft Clarity, which records how the signed-in app is used, is configured with its cookies turned off - it writes no _clck or _clsk cookie unless you have given consent for it. We use your browser's local storage for exactly two things:
- Your login session, so you stay signed in between visits. Signing out or clearing site data removes it.
- Anything typed into onboarding but not yet saved, so a refresh does not lose your answers. It is cleared when onboarding finishes.
Both are strictly necessary for the app to work, and neither follows you anywhere else.
One caveat we would rather state than hide: our pages load fonts from Google Fonts, so your browser makes a request to Google's servers and Google receives your IP address as part of it. We are moving to serving those fonts ourselves to remove that.
Who we share your data with
We use a small number of providers to run AlmightyFormulaSEO. Each receives only what it needs.
| Provider | What it does for us | What it receives |
|---|---|---|
| Supabase | Database, login, file storage and the server functions behind our features | Everything described above, since this is where the application data lives |
| DeepSeek | Writes your articles, drafts your LinkedIn posts, summarises the website you ask us to analyse | Your topics and keywords, your business profile, article content, and the text of the site you asked us to analyse |
| Pexels | Supplies stock hero images | The search term derived from your keyword |
| Apify | Runs the Reddit and Quora searches behind the listening feed | Your keywords |
| YouTube Data API, for the YouTube part of the listening feed | Your keywords | |
| Microsoft | Clarity, which records masked sessions and heatmaps of the signed-in app so we can find where the interface fails | How you move around the app - clicks, scrolls and page transitions. Page content is masked, and text boxes are never captured |
| Receives the posts we publish for you | Your post content, and your token so LinkedIn knows who is posting | |
| Your CMS | WordPress, Shopify, Webflow or your own webhook, receiving the articles we publish | The article and its images, plus your credentials for that platform |
| Hetzner | Hosts the servers that serve this site | Web server logs, including your IP address |
We may also disclose data where we are legally required to, for example under a court order, or to protect our rights or someone's safety. We will tell you when that happens unless we are legally barred from doing so.
If AlmightyFormulaSEO is ever sold, your data may transfer with it. We would tell you before that happened, in time for you to delete your account first.
Where your data goes
We are based in Nigeria. The application database, your files and your account records are stored in the European Union, in the AWS eu-central-1, Frankfurt, Germany region. The web servers are operated by Hetzner Online GmbH, Falkenstein, Germany.
We say that plainly rather than burying it, because China has no UK or EU adequacy decision and you deserve to decide with your eyes open. In practice: do not put personal data, customer names, confidential information or anything sensitive into article topics, context fields or your business profile. Article generation is the core of the product and there is currently no version of it that avoids this transfer. If that is not acceptable for your business, AlmightyFormulaSEO is not the right tool for you, and we would rather tell you now than after you have signed up.
Where our providers offer standard contractual clauses or the UK International Data Transfer Addendum, we rely on those. Where a provider does not, we have told you above so the choice is yours.
Our legal bases
Under UK GDPR we need a lawful basis for each use of your data. Ours are:
- Performing our contract with you: running your account and providing the features you signed up for, including generating and publishing articles.
- Consent: connecting a third party account such as LinkedIn or your CMS. You give it by completing the connection flow and withdraw it by disconnecting, which you can do at any time in the app.
- Legitimate interests: keeping the service secure, investigating abuse, diagnosing faults and understanding which features break. We have weighed these against your rights and consider them uses you would expect from a product like this.
- Legal obligation: keeping records the law requires us to keep, such as tax and accounting records once we start charging.
How long we keep things
We keep your account and your content for as long as your account exists.
If you delete your account we delete your data. Articles, keywords, settings, connected credentials, listening feed, activity log, automations and uploaded images all go. This is enforced in the database itself, so deleting the account removes everything attached to it rather than leaving orphaned rows behind. Email privacy@almightyformulaseo.com and we will action it.
Two exceptions, stated so they are not a surprise:
- The shared keyword cache is not tied to any account and is not deleted with one. It holds public posts and nothing about you.
- Database backups roll off on their own cycle. Deleted data can persist in a backup for up to 7 days, after which it is gone.
One thing is kept for less time than your account: anything retrieved from YouTube is deleted automatically within 30 days of being retrieved, whether or not your account still exists, because YouTube's developer policies require it. YouTube items therefore drop out of your listening feed after 30 days, and a later scan finds them again if they are still public. Articles you wrote from them are yours and are not affected.
If you connect Google Search Console, the connection details and tokens are kept while you stay connected, and deleted as soon as you disconnect or delete your account.
Web server access logs are kept for 30 days.
Your rights
Under UK GDPR and the equivalent EU rules, you have the right to:
- Get a copy of the personal data we hold about you.
- Correct anything inaccurate. Most of it you can edit yourself in Settings.
- Delete your data, as described above.
- Restrict or object to how we use it, including objecting to anything we do on the basis of legitimate interests.
- Take your data elsewhere in a portable format. Your articles are yours and we will export them for you.
- Withdraw consent for any connected account at any time by disconnecting it. That does not undo posts already published.
Email privacy@almightyformulaseo.com to use any of these. We will respond within one month and we will not charge you for it.
If you think we have handled your data badly, please tell us first so we can put it right. If we do not, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection regulator in your own country if you are elsewhere in Europe.
Security
What we do:
- All traffic to the site is encrypted with TLS.
- Every table holding customer data has row level security enabled, so one account cannot read another's rows even if a bug in the app tried to make it.
- Your LinkedIn tokens live in a table your browser cannot read at all. Only our server side functions can reach them, which means a hijacked browser session cannot walk off with your LinkedIn token.
- Passwords are hashed, never stored as text.
- Access to production data is limited to the smallest number of people possible, currently a very small team.
What we would rather you knew than discovered:
- CMS credentials, meaning your WordPress application password, Shopify token and Webflow key, sit in a table your own signed in account can read. They are protected from other customers, but they are not held in a separate encrypted vault. Use application passwords and scoped API keys rather than your main account password, and revoke them on the platform's side if you stop using AlmightyFormulaSEO.
- The image bucket is public, as described above.
- No system is perfectly secure. If we suffer a breach affecting your personal data we will notify the Nigeria Data Protection Commission, and the UK Information Commissioner's Office where UK GDPR applies, within 72 hours where required, and tell you directly where there is a real risk to you.
Content about other people
The listening feed hands you public posts written by other people, including their usernames. If you act on that material, you are the one deciding what to do with it, which under data protection law generally makes you the controller for that use.
In practice: quoting a public post and linking to it is normal practice. Republishing someone's post wholesale, pulling a named individual into your marketing, or trying to identify or contact people from what you found is not what AlmightyFormulaSEO is for, and it may put you in breach of the law and of those platforms' terms. Please do not.
Children
AlmightyFormulaSEO is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
If we change this policy in a way that materially affects you, such as adding a provider that receives your data, we will email you before the change takes effect. Smaller corrections will just be made here with the date at the top updated. We will not quietly reduce your rights.
Contact
Privacy and data requests: privacy@almightyformulaseo.com
General: hello@almightyformulaseo.com
Support: support@almightyformulaseo.com