pelagic (“we”, “us”) is a privacy-first web analytics platform. this policy explains what we collect, why, and the choices you have. it covers two very different things: data about you (our customer, with an account) and data we process for you about visitors to your website. by using pelagic, you agree to this policy.
data about your visitors (the analytics)
pelagic's tracking script is cookieless by design. when you install it on your site, for each visit we process:
- the page viewed, the referrer it came from, and the time.
- device type and browser family (from the user agent).
- coarse location only: country and, where available, state or province. we never store precise coordinates, and city-level precision is deliberately discarded.
- custom events and revenue events you choose to send.
to count unique visitors without cookies, we compute a salted hash from the visitor's ip address and browser signature. the salt rotates every day, so the same person can't be recognized across days, and the raw ip address is never stored with analytics data. there are no cookies, no fingerprinting beyond that daily hash, no cross-site tracking, and no advertising ids. visitor data belongs to you: we show it in your dashboard and never sell it or use it for advertising.
data about you (your account)
- account details. your email and sign-in identity, managed by our authentication provider (clerk).
- your project details. the domains you add, product descriptions, brand voice, plus the keywords, articles, audits, and reports pelagic generates for you.
- billing. payments run through stripe. your card details go to stripe, never to our servers; we store only your subscription status, plan, and a customer reference.
- usage metering. counts of ai features you use (such as article tokens), so plan limits work.
- feedback. if you send in-app feedback, we store your message linked to your account email so we can follow up.
- basic technical data. standard logs your browser and our hosting provider generate (such as ip address and timestamps), used for security and reliability.
revenue integrations
if you connect a payment provider webhook (stripe, paddle, lemon squeezy, or polar), we receive the events you configure, verify their signatures, and store only aggregate revenue amounts attributed to traffic sources and pages. we don't store your customers' personal or card details.
google user data
if you choose to connect google search console, we access your search performance data (clicks, impressions, queries, pages) with read-only permission and store the oauth tokens needed to fetch it. we use this data only to display your performance and to inform article rewrites you request. we do not sell it, use it for advertising, or share it except with the service providers below. you can disconnect at any time, which deletes the stored tokens, and you can also revoke access from your google account permissions.
ai processing
features like chat, article generation, keyword research, audits, and ai visibility checks are powered by trusted third-party ai providers. we send them only what's needed to produce the result: your question, project details, and aggregate analytics (never raw visitor-level data). please avoid putting secrets such as passwords or api keys into your project description or chat.
cookies
pelagic's own site uses only cookies that are strictly necessary: clerk sets them to keep you signed in and protect your session. no advertising, analytics, or cross-site tracking cookies. the tracking script you install on your site sets no cookies at all, which is why your visitors don't need a consent banner for it.
sharing
we do not sell personal information. we share data only with the service providers that run pelagic (hosting, storage, authentication, payments, and ai processing), each only receiving what they need, and when required by law.
data retention & deletion
your projects and their analytics are kept so your dashboard works across visits. deleting a project from settings removes its analytics, keywords, articles, audits, and connected tokens. to delete your entire account, email us and we'll remove it along with its data.
children
pelagic is intended for adults (18+) and is not directed to children.
changes
we may update this policy from time to time. we'll update the date above.
contact
questions? email us at support@heypelagic.com.