Privacy Policy

Winking Toad — SEO Crawler & Site Audit Tool

Last updated: October 2026

This policy describes what Winking Toad ("we," "our," "the Service") collects when you use winkingtoad.com, why we collect it, and who we share it with. We've written it to describe what the application actually does, not generic boilerplate.

1. What we collect

Account information

Crawl data

Winking Toad SEO Fixer (Shopify App Store app)

If you install Winking Toad SEO Fixer from the Shopify App Store, this section describes exactly what that app accesses and stores, separately from the connection-based Shopify integration described in the table below (that one is for winkingtoad.com account holders who manually paste in their own store's credentials; this one is the installable Shopify app itself).

What's storedWhy
Your shop's .myshopify.com domain and an Admin API access token (scopes: read_products, write_products) Reading your product catalogue's SEO/alt-text completeness, and writing the specific SEO title, meta description, or image alt-text values you approve
A record of each SEO/alt-text change the app makes to your store (old value, new value, timestamp)Powers the in-app Fix History/Undo feature, so you can revert a change
Your Shopify subscription status (active/cancelled/etc.), via Shopify's own Billing APIDetermines whether AI drafting and indexing-request features are unlocked for your store
A Google OAuth token, only if you separately connect Google in the app Submitting your product page URLs to Google's Indexing API as a best-effort "please recrawl this page" signal — see the in-app disclosure for why this is never a guarantee of faster indexing

This app never accesses customer, order, or checkout data — only product content and your own store/subscription/Google-connection metadata listed above. For each AI draft you ask for, our AI provider, OpenAI, receives the product's title, type, tags, options, the names of the collections it is in and the first part of its description; for a collection, its title, description and the titles of some of its products. When drafting image alt text, it also receives the public web address of that product image so the AI can look at the photo. Google Gemini or Anthropic Claude are used only as backups if OpenAI is unavailable, and receive text only, never the image. Nothing else about your store is sent, and we do not keep what is sent.

Per Shopify's mandatory privacy webhooks: a customers/data_request or customers/redact webhook is acknowledged but has no customer data to act on (this app never stores any); a shop/redact webhook (sent ~48 hours after uninstall) erases your stored Admin API access token and Google OAuth token. Fix History records and subscription status are retained for your own reference unless you request full deletion via the contact below.

Winking Toad SEO Fixer (WordPress plugin)

If you install the Winking Toad SEO Fixer WordPress plugin, scanning your site, editing values, the fix history and undo all happen inside your own WordPress site and send nothing to us. The plugin contacts winkingtoad.com only for the optional “Draft with AI” button, and only after a site administrator has entered a plugin key and ticked a consent box, at the moment someone clicks that button.

What's sent for one draftWhat we keep
The item's title, its type (post, page or product), the name of its first category, a plain-text excerpt of its content (at most 1,200 characters), and, for images without alt text, the image file names and attachment IDs Nothing. This text is used once to build the request to the AI provider (OpenAI, with Google Gemini or Anthropic only as backups) and is discarded; it is not stored or logged by us.
Your plugin key (a wtk_ key) A one-way hash of the key, linked to your account, so we can charge usage credits. The raw key is never stored.
— A usage-credit ledger entry (amount and time) for each draft, with no content from your site.

The plugin sends no visitor data, no WordPress user data, no email addresses and no site address. Deleting the plugin removes its settings and history table from your site; you can revoke a key at any time from your account.

Winking Toad SEO Fixer (BigCommerce app)

If you install Winking Toad SEO Fixer from the BigCommerce App Marketplace, this section describes exactly what that app accesses and stores. It requests one permission, Products: modify (store_v2_products), and never accesses customer, order, payment or shipping data.

What's storedWhy
Your store's hash and an API access token for it (stored encrypted) Reading your product catalogue and writing the SEO title, meta description or image alt-text values you approve
The ID and email of each control-panel user who opens the app BigCommerce requires apps to support multiple users and to delete a user's data when they are removed from the store
A record of each change the app makes (product name, old value, new value, time) Powers Fix History and Undo
A count of AI drafts used per month Enforces the free monthly allowance

The app uses no cookies: when you open it, BigCommerce sends a signed proof of who you are and the app keeps a short-lived token in the page only. To write a draft, the product's name and the first part of its description text (up to 1,500 characters) are sent to our AI provider (OpenAI, with Google Gemini or Anthropic as backups); nothing else about your store is sent, and we do not keep that text.

When the app is uninstalled, the stored token, users, fix history and usage counts for the store are erased immediately. When a store owner removes a user, that user's record is deleted. Changes already applied to your products stay on your products.

Third-party connections you set up yourself

Some features require you to connect a third-party account. We only use these credentials for the specific action you request, and only against the site/account you provide:

FeatureWhat's storedWhat it's used for
Shopify Apply FixShop domain, Admin API access tokenReading/updating the product data you approve in the review table
WordPress Apply FixSite URL, username, Application PasswordReading/updating the post/page data you approve in the review table
MCP accessA hashed API key (the raw key is never stored)Authenticating your own MCP client (e.g. Claude Code, Cursor) to your own crawl data
Google Search ConsoleAn OAuth token issued by Google, scoped to read-only Search Console dataShowing your real search impressions/clicks alongside crawl issues on the same URLs

Usage of AI features

Features like AI Visibility and Prompt Explorer send a question you type (or a generated buyer-style question about a category you specify) to Google's Gemini API to get a real AI-generated answer. We don't send your crawl data, account details, or website content to these APIs unless it's part of the specific text you're asking about.

Automatically collected information

2. Why we collect it

To operate the core features of the Service (crawling, storing and displaying your results, letting you export or schedule crawls), to authenticate you and maintain your account, to process payment once billing is enabled, to prevent abuse of the free tier, and to provide the optional AI-powered and third-party-connected features described above — only when you actively use them.

3. Who we share it with

We don't sell your data. We share it only with:

4. Data retention and deletion

We retain your account and crawl data for as long as your account is active. If you want your account and associated data deleted, contact us using the details below and we'll delete it, other than records we're legally required to retain (e.g. billing records).

5. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these, contact us using the details below.

6. Security

Passwords are hashed with bcrypt, never stored in plain text. API keys and access tokens you provide (Shopify, WordPress, MCP) are used only for the connection you set up. We use HTTPS for all traffic to the Service. No online service can guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.

7. Children's privacy

The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13.

8. Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above and, where required by law, notify account holders directly.

9. Contact

Questions about this policy, or requests to access, export, or delete your data, can be sent to privacy@winkingtoad.com.

← Back to Winking Toad