Legal
Privacy Policy
This policy explains what personal data Searva processes, why, and what you can do about it.
Last updated 6 September 2026 · Version 2026-09-06
Who is responsible for your data
Neurosoft (org. nr 971218-4150), Noraskogsgatan 12B, 713 32 Nora, Örebro län, Sweden, is the data controller for personal data processed through Searva. You can reach us at philip@neurosoft.se.
For the content of the websites you connect, Searva acts as a processor on your behalf: you decide what is analysed and what changes are applied.
What we collect
- Account data — name, email address, password hash (handled by our authentication provider), company name, and your Google account email if you sign in with Google.
- Website data — the addresses you add, publicly available page content we crawl (titles, descriptions, headings, links, images, structured data), scan results, issues, opportunities and optimizations.
- Connected service data — when you connect Search Console, Analytics, WordPress or Shopify: access tokens, property or store identifiers, and aggregated search and traffic statistics.
- Free scan data — the address you enter on our public scanner and the resulting scores.
- Billing data — once paid plans are active: billing name, email and invoice records. Card details are handled by the payment provider and never reach our servers.
- Technical data — IP address, browser type and request logs, used to operate and secure the service.
Why we process it, and on what legal ground
- To provide the service (account, scanning, optimizations, reports) — performance of our contract with you.
- To keep the service secure and reliable (logging, abuse prevention, backups) — our legitimate interest in a safe, working product.
- Optional analytics — your consent, which you can withdraw at any time.
- Billing and bookkeeping — performance of contract and our legal obligations under Swedish accounting law.
- Service emails (verification, password reset, important changes) — performance of contract.
How long we keep it
- Account and website data: for as long as your account exists.
- After you delete your account: removed immediately, apart from backups which age out within 30 days.
- Free public scans: kept for a limited period and not linked to an account.
- Invoices and accounting records: seven years, as required by Swedish law.
These periods are our current practice. If you need a specific retention commitment for your own compliance work, contact us.
Who we share it with
We do not sell personal data. We share it only with the service providers we need to run Searva — hosting, database, Google APIs you connect yourself, AI model providers for generating proposals, and the payment provider. They act on our instructions under data processing agreements. The current list is on our subprocessors page.
Some providers process data outside the EU/EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
Your rights
- Access a copy of your data — available directly in Settings → Privacy.
- Correct data that is wrong or incomplete.
- Delete your account and data — also available in Settings → Privacy.
- Receive your data in a portable format (our export is machine-readable JSON).
- Object to or restrict processing based on legitimate interest.
- Withdraw consent at any time, including cookie consent.
Write to philip@neurosoft.se and we will respond within one month. If you are unhappy with our answer you can complain to Integritetsskyddsmyndigheten (IMY).
Security
Data is stored in a managed database with access rules that isolate each account, and credentials for connected services are stored so they are only readable by our server — never by the browser and never by other customers. Access to production systems is limited to people who need it.
Cookies
We use a small number of cookies and browser storage entries. See the Cookie Policy for the details and to change your choice.
Automated decisions
Searva generates optimization proposals automatically, and can apply them to your own website when you enable that. These decisions concern website content, not people, and you can require approval for every action type or revert any change.
Changes to this policy
When we change this policy we update the version above and, for material changes, ask for your cookie consent again and notify you by email.

