tengri SEO
YOUR WORKSPACE DATA

Privacy and data

Updated October 10, 2026. This page describes the current Tengri SEO product.

What the application stores

Your account name and email, a salted password hash, sessions, website details, ownership challenges, audits, content, topic plans, imported search query data, subscription identifiers and operation history are stored in the hosted database. The session cookie keeps you signed in and expires after seven days. Authentication rate limits use hashed account and IP identifiers.

Credentials and external services

Saved API and CMS credentials are encrypted and are not returned by settings or workspace exports. An authorized application runtime can decrypt them when performing your requested operation. Credentials are sent to the selected provider to authenticate that operation. OpenAI receives the brief when you explicitly generate a draft; the request disables API response storage. Connected CMS platforms receive approved content when you explicitly publish. PayPal manages subscription approvals and payments. Resend handles account emails when the owner configures email delivery. Hosting and database infrastructure use Cloudflare.

Visibility and your controls

Your saved workspace is accessible after sign-in and scoped to your account. Administrators can view account names, emails and service readiness; this does not make workspace content public. Use Settings to export your workspace, change your password and revoke other sessions. Remove your OpenAI key in Settings or disconnect a CMS credential in Manage website. Archiving keeps an item stored and recoverable. Archived items can be permanently deleted after a separate confirmation. Deleting a website also deletes its related archived records and CMS credential.

Limits and retention

The current product stores up to 500 records per workspace and 30 performance imports. There is no automatic deletion of saved workspace content. Expired sessions, expired account tokens and old authentication rate-limit buckets are removed during relevant account operations. Completed or failed operation details older than 30 days can be removed through Settings. Durable request markers remain to prevent accidental repeat requests; unresolved operation details are retained. Avoid uploading unnecessary sensitive information into content or imported files.