Privacy Policy
Last updated: August 22, 2026
Sunel is a marketing dashboard. You give it your own website, and it analyzes that site, shows you your own performance data from services you connect, and drafts marketing work for you to review. This policy explains exactly what we collect, who else processes it, how long we keep it, and how to get it deleted. The short version: we collect what the service needs in order to work for you, we never sell personal data, we never use your data or your customers' data to train AI models, and you can delete everything yourself at any time.
1. Who we are and how to contact us
Sunel (“Sunel”, “we”, “us”) is operated by Guardianz, a company registered with the Dubai Department of Economy and Tourism (the Dubai Economic Department), Dubai, United Arab Emirates. We are the data controller for the personal data described in this policy, and you can reach us at the addresses below.
- Privacy, data access and deletion requests: [email protected]
- General support: [email protected]
2. What data we collect
Account data
Your name, email address, and either a password hash (we never store the password itself) or your Google account identifier and profile picture URL if you sign in with Google. We also store your interface language, your theme, and any optional “about you” notes you choose to add so the in-app assistant knows your context. If you change your email address, we hold the new address until you confirm it.
Session and device data
For each active sign-in we store a session token, your IP address, your browser, your operating system, your user-agent string, and when the session was last used. This is what powers the Devices page in Settings, where you can see and revoke every session on your account. You can also give a session your own label.
Content from your own website
When you add a website, our crawler fetches its publicly reachable pages and stores their text, headings, links and metadata so the product can derive your product profile, audience, competitors and brand voice. We crawl only sites you explicitly submit, we respect robots.txt, and our crawler identifies itself (see About our crawler). We also fetch publicly available pages of the competitors identified for your project.
Data from services you connect
Only for the services you choose to connect, and only what the feature needs: traffic and search metrics from Google Analytics and Google Search Console; page performance data from PageSpeed Insights; backlink and search-result data from our SEO data provider; post and account metrics from social platforms; the content of your CMS or repository where you have asked us to publish or open pull requests; and, if you connect a Google Business Profile, your business listing details, local posts and reviews — which reach us through our publishing partner rather than through a Google API (see section 8).
Work produced for you, and your feedback on it
The drafts our system produces, the edits you make to them, and the actions you take (publish, mark done, archive, dismiss). We record those actions as preference signals and summarize them so future drafts match your taste. This learning is scoped to your own projects and is never pooled across customers.
Messages and uploads
Messages you send to the in-app assistant, images you upload for use in posts and articles, and — if you link Telegram — the messages you exchange with our bot on that channel.
Billing data
Your Stripe customer identifier, subscription status, purchase records and credit ledger. Payment card details go directly to Stripe and are never sent to, seen by, or stored on our servers.
Credentials for connected services
OAuth tokens and API credentials for every service you connect. These are encrypted at rest with AES-256-GCM under a key held only in our server environment, are never returned to the browser, and are never written to logs.
Technical and operational data
Server logs, job records, and error reports. Error reports contain the error type, message, stack trace and low-cardinality labels such as which queue or feature failed. They do not include request bodies, credentials or your content.
3. How we use your data
We use the data above only to operate and improve the service you are paying for:
- To crawl and analyze the website you submit and build your marketing context.
- To generate marketing drafts, strategy documents and recommendations, and to check them against a quality rubric before showing them to you.
- To display your own analytics — traffic, search performance, page speed, backlinks and AI-search visibility — and to prioritize recommendations using those numbers.
- To publish, schedule or post content to the accounts you have connected, on your instruction or under an automation setting you have explicitly enabled.
- To learn your preferences from your own feed decisions so the work gets closer to what you actually approve.
- To send transactional email (verification, digests, billing notices) and, if you opt in, messages on channels such as Telegram.
- To process payments, manage subscriptions and maintain your credit balance.
- To secure the service, prevent abuse, diagnose faults and meet legal obligations.
We do not sell personal data. We do not use it for advertising or ad profiling. We do not run cross-site tracking. We do not use your content, your customers' data, or any data obtained from Google APIs to develop, train or improve AI or machine-learning models — ours or anyone else's.
4. Legal bases for processing
Where the GDPR or a comparable law applies, we rely on these bases:
- Performance of a contract (Art. 6(1)(b)) — running your account, crawling your site, generating your work, billing you.
- Consent (Art. 6(1)(a)) — connecting each optional third-party service, and enabling any setting that lets us post on your behalf. You can withdraw consent by disconnecting the service or turning the setting off, at any time, without affecting processing already carried out.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, and keeping operational records; balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting and record-keeping duties attached to payments.
5. Google user data
This section describes every Google API Sunel uses, the exact OAuth scope it requests, and what we do with the data. Each Google connection is separate: you can connect different Google accounts for different features, and none of them has to be the account you sign in with.
We request exactly two Google API scopes, and both are read-only: analytics.readonly and webmasters.readonly. We do not request any Google Business Profile API scope, and we hold no Business Profile API access. If you connect a Business Profile, that connection runs through our publishing partner and is described separately in section 8.
5.1 Signing in with Google
openid, email, profile — to create and authenticate your Sunel account. We store your email address, your name and your profile picture URL. Signing in with Google gives us no access to any other Google service.
5.2 Google Analytics
https://www.googleapis.com/auth/analytics.readonly — read-only. Used with the Google Analytics Data API and the Google Analytics Admin API. The Admin API is used once, when you connect, to list the properties on your account so you can pick which one to link. The Data API is then read on a recurring schedule to display your own traffic metrics — sessions, users, top pages, traffic sources, trends over time — in your dashboard, and to inform which marketing recommendations we surface first. We cannot create, edit or delete anything in your Analytics account with this scope.
5.3 Google Search Console
https://www.googleapis.com/auth/webmasters.readonly — read-only. Used with the Google Search Console API to read the search queries, impressions, clicks and average positions for the site you link, so we can show your search performance in your dashboard and prioritize the SEO fixes that would move the pages and queries you already rank for. We cannot submit, modify or remove anything in your Search Console property with this scope.
5.4 Limited Use
Sunel's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to all data we receive from the Google APIs above — Google Analytics, Google Search Console, and Google sign-in. Specifically, that data is:
- not sold — to anyone, under any circumstances;
- not transferred to others, except as necessary to provide or improve the user-facing features you have asked for (see section 5.5), to comply with applicable law, or as part of a merger or acquisition in which the acquirer honours this policy;
- not used for advertising — no ad targeting, no ad measurement, no audience building, no sale to data brokers;
- not used to develop, train or improve any AI or machine-learning model — ours or a third party's;
- not read by humans, except where you explicitly ask us to look at something for support, where it is necessary for security purposes or to investigate abuse, or where the law requires it.
5.5 Google data and our AI providers
We want to be precise about this, because a vague answer would be misleading: some data derived from Google APIs is sent to our AI provider.
When we compute your weekly analytics movements, the resulting summaries contain data from Google — for example “traffic to /pricing dropped 24% week over week” or “the query ‘accounting software dubai’ climbed from position 8.2 to 4.1”. Those summaries are included in the prompts we send to Anthropic when the system plans your week, drafts LinkedIn posts, and selects social topics. This is what makes the recommendations specific to your business rather than generic advice.
Our contractual and technical position on that transfer:
- Anthropic is the only provider that receives Google-derived data. Our other AI providers do not. OpenAI and Perplexity receive only the generic buying-intent questions we use to measure how AI assistants describe your market — questions that contain no Google data and no personal data. Voyage AI receives text from your own site and drafts for duplicate detection, not Google data. Replicate is used only for optional video generation and receives no Google data.
- Anthropic does not train its models on our API inputs or outputs. Under its commercial terms, data submitted through the API is not used to train Anthropic's models. Inputs may be retained for a limited period for safety and abuse monitoring, as described in Anthropic's own terms, and are then deleted.
- We do not use Google user data to train models at all, including our own preference-learning features. Those learn only from your approve/edit/archive decisions inside your own project.
- No advertising use, no resale, no pooling across customers. Google-derived data is used only to produce output for the account it came from.
Two related things are not Google user data, but are worth clarifying so the picture is complete. We query the PageSpeed Insights API with an API key of our own against your public URLs — this uses no account access and returns only publicly measurable page performance. And where we report how your brand appears in Google's AI Overviews, that comes from a third-party search-data provider's public results, not from your Google account.
5.6 Disconnecting a Google account
Both Google connections can be disconnected from Settings → Integrations. When you disconnect:
- we call Google's revocation endpoint to invalidate the grant at Google's end;
- the stored refresh and access tokens are removed from our database and the integration is marked disconnected;
- all further access stops immediately — no scheduled job can read your Analytics or Search Console data again unless you reconnect;
- metrics we had already synced and stored (charts, historical trends, computed insights) remain in your dashboard so your history does not vanish. If you want that removed too, delete the project or email us — either erases it.
When you delete a project or your account, all of it goes: the encrypted tokens, every stored Google metric, every insight derived from it, and every draft produced from it, in a single cascade delete. See section 10. You can also revoke Sunel's access directly at Google Account permissions at any time.
6. AI providers and model training
Generating marketing work requires sending your material to AI providers. Here is exactly who receives what, and on what terms.
- Anthropic — receives the text of the pages we crawled from your site, summaries of your competitors' public pages, your strategy documents, your drafts and edits, your analytics insight summaries (including the Google-derived ones described in section 5.5), your messages to the in-app assistant, and — if you connect a Business Profile — review text used to draft suggested replies. Anthropic does not use API data to train its models.
- Voyage AI — receives short text passages from your site pages and your drafts, converted into numeric embeddings so we can detect duplicate and near-duplicate work before it reaches you. No Google data.
- OpenAI — receives generic market questions for AI-visibility measurement, and image prompts when we generate an illustration for one of your articles. No Google data, no personal data.
- Perplexity — receives the same generic market questions for AI-visibility measurement. No Google data, no personal data.
- Replicate — used only if video generation is enabled for your account; receives the video prompt. No Google data.
Across all of them: we do not permit training on your data, we use business/commercial API terms rather than consumer products, and we do not pool one customer's material into another customer's output. Providers may retain inputs briefly for abuse monitoring under their own published terms.
7. Third-party processors
Beyond the AI providers above, we rely on a small number of subprocessors. Each receives only the categories of data its feature requires, and several receive nothing at all unless you connect them. The categories of recipient are:
- Hosting and infrastructure — the server that runs the application and database, the network in front of it, encrypted backup storage, and error monitoring.
- Publishing and connected accounts — the platforms you choose to publish to, and the authorized publishing provider through which some of them are connected.
- Marketing data sources — SEO and search-result data providers, which receive your domain and research keywords but no personal data.
- Business operations — payment processing and transactional email.
Every subprocessor is named individually, with what it receives and where it operates, on our Subprocessors page, which forms part of this policy. We keep it as a separate page so it stays current without re-versioning this document — but we do not add subprocessors silently: adding one that receives your content or personal data is a material change under section 15, and we email you before it takes effect.
Two entries there are worth calling out here, because they carry the commitments in this policy. Anthropic is the only subprocessor that receives Google-derived data (see section 5.5). SocialAPI.ai is the authorized provider through which Instagram, Facebook, X and Google Business Profile are connected; for Business Profile the categories flowing through it are business location information, local posts published on your approval, and reviews we read and reply to with your approval (see section 8).
We also read public discussions on Reddit and Hacker News to find conversations worth joining. We send them no personal data, so they are not subprocessors.
8. Google Business Profile
If your business has a Google Business Profile, you can connect it so that Sunel can help you keep it current. This is not a Google API integration. Sunel does not request or hold any Google Business Profile API scope. The connection is made through SocialAPI.ai, an authorized third-party publishing provider, which holds the connection to your listing and passes data between it and Sunel. Your Business Profile data therefore travels through SocialAPI.ai, and SocialAPI.ai is a processor for it (see section 7).
What Sunel does with a connected Business Profile
- Location information (business name, address, categories, opening hours, attributes) — read, so that generated local content uses your business's real details instead of guesses.
- Local posts — read and write, to publish updates and offers that you have reviewed and approved to your Business Profile.
- Reviews — read, to notify you of new reviews, to generate suggested replies for your approval, and to show reputation trends (rating over time, review volume, recurring themes) in your dashboard. Write is used only to post a reply you have approved.
- Performance and discovery data — read, where our provider makes it available, to show how customers find your listing and to inform which keywords and topics we prioritize for you.
Approval, automation and revocation
Replies are never posted automatically by default. If — and only if — you turn on the optional setting for positive reviews, approved-style replies to favourable reviews may be posted without a separate click. That setting is off unless you enable it, it is disclosed on every reply it posts, and you can switch it off at any time in one click. Replies to negative or critical reviews always require your explicit approval and have no automatic path.
What we never do
Sunel never deletes or edits your reviews — replies are the only review write we perform. Sunel never posts anything to your Business Profile except content you approved, or content produced under the positive-review setting described above that you switched on yourself. We do not change your business information, your categories, your hours or your address.
AI processing of Business Profile content
Review text and your listing details may be sent to our AI provider, Anthropic, in order to draft suggested replies and local content. Anthropic does not use API data to train its models; inputs may be retained briefly for abuse monitoring under its own terms and are then deleted. This content is never sold, never used for advertising, and never used to train any AI or machine-learning model — ours or a third party's.
Disconnecting
You can disconnect your Business Profile at any time from Settings → Integrations. Disconnecting stops all further access and removes the stored connection references from our database. You can additionally revoke the provider's access from your own Google account at any time. Deleting the project or your account erases everything we derived from the listing, as described in section 10.
9. International transfers
Your account data and your project content are stored on our servers in Singapore. Our processors operate from several other countries, including the United States and the European Union, so your data is transferred internationally in the course of providing the service.
Where data leaves the European Economic Area or the United Kingdom, transfers are made under the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), incorporated into our agreements with each processor, together with the technical measures described in section 11.
10. How long we keep data, and deletion
We keep your data for as long as your account is active, and then only as long as the law requires. Every deletion below is a real cascade delete, not a hidden flag.
- Deleting a website/project (Settings → Websites) removes everything derived from it: crawled pages, page summaries and embeddings, strategy documents, competitor records, agent runs and logs, every draft and feed item, analytics snapshots, insights and AI-visibility measurements, articles, chat history, saved memories, encrypted integration credentials, team invitations and share links, and the project's credit records. Any live subscription is cancelled first.
- Deleting your account (Settings → Account & Security) cancels your subscriptions, deletes every project you own with the cascade above, then deletes your user record — sessions, device records, linked OAuth accounts, email tokens and your memberships of other people's projects.
- Changing a project's website URL deliberately wipes everything derived from the old site before re-analyzing the new one.
- Sessions expire on their own and can be revoked individually at any time from the Devices page.
- Encrypted backups are retained for 14 days on a rolling basis and then overwritten, so deleted data can persist in backups for up to that window.
- Administrative audit records — a log of operator actions such as an account suspension or an erasure request, keeping only identifiers and the email address the action concerned — are retained as our own record of processing.
- Stripe retains its own transaction records to meet its financial and tax obligations, independently of us.
11. How we protect your data
- All traffic is encrypted in transit with TLS, with HSTS enforced.
- Every third-party token and API credential is encrypted at rest with AES-256-GCM under a key held only in the server environment. Credentials are never sent to the browser and never written to logs.
- Passwords are hashed with Argon2id. We cannot read your password.
- Every database query is scoped to your project and account through a repository layer, so one customer's data cannot be returned to another.
- All incoming webhooks are signature-verified before they are processed, and the app sends strict Content-Security-Policy and related security headers.
- External content — pages we crawl, competitor sites, search results, public discussions — is always handled as untrusted data and is never allowed to act as an instruction to our systems.
- Access to production systems is restricted, and destructive administrative actions require re-authentication and are logged.
- Backups are encrypted and stored off-server.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.
12. Your rights and how to exercise them
Subject to applicable law, you have the right to access your data, to correct it, to delete it, to receive a portable copy, to restrict or object to certain processing, and to withdraw consent for anything you consented to. Exercising any of these never costs you anything and never degrades your service.
Most of these you can do yourself, immediately:
- Access and correction — Settings → Account & Security for your profile; the Company panel for everything we derived about your business, which you can edit directly.
- Export — strategy documents, articles and feed items can be exported from the app; for a full machine-readable copy of your account, email us.
- Deletion — Settings → Websites to delete a project; Settings → Account & Security to delete your entire account.
- Withdrawing consent — Settings → Integrations to disconnect any service; agent and automation settings to turn off anything that acts on your behalf.
For anything else, email [email protected] from your account address. We respond within 30 days. If you are in the EEA or the UK and you believe we have mishandled your data, you may also complain to your local supervisory authority.
14. Children
Sunel is a business tool and is not directed at children. You must be at least 16 years old to create an account, and older if the law where you live sets a higher age for entering into this kind of contract. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email [email protected] and we will delete it.
15. Changes to this policy
If we change this policy we will update the date at the top and post the new version here. For material changes — a new category of data, a new purpose, a new processor receiving your content, or any change to how Google data is handled — we will notify you by email before the change takes effect. Continuing to use Sunel after that date means you accept the updated policy.
Questions about anything on this page: [email protected].