Privacy Policy

How researchMTR collects, uses, and protects your data

This Privacy Policy explains what information researchMTR collects across our platform, the WordPress plugin, and connected services, how we use it, who we share it with, and the rights available to you — wherever in the world you're using the Service.

Last updated: September 4, 2026

1. Information we collect

What we collect and where it comes from

Account information. When you sign up, we collect your username, email address, and a securely hashed password. If you sign in with Google, we receive your Google account email and basic profile information.

Google Search Console data. If you connect Google Search Console (from the dashboard or the WordPress plugin), we request read-only access to your Search Console properties (scope webmasters.readonly) plus your Google account email. We use this solely to display search performance data and suggest keywords inside your workspace — see the Google API disclosure below for how this data is handled.

Content and workspace data. Domains, keywords, workspaces, content briefs, generated articles, and related metadata you create or import (including through the WordPress plugin) are stored so the platform can generate, plan, and track content on your behalf.

Billing information. Subscription plan, wallet balance, and transaction history are stored for billing purposes. Card and payment details are processed directly by our payment processor, Flutterwave — we do not store full card numbers on our servers.

Usage and technical data. We record API usage, AI call volumes, error logs, and general request metadata (IP address, browser/user agent, timestamps) for security, fraud prevention, and service improvement.

Cookies and analytics. We use a small cookie to remember your login session — this is strictly necessary for the Service to work and doesn't require consent. Separately, we use Google Analytics to understand aggregate traffic and usage patterns; analytics cookies are only set if you click "Accept" on the cookie banner shown on your first visit. You can change your choice at any time via "Cookie Preferences" in the footer, or through your browser settings.


2. How we use your information

Why we process this data

  • To provide, operate, and improve the platform and WordPress plugin integration.
  • To generate AI-assisted keyword research, content plans, and written content on your behalf.
  • To display Google Search Console performance data you've connected, inside your own workspace.
  • To process payments and manage subscriptions and billing records.
  • To detect, investigate, and prevent abuse, fraud, or security incidents.
  • To communicate important service, security, and billing updates — and, where you've separately consented, promotional messages.

3. Google API Services User Data

Use of Google user data

researchMTR's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: Google Search Console data accessed through your connected account is used only to display performance metrics and generate keyword suggestions inside your researchMTR workspace. It is never sold, used for advertising, or shared with third parties outside of the AI processors described below where strictly necessary to generate the keyword suggestions you've requested. You can revoke researchMTR's access to your Google account at any time from your Google Account permissions page, or by disconnecting Search Console from your dashboard.


4. Third-party processors and data sharing

Who else touches your data

We do not sell your personal data. We work with a small number of trusted processors, and only send each one the data necessary to perform its function.

AI providers

Google Gemini, OpenAI, and Anthropic process the content, prompts, and page data you submit, solely to generate the keyword suggestions, briefs, and articles you request.

Flutterwave

Processes subscription and wallet payments. Payment card details are handled directly by Flutterwave under its own privacy and security policies.

Google APIs

Search Console and Google sign-in, used only for the purposes described above.

Google Analytics

Aggregate, cookie-based traffic analytics on the marketing site, only after you've accepted analytics cookies.

We have agreements with these processors that require them to handle your data securely and use it solely for the purposes described in this policy — not to sell it or use it for their own unrelated purposes.


5. International data transfers

Where your data may be processed

researchMTR and the processors listed above operate internationally, which means your data may be transferred to and processed in countries outside your own — including the United States, where several of our AI and infrastructure processors are based. Where applicable law requires it, we rely on appropriate safeguards for these transfers, such as Standard Contractual Clauses or an equivalent recognized transfer mechanism. By using the Service, you understand that your information may be processed outside your country of residence.


6. Data security

How we protect your data

We use reasonable administrative, technical, and physical safeguards designed to protect your data, including:

  • Encryption in transit (TLS) for data moving between your browser, WordPress site, and our servers.
  • Securely hashed passwords — we never store passwords in plain text.
  • Access controls limiting who can reach production data, and logging of security-relevant activity.
  • Scoped credentials for third-party integrations (e.g. read-only Google Search Console access) rather than broader access than necessary.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify affected users and relevant authorities as required by applicable law.


7. Data retention and deletion

How long we keep data, and how to remove it

We retain account, workspace, and billing data for as long as your account is active, and for a reasonable period afterward to satisfy legal, accounting, or dispute-resolution obligations. You can request deletion of your account and associated workspace data at any time by contacting us at contact@researchmtr.com. Disconnecting Google Search Console removes our stored access token; historical performance data already imported into your workspace is deleted along with your account.


8. Your rights

Access, correction, and control

Depending on your location (for example, under GDPR, CCPA/CPRA, Nigeria's NDPA, or similar laws), you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email contact@researchmtr.com. We aim to respond to all such requests within 30 days.


9. Children's privacy

Not directed at children

researchMTR is not directed to individuals under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will remove it.


10. Changes to this policy

Keeping this page current

We may update this policy as the service evolves. We'll reflect changes by updating the "Last updated" date above, and for material changes, we'll also provide notice through an in-app notice or email where practical. Continued use of the service after a change constitutes acceptance of the revised policy.


11. Contact

Questions about this policy

Reach us at contact@researchmtr.com or via the contact page.