This section applies specifically to the Semflow app available through the Webflow App Marketplace (the "Webflow App") and supplements the Privacy Policy above.
When you install and authorize the Semflow Webflow App, you grant Semflow permission to access certain data on your Webflow site(s) through the Webflow API, limited to the following scopes:
- **Sites** — basic site information, including site ID, name, and connected domains.
- **Pages** — page content and on-page SEO fields, including titles, meta descriptions, headings, Open Graph tags, and page structure, so Semflow can audit your SEO and let you apply fixes directly.
- **CMS** — CMS collection items, so Semflow can audit and score SEO for CMS-driven and dynamic pages.
- **Custom Code** — your site's custom code, so Semflow can read existing code and, only when you take an explicit action within Semflow, insert schema markup (structured data) or other SEO-related code snippets you request.
We do not request or access your Webflow password, payment details, or account credentials, and we request only the scopes needed to provide Semflow's SEO audit, optimization, and reporting features inside Webflow.
Webflow site data accessed through the App is used solely to power Semflow's SEO analysis, scoring, schema and meta-tag recommendations, site monitoring, and reporting features for the account holder who authorized the connection. We do not sell this data, and we do not share it with third parties except as described in the "With whom we share your personal information" section above.
Your Webflow OAuth access token is encrypted at rest, stored only on our servers (never client-side), and is automatically deleted when you uninstall the Semflow App or revoke its access from your Webflow account.
You can revoke Semflow's access to your Webflow site(s) at any time from your Webflow account under Site Settings > Apps & Integrations. Revoking access or uninstalling the App stops all further data collection from that site and deletes the associated access token.
This section describes how the Semflow Chrome Extension ("the Extension") collects, uses, stores, and shares data, in addition to the practices described elsewhere in this Privacy Policy.
What the Extension does. The Extension's single purpose is to analyze the on-page SEO and content elements of websites you visit in order to provide SEO recommendations, scoring, and reporting within the Semflow product.
What we collect. The Extension collects two categories of data.
Account credentials. The Extension requires you to sign in to your Semflow account before it can be used. When you sign in, the Extension collects the email address and password you enter and transmits them to Semflow's servers over an encrypted HTTPS connection in order to authenticate you and maintain your signed-in session. Your password is stored in our database in protected form using modern cryptographic standards. We never display your stored password, and we never publicly disclose authentication, payment, or financial information.
Page content. While the Extension is active, we collect the publicly available content of the web pages you visit, including elements such as page HTML, headings, meta tags, links, images, and other on-page SEO-relevant content. We do not collect passwords, payment details, login form entries, or private or non-public account content from the third-party websites you visit.
How we use it. Page content is used solely to power the Extension's SEO analysis, scoring, and reporting features, that is, to provide and improve the single purpose described above. Your Semflow account credentials are used solely to authenticate you, maintain your signed-in session, and associate your SEO analysis results with your account. We do not use any data collected by the Extension for advertising, to build user profiles unrelated to Semflow's SEO features, to assess creditworthiness, or for any purpose unrelated to providing the Extension's functionality.
Where it's stored. Data collected by the Extension, including account credentials and page content, is transmitted over encrypted connections and stored on Semflow's own servers and database (see "Location of data processing" above). Credentials are stored in protected form, and access is restricted to the systems and authorized personnel required to operate and support the service. We do not route Extension data through third-party analytics or advertising platforms.
Who we share it with. We do not sell the data collected by the Extension, and we do not share it with third parties, advertisers, or data brokers. It is accessed only by Semflow personnel and systems as necessary to operate and support the Extension, and may be disclosed only where required by law, legal process, or a valid government request.
Retention. We retain page content collected by the Extension only as long as necessary to provide the Extension's features to you, consistent with the "Information retention" section above. We retain your account credentials for as long as your Semflow account remains active. When you delete your Semflow account, the associated credentials are removed from our systems, subject to any retention required by law.
Your choices. You can stop all page content collection by the Extension at any time by disabling or uninstalling it from Chrome. You may delete your Semflow account, and the credentials associated with it, at any time from your account settings or by contacting us. The rights described in the "Your rights" section of this Privacy Policy (access, deletion, correction, and others) apply equally to data collected through the Extension.
Compliance. Our collection and use of data through the Extension is limited to what is necessary to provide and improve the Extension's disclosed single purpose, consistent with the Chrome Web Store's User Data Privacy policy and Limited Use requirements.