Last Updated: July 16, 2026

Privacy Policy

How Search Genie (by HYVE Labs) collects, uses, stores, and protects your data.

1. Who We Are

Search Genie is a business-to-business software service operated by HYVE Labs ("HYVE Labs", "we", "us"), available at search-genie.hyvelabs.tech. It provides AI-search and SEO analytics, search-demand intelligence, and content generation for retail brands operating across multiple markets (including Saudi Arabia, Egypt, Lebanon, and the United Arab Emirates). This policy explains what data we handle when you use Search Genie and the choices you have. Questions and requests go to contact@hyvelabs.tech.

2. Roles: Controller and Processor

Search Genie is used by organizations ("customers"). For the brand, market, and connected-account data a customer brings into its workspace, the customer is the data controller and HYVE Labs acts as a data processor, handling that content only to provide the service. For account registration, authentication, billing, and usage records, HYVE Labs is the data controller. A Data Processing Agreement (DPA) covering our processor role is available on written request to contact@hyvelabs.tech.

3. Information We Collect

We collect the following categories of data:

  • Account data. Your email address, one-time sign-in codes (short-lived), two-factor authentication (TOTP) enrollment status, and your workspace memberships and roles. We do not store passwords — sign-in uses email one-time codes plus optional TOTP.
  • Workspace and brand data. Brand configurations, market selections, tracked prompts and keywords, content briefs, generated content, reports, and settings created by you or your teammates inside a workspace.
  • Billing data. Subscription tier, billing status, and invoice history. Payment card details are entered on Stripe-hosted pages and are processed entirely by Stripe — card numbers never touch our servers. Some enterprise customers are invoiced manually under separate agreements.
  • Google user data (optional, admin-connected). If a workspace administrator connects a Google account, we access the data described in section 4 under read scopes granted through Google OAuth.
  • Third-party search data. Keyword and search-volume data obtained from DataForSEO to power keyword research features.
  • Usage and log data. Actions metered against your subscription tier (for example AI generations and scrapes), sync history, and technical logs (timestamps, IP addresses, device/browser information) used for security and troubleshooting.

4. Google User Data We Access

When a workspace administrator connects a Google account, Search Genie requests the following read-oriented OAuth scopes and accesses only the data needed for the corresponding features:

  • Google Search Console (read-only): search performance metrics, indexed pages, and property information for SEO dashboards and reports.
  • Google Analytics 4 (read-only): session, traffic, and conversion metrics for analytics dashboards.
  • Google Merchant Center: product and feed data, item diagnostics, and disapproval statuses for product-feed readiness features.

Search Genie does not request access to your Google Calendar. Content-calendar features read only calendars you have made publicly available.

OAuth tokens are stored encrypted on our server side and are never exposed to the browser. You can disconnect Google at any time in the app (Settings → Integrations) or revoke Search Genie's access from your Google account at myaccount.google.com/permissions.

5. Google API Services — Limited Use Disclosure

Search Genie's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

  • Google user data is used only to provide user-facing features you can see in the product — dashboards, reports, and product-feed diagnostics.
  • We never sell Google user data, and we never use it for advertising or ad targeting.
  • We never use Google user data to train generalized artificial intelligence or machine-learning models.
  • Humans do not read this data except with your explicit permission (for example, when you ask for support), when necessary for security or abuse investigation, or when required by law.

6. How We Use Information

We use the data described above to:

  • Provide, operate, and secure the service: dashboards, reports, keyword research, product-feed diagnostics, and content generation.
  • Authenticate you and protect accounts (one-time codes, TOTP, session management).
  • Meter usage against your subscription tier's caps and bill subscriptions through Stripe.
  • Send transactional email such as sign-in codes and service notifications (we do not send third-party marketing to your users).
  • Investigate abuse, enforce our Terms of Service, and comply with legal obligations.

We do not sell personal data, and we do not share customer data with third parties except the subprocessors listed in section 8.

7. AI Content Generation

When you use AI features, the inputs you provide (for example briefs, keywords, and prompts) and summaries of your connected data may be sent to OpenAI and Google Gemini to generate outputs on your behalf. We use these providers as processors to generate results for you; we do not use your inputs or connected data to train our own or anyone else's generalized models. Generated outputs are stored in your workspace and belong to you (see the Terms of Service).

8. Subprocessors and Data Location

We use the following service providers to run Search Genie. Each processes data only as needed for the stated purpose:

ProviderPurposeLocation
SupabaseApplication database and authenticationEU (Frankfurt, Germany)
Google Cloud / BigQuerySearch-metrics data warehouseUnited States
Google Firebase HostingWeb application deliveryGlobal CDN
StripePayment processing and subscription billingUnited States / global
TurboSMTPTransactional email (sign-in codes, notifications)EU
OpenAIAI content generationUnited States
Google GeminiAI content generationUnited States
DataForSEOKeyword and search-volume dataUnited States

Application data and authentication live in the EU (Supabase, Frankfurt). The search-metrics warehouse runs on Google Cloud in a US region. Where data is transferred outside the region it was collected in, we rely on appropriate safeguards such as the providers' standard contractual clauses.

9. Data Retention and Deletion

  • Account and workspace data are retained for the life of your subscription.
  • On written request to contact@hyvelabs.tech, we delete your account and workspace data within 30 days. Residual copies in encrypted backups are purged within 90 days.
  • Google-connected data can be disconnected at any time in-app (Settings → Integrations); disconnecting stops further collection, and stored tokens are invalidated. You can also revoke access at myaccount.google.com/permissions.
  • We may retain limited billing records where required by tax and accounting law.

10. Security

We protect data with industry-standard measures: encryption in transit and at rest, server-side storage of OAuth tokens (no credentials in the browser bundle), email one-time-code sign-in with TOTP two-factor authentication, role-based workspace access controls, and logged sync and connector activity. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you as required by applicable law.

11. Your Rights

Subject to applicable law (including GDPR-style rights where they apply), you may request access to, correction of, export of, or deletion of your personal data by emailing contact@hyvelabs.tech. If your data is in a workspace controlled by your employer or client (the customer), we may redirect your request to that customer, as they are the controller for workspace content. You may also lodge a complaint with your local data protection authority.

12. Children

Search Genie is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will give notice in the app or by email before the change takes effect. The "Last Updated" date at the top of this page reflects the current version.

14. Contact Us

For any questions about this policy, our data practices, deletion requests, or to request a DPA, contact HYVE Labs at contact@hyvelabs.tech.