Privacy Policy
Last updated: 15 August 2026
Läs på svenska →This Privacy Policy explains how Tedrix (“we”, “us”) collects and processes personal data when you use our website and application at tedrix.io (the “Service”). Tedrix is an AI content co-pilot: you connect a website’s Google Search Console (read-only) and we help you find decaying pages and draft on-brand refreshes that you approve. We are the data controller for your account data. For the site data you connect and process through the Service, we act as a data processor on your behalf. See the “Data you process through the Service” section below.
Who we are
Tedrix is a sole proprietorship (enskild firma) run by Teddy Wasserman, Vinningsbovägen 1, 445 34 Bohus, Sweden. Given our size we are not required to appoint a Data Protection Officer; for any privacy question, or to exercise your rights, contact us at info@tedrix.io.
Data we collect
Account data: your name or company name, email address, and a securely hashed password (we never see your password in plain text).
Google connection data: when you connect Google Search Console, we receive the Google account email you authorise and a read-only access token. We use it only to read the Search Console properties you choose.
Billing data: subscription status and billing details, handled by our payment processor, Stripe. We do not store full card numbers.
Usage data: basic technical logs needed to operate and secure the Service.
Cookies
We use essential cookies required for authentication and security (for example, to keep you signed in). If we introduce optional analytics or marketing cookies in future, we will request your consent where required by law.
Data you process through the Service
To do its job, the Service processes data about the websites you connect: Search Console search-performance metrics (clicks, impressions, positions and the search queries they relate to), the URLs and page content of the pages you analyse, and the draft text we generate for you. This data can occasionally contain personal data (for example, a name mentioned on a page or in a search query). We process it only to provide the Service to you and to power the per-client memory bank that keeps drafts on-brand. For this data you are the controller and Tedrix is your processor; a Data Processing Agreement is available upon request or incorporated by reference.
If you connect a website on behalf of someone else (for example, an agency connecting a client’s Search Console), you are responsible for having that client’s authorisation to connect the property and to let us process its data, and for having a lawful basis for any personal data contained in that content, as required by the GDPR.
Automated processing
The Service uses AI to analyse your pages and search data and to produce a result, for example a decay score or a suggested content refresh. These results are designed to assist a human, not to replace one. By default nothing is published to your website automatically: Tedrix produces drafts and recommendations (including “leave it”, “merge” or “retire”) and you decide what, if anything, goes live. If you switch autopilot on yourself for a site, the Service applies approved changes for you, reports every single change to you, and keeps a one-click revert. You can switch it off at any time. No decision here produces legal effects concerning you. We do not use your content to train AI models.
Legal bases (GDPR)
We process account, Google-connection and billing data to perform our contract with you (Article 6(1)(b)) and to meet legal obligations such as bookkeeping (Article 6(1)(c)). Limited technical logging relies on our legitimate interest in operating a secure Service (Article 6(1)(f)), which we have weighed against your interests and rights and consider not to override them given the limited, security-focused nature of the data. The site data you connect and process is handled under your instructions as controller.
Sub-processors
We rely on a small number of trusted providers to run the Service:
- Supabase: authentication and database hosting.
- Vercel: application hosting.
- Stripe: payment processing.
- Anthropic (AI models): the models that analyse your pages and generate draft refreshes. Content is sent only to produce your result and is not used to train their models.
- Google: the Google Search Console and related APIs we read from, once you authorise a read-only connection.
- Zoho: sending transactional email (e.g. confirmation and password-reset messages).
International transfers
Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. We prefer EU processing regions where available.
Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. This includes encrypted connections, hashed passwords, and restricted access to systems handling personal data.
How long we keep data
Account data is kept while your account is active and deleted within about 30 days after you close it. Billing and accounting records are kept for 7 years as required by the Swedish Bookkeeping Act (bokföringslagen). Connected site data, meaning the metrics, page content, and the drafts and memory-bank entries we hold for your workspace, is kept only while it is useful to the Service and is deleted when you disconnect a property, delete the workspace, or close your account. You can revoke the Google Search Console connection at any time from your Google account or from Tedrix. You can request deletion at any time; some information may be retained where required by law, such as accounting records.
Children
The Service is not intended for children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and, where we rely on consent, the right to withdraw that consent at any time. We respond to requests within one month (extendable by two further months for complex requests, in which case we will tell you). You may also lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY). To exercise any right, email info@tedrix.io. If your request concerns data from a website connected by one of our customers, we will direct you to that customer as the controller.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.