Privacy and data
This page lists every request that Vantage SEO sends off your site, when it sends it, and what data the plugin stores. The list comes from the plugin source code.
Principles
- No ads in the free UI, ever. Pro features appear locked in place with one line of explanation.
- The plugin can contact only the hosts that its manifest lists. Instatic blocks every other host. The free edition lists one host:
api.indexnow.org. - No visitor data goes to a third party. The analytics counter sends data only to your own site.
- Secrets, such as API keys and Google credentials, are stored encrypted by Instatic. The plugin never shows them in the admin and never returns them through the MCP server.
Requests the plugin sends off your site
| Destination | Edition | When | What it sends | How to stop it |
|---|---|---|---|---|
IndexNow, api.indexnow.org | Free | From the maintenance task every 15 minutes, only when pages changed since the last request. | Your site host, your IndexNow key, the address of your key file, and up to 50 changed page URLs. | Turn off IndexNow instant indexing on the General tab. Without a saved site URL, nothing is sent. |
| The Vantage license server | Pro | When you activate or deactivate a license, one time each day, and when you click Re-check now. | Activation: the product id, the license key, an install id and your saved site URL. Daily check: the product id, the license key, the install id, a random nonce and a timestamp. Deactivation: the product id, the license key and the install id. | Deactivate the license, or use the free edition. |
Google OAuth, oauth2.googleapis.com | Pro | When the plugin needs a new Google access token. The plugin keeps the access token in memory until it expires. | Your OAuth client ID, client secret and refresh token, to get a short-lived access token. | Leave the Search Console settings empty. |
Google Search Console, searchconsole.googleapis.com | Pro | One sync each day, and when you click Test connection, Sync now or Submit sitemap. | Your property name and a query for the last 28 days of page data. Submit sitemap sends your sitemap address. | Leave the Search Console settings empty. |
Your AI provider: api.anthropic.com, api.openai.com or openrouter.ai | Pro | When you click a suggest button, Test connection or Load models, and for each page of a bulk description job. | Your API key, and for suggestions: the site name, the page title, the current field value, the page language and up to 4,000 characters of page text. | Leave the AI settings empty. The plugin makes no AI call without a key. |
The plugin sends nothing else off your site. The publish step itself sends no network request.
Requests from your visitors' browsers
These requests go from the browser of a visitor to your own site. They do not reach a third party.
| Request | Edition | When | What it sends |
|---|---|---|---|
Analytics beacon, …/runtime/beacon and …/runtime/beacon404 | Free | One request per page load, only when you turn analytics on. Not sent when the browser has Do Not Track or Global Privacy Control on. | The page path without the query string, the origin of the referring site if it is a different site, a screen size bucket and a site id. |
Redirect lookup, …/runtime/redirect-lookup | Pro | When a visitor lands on your 404 page while Pro is active. | The path of the missing page. The request carries no cookies. |
Instatic adds the plugin's tracker.js file to every published page. When analytics is off, the script sends nothing. See Analytics.
What the plugin stores
The plugin stores its data in Instatic plugin storage on your server.
| Data | Edition | Kept for |
|---|---|---|
| SEO settings: site name, site URL, templates, schema publisher, verification tokens, feature switches | Free | Until you change them. |
| Per-page SEO values: title, description, canonical, robots flags, Open Graph values, Twitter card, focus keywords, schema values | Free | Until you clear them. |
| Published page list: slug, title, last change date, a content fingerprint, image counts | Free | While the page is published and indexable. |
| IndexNow key and the result of the last request | Free | Until the plugin data is removed. The admin screens have no reset button. |
| Daily page-view and 404 counts per path | Free | 30 days. |
| Recorded slug changes | Free | Newest 200 changes. |
| MCP tokens: label, scope, SHA-256 hash, dates. Never the token itself. | Pro | Revoked and expired tokens: 30 days. |
| MCP audit log: time, tool, token label, argument hash, result. Never the arguments. | Pro | Newest 500 entries. |
| Background jobs, redirect rules, schema templates, audit facts and reports | Pro | Until you delete them or the page leaves the sitemap. |
| Search Console cache: per-page clicks, impressions, CTR, position | Pro | Replaced on each sync. |
| License record: key, install id, install secret, status, plan, dates | Pro | Until you deactivate. |
Secrets
These values go into the plugin settings form of Instatic. Instatic encrypts them. Only the plugin server code can read them. The admin screens show only whether a value is set.
- Google OAuth client secret and refresh token Pro
- AI provider API key Pro
What the plugin does not collect
- No cookies.
- No visitor ids or fingerprints.
- No IP addresses.
- No query strings from visited pages.
Remove the plugin data
When you uninstall the plugin in Instatic, Instatic removes the plugin settings and its stored records. Published pages keep the tags that the plugin wrote until you publish them again.