Privacy Policy
Last updated: [DATE] · Operated by [LEGAL ENTITY NAME], [ADDRESS]
What we collect
- Google account basics — your name, email address, profile picture and Google account ID, used to identify your account.
- A Google refresh token — the credential that lets us read your Search Console data on your behalf. It is encrypted with AES-256-GCM before storage.
- A Bing Webmaster Tools API key — only if you choose to add one. Also encrypted before storage.
- Access tokens we issue — stored only as irreversible hashes.
What we do not do
- We do not store your Search Console performance data. It is fetched on demand, held in memory to answer your request, and cached for at most 10 minutes.
- We do not sell, rent or share your data with third parties.
- We do not use your data to train machine learning models.
- We never write to your website or change your Search Console settings.
Google API Services User Data Policy
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request, and why
| Scope | Why |
|---|---|
openid, email, profile | To identify your account and show who is signed in. |
webmasters | To read your Search Console properties, performance data, URL index status and sitemaps, and — only when you explicitly ask — to submit a sitemap. |
Where your data lives
On [HOSTING REGION] infrastructure provided by Vercel (application) and Neon (database). Both hold data encrypted in transit and at rest, in addition to our own encryption of credentials.
Retention and deletion
Credentials are kept until you delete your account or revoke access. To delete everything: revoke access at myaccount.google.com/permissions and email [SUPPORT EMAIL]. We erase your record within 30 days.
Your rights
You may request access to, correction of, or deletion of your personal data at any time via [SUPPORT EMAIL]. If you are in the EEA or UK, our legal basis for processing is the performance of our agreement with you.
Contact
[LEGAL ENTITY NAME], [ADDRESS] — [SUPPORT EMAIL]