Privacy policy
Draft for GSC Searchlight. Effective date: not set. The service operator must review and complete the contact details before public launch.
Operator identity is not configured. The service owner must add the verified legal or business name before relying on this draft.
Who operates the service
Operator name not supplied — owner action required before launch. (the “operator”) operates GSC Searchlight. Contact details are listed on the Support page.
Information processed
- Google account and connection: if you connect Google, the service receives your account email and profile name, the Google Search Console properties and permission labels available to that account, and OAuth credentials needed to refresh access.
- Search Console requests: the service requests property lists, Search Analytics results, and URL Inspection results when you or an authorized AI client asks for them. The current application stores the property identifiers and permission labels you select for reports, but does not write Search Analytics or URL Inspection response rows into its database.
- Account and integration records: in live mode, the database stores account email/name, the first successful connection timestamp used to enforce an enabled seven-day trial, encrypted Google access and refresh tokens, API token hashes, MCP client and authorization records, and usage events containing the user, tool name, and timestamp.
- Abuse prevention: live request limits store keyed digests derived from a trusted Vercel client address when available, an internal user identifier, or a shared fallback together with a route category. Raw addresses, bearer tokens, and other credentials are not stored in these counters. Client address grouping assumes direct Vercel ingress; other hosts share a fallback route bucket rather than trusting forwarding headers.
- Browser data: the sign-in session is held in an HttpOnly cookie. Reports you explicitly save from the Analysis page are stored in that browser's local storage; they are not synced to the service database.
- Billing: where billing is enabled, Stripe processes payment details. The application stores Stripe customer/subscription identifiers, subscription status and period end, and a per-account checkout attempt containing the chosen plan, idempotency key, and available session identifier/expiry. It also retains webhook event identifiers, event types and processing timestamps to prevent duplicate processing. Webhook payloads, signatures and card numbers are not stored in those event records.
How information is used and shared
Information is used to sign you in, maintain the Google connection, check property access, return the requested read-only reports, authorize AI clients, enforce trial duration and usage limits where enabled, meter usage, and operate billing where enabled. When you use an AI client, information needed to answer your request is sent to that client under its own terms. Google and, where enabled, Stripe process information as part of the requested integration. The operator does not sell Search Console report data.
Google access
The Google sign-in flow requests openid, email, profile, and https://www.googleapis.com/auth/webmasters.readonly. Search Console data is accessed only to provide the features you request. The service does not change Search Console settings or submit changes to Google. In AI Connections, you can disconnect Search Console: the service removes the saved connection and its property records before asking Google to revoke the grant, preventing new Search Console requests from using that connection. Requests already in progress may finish. A confirmed Google response may take time to take full effect. If the request fails or times out, the local connection is still removed, but you must check Google Account connections to remove or confirm the grant. Google notes that a grant can cover scopes and OAuth clients in the same Cloud project.
Sample mode
When the service is explicitly configured for demo mode, it returns illustrative sample data, ignores account sessions, and disables Google access, persistent database access, billing, and database-backed MCP authorization. Demo reports saved through Analysis remain in the local browser until you remove them or clear that browser storage.
Retention and deletion
Signed-in users in live mode can download a JSON export or request account deletion in AI Connections. Deletion requires typing the confirmation word and submitting from the signed-in session. It removes the user account and its user-owned database records using the declared database relations, requests Google revocation when a stored credential is available, and clears the session cookie. If Google does not confirm revocation or no credential is available to attempt it, the page directs the user to Google Account connections. Billing-linked and paid-plan accounts are blocked for operator review; outside trial mode, enabled Stripe billing also blocks deletion; this action does not cancel or change Stripe. Reports saved in this browser are not removed, and database backup copies are outside this deletion request. Rate-limit counters use fixed windows; their rows receive an expiry time one day after the current window and the application attempts to remove expired rows in batches of up to 100 at intervals of at least five minutes while handling traffic. This cleanup is opportunistic and does not guarantee a deletion deadline. Billing webhook event receipts have no user relation. The application attempts to remove receipts older than 30 days in batches of up to 100 at intervals of at least five minutes while handling billing traffic; this cleanup does not guarantee a deletion deadline. Checkout attempts belong to the account and follow its database deletion relations. No backup deletion schedule or general retention period is currently defined. Do not treat this draft as a promise that backup or browser copies are removed after a particular period.
Security and changes
The application encrypts stored Google tokens and stores API/MCP bearer-token hashes rather than their original values. No method of transmission or storage is guaranteed to be risk-free. This draft must be updated if data practices, providers, or product behavior change.
Contact
gscsearchlight.support@gmail.com Use the support page to contact the operator.