← Back to dashboard
PRIVACY

Privacy policy

Draft for GSC Searchlight. Effective date: not set. The service operator must review and complete the contact details before public launch.

Operator identity is not configured. The service owner must add the verified legal or business name before relying on this draft.

Who operates the service

Operator name not supplied — owner action required before launch. (the “operator”) operates GSC Searchlight. Contact details are listed on the Support page.

Information processed

How information is used and shared

Information is used to sign you in, maintain the Google connection, check property access, return the requested read-only reports, authorize AI clients, enforce trial duration and usage limits where enabled, meter usage, and operate billing where enabled. When you use an AI client, information needed to answer your request is sent to that client under its own terms. Google and, where enabled, Stripe process information as part of the requested integration. The operator does not sell Search Console report data.

Google access

The Google sign-in flow requests openid, email, profile, and https://www.googleapis.com/auth/webmasters.readonly. Search Console data is accessed only to provide the features you request. The service does not change Search Console settings or submit changes to Google. In AI Connections, you can disconnect Search Console: the service removes the saved connection and its property records before asking Google to revoke the grant, preventing new Search Console requests from using that connection. Requests already in progress may finish. A confirmed Google response may take time to take full effect. If the request fails or times out, the local connection is still removed, but you must check Google Account connections to remove or confirm the grant. Google notes that a grant can cover scopes and OAuth clients in the same Cloud project.

Sample mode

When the service is explicitly configured for demo mode, it returns illustrative sample data, ignores account sessions, and disables Google access, persistent database access, billing, and database-backed MCP authorization. Demo reports saved through Analysis remain in the local browser until you remove them or clear that browser storage.

Retention and deletion

Signed-in users in live mode can download a JSON export or request account deletion in AI Connections. Deletion requires typing the confirmation word and submitting from the signed-in session. It removes the user account and its user-owned database records using the declared database relations, requests Google revocation when a stored credential is available, and clears the session cookie. If Google does not confirm revocation or no credential is available to attempt it, the page directs the user to Google Account connections. Billing-linked and paid-plan accounts are blocked for operator review; outside trial mode, enabled Stripe billing also blocks deletion; this action does not cancel or change Stripe. Reports saved in this browser are not removed, and database backup copies are outside this deletion request. Rate-limit counters use fixed windows; their rows receive an expiry time one day after the current window and the application attempts to remove expired rows in batches of up to 100 at intervals of at least five minutes while handling traffic. This cleanup is opportunistic and does not guarantee a deletion deadline. Billing webhook event receipts have no user relation. The application attempts to remove receipts older than 30 days in batches of up to 100 at intervals of at least five minutes while handling billing traffic; this cleanup does not guarantee a deletion deadline. Checkout attempts belong to the account and follow its database deletion relations. No backup deletion schedule or general retention period is currently defined. Do not treat this draft as a promise that backup or browser copies are removed after a particular period.

Security and changes

The application encrypts stored Google tokens and stores API/MCP bearer-token hashes rather than their original values. No method of transmission or storage is guaranteed to be risk-free. This draft must be updated if data practices, providers, or product behavior change.

Contact

gscsearchlight.support@gmail.com Use the support page to contact the operator.