Skip to content
SERPCompass

What we access, and what we never do with it.

Connecting your Search Console is a real act of trust, so this page states plainly what permissions we request, what we store, and the specific things we commit to not doing.

Our pledges

  • Read-only accessEvery integration we request is read-only. We cannot change, submit or delete anything in your Google properties, because we never ask for permission to.
  • Your data stays yoursWe don't sell it, share it with other customers, or use it to build products for anyone else.
  • Workspace isolationEvery query is scoped to your organisation. Models that learn from your data are trained on your workspace alone.
  • Revocable any timeDisconnect inside SERPCompass or revoke from your Google account directly. Either works, immediately.

The exact permissions we request

We ask for the narrowest scope that makes a feature work. Nothing here grants write access to anything.

Permissions requested
PermissionWhat it allowsWhy we need it
Sign in with Googleopenid, email, profile Confirms who you are and gives us your email address and display name So you can log in without creating another password
Search Consolewebmasters.readonly Read-only access to performance data for properties you already own Your real clicks, impressions and positions — the ground truth behind opportunity detection and outcome verification
Analyticsanalytics.readonly Read-only access to reporting data for properties you select Connecting search performance to what visitors actually did on the page

Google API Services Limited Use: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except where you have explicitly asked us for support, where required by law, or for security investigation.

What we store

  • Account details — your name, email address, and organisation name.
  • Connection tokens — the access and refresh tokens Google issues so we can refresh your data on schedule without asking you to reconnect weekly.
  • Performance data — the search and analytics metrics we pull for your connected properties, stored as a time series so trends and verification work.
  • Analysis output — crawl results, reports, keyword studies and the evidence behind each finding.
  • Operational logs — what ran, when, and whether it succeeded.

What we never store

  • Card details. Payments are handled by our payment processor. Card numbers never reach our servers and we could not retrieve them if asked.
  • Your Google password. Authentication happens on Google's side; we only receive a token.
  • Write credentials for anything. We hold no permission that could modify your site, your Google properties or your content.

How we protect it

  • Encryption in transit. All traffic to the application runs over HTTPS.
  • Scoped access. Data access is filtered by organisation at the query layer, so one workspace cannot read another's records.
  • Least privilege. We request the minimum scope per integration, and only at the moment you connect that integration.
  • Isolated processing. Analysis jobs run against your workspace's own data and write results back to that workspace only.
  • Revocation honoured immediately. Disconnecting removes our stored tokens; scheduled refreshes for that property stop.

How we behave on the web

SERPCompass crawls sites to audit them. We think how a tool behaves as a web citizen matters, so:

  • We respect robots.txt directives.
  • We rate-limit requests to avoid placing load on the sites we analyse.
  • We identify our crawler rather than disguising it as an ordinary browser.
  • We only fetch publicly reachable pages — we don't attempt to get past logins, paywalls or access controls.

Where AI is and isn't used

This matters for data handling, so it's worth being precise. Measurable facts — rankings, link counts, crawl results, demand signals — are crawled or computed. They are never produced by asking a language model to guess.

Language models are used in exactly two places:

  • Measuring AI-answer visibility — we send category questions to public assistants and record how brands appear in the response. These prompts are about your market, not your private data.
  • Drafting content — only when you explicitly ask for a draft.

We do not send your connected Search Console or analytics data to third-party language models. The one exception, and how it's bounded, is on our privacy notice.

Retention and deletion

We keep your workspace data for as long as your account is open, because the value of trend analysis is in its history. If you disconnect an integration, we stop collecting new data from it and delete the stored tokens.

To delete your account and its data entirely, contact us. We'll action the deletion and confirm when it's complete rather than leaving you to wonder.

Where we are today

We'd rather be accurate than impressive: SERPCompass is a product from a small team, and we don't currently hold a formal certification such as SOC 2 or ISO 27001. The practices above are what we actually do, not a description of an audit we haven't had. If your procurement process requires specific attestations, talk to us and we'll tell you honestly whether we can meet them today.

Reporting a vulnerability

If you believe you've found a security issue, please tell us and choose the security topic — it routes straight to the team rather than a general queue. Give us a description and steps to reproduce. We'll acknowledge it, keep you updated, and we won't pursue anyone who reports a genuine issue in good faith.

Start with a free scan of your site.

Two to five minutes, no account. You get your three most urgent findings, and the exact count of everything else.

Free, 2–5 minutes, no account needed.