Billing and privacy
What data does SEOKit access, store and encrypt?
SEOKit reads your Search Console data with read-only permission, keeps your Google tokens encrypted on the server and stores report history only for properties where you turn that on. Here is each permission and each stored item.
Checked against the SEOKit code, privacy policy and Google documentation · October 2026
Short answer
A normal sign-in requests only your Google identity. Read-only Search Console access is requested when you open a Search Console tool, Google Analytics 4 is asked for separately, and write access to Search Console is a further, explicit grant. Tokens are encrypted on the server; your browser keeps only a random session identifier.
The policy that governs this is Google’s API Services User Data Policy ↗ , including its Limited Use requirements.
What each permission lets SEOKit do
Permissions are requested in groups, so a feature you do not use does not ask for more than it needs.
Identity
Sign-in uses the OpenID and email permissions to learn your account identifier, name, email and picture. It does not read your mail or files.
Search Console, read-only
Lets SEOKit list your properties and read aggregated clicks, impressions, CTR and position by query, page, country and device. It cannot change your sites.
Google Analytics 4, read-only
Requested only when you connect GA4 on purpose. Lets SEOKit list properties and read aggregated traffic and conversion metrics.
Search Console, write
A separate grant, requested only for actions that change Search Console: adding a property or submitting a sitemap, and the MCP write mode. Ordinary reports never ask for it.
Google Drive
Normal sign-in does not request Google Drive.
What is stored and for how long
Saved on the server in encrypted form (Fernet authenticated encryption). The browser cookie holds only a random identifier, with Secure, HttpOnly and SameSite flags; a session lasts up to seven days.
Saved only for properties where you switch storage on: date, query, page, country, device, clicks, impressions, CTR and position. Kept up to ten years; deleted 30 days after you switch storage off.
Only a SHA-256 hash plus the first and last characters are kept. The full key is shown once, when you create it.
The Slack access token is stored encrypted and removed from use when you disconnect the workspace.
Run only when you start them and agree. The provider receives the page URL, current title and description and up to ten relevant queries, never your Google token or email.
ACCESS
Signing out is not the same as revoking access
Signing out deletes SEOKit’s stored token record. It does not tell Google that the permission is withdrawn. To remove the grant itself, open your Google Account’s list of third-party apps and remove SEOKit there; after that no token can be used, even a copy.
Deleting what SEOKit holds
You can sign out, switch off storage per property and disconnect Slack. To have stored credentials and reports deleted, write to the contact address in the privacy policy; a verified request is completed within 30 days unless the law requires otherwise.
Habits that keep your data safer
Do not paste an MCP key into chats or tickets
Anyone holding the key can call the tools it allows. Revoke it in the workspace and create a new one.
Do not grant write access “just in case”
Approve the write permission only when you are about to add a property or submit a sitemap.
Do not rely on sign-out to cut off access
Remove SEOKit from your Google Account when you stop using it.