Skip to content

Billing and privacy

What data does SEOKit access, store and encrypt?

SEOKit reads your Search Console data with read-only permission, keeps your Google tokens encrypted on the server and stores report history only for properties where you turn that on. Here is each permission and each stored item.

Checked against the SEOKit code, privacy policy and Google documentation · October 2026

Short answer

A normal sign-in requests only your Google identity. Read-only Search Console access is requested when you open a Search Console tool, Google Analytics 4 is asked for separately, and write access to Search Console is a further, explicit grant. Tokens are encrypted on the server; your browser keeps only a random session identifier.

The policy that governs this is Google’s API Services User Data Policy ↗ , including its Limited Use requirements.

What each permission lets SEOKit do

Permissions are requested in groups, so a feature you do not use does not ask for more than it needs.

01
openid · email

Identity

Sign-in uses the OpenID and email permissions to learn your account identifier, name, email and picture. It does not read your mail or files.

02
webmasters.readonly

Search Console, read-only

Lets SEOKit list your properties and read aggregated clicks, impressions, CTR and position by query, page, country and device. It cannot change your sites.

03
analytics.readonly

Google Analytics 4, read-only

Requested only when you connect GA4 on purpose. Lets SEOKit list properties and read aggregated traffic and conversion metrics.

04
webmasters

Search Console, write

A separate grant, requested only for actions that change Search Console: adding a property or submitting a sitemap, and the MCP write mode. Ordinary reports never ask for it.

05
not requested

Google Drive

Normal sign-in does not request Google Drive.

What is stored and for how long

Google tokens

Saved on the server in encrypted form (Fernet authenticated encryption). The browser cookie holds only a random identifier, with Secure, HttpOnly and SameSite flags; a session lasts up to seven days.

Report history

Saved only for properties where you switch storage on: date, query, page, country, device, clicks, impressions, CTR and position. Kept up to ten years; deleted 30 days after you switch storage off.

MCP API keys

Only a SHA-256 hash plus the first and last characters are kept. The full key is shown once, when you create it.

Slack connection

The Slack access token is stored encrypted and removed from use when you disconnect the workspace.

AI features

Run only when you start them and agree. The provider receives the page URL, current title and description and up to ten relevant queries, never your Google token or email.

ACCESS

Signing out is not the same as revoking access

Signing out deletes SEOKit’s stored token record. It does not tell Google that the permission is withdrawn. To remove the grant itself, open your Google Account’s list of third-party apps and remove SEOKit there; after that no token can be used, even a copy.

Deleting what SEOKit holds

You can sign out, switch off storage per property and disconnect Slack. To have stored credentials and reports deleted, write to the contact address in the privacy policy; a verified request is completed within 30 days unless the law requires otherwise.

Habits that keep your data safer

Do not paste an MCP key into chats or tickets

Anyone holding the key can call the tools it allows. Revoke it in the workspace and create a new one.

Do not grant write access “just in case”

Approve the write permission only when you are about to add a property or submit a sitemap.

Do not rely on sign-out to cut off access

Remove SEOKit from your Google Account when you stop using it.

Official sources

  1. Google API Services User Data Policy
  2. Google: third-party apps with access to your account
  3. Google OAuth 2.0 scopes
  4. Search Console API: authorizing requests

Continue in the FAQ

Reports and toolsHow the workspace reports, exports and saved views work.Data and metricsClicks, impressions, CTR, position and report differences.
← Back to all FAQ questions
SEOKIT · GROQ

SEOKit assistant

0 / 1000