Service information
Privacy Policy
Effective date: October 1, 2026
This policy covers the Google Search Console MCP service and its public website at vosiksignals.win. The service is operated as an independent developer project. For privacy questions or requests, contact vosikvos@gmail.com.
Google sign-in and permissions
The service uses Google OAuth and OpenID Connect to authenticate you and obtain permission to access Google Search Console. It requests basic OpenID authentication and the Google Search Console read-only permission (webmasters.readonly). Your Google account's stable subject identifier is used to derive an internal account identifier; your email address is not used as the account identity. The service does not receive your Google password.
Information accessed
When your connected MCP client requests a tool, the service may access properties and permission levels associated with your Google account; search analytics such as search queries, page URLs, dates, countries, devices, clicks, impressions, click-through rates and positions; URL inspection and indexing information; and submitted sitemap information. Requests may include property URLs, inspection URLs, date ranges, dimensions and filters. The information returned depends on your permissions and Google's API availability.
How information is used and shared
Account identifiers and OAuth credentials are used to authenticate your connection and call Google's APIs on your behalf. Search Console information is used only to provide the MCP functionality you request. Results are returned to the MCP client you authorize. If that client is an AI service, it may process those results under its own privacy policy and settings. Choose your client carefully; this service cannot control how a separate client handles results after receiving them.
Cloudflare hosts the service and its credential storage and processes information needed to operate the infrastructure. Google processes authorization and API requests. Data may also be disclosed where necessary to comply with law or investigate security incidents. User data is not sold, rented or used for advertising.
Credentials, storage and security
The service stores Google refresh tokens and temporarily caches access tokens for each internal account so your connection can continue functioning without signing in for every request. It also stores MCP authorization grants and short-lived authorization transaction information. Credentials are not intentionally included in tool results. HTTPS is used for connections to the service and Google's APIs, and credential access is restricted by the authenticated account.
Search Console results are fetched to answer requests; the service does not maintain a separate analytics database of those results. Infrastructure may process technical request metadata and operational logs, such as timestamps, network information and error status. No system can guarantee absolute security.
Retention and deletion requests
Refresh credentials and authorization records can remain stored while the connection exists; access-token caches and temporary authorization transactions expire. Revoking Google access prevents future authorized API use but does not automatically delete every stored record or data already received by your client. To request deletion of service-held connection records, email the contact address above. You may be asked to verify control of the account before a request is processed. The service does not promise automatic deletion on a fixed schedule; legal or security obligations may require some records to be retained.
Google API information and Limited Use
The service's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google API information is used to provide the visible, user-requested MCP features. Transfers are limited to delivering those features with your consent, necessary security purposes or legal compliance. It is not used for advertising, data brokerage, credit decisions or training generalized AI models by this service.
Human access is limited to your affirmative permission to examine specific data, necessary security investigations, legal requirements, or other access expressly permitted under that policy. A transfer following a merger, acquisition or asset sale would require your prior explicit consent as required by the policy.
Revoking access
You can remove the service's access through your Google Account's third-party connections settings. You can also disconnect the MCP server in your client. Disconnecting a client may not revoke Google's grant; use Google's settings to revoke Google access. Your client may retain previous conversations or results according to its own policies.
Public website
This public website has no analytics scripts, advertising, signup forms or application-set cookies. The MCP authorization flow uses short-lived cookies to bind authorization to your browser. Cloudflare may process network metadata or apply infrastructure security measures when serving either the website or the MCP service.
Changes and contact
Updates will be published here with a revised effective date. Material changes in Google data use will require appropriate notice and renewed consent before the new use begins. Contact vosikvos@gmail.com with questions about this policy or your connection.