Legal

Privacy policy

What gsc.k-o.pro does with your data when you connect your Google account to it. It is written to match what the software actually does; the source is public, so it can be checked.

Who runs this service

An instance of the open-source gsc-mcp-remote server, operated by whoever deployed it at gsc.k-o.pro. It is not operated by, affiliated with, or endorsed by Google or by Anthropic.

What is collected

DataWhy
Your Google account email address and account identifier To recognise you across sessions and to attach your saved settings and stored credential to you
A Google refresh token, encrypted at rest To call the Search Console API on your behalf without making you sign in again for every question
Your chosen default property, if you set one So tool calls that do not name a property can use it
Irreversible hashes of the access tokens issued to your Claude client To recognise valid requests. The tokens themselves are never stored, so a copy of the database does not yield working credentials
Server logs: session open and close events, errors, timestamps To keep the service running and diagnose failures

What is not collected

What access is requested

One Google permission only: https://www.googleapis.com/auth/webmasters.readonly, plus your email address for identification. This is read-only. The service cannot submit URLs for indexing, change sitemaps, modify your properties, or reach any other Google service. Google's own Search Console permissions still apply on top: you see exactly the properties Google would show you.

How your data is protected

Sharing

Your data is not sold, rented, or shared with third parties. It is not used for advertising, and it is not used to train any machine-learning or AI model. The only third party involved is Google, whose API is called on your behalf with the permission you granted.

How long it is kept, and how to delete it

Data is kept until you remove it. You can do that at any time, in either of two ways, and doing either is enough:

Run export_my_data at any time to see everything held about you. Expired tokens and abandoned sign-in attempts are swept automatically.

Changes

If this policy changes materially, the change will appear on this page. The repository's history is the authoritative record of what changed and when.

Contact

For any question about your data, or to ask for it to be deleted by hand, write to hi@k-o.pro.