Privacy Policy

Last updated 5 September 2026

Searchlight provides a mobile app, web dashboard and MCP tools for search, analytics and advertising. This policy describes exactly what it stores, why, who it is shared with, and how to remove it. It is written to be read, not to be survived.

The short version

What we store

DataWhy
Google account ID, email address, name and profile picture URL To identify your account and show who is signed in. One record per connected Google account.
Google OAuth refresh token To request Search Console, Analytics and Google Ads data on your behalf without asking you to sign in repeatedly. Stored server-side only and never sent to the app.
The list of properties you choose to track, and which are favourited To show your list and to enforce the limit on the free plan.
Optional Bing and Meta connection tokens To read the provider data you authorise. Stored server-side; removed when you disconnect the web connection or delete your account.
Subscription status To know whether your account is on the free or Pro plan.
Cached Search Console responses Held briefly (about 15 minutes) so the app is fast and to stay within Google's rate limits. Expires automatically.

We do not store your Google password, and we never receive it — sign-in happens on Google's own pages.

Google access

One Google sign-in requests Search Console (https://www.googleapis.com/auth/webmasters), Analytics (https://www.googleapis.com/auth/analytics.readonly) and Google Ads (https://www.googleapis.com/auth/adwords), alongside basic profile information (openid, email, profile). Previously connected accounts keep their existing permissions until you reconnect.

Search Console

Searchlight uses that scope for two things: reading your reports, and submitting a sitemap when you explicitly ask it to. Sitemap submission is the only change it makes to your Search Console. Nothing in Searchlight can delete a sitemap, add or remove a property, change users or permissions, request indexing, or alter any other setting.

The permission is wider than the use, and it is worth being plain about why. Google publishes only two Search Console scopes: a read-only one, and this one. There is no scope that permits submitting a sitemap without also permitting everything else, so the restriction is enforced in the app rather than by the permission you grant. You are trusting our implementation on that point, which is exactly why it is written down here.

Accounts connected to Searchlight before sitemap submission existed hold a read-only grant. Permissions are not widened retroactively, so those accounts stay read-only until you choose to sign in again.

Google Analytics

Signing in with Google also grants https://www.googleapis.com/auth/analytics.readonly, as part of the same consent as Search Console and Google Ads. If you connected a Google account before Analytics was part of that request, it keeps the narrower permission until you choose to reconnect — permissions are not widened retroactively.

That scope is read-only. Searchlight uses it for exactly two things: listing the GA4 properties your account can see, so you can pick one, and running reports on a property you have picked. It cannot change a property, edit a data stream, alter user access, or delete anything.

What it reads is aggregated reporting, not individual people: sessions, users, page views, engagement rate, session duration, and those figures broken down by page, landing page, channel, source, country and device. Searchlight does not request or receive the User Data Deletion or user-activity APIs, and it does not read individual user or event-level records.

Revoking Searchlight from your Google account permissions page removes the Google permissions together, because they are one grant.

Google Ads

The Google Ads permission allows changes, but Searchlight implements read APIs only. It reads accessible accounts, campaign performance, search terms, landing pages, ad copy, budgets, conversion settings and recommendations. It cannot create or edit ads, change a budget, apply a recommendation or upload conversions. Cost and conversion reports retain the advertising account's currency and attribution settings.

Meta Ads

Meta is optional and has its own sign-in. Searchlight requests ads_read to read the ad accounts you can access, campaign and ad performance, creative details, targeting and conversion settings. It does not publish ads, change budgets or upload events.

Your Meta access token is stored server-side, with an association to your Searchlight account. It is never sent to the web app. Tokens expire, so you may need to reconnect. Disconnecting Meta in Connections deletes the stored web connection and token. You can also remove the integration in your Meta account settings. Separately authorised MCP connections must be disconnected in the MCP client or revoked with the provider.

Bing Webmaster Tools

Bing is a separate provider with its own sign-in, and connecting it is entirely optional. Searchlight requests Bing's webmaster.manage scope — the only scope Bing Webmaster Tools publishes; it has no read-only alternative.

Searchlight reads your verified sites, click and impression history, and query and page breakdowns. It does not submit or delete sitemaps, add or remove sites, or change any Bing setting from this web app. As with Search Console, the permission is wider than the use because Bing offers nothing narrower, and the limit is in our code rather than in the grant.

Bing's API exposes no email address or account identifier, so a Bing connection carries no identity — it is described in the app by the sites it can read. Disconnect it at any time from the property manager, or revoke it in Bing Webmaster Tools under Settings and API access.

Searchlight's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, and we do not use it to develop, improve or train generalised AI or machine learning models.

You can revoke Searchlight's access at any time at myaccount.google.com/permissions. Doing so immediately stops us from fetching any further data.

Who else is involved

That is the complete list. We do not sell personal information, and we do not share it with advertisers or data brokers.

How long we keep it

Account records are kept while your account exists. Cached Search Console responses expire within roughly 15 minutes, and Google access tokens within about an hour. When you delete your account, your records are removed from our database and any cached tokens are discarded.

Deleting your data

In the app: Settings → Delete account. This removes your account, your connected Google, Bing and web Meta accounts, and your tracked properties. This does not delete data or advertising campaigns held by those providers.

Disconnecting a single Google account (Settings → Google accounts) removes that account's stored token and tracked properties while leaving the rest intact.

Children

Searchlight is a tool for website owners and is not directed at children. We do not knowingly collect information from anyone under 13.

Changes

If this policy changes materially, the date at the top will change and the updated policy will be posted here before the change takes effect.

Contact

Questions about privacy, or a request to access or delete your data: [email protected].