How We Use Data
We use the data we hold to:
- Provide, operate, and maintain the Service (run crawls, generate scores and reports, enable sharing);
- Authenticate you, secure accounts, and prevent fraud or abuse;
- Process subscriptions, billing, and renewals;
- Provide support and respond to your requests;
- Improve, troubleshoot, and develop features (using aggregated or minimized data where possible);
- Send service and transactional messages, and — with your consent where required — product updates;
- Comply with legal obligations and enforce our Terms.
Legal Bases
Where the GDPR/KVKK applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, improve, and operate the Service, balanced against your rights); consent (e.g., certain cookies or marketing, which you can withdraw); and legal obligation (e.g., tax and accounting).
Data From Sites You Crawl
When you submit a Target Site, we crawl it on your instruction and store technical results in your account. With respect to any personal data contained in the pages you crawl, you act as the controller and we act as a processor on your behalf; you are responsible for having a lawful basis and the right to crawl and analyze that site. We process such data only to provide the Service to you.
You must only crawl websites you own or are authorized to analyze. Do not use Octolyze to collect personal data unlawfully.
Google Search Console & Analytics Data
Octolyze can connect to your Google Search Console and Google Analytics 4 accounts. The connection is optional, is made only when you start it yourself from the Integrations screen, and can be undone at any time. This section describes exactly what we request, retrieve, store, share and do with data received from Google APIs.
Scopes we request. Both API scopes are read-only — Octolyze cannot create, change or delete anything in your Google account:
- Search Console (
https://www.googleapis.com/auth/webmasters.readonly) — to list the properties your Google account is verified for, so you can pick the one that matches your project, and to run Search Analytics queries for that property. Why not narrower: Search Console publishes no read scope below this one. The alternative, webmasters, is broader — it adds write access to sitemaps and property settings, which Octolyze neither needs nor wants.
- Analytics (
https://www.googleapis.com/auth/analytics.readonly) — to list the GA4 properties your account can read, so you can choose one, and to run reports against the property you link. Why not narrower: this is the narrowest scope covering both calls. The Admin API is the only way to discover which properties you can read, and the Data API serves the reports. Google publishes no per-property or report-only read scope, and the alternatives (analytics.edit, analytics.manage.users) grant write access we do not need.
- openid and email (
https://www.googleapis.com/auth/userinfo.email) — requested only so the connection can be labelled with the Google address it belongs to (“connected as [email protected]”) and so two connected accounts can be told apart. They are never used to sign you in to Octolyze and never used for authorisation.
Search Console and Analytics are connected separately, and you can connect either without the other. If you connect both with the same Google account, Google carries the earlier grant forward onto the same credential, so the two integrations share one encrypted refresh token. Disconnecting removes that credential and both integrations with it.
What we retrieve from Search Console, for the property you link and the date window you choose: search queries and page URLs with their clicks, impressions and average position; the same figures by day and per page per day; the device split (desktop, mobile, tablet); the country breakdown; and the totals for the preceding equal-length period, so the dashboard can show a comparison.
What we retrieve from Analytics, for the property you link and the date window you choose: landing pages and channel groupings with sessions, engaged sessions, new users, key events, revenue and engagement duration; the same figures by day; device category, browser and screen resolution; country, city and language; site-search terms typed into your own site’s search box; and the referring source of sessions that arrived from an AI assistant. These are aggregated reports — Octolyze never exports user-level or event-level rows.
We do not request or store demographic data. Age, gender and interest dimensions are never asked for, never received and never stored — the integration has no code path that reads them.
Where it is stored, and for how long. The figures above are stored in our own database, keyed to your Octolyze account and to the project you linked, alongside the Google account address, the scopes you granted and which property is linked. Each sync replaces the stored copy for that date window rather than adding to it, so we hold the most recent pull and not a growing archive. We keep it while your account is open and the integration is connected. It is deleted immediately when you disconnect the integration, and within 30 days when you close your account or ask us to delete it at [email protected].
How the credentials are protected. The refresh token Google issues is encrypted with AES-256-GCM before it is written, using a key held in the server’s environment and never stored in the database — so a database backup on its own yields nothing usable. Short-lived access tokens are held in memory only: never written to the database or to disk, discarded when the server restarts, and cleared the moment you disconnect.
How it is used, and who receives it. Google user data is used only to render your own dashboards, worklists and reports. We do not sell it and we do not transfer it to third parties for their own purposes. It is processed only by the infrastructure that runs Octolyze — our application servers and our PostgreSQL database, on servers we control and operated on our instructions. It is not sent to any analytics, advertising or AI provider, and it is not used to train machine-learning models. Publicly shared report links and reports sent to report members contain crawl findings only; no Search Console or Analytics figures are included in a shared or public report. No human reads your Google data except with your explicit permission, where necessary for security purposes such as investigating abuse, or where required by law.
Channel reporting shows paid channels alongside the rest, because that is how Google Analytics groups traffic. We never use any of it to build audiences or to target advertising.
Octolyze’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect. Open Integrations in the app and choose Disconnect. This deletes the stored refresh token, the links between your projects and their Google properties, and the Search Console and Analytics figures already synced for those projects — in the same operation, so no data obtained from Google outlives the permission that allowed us to hold it. Projects linked through a different Google account are unaffected. Because the two integrations share one connection, this removes both at once. Reconnecting and re-syncing retrieves the data again from Google. You can also revoke our access directly at myaccount.google.com/permissions.
Shared Reports & Client Accounts
If you share a report via a public link or provision a Report Member account, the recipient can view the shared report. When you create a client account, we process that person’s name and email to give them access and to show you their status in your Clients (CRM). You are responsible for ensuring you may share this data with them.