SEO Command Center And Google Search Console Data
SEO Command Center can connect to Google Search Console when an authorised user chooses to sign in with Google and grant access. Google connection is optional and is used only for the visible SEO analysis features described on this page.
What Data Is Accessed
SEO Command Center may access Google Search Console data authorised by the user, including the list of verified Search Console properties available to the authorised Google account and each property's permission level.
For an authorised property, SEO Command Center may request Search Analytics performance rows grouped by search query, landing page URL and date. Those rows can include clicks, impressions, click-through rate and average search position. The application does not request write access, does not request Gmail, Drive, Calendar, profile or advertising scopes, and does not collect Google Account passwords.
Why It Is Accessed
This information is used to analyse organic search performance, combine Search Console evidence with website crawl evidence, identify SEO opportunities and problems, prioritise recommended SEO actions, and display performance information inside SEO Command Center. Examples include showing top queries and pages by clicks, showing impressions, CTR and average position, and helping prioritise content or technical SEO review based on real authorised Search Console evidence.
SEO Command Center does not use Google Search Console data for advertising, retargeting, credit decisions, resale, public surveillance, or unrelated products.
AI And Machine Learning
Google user data obtained through Google APIs is not used to train generalized AI models, train non-personalized machine-learning models, improve generalized foundation models, or build data products for third parties. The reviewed SEO Command Center implementation does not send Google Search Console data to an external AI or LLM provider.
Access Level
SEO Command Center requests the Google Search Console read-only OAuth scope https://www.googleapis.com/auth/webmasters.readonly. This permission lets SEO Command Center read authorised Search Console information. It does not allow SEO Command Center to modify Search Console properties, submit sitemaps, change users, update settings or alter Search Console data.
Storage
SEO Command Center stores imported Search Console performance rows and connection metadata in the application database so the application can display performance history and combine it with crawl evidence. Stored performance rows may include query, landing page, date, clicks, impressions, CTR and average position. Connection metadata may include the selected Search Console property URL, OAuth scope, connection status, connection time, last sync time and provider error messages.
OAuth access tokens and refresh tokens are stored in the application database for the connected account so SEO Command Center can import authorised Search Console rows and refresh access when necessary. The production implementation supports protected provider token storage when the provider token secret is configured. Local or pre-production environments without that secret are not suitable for declaring production provider login ready.
Raw Google API responses are not intended to be stored as public website content. The application stores mapped Search Console rows and metadata needed for the visible product features.
Retention
Imported Search Console rows are retained while they are useful for SEO analysis and operational history unless Greg Staunton removes the relevant local application data. Disconnecting Google removes local OAuth tokens for that connection and attempts provider revocation, but it does not automatically delete historical imported performance rows.
Google user data is retained only for as long as reasonably necessary to provide the SEO Command Center functionality for which access was authorised, unless a longer period is required by law. Data no longer required for the stated purpose is deleted or anonymised where applicable.
Deletion Requests
A user can request deletion of Google-derived data associated with SEO Command Center by using the contact form on greg-staunton.com or contacting Greg Staunton through the LinkedIn profile linked in the site footer. A deletion request can cover stored Search Console performance rows, connection metadata and other Google-derived data associated with that user's connection, subject to legal or operational records that must be retained.
Sharing
SEO Command Center does not sell Google user data. Google Search Console data is used to provide and improve the visible SEO analysis features in SEO Command Center. Google Search Console data is not transferred to advertising platforms, data brokers, information resellers or unrelated third-party products.
The application makes provider requests to Google only where needed to connect, refresh, import authorised Search Console data or revoke authorised access. The reviewed implementation does not send Google Search Console data to an external AI or LLM provider.
Security
SEO Command Center is operated as a private contractor tool. The production application is intended to be protected behind access controls, uses HTTPS in production, stores OAuth configuration outside source control, validates OAuth state during the callback, and keeps provider tokens out of browser-visible pages.
Google Limited Use
SEO Command Center's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for targeted advertising, personalised advertising, retargeting, interest-based advertising, selling data, providing data to brokers or resellers, credit-worthiness decisions, lending, or training generalized or non-personalized AI or machine-learning models.
Revocation And Disconnection
Users can revoke SEO Command Center's Google access through their Google Account security settings for third-party apps, connections or account access. SEO Command Center also includes a Disconnect Google control that removes local Google tokens for the selected connection and attempts a provider revocation request when a token is available. Revoking or disconnecting prevents future authorised Google API access. Existing imported Search Console performance rows may remain in the application database as historical SEO evidence unless removed separately or included in a deletion request.