---
title: "Privacy · gscdump"
canonical_url: "https://gscdump.com/privacy"
last_updated: "2026-10-03T07:15:30.500Z"
meta:
  description: "What personal data gscdump collects, why, who receives it, how long it is kept, and how to disconnect a Site, revoke access, or delete your account."
  "og:description": "What personal data gscdump collects, why, who receives it, how long it is kept, and how to disconnect a Site, revoke access, or delete your account."
  "og:title": "Privacy · gscdump"
---

# Privacy

This page covers gscdump.com, the platform, the hosted MCP server, the API, and the CLI in cloud mode. Harlan Wilton, an individual in New South Wales, Australia, operates gscdump and is the data controller.

Last updated 2026-10-01.

## Data gscdump collects

<dl>

<dt>**Google profile**</dt>
<dd>Your Google account id, email address, name, and profile picture. Google sends these when you sign in.</dd>

<dt>**Google tokens**</dt>
<dd>The access token, refresh token, token expiry, and the scopes you granted. Tokens are encrypted with AES-256-GCM before they are stored in the database. Your session cookie does not carry your Google tokens. An older session cookie can still hold them, sealed by the session encryption, until you sign in again, sign out, or the session ends. Your browser cannot read a sealed cookie.</dd>

<dt>**Bing tokens**</dt>
<dd>If you connect Bing Webmaster Tools, gscdump stores that connection's tokens in the same encrypted form.</dd>

<dt>**Search data**</dt>
<dd>For each Site you connect: Search Console performance data (clicks, impressions, CTR, and position by page, query, country, device, date, search type, and search appearance), sitemaps, index coverage, and URL inspection results. If you connect Bing, the Bing Webmaster data for that Site. gscdump also stores the list of Search Console properties your Google account can access.</dd>

<dt>**Sites and Teams**</dt>
<dd>The Sites you connect, your Teams and their names, your Team memberships and roles, the email address of each person you invite to a Team, and a Team audit log of changes.</dd>

<dt>**Credentials**</dt>
<dd>API keys and API tokens are stored as hashes with a short preview. CLI sessions store your user agent, the last-used time, and a call count. A CLI session ends 90 days after you authorize it. Then you sign in again.</dd>

<dt>**Usage records**</dt>
<dd>For each API request and MCP tool call: your user id, Team, the operation or tool name, the method and path, the target Site, the client name, the result status, the duration, your user agent, and a salted hash of your IP address. The raw IP address is not stored. Rate limits keep an unsalted hash of your IP address until a day after the limit resets. gscdump also counts requests per route per day, and logs account events such as a sync failure.</dd>

<dt>**Cookies**</dt>
<dd>An encrypted session cookie keeps you signed in for up to 90 days after you sign in. Then you sign in again. Two short-lived cookies hold your place during Google sign-in. A cookie records the deployed version, so the page can reload after a release. Dashboard cookies remember your filters, columns, and collapsed panels. gscdump loads no advertising or third-party analytics scripts.</dd>

<dt>**Waitlist**</dt>
<dd>If you join the waitlist: your email address, the form you used, an optional note, your user agent, and the referrer.</dd>

<dt>**Feedback**</dt>
<dd>If you send feedback: your user id, the page, your rating, your comment, your user agent, your screen size, and the Site you had open. If you report a CLI problem: the agent, the CLI version, the Node.js version, and the platform.</dd>

<dt>**Error reports**</dt>
<dd>When a request, a job, or a page in your browser fails, an error report goes to Sentry. It can include your numeric user id and request details. A filter removes known secrets, your email address, and your IP address from error reports before they are sent. Sentry also receives performance traces and warning logs, which this filter does not process. Sentry can record the IP address of your browser.</dd></dl>

## How gscdump uses it

- Sign you in and keep you signed in.
- Sync, backfill, and preserve the Search Console data for the Sites you connect.
- Serve that data to you and to the agents you authorize, through the dashboard, MCP, the API, and the CLI.
- Send email about your account: onboarding, sync results, lost Site permission, expired Google access, Team invitations, and waitlist confirmation.
- Enforce rate limits and quotas, and detect abuse.
- Find and fix errors, and plan capacity.

We never sell your data. We do not use Google user data for advertising, and we do not use it to train AI models.

gscdump's use and transfer of information received from Google APIs adheres to the [~~Google API Services User Data Policy~~](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

## Who receives it

<dl>

<dt>**Cloudflare**</dt>
<dd>Hosts gscdump. Cloudflare runs the Workers, stores data in D1, KV, R2, the R2 Data Catalog, Durable Objects, and Workers Analytics Engine, runs queues, keeps request logs and traces, and sends email for gscdump. While a dashboard tab is open, its live connection holds your IP address in memory.</dd>

<dt>**Cloudflare Workers AI**</dt>
<dd>gscdump can send search queries, page rows, sync errors, and feedback comments to a model on Cloudflare Workers AI. The model classifies them, for example to tell brand queries from other queries.</dd>

<dt>**Google**</dt>
<dd>gscdump sends your tokens to Google to read Search Console data for your Sites. When you authorize an MCP client, the sign-in page loads fonts from Google Fonts, so Google receives your IP address.</dd>

<dt>**Microsoft**</dt>
<dd>Only if you connect Bing. gscdump sends your Bing tokens to Bing Webmaster Tools to read data for your Sites.</dd>

<dt>**Sentry**</dt>
<dd>Receives error reports, performance traces, and warning logs. Sentry stores them in the United States.</dd>

<dt>**Your Team**</dt>
<dd>Members of a Team can read the Sites that belong to that Team.</dd>

<dt>**Your agents**</dt>
<dd>An MCP client or API client that you authorize can read your Sites and their data.</dd>

<dt>**Authorities**</dt>
<dd>gscdump shares your data with authorities only when the law or a court order requires it.</dd>

<dt>**Partners**</dt>
<dd>A partner product, such as Nuxt SEO, can create a gscdump user for you. The partner sends your Google account id, email address, name, and tokens to gscdump. gscdump returns your Search Console data to that partner and sends account and sync events to the partner's webhook. Partner tokens can carry more Google scopes, for example to submit a sitemap or to add and verify a Site.</dd></dl>

## How long it is kept

<dl>

<dt>**Your account**</dt>
<dd>Your profile, tokens, Sites, Team data, and synced data stay until you delete your account. Deletion deletes your Sites and their synced data, including your per-user database. It deletes the Teams you own that nobody else uses, and removes you from other Teams. Those Teams stay. It also deletes your Bing tokens, API keys, CLI sessions, MCP connections, and email logs. Audit events stay, with your email address replaced by "deleted-user".</dd>

<dt>**A disconnected Site**</dt>
<dd>Disconnecting a Site deletes its registration, its sitemap and indexing records, and its stored files. Its analytics rows stay in the Team's storage until the Team is deleted.</dd>

<dt>**Jobs and reports**</dt>
<dd>Background job records are deleted after 7 days. A report result is deleted 30 days after it was made, when a newer result for the same report exists. The latest result stays. Storage error records and revoked partner keys are deleted after 30 days. Rate limit records are deleted a day after they expire.</dd>

<dt>**Logs and usage**</dt>
<dd>Usage records, the activity log, daily request counts, waitlist entries, and feedback have no automatic deletion while your account exists. Account deletion deletes them, together with pending Team invitations sent to your email address.</dd>

<dt>**Service logs**</dt>
<dd>Cloudflare request logs and Sentry error reports follow those providers' retention periods.</dd></dl>

## Your controls

<dl>

<dt>**Disconnect a Site**</dt>
<dd>In the dashboard, open Organic Search. Select the delete icon on the Site, then select Disconnect. Sync for that Site stops.</dd>

<dt>**Revoke Google**</dt>
<dd>Remove gscdump at <a href="https://myaccount.google.com/permissions">~~myaccount.google.com/permissions~~</a>. Sync pauses and the dashboard asks you to reconnect. Your preserved history stays until you delete it.</dd>

<dt>**Revoke an agent**</dt>
<dd>Remove the gscdump connector in your MCP client. Account deletion ends every MCP connection on the server. To revoke a Team API token, open Team settings, then API tokens.</dd>

<dt>**Delete your account**</dt>
<dd>Open Settings, then Account, and type your email address to confirm. Deletion starts at once and signs you out. It follows the steps in the <a href="#retention">~~retention section~~</a> and revokes gscdump's access to your Google account. If you own a Team that other people still use, delete that Team first. Access that a partner app holds in your Google account stays until you remove it at <a href="https://myaccount.google.com/permissions">~~myaccount.google.com/permissions~~</a>.</dd>

<dt>**Stop optional email**</dt>
<dd>Onboarding email and "Sync finished" email carry an unsubscribe link. You can also turn them off in Settings, then Preferences. Email about lost access, failed sync, and Team invitations still sends, because it asks you to act.</dd>

<dt>**Export your data**</dt>
<dd>The CLI writes your Search Console data to your own disk as DuckDB and Parquet. The <a href="https://gscdump.com/trust">~~trust page~~</a> states what export covers today.</dd>

<dt>**Access or correct**</dt>
<dd><a href="mailto:hello@gscdump.com">~~Email us~~</a> to get a copy of the personal data gscdump holds about you, or to correct it.</dd></dl>

## Security, children, and changes

The [~~trust page ~~](https://gscdump.com/trust) describes the OAuth scopes, token encryption, and storage boundaries.

gscdump is for site owners and developers. It is not directed at children under 13, and we do not knowingly collect their data.

When this policy changes, we update the date at the top of this page. Before a material change, we email account holders 30 days ahead.

Questions about your data?

Email [~~hello@gscdump.com~~](mailto:hello@gscdump.com) for privacy questions and deletion requests. Security reports go to [~~security@gscdump.com~~](mailto:security@gscdump.com).

[**Email us **](mailto:hello@gscdump.com) [**Read the terms **](https://gscdump.com/terms)

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
