Privacy Policy
Last updated 27 July 2026
Searchlight is a mobile client for Google Search Console. This policy describes exactly what it stores, why, who it is shared with, and how to remove it. It is written to be read, not to be survived.
The short version
- Searchlight reads your Search Console data. It cannot change it.
- We store the minimum needed to sign you in and fetch that data on your behalf.
- Your search data is never sold, shared for advertising, or used to train anything.
- There is no advertising SDK, no analytics SDK, and no cross-app tracking in the app.
- You can delete everything from inside the app, at any time.
What we store
| Data | Why |
|---|---|
| Google account ID, email address, name and profile picture URL | To identify your account and show who is signed in. One record per connected Google account. |
| Google OAuth refresh token | To request Search Console data on your behalf without asking you to sign in repeatedly. Stored server-side only and never sent to the app. |
| The list of properties you choose to track, and which are favourited | To show your list and to enforce the limit on the free plan. |
| Subscription status | To know whether your account is on the free or Pro plan. |
| Cached Search Console responses | Held briefly (about 15 minutes) so the app is fast and to stay within Google's rate limits. Expires automatically. |
We do not store your Google password, and we never receive it — sign-in happens on Google's own pages.
Google access
Searchlight requests a single Search Console scope,
https://www.googleapis.com/auth/webmasters.readonly, alongside basic profile
information (openid, email, profile).
That scope is read-only. Searchlight cannot submit sitemaps, request indexing, add or remove properties, change users, or alter anything else in your Search Console.
Searchlight's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, and we do not use it to develop, improve or train generalised AI or machine learning models.
You can revoke Searchlight's access at any time at myaccount.google.com/permissions. Doing so immediately stops us from fetching any further data.
Who else is involved
- Google — the source of the Search Console data, accessed with your permission.
- Cloudflare — hosts the Searchlight API and database. Your data is stored on Cloudflare infrastructure.
- Apple and RevenueCat — process subscriptions and tell us whether yours is active. Payment details go to Apple; we never see them.
That is the complete list. We do not sell personal information, and we do not share it with advertisers or data brokers.
How long we keep it
Account records are kept while your account exists. Cached Search Console responses expire within roughly 15 minutes, and Google access tokens within about an hour. When you delete your account, your records are removed from our database and any cached tokens are discarded.
Deleting your data
In the app: Settings → Delete account. This removes your account, your connected Google accounts, and your tracked properties. Nothing in your Search Console is affected — the data there belongs to Google and to you, and Searchlight only ever read it.
Disconnecting a single Google account (Settings → Google accounts) removes that account's stored token and tracked properties while leaving the rest intact.
Children
Searchlight is a tool for website owners and is not directed at children. We do not knowingly collect information from anyone under 13.
Changes
If this policy changes materially, the date at the top will change and the updated policy will be posted here before the change takes effect.
Contact
Questions about privacy, or a request to access or delete your data: privacy@gscmobile.app.