You choose which search sources to connect and which AI clients can access your reports.
Who we are and what this policy covers
PostMCP AI provides GSC MCP Server to help you explore search performance from Google Search Console and Bing Webmaster Tools. This policy covers our website and services we operate. If you run the software yourself or use a server operated by someone else, that operator controls its storage, hosting, and data handling. Their privacy practices also apply.
Information we collect
- Account information: your name, email address, profile image, sign-in provider, provider account identifier, login times, and workspace preferences.
- Connected search sources: authorized site properties, permissions, selected properties, connection status, and credentials needed to retrieve reports, including Google authorization tokens or a Bing API key.
- Search reports: queries, page URLs, clicks, impressions, click-through rates, positions where available, and date ranges returned by your connected providers.
- Service information: API key names, prefixes, hashes, expiry and usage times; questions submitted in the playground; and technical request and error information needed to operate and protect the service. Hosting systems may also process IP addresses and browser information.
- Correspondence: information you provide when you email us for support or make a privacy request.
Signing in and connecting a search source are separate actions. Signing in alone does not grant access to your search reports.
How we use information
We use information to authenticate you, save your preferences, retrieve and display reports you request, answer playground questions, and serve reports to AI clients you authorize. We also use necessary information to provide support, prevent abuse, investigate errors, and meet applicable legal obligations. We do not sell your personal information or connected search data, use it for targeted advertising, or use it to train our own AI models.
Google data and permissions
Connecting Google Search Console requests read-only access to your Search Console properties and reports. This permission lets us read search performance; it does not let us modify your website or Search Console settings.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the search reporting and client connections you request. Human access is limited to your consent or circumstances allowed by that policy, such as security investigations or legal obligations.
Cookies and browser storage
We use a session cookie to keep you signed in. The current browser session is configured to expire after approximately 24 hours. We also use local storage for cached account information and sign-out coordination, and session storage to return you to your workspace after sign-in. These support the account experience rather than advertising.
You can clear cookies and site storage in your browser; doing so may sign you out. Clearing browser storage does not delete your server-side account. The website loads fonts from Google Fonts, which receives the network information needed to serve those fonts, such as your IP address.
Retention and security
Account records, preferences, connection metadata, and API key records are stored on the service operator’s server while needed for your workspace. Reports are retrieved from the search providers when requested; the current application does not save a separate report history or playground conversation history in its database. Infrastructure logs, backups, and external clients may have their own retention periods.
Stored search-provider credentials are encrypted, workspace API keys are stored as hashes, and browser session cookies are HttpOnly. These safeguards reduce risk but cannot guarantee absolute security. Data may be processed in the countries where the operator and its infrastructure providers run the service.
Your choices and privacy requests
- Change or cancel your plan in Billing.
- Disconnect a source in Data sources to remove its stored connection and credentials. Disconnecting does not delete data held by Google or Microsoft. You can also revoke access in your Google account or rotate your Bing API key.
- Revoke workspace API keys in Setup to stop further access through those keys. This does not erase reports already received by an external client.
- Email us to request access, correction, or deletion of your hosted account information. We may need to verify ownership. Some information may need to be retained for legal or security reasons. Available privacy rights depend on applicable law.
Children and policy changes
This service is intended for people managing websites and search data, and is not directed to children. Contact us if you believe a child has supplied personal information. We may update this policy as the service changes, post the revised version here, and update its date. We will provide notice of material changes and obtain additional consent when required before using data for a new purpose.
Contact us
GSC MCP Server is a product of PostMCP AI. For privacy requests, account questions, or questions about these terms, email hello@postmcpai.com. Include the email associated with your account and a description of your request. Please do not send passwords, access tokens, or API keys. For a self-hosted workspace, contact its operator about data held on that server.