Privacy Policy
This policy explains how Searchata handles information when you use the website, connect a search-data source, or authorize an AI agent.
Last updated: September 9, 2026
1. Scope
This policy applies to Searchata and its remote Model Context Protocol service. Model Context Protocol, or MCP, is the standard that lets an AI agent call Searchata tools.
Searchata connects to Google Search Console, Bing Webmaster Tools, and Google Analytics 4. Its MCP tools can read aggregated visitor analytics from GA4 properties you select. They do not provide competitor analysis. Bing crawl data comes from Bing Webmaster Tools. Searchata uses Microsoft Clarity and PostHog only to understand and improve use of the Searchata website.
2. Information we process
Account information
We process information used to create and secure your account. This can include your name, email address, profile image, authentication-provider identifier, and session records.
Google Search Console connection
We process the Google OAuth credentials that you authorize, their expiry details, and metadata for the Search Console properties that your Google account can read. We encrypt Google OAuth credentials at rest.
Google Analytics 4 connection
We store encrypted Google authorization credentials, accessible GA4 property metadata, selected properties, and their Searchata site associations. We read aggregated reports for the properties you select. Encrypted GA4 report caches expire after five minutes. Disconnecting GA4 removes its stored credentials, property selections, and cached reports.
Bing Webmaster Tools connection
We process the Microsoft OAuth credentials that you authorize for Bing Webmaster Tools, their expiry details, and metadata for the verified Bing sites that your Microsoft account can read. We encrypt these OAuth credentials at rest.
Agent connection
We process MCP client-registration records, authorization records, token hashes, scopes, expiry times, and recent-use times. We use these records to authenticate the AI agent that you approve.
Tool requests and search-source data
We process the parameters that an agent sends to a Searchata tool. We request the selected data from Google Search Console, Bing Webmaster Tools, or Google Analytics 4 and return it to the agent. We can keep encrypted response caches. Google performance caches expire after 10 minutes or, for older final data, up to 24 hours. Bing caches expire after 10 minutes, one hour, or six hours based on the report type.
For each MCP tool call, we store the account and workspace identifiers, tool name, plan category, scheduled-cancellation state, time, duration, and result status for up to 30 days. We also keep daily counts and timing summaries for these fields for up to 400 days. These records exclude request parameters, source property identifiers, source URLs, report contents, credentials, and error messages. We use them to understand tool adoption, compare trial and paid use, find errors, and apply service limits.
Page performance tools
When you request a PageSpeed Insights audit or Chrome UX Report, we send the selected public URL or origin and device option to Google. PageSpeed tests the page; Chrome UX Report returns aggregated real-user measurements where available. We store encrypted report caches for 6 hours for PageSpeed and 24 hours for Chrome UX Report. We also store request counts and temporary concurrency records to enforce service limits. These tools do not require access to your Google account.
Plan, billing, and technical information
We process plan status, request counts, Stripe subscription identifiers, PayPal order and payer identifiers, lifetime-license records, and related billing records. Stripe and PayPal process payment details. We hash lifetime license keys for activation. We keep an encrypted copy only while a license email is pending. We also process standard web-request data, such as IP address, browser type, time, route, and error details, when our infrastructure creates service and security logs.
Website interaction information
Microsoft Clarity can process page visits, clicks, scrolls, device and request information, behavioral metrics, heatmaps, session replay, and approximate location. Searchata also sends named authorization-funnel events to Clarity. These events identify the completed funnel step.
After sign-in, Searchata sends an opaque Searchata account identifier to Clarity. Clarity hashes this identifier before it stores it. Searchata stores the date and method used to create this link in the account record. We use the link to match a Searchata account to its Clarity visitor profile. We do not send the account name, email address, IP address, search-source data, MCP tool results, or OAuth values through this link.
PostHog can process page visits, clicks, device and request information, product-use events, and session replay. After sign-in, Searchata sends your account identifier, name, and email address to PostHog to link your website activity and session replays to your account. PostHog also records the referring website, landing page, and campaign tags to help us understand how visitors find Searchata. Searchata configures PostHog to create person profiles only for identified users.
3. How we use information
- Provide and secure Searchata accounts and sessions.
- Connect to Google Search Console, Bing Webmaster Tools, or Google Analytics 4 with the permission you approve.
- Authenticate approved agents and complete MCP tool requests.
- Apply service limits, process purchases and subscriptions, deliver account, onboarding, trial, and license emails, and prevent misuse.
- Find errors, maintain reliability, and respond to support or security requests.
- Measure signup, authorization-funnel, and purchase conversions.
- Meet legal obligations and enforce the Terms of Service.
4. Google user data
For Search Console, Searchata requests https://www.googleapis.com/auth/webmasters.readonly. This permission lets Searchata read the Search Console properties available to your Google account. It does not let Searchata change Search Console settings or submit data to Google Search Console.
Searchata's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
We use Google Search Console data only to provide user-requested Searchata features, secure those features, and maintain the service. We do not sell Google Search Console data. We do not use it for advertising. We do not send it to X or Microsoft Clarity for measurement.
For optional GA4 connections, Searchata requests https://www.googleapis.com/auth/analytics.readonly. We use this data only for user-requested features, security, and service operation. We do not sell it, use it for advertising, or send it to X or Microsoft Clarity.
Bing Webmaster Tools data
Searchata requests only webmaster.read for Bing Webmaster Tools. This permission lets Searchata read the verified sites and webmaster reports available to your Microsoft account. It does not let Searchata change Bing site settings or submit data.
We use Bing Webmaster Tools data only to provide user-requested Searchata features, secure those features, and maintain the service. We do not sell this data. We do not use it for advertising. We do not send it to X or Microsoft Clarity for measurement.
7. Retention and deletion
We keep account and connection records while they are needed to provide Searchata. MCP authorization codes expire after 10 minutes. MCP access tokens expire after one hour. MCP refresh records expire after 30 days. Encrypted source-response caches expire after 10 minutes, one hour, six hours, or up to 24 hours based on the source and report type.
Disconnecting Google or Bing disables that source connection. It does not by itself delete all account, billing, security, or legal records. We keep these records only while they are needed for the purposes in this policy, for required records, or to resolve a dispute.
To request account-data deletion, email privacy@searchata.com. We can ask you to verify control of the account before we complete the request.
8. Your choices and rights
You can use the unsubscribe link in an onboarding or trial email to stop these automated messages.
You can disconnect an AI agent in that agent's connector settings. You can disconnect Google Search Console, Bing Webmaster Tools, or Google Analytics 4 on the Searchata Sources page. You can also revoke Searchata in your Google Account or Microsoft account permissions.
Depending on where you live, you can have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Send a request to privacy@searchata.com. You can also contact your local data-protection authority.
9. Security
We use technical and organizational controls that are designed to protect information. These controls include encryption for source OAuth credentials and cached source responses, hashed MCP credentials, access limits, and token expiry. No online service can guarantee complete security.
Send a possible vulnerability to security@searchata.com. Do not include live credentials or search-data exports.
10. Children
Searchata is not directed to children. Do not use Searchata if you cannot legally consent to this policy and the Terms of Service.
11. Changes and contact
We can update this policy when the service or legal requirements change. We will change the date at the top of this page. We will give additional notice when applicable law requires it.
For privacy questions or requests, email privacy@searchata.com.