Migration Risk

Privacy

This free beta uses the minimum access and data handling needed to create a migration risk report from your Search Console property.

Last updated: 14 September 2026

What we access

When you choose to connect Google, the service uses Google OAuth for the openid, email, profile and webmasters.readonly scopes. The Search Console scope is read-only and is used to request the property list and search performance data needed for the report.

What we keep

Connecting Search Console uses an encrypted, HttpOnly session cookie. The cookie can contain a Google refresh token so the service can renew access while you use the analyser. The connection lasts for up to seven days, or less if Google ends access sooner. Disconnecting clears the connection and asks Google to revoke access.

Connecting Search Console does not create a report account or save a report. Without an account save, report data stays in browser memory while this page is open. If reconnection is needed, your selected website, dates and brand names are kept in this tab's session storage for up to 15 minutes to restore the form. This temporary draft contains no Search Console query rows, reports or Google tokens and is cleared after restoration or disconnection.

Accounts and saved reports

To enforce report allowances, we keep a protected identifier derived from your Google identity, each run's website and period, start time and completion status. Free allows 3 total runs; Pro allows 15 per UTC calendar month. This usage record remains after report or account deletion so deletion cannot reset the allowance. It contains no search query rows or report contents.

Creating a report account is a separate choice. Account sign-in uses your Google identity and does not require access to Search Console. If Search Console is already connected, we can use that verified identity when you explicitly create your report account.

Your account uses a separate encrypted, HttpOnly cookie that lasts up to seven days. We store a protected identifier derived from your Google account, the terms version you accepted and the acceptance date. Your name and email are held in the encrypted account cookie; Google access and refresh tokens are not saved in the report database.

When you choose Save this report, the report contents, page CSV, website, selected period, title and summary are uploaded to your private account library. Free accounts can store one report; Pro accounts can store ten. Saved reports can contain business information and search queries. Account records and saved reports are held in a restricted part of our existing Supabase database in London.

You can delete an individual audit or delete your report account and its saved audits from the library. Signing out does not delete saved reports. Disconnecting Search Console ends that connection independently of your report account.

Service processing

Google processes the OAuth and Search Console requests under Google's terms. Vercel hosts this beta and processes request metadata needed to run and protect it, such as timestamps, network information and error logs. Supabase processes saved account and report data. Stripe processes subscription and payment details when you choose a paid plan. We keep the subscription references and status needed to apply your plan; card details are handled by Stripe. We do not use advertising trackers or ad personalisation on this analyser.

Report branding

For white-label reports, you can upload a logo or provide a brand domain. Domain lookup fetches the public website and its logo candidates. The selected logo and brand name are included in the saved report. Only provide branding you have permission to use.

Downloads

Pro users can export a saved report to Google Slides. At export time, Google asks for permission to create and access files used with this app (drive.file). The selected report and its branding are sent to your Google Drive to create a private, editable presentation. We keep the export reference to avoid duplicate decks. The temporary Drive access token is held in an encrypted, HttpOnly cookie and cleared when you sign out; no Drive refresh token is stored. Deleting a report here does not delete an exported deck from your Google Drive.

Page CSV downloads are available without a report account. Downloading the HTML report requires a report account. A download saves the file to your device; it does not by itself save a copy to the account library. Charts and styles in the HTML file are included so it can be read without this service. Anyone you give a downloaded file to may be able to read its contents.

Your Google permissions

You can revoke this beta's Google access at any time from your Google account permissions page, or by choosing Disconnect Search Console in the analyser.

Questions

For privacy questions, use the Mersudin Forbes contact page.