S/ SerpSidekick
in effect 4 September 2026

Privacy policy

SerpSidekick is operated by Andrius Butkevicius, self-employed and registered in Lithuania, who is the controller of the personal data described here. This policy covers serpsidekick.com and the MCP server at https://serpsidekick.com/mcp. The way to reach the operator is support@serpsidekick.com. It is written to be read rather than to be defensible, so if something here is unclear, mail that address and it will be fixed.

What we collect

  • Your Google account identity. Email address, display name, and Google's stable account identifier. This is what an account is; we have no password and no separate signup form.
  • A session. One opaque cookie so you stay signed in to the dashboard.
  • Search Console credentials, if you connect them. The refresh and access tokens Google issues, stored encrypted with a key we hold separately from the database.
  • Usage history. One row per tool call: which tool, when, whether it succeeded, what it cost, and which provider endpoints it hit. This is what the usage list on your dashboard is reading, and it is how a charge can be explained.
  • A credit ledger. Every top-up, charge and refund, as amounts in credits with the order or usage row that caused them.
  • Server logs. Request metadata including IP address, kept briefly for debugging and abuse handling.

We do not collect analytics on the public pages, we run no advertising or tracking pixels, and we do not sell or share anything with anyone not named below.

Google permissions, precisely

Two separate consents, asked at two different moments.

  • openid, email and profile, at sign-in. Your email address and name, so we know whose account and whose credits these are.
  • https://www.googleapis.com/auth/webmasters.readonly, only when you choose to connect Search Console from your dashboard. Read-only. We can read your search performance, index status and property list. We cannot submit sitemaps, request indexing, change settings or modify anything about your site.

Limited Use. SerpSidekick's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Search Console data is used only to answer the questions you ask through the tools, is never used for advertising, is never sold or transferred to third parties, is not used to train any machine-learning model, and is not read by a human except with your explicit permission for support you have asked for.

Your Search Console data is never sent to our paid data provider. When you ask a paid question, the provider receives only the keyword, domain or URL in the question.

Who else processes your data

Five, and here is what each one actually receives. Nothing else has access to any of it.

  • Cloudflare — Hosting, database and edge network. Everything stored by the service: your account record, session, encrypted Search Console tokens, credit ledger and usage history. Also request metadata such as IP address, in logs retained for a short period.
  • Google — Sign-in and Search Console data. Your sign-in is a Google OAuth flow, so Google knows you authorised this application. Search Console queries are made against Google's API with your own read-only grant.
  • DataForSEO — Paid SEO data provider. The query you asked about — keywords, domains or URLs — sent under our master account. It does not receive your identity, your email address or your Search Console data.
  • Polar — Payments, as merchant of record. Your email address, the amount paid, and the payment details you enter on their checkout. Card numbers never reach us.
  • Google Fonts — Typefaces on the public pages. Your browser requests font files from Google's CDN on every page, including the dashboard, which discloses your IP address to Google. Nothing about your account or your queries is sent with that request.

Some of these process data outside the EU. Those transfers rely on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses, whichever the provider has in place.

How long we keep it

  • Search Console tokens: until you disconnect that Google account, at which point the stored credential is deleted.
  • Usage history and the credit ledger: for as long as the account exists. These are the records that explain a charge, so they cannot be pruned while a balance exists.
  • Sessions: until they expire or you sign out.
  • Server logs: days, not months.

Deleting your data

Disconnecting a Google account from your dashboard deletes its stored credential immediately. To delete the whole account, mail support@serpsidekick.com from the address you signed in with; the account, its sessions and its Search Console credentials are removed. Payment records held by Polar as merchant of record are subject to their own retention obligations and are outside our control.

You can also revoke our Search Console access from your Google account's permissions page at any time, without telling us. Nothing breaks except the tools that needed it, which will say so.

Your rights

Wherever you are, you can ask to access, correct, export, restrict or delete your personal data, and object to how it is processed. Mail support@serpsidekick.com from the address you signed in with and expect a reply from a person within a month. If the answer does not satisfy you, you can complain to the data protection authority where you live. The legal bases we rely on are performing the contract you entered by using the service, your consent for Search Console access, and our legitimate interest in keeping the service working and unabused.

Children

The service is not intended for anyone under 16 and we do not knowingly hold data about them.

Changes

Material changes will be announced on this page with a new effective date before they take effect. This version is in effect from 4 September 2026.

Bring your next SEO question.

Free with Search Console · Credits never expire · Nothing to cancel