Legal
Privacy policy
Last updated: 30 September 2026
ScopeMCP exists to read your search data on your behalf, through your own credentials, and to tell you what it found. It has no advertising, no third-party analytics, and no interest in your data beyond making the next report work. This page describes that concretely.
Who is responsible for your data
If you use the hosted version, ScopeMCP is the processor and you are the controller. If you self-host, you are both, and nothing leaves your infrastructure except calls to the providers you configured.
What we store
- Account — your email address, and the name and picture from your sign-in provider if you chose to share them.
- Encrypted OAuth tokens — sealed with AES-256-GCM. Necessary to read your data on your behalf. Never readable by us in plain text at rest, never returned to an agent, never logged.
- Property metadata — the site identifiers your connected accounts can reach, so the property list does not require a fresh upstream call every time.
- Report cache — performance reports for six hours and CrUX records for twenty-four, so repeated questions do not consume upstream quota. Entries expire automatically.
- Monitors, alerts and snapshots — only what you asked to be monitored. Snapshots exist so a monitor can tell you whether something changed, and so you can diff two runs.
- Competitor domains — the list of domains you entered. We do not fetch their private data; we read public result pages.
- Share links — an opaque token, a title and a view count for links you create.
What we do not store
- Page content. No tool fetches or retains your HTML, and no tool reads your copy.
- Plaintext API keys. Only a SHA-256 hash is kept. A lost key is replaced, not recovered.
- Your agent’s conversations or tool arguments. We do not log what you asked your assistant.
- Anything about your visitors. ScopeMCP is a search-data connector, not an analytics product. Where you connect GA4, the data stays between your browser and Google.
Who we share it with
Nobody, except the providers you authorised: Google, Microsoft, and — if you configure an email provider — whoever sends your monitor alerts. Competitor analysis reads public search result pages, which anyone can do.
We do not sell data, share it for advertising, or hand it to data brokers. If we ever needed to disclose anything, we would tell you first and narrow it to what is legally required.
How long we keep things
- Cached reports: six to twenty-four hours, then deleted automatically.
- Snapshots and alerts: until you delete them, or delete your account.
- Sessions: 30 days, then they stop working even if the cookie persists.
- Connections and properties: until you disconnect the source or delete your account.
Deleting your account
Deleting your account removes your user record. Because connections cascade from it, that also removes the encrypted tokens, the property list, your monitors, alerts, snapshots and share links. Share URLs return 404 immediately.
Nothing remains on our side. What still exists is with Google, Microsoft and your email provider, and you revoke those grants in your own account settings.
Cookies
- One session cookie, httpOnly and SameSite=Lax, holding a signed session id and nothing else.
- A short-lived PKCE cookie during OAuth, deleted immediately after the callback.
- No advertising, tracking or fingerprinting cookies, on this site or in the product.
International transfers
The upstream providers we call operate globally, so a request necessarily reaches them. That is inherent to reading Google Search Console or Bing Webmaster Tools at all, and it is why we made the tool set read-only: nothing is written back.
If you need the calls to stay in one region, self-host with your own infrastructure and choose your providers accordingly.
Children
ScopeMCP is a professional tool for people who run websites. It is not directed at children, and we do not knowingly collect data from them.
Changes
If this policy changes in a way that affects what we store, we will say so in the app before the change takes effect. The previous version is always in version control, since the whole project is open.