Google API Disclosure
Data Deletion & Google API Usage
Last updated: 16 June 2025
SEO by 15MT's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Google Data We Access
When you voluntarily connect your Google account to SEO by 15MT, we request access to the following read-only OAuth scopes:
| Scope | What it allows us to read | Why we need it |
analytics.readonly |
Google Analytics 4 traffic and engagement metrics |
Display your GA4 performance data (sessions, users, pageviews) in your SEO dashboard |
webmasters.readonly |
Google Search Console impressions, clicks, average position by query and page |
Display your search performance data to inform content and keyword decisions |
analytics.manage.users.readonly |
List of GA4 properties on your account |
Let you select which GA4 property to connect to your workspace |
openid, profile, email |
Your Google account name and email address |
Display which Google account is connected and confirm identity for OAuth |
How We Use Google Data
- Google data is used only to display your own SEO and Analytics performance metrics within your SEO by 15MT dashboard.
- Data is displayed back to you — the account owner — and to no one else.
- We do not use Google data to serve advertisements.
- We do not share, sell, transfer, or disclose Google data to any third party.
- We do not use Google data to train or improve AI models.
- We do not use Google data for any purpose other than the SEO reporting feature described above.
- We only access data from the specific Analytics property and Search Console site you select during setup.
Read-only access only. We never write to, modify, or delete any data in your Google Analytics or Search Console accounts. All scopes requested are strictly read-only.
How Google Data Is Stored
- OAuth access tokens and refresh tokens are stored in our database, encrypted at rest using AES-256-GCM encryption.
- Tokens are never logged, never exposed in HTML or JavaScript, and never transmitted outside of server-side API calls to Google.
- Synced performance metrics (traffic data, query rankings) are stored in your isolated workspace database — completely separate from other users.
- Token exchange and refresh occur exclusively server-side (PHP). Client browsers never see raw tokens.
Revoking Access
You can disconnect your Google account at any time by visiting your account → Connect Google → Disconnect. This will:
- Revoke the OAuth access token at Google's servers.
- Immediately delete the stored access token and refresh token from our database.
- Delete all synced Analytics and Search Console metrics associated with your workspace.
You can also revoke access directly via Google Account → Security → Third-party apps with account access.
Data Retention
- Google OAuth tokens are retained only while your Google account is connected.
- Synced performance metrics are retained while your SEO by 15MT account is active.
- All Google-sourced data is permanently deleted when you disconnect Google (above) or when you delete your account (below).
Request Data Deletion or Export
To request deletion of your account data (including any Google API data we hold), or to request a data export, complete the form below. We will respond within 5 business days and complete all deletions within 30 days.
If you prefer, you can also email us directly at info@15metech.com with the subject line "Data Deletion Request".