PRIVACY

Where your data lives

Local means no backend, no telemetry, no accounts. It does not mean responses stay on your machine.

The four places

WhatWhereWho sees it
OAuth tokens / keys~/.gsc-mcp/ (or GSC_DATA_DIR), dir 0700, file 0600Only your machine and Google
Profiles (allowlists)Same directory, no secretsOnly your machine
Tool responsesMCP process → your MCP clientYour client and its AI provider
Cache / datasetsProcess memory (15-minute datasets)The local process

What “local” does not mean

  • “Local” means: no backend of ours, no telemetry, no accounts.
  • It does NOT mean responses stay local: your MCP client sends them to its AI provider to draft the answer. Read your client’s policy before querying sensitive properties.
  • Your Search Console data goes direct from this machine to Google.
  • You → this machine → Google, then tool response → your MCP client → its AI provider.

Cleanup

  • auth logout deletes the local OAuth session (it does not revoke at Google).
  • auth revoke --yes revokes at Google and deletes locally.
  • Deleting ~/.gsc-mcp/ removes all local state (tokens, profiles).
  • Removing the client config never revokes the Google grant — revoke first if you want access gone. Full procedure: Uninstall.

Minimum scopes

  • Single scope webmasters.readonly by default.
  • GSC_ACCESS_MODE=full additionally requests webmasters and indexing and enables sitemap submissions and URL notifications.
  • No Gmail, Drive, or Analytics scopes requested.

Google API use

  • GSC MCP calls the Search Console and Indexing APIs directly from your machine. The developer operates no servers and receives no user data.
  • Reads analyze your own verified properties when you ask your assistant. Writes run only when you choose full access and trigger them: sitemap submissions and URL notifications for your own properties.
  • Image audits additionally fetch pages from your own site for on-page checks. Those fetches go to your site, not to Google.
  • No advertising use. Optional export files stay on your machine and are never uploaded automatically.
  • Tool responses travel to your MCP client and its AI provider to draft the answer. Retention on their side follows your client’s policy, not this page.
  • Google’s data rules live here: Google API Services User Data Policy. This page claims no verification or approval status.

Contact

Maintainer: Sonni Vasquez — sonnivasquez.com · github.com/sonnivasquez. No additional support email is published on this page.