PRIVACY
Where your data lives
Local means no backend, no telemetry, no accounts. It does not mean responses stay on your machine.
The four places
| What | Where | Who sees it |
|---|---|---|
| OAuth tokens / keys | ~/.gsc-mcp/ (or GSC_DATA_DIR), dir 0700, file 0600 | Only your machine and Google |
| Profiles (allowlists) | Same directory, no secrets | Only your machine |
| Tool responses | MCP process → your MCP client | Your client and its AI provider |
| Cache / datasets | Process memory (15-minute datasets) | The local process |
What “local” does not mean
- “Local” means: no backend of ours, no telemetry, no accounts.
- It does NOT mean responses stay local: your MCP client sends them to its AI provider to draft the answer. Read your client’s policy before querying sensitive properties.
- Your Search Console data goes direct from this machine to Google.
- You → this machine → Google, then tool response → your MCP client → its AI provider.
Cleanup
auth logoutdeletes the local OAuth session (it does not revoke at Google).auth revoke --yesrevokes at Google and deletes locally.- Deleting
~/.gsc-mcp/removes all local state (tokens, profiles). - Removing the client config never revokes the Google grant — revoke first if you want access gone. Full procedure: Uninstall.
Minimum scopes
- Single scope
webmasters.readonlyby default. GSC_ACCESS_MODE=fulladditionally requestswebmastersandindexingand enables sitemap submissions and URL notifications.- No Gmail, Drive, or Analytics scopes requested.
Google API use
- GSC MCP calls the Search Console and Indexing APIs directly from your machine. The developer operates no servers and receives no user data.
- Reads analyze your own verified properties when you ask your assistant. Writes run only when you choose full access and trigger them: sitemap submissions and URL notifications for your own properties.
- Image audits additionally fetch pages from your own site for on-page checks. Those fetches go to your site, not to Google.
- No advertising use. Optional export files stay on your machine and are never uploaded automatically.
- Tool responses travel to your MCP client and its AI provider to draft the answer. Retention on their side follows your client’s policy, not this page.
- Google’s data rules live here: Google API Services User Data Policy. This page claims no verification or approval status.
Contact
Maintainer: Sonni Vasquez — sonnivasquez.com · github.com/sonnivasquez. No additional support email is published on this page.