Skip to content

is giving you access safe

Privacy, in plain English.

Every job I take runs on the same permission: a client adds me to their Search Console. That deserves a straight explanation of what I can see, what I cannot, and how you switch it off. No legal fog.

What I ask for

One thing: user access to your Search Console property. You add my account yourself, from your own Settings screen, at the permission level you choose. The grant happens inside your Google account, under your control, from the first minute to the last.

What that access lets me see

Search Console shows how Google treats your site: which pages are indexed and which are not, coverage and crawl reports, sitemaps, and search performance for that one property. That is the data the whole job runs on. It does not expose your emails, your files, your customers, or anything else in your Google account.

What I never ask for

Your Google password. Your hosting or domain registrar login. Your payment details. If a fix needs a change inside your site, I tell you exactly what to change and where, or you grant the specific access you are comfortable with. Anyone claiming to be me and asking for a password is not me.

How to revoke access

Open Search Console, go to Settings, then Users and permissions, and remove me. It takes effect immediately and you do not need to warn me first. Most clients remove me the day the ledger is done; monthly clients keep me on while the monitoring runs. Either way the switch stays on your side of the table.

What ends up public

Case studies on this site name the niche, never the client, unless a client has given permission to be named. Ledger excerpts show page paths, indexing status, and dates. Account screenshots, client names, and private correspondence stay private.

The free tools on this site

The tools ask for read-only Search Console access through Google's own sign-in screen. What happens next is the whole policy: the access token Google returns is held in your browser tab, used by your browser to call Google's API directly, and gone when you close the tab or press Disconnect. It is never sent to this site, never written to storage or a cookie, and never seen by me. The URLs you check and the results that come back live in the same place, the page, until you leave it.

There is no account system and no database behind them. The single server-side piece is a sitemap reader, used whenever you check a sitemap, because browsers are not allowed to read another site's sitemap directly: it takes a public sitemap address, returns the XML, keeps no copy and writes no log entry. Paste mode does not touch it, so if you want nothing at all to leave your browser, paste the URLs. No Google data ever passes through it. Google's sign-in library loads on the tool pages only, and nothing the tool sees is ever measured: not the URLs you paste, not the property you pick, not a single result.

Search Console data obtained through these tools is used for one purpose: showing you your own results in that session. It is not transferred to anyone, not used for advertising, not used to train anything, and not retained. You can withdraw the permission at any time at myaccount.google.com/permissions.

This website

No cookies, no ad pixels, no advertising, and nothing that follows you to another site. The site is static HTML; the host (Vercel) keeps ordinary server logs the way every host does. If you message me, it lands on WhatsApp or in my email inbox and goes nowhere else.

There is one measurement script, Umami, and this is everything it records: the page address, the referring site, coarse device and country information derived from the request, and how quickly the page rendered for you. It sets no cookies, stores no identifier on your device, and cannot follow you across sites, so there is no consent banner to click because there is nothing to consent to. I also count two actions so I know whether the site is doing its job: clicking a WhatsApp or email link, and finishing a run in the inspection tool. Those record the page you were on and, for a tool run, roughly how many URLs were in the batch. Never the URLs themselves.

I use it to see which guides get read, whether anyone uses the tools, and whether the site is slow for people on connections unlike mine. It is not shared, not sold, and not used for advertising.

Questions about any of this: WhatsApp or mr.shahidali.sa@gmail.com. Last updated 21 July 2026.