Privacy Policy
Last updated: September 29, 2026 · גרסה עברית
PushSEO is a service by Push Digital for analysing and improving websites in search engines (SEO) and AI answer engines (GEO). This policy explains what data we collect, why, how it is stored, and how to delete it.
Account data
Email address, name, organization, role, and project data you enter (website address, onboarding questionnaire answers and search phrases to track). This data is used to operate your account, permissions and security.
Data from Google
Connecting Google is optional and done per project. We request two read-only scopes, each in a separate connection and only when you choose it:
1. Google Search Console — https://www.googleapis.com/auth/webmasters.readonly
- The list of properties (sites) your account is permitted to view;
- Performance data for the property you select: clicks, impressions, CTR and average position, by date, query, page, country and device;
- URL Inspection results as returned by Google, when you request them.
2. Google Analytics 4 — https://www.googleapis.com/auth/analytics.readonly
- The list of GA4 accounts and properties your account is permitted to view, and their data streams — to verify the property belongs to the project's website;
- Property settings: currency, time zone and attribution settings;
- Aggregated metrics: sessions (including organic traffic), users, engagement, key events, and revenue only if the property measures purchases;
- Landing pages and traffic sources (including referrals from AI assistants), by date and device.
We do not request access to Gmail, Drive or any other Google data, and we never write to or modify Search Console, Google Analytics or your website. We do not read user-level data about your site's visitors.
How we use the data
Google data is used solely to show your website's performance inside PushSEO — search performance from Search Console alongside business outcomes from GA4, trends over time, and recommendations for improving your site. It is shown only to organization members assigned to the project.
How the data is stored
- Google access tokens are stored encrypted (AES-256-GCM) on the server only and are never sent to the browser.
- Retrieved data is stored under the organization and project that connected it; access is isolated and enforced in the database.
- All traffic is encrypted (HTTPS).
Sharing and sub-processors
We do not sell, rent or share user data or Google data with third parties, and we do not use it for advertising. Sub-processors:
- Infrastructure providers (hosting and database) — only as needed to operate the service.
- DataForSEO — receives only search phrases, country and language for keyword research. No information received from the user's Google APIs is sent to it.
Data is disclosed to authorities only where required by law.
Disconnecting and deletion
- Search Console: project page → Search Console → "Disconnect". GA4: project page → Google Analytics 4 → "Disconnect". Disconnecting deletes the token from our servers and stops syncing. You can also revoke access at any time at myaccount.google.com/permissions.
- Data deletion: to delete stored Google data or your whole account, email us. We handle requests within 30 days.
Limited Use disclosure
PushSEO's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
In particular: use is limited to providing and improving user-facing features; no transfer to third parties except for that purpose, for security, or as required by law; no use for advertising; and no human reading of the data except with your consent, for security, to comply with law, or when aggregated and anonymised for internal operations.
Contact
Push Digital — pushdigital.mark@gmail.com