← 10xSearch

Google API Services Limited Use Disclosure

Last updated: July 10, 2026

Compliance statement

10xSearch Inc.’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes we request

When an operator (agency user) or client connects their Google account to 10xSearch, we request the minimum set of OAuth scopes required to power our analytics and indexing features:

  • openid, email

    Identifies which Google account authorized access, so we can label the connection and let the operator revoke or re-authorize it later.

  • https://www.googleapis.com/auth/webmasters.readonly

    Read-only access to Google Search Console. Used to read the client’s indexed URLs, query performance (clicks, impressions, average position, CTR), and sitemap status. Data is displayed in the client’s dashboard and used to compute SEO progress reports. We never write, submit, or modify property data through this scope.

  • https://www.googleapis.com/auth/analytics.readonly

    Read-only access to Google Analytics 4. Used to read the client’s aggregated site metrics (sessions, users, conversions, traffic sources) for their own dashboard. We never write, modify, create, or delete GA4 properties, streams, audiences, or events.

  • https://www.googleapis.com/auth/indexing

    Write access to the Google Indexing API, used solely to notify Google when the client publishes, updates, or removes a page on their own verified site — so the change is crawled and reflected in search faster. We do not submit URLs for domains the client does not own or control.

  • https://www.googleapis.com/auth/business.manage

    Read and write access to the client’s Google Business Profile locations that they explicitly authorize. Used to (a) read profile information (name, address, hours, categories, attributes, services), performance metrics (views, calls, direction requests, website clicks, search queries), reviews, posts, and media items so we can display them in the client’s own analytics dashboard and monthly reports; and (b) publish posts, reply to reviews on the client’s behalf, and update profile fields (hours, attributes, services) only when the client requests those changes through our portal or has configured an automation they enabled. We only touch Business Profile locations owned by the connecting Google account.

Limited Use commitments

In accordance with the Limited Use requirements of the Google API Services User Data Policy, 10xSearch Inc.:

  1. Uses data obtained through the scopes above only to provide or improve user-facing featuresthat are prominent in the requesting application — specifically, the client’s own SEO analytics dashboard, progress reports, and indexing automation on the 10xSearch platform.
  2. Does not use the data to develop, improve, or train generalized or general-purpose AI and/or ML models.No data received from Google Workspace APIs (Search Console, Analytics, Indexing) is used to train any large language model, embedding model, or other machine-learning model, whether our own or a third party’s.
  3. Does not transfer the datato any third party except (a) to provide or improve the user-facing features described above, (b) as required for security or fraud prevention or to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets with the user’s explicit consent.
  4. Does not use the data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
  5. Does not allow humans to read the dataunless we have obtained the user’s affirmative agreement to view specific messages, doing so is necessary for security purposes, or the data (including derivations) has been aggregated and anonymized and is used for internal operations.

Data storage and retention

Refresh tokens obtained through the OAuth flow are stored encrypted at rest using AES-256-GCM on our Supabase-managed Postgres database. Data fetched from Google APIs is cached on our infrastructure (Vercel and a private Hetzner engine) only as long as is needed to render dashboards, generate scheduled reports, and honor the client’s configured retention window (default 24 months). Aggregate metrics may be retained longer for the sole purpose of the client’s own historical trend reporting; raw per-URL and per-query rows are purged on schedule.

Revocation and deletion

A user may revoke 10xSearch’s access at any time from their Google Account → Data & privacy → Third-party apps & services settings. Revocation immediately invalidates our stored refresh token and stops all further API calls. Cached Google-derived data can be deleted on request by emailing privacy@10xsearch.com from the address associated with the Google account — we honor deletion requests within thirty (30) days.

Related documents

Contact

Questions about this disclosure or 10xSearch’s use of Google user data can be sent to privacy@10xsearch.com.