Colewood DigitalSEO AUDIT TOOL
GOOGLE API DATA

A clear explanation of the Google connection

The connection is optional, read-only and controlled per client workspace.

SEARCH CONSOLE

Read-only organic search evidence

Clicks, impressions, CTR, average position, queries, pages and dated comparisons for properties the connecting account can access.

GOOGLE ANALYTICS 4

Read-only organic visitor evidence

Aggregate users, sessions, engagement, key events, channel mix and landing-page results for a property selected by an authorised user.

ACCOUNT CONTROL

Connect, choose, disconnect

The account owner grants consent through Google. Colewood then selects only the appropriate client properties and can disconnect the account at any time.

Permissions requested

openid

Confirms the Google identity completing the connection.

email

Records which Google account authorised the connection.

webmasters.readonly

Reads available Search Console properties and authorised search-performance information.

analytics.readonly

Reads available Analytics accounts/properties and authorised GA4 reporting information.

The application does not request permission to edit, create or delete Search Console or Google Analytics information.

How the information is used

An authorised Colewood user connects a Google account inside a named client workspace, selects the relevant Search Console and/or GA4 property, chooses a comparison period and starts collection. The resulting aggregate evidence is displayed in that workspace and may be frozen into an SEO report.

We use it to explain measured organic visibility, landing-page behaviour, engagement and key-event outcomes; identify trends and opportunities; and support recommendations for that client. It is not used for advertising, credit decisions or sale to data brokers.

What is stored

  • The connected account email and permissions granted.
  • OAuth access and refresh tokens, encrypted in the application database.
  • The chosen Search Console property and GA4 property identifiers/names.
  • Aggregate evidence returned for requested periods and calculations derived from it.
  • Audit history, approved reports and activity records needed to administer the engagement.

Who receives Google user data

Google user data is disclosed only as needed to provide the requested audit service:

  • Authorised Colewood personnel may access it to deliver, review and support the client’s audit.
  • The relevant client organisation may receive its evidence, insights and approved reports through authorised workspace users or an approved exported report supplied to an authorised client representative.
  • Our hosting and database provider, currently iFastNet, stores and processes the application database, encrypted tokens and audit evidence on our behalf to provide hosting, backup and security infrastructure.
  • OpenAI receives a limited selection of aggregate or derived evidence only when an authorised user explicitly starts an AI-assisted assessment. OAuth tokens are never sent to OpenAI.

Google-derived data is not shared with other client organisations, DataForSEO, Semrush, Apify, advertising platforms or data brokers. It is not sold, used for advertising or retargeting, or used for credit or lending decisions.

We may disclose information where necessary for application security or abuse investigation, or where required by applicable law. It will not be transferred as part of a merger, acquisition or sale of assets without the affected user’s explicit prior consent. See the privacy policy’s data-sharing section for the complete disclosure.

Use in AI-assisted assessments

If an authorised user explicitly generates an AI assessment, the minimum relevant aggregate or derived Search Console and GA4 evidence may be transmitted to the OpenAI API to draft the requested analysis. Google OAuth access and refresh tokens are never included. The output is treated as a draft and reviewed by Colewood personnel. Colewood does not use or permit Google user data to be used to train a general-purpose AI model.

How to disconnect Google

  1. Sign in to the Colewood Digital SEO Audit Tool.
  2. Open the relevant client area.
  3. Choose Search Console & GA4.
  4. Select Disconnect and confirm.

This deletes the active Google connection and its stored OAuth tokens. You can additionally revoke Colewood Digital SEO Audit Tool access from the security/third-party access section of your Google Account.

How to request deletion

Disconnecting stops future access but deliberately preserves previously collected audit evidence. To request deletion of historical Google-derived evidence, an audit report or the associated user account, email enquiries@colewood.net.

Include your name, organisation, client workspace and the information you want deleted. We will verify that you are authorised to make the request and remove eligible data, subject to any legal, security or contractual retention requirement.

Google Limited Use

The Colewood Digital SEO Audit Tool’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.