Privacy Policy

Northwind Lab Search Console MCP
Last updated: 20 September 2026

This policy applies only to the private Northwind Lab Search Console MCP service. It does not govern Northwind Lab Music or other Northwind Lab products.

Purpose and access

The service is an internal administrative tool. Access is limited to specifically authorised Northwind Lab Google accounts. It uses Google's read-only Search Console permission to retrieve indexing status, submitted sitemap status and search-performance metrics for explicitly allowed Northwind Lab properties.

Google data we process

The service processes the authorised user's Google account email address, immutable account identifier and email-verification status to enforce its access list. It also processes Search Console property details, URL inspection results, sitemap status, and search analytics such as queries, pages, countries, devices, clicks, impressions, click-through rate and average position.

Credentials and storage

OAuth credentials and tokens are stored only in access-restricted service infrastructure and are not committed to source control. OAuth session state may be retained so authorised administrators can reconnect without repeating consent. Search Console API responses are returned to the requesting administrator and are not sold, shared for advertising, or used to train general-purpose AI models by Northwind Lab.

Use, sharing and retention

Google data is used only to operate, secure and troubleshoot this private service and to improve Northwind Lab's own search visibility. Access is limited to authorised administrators and infrastructure providers required to operate the service. Credentials and OAuth state are retained only while access is needed. Operational logs are minimised and must not contain OAuth tokens. Data may be retained longer when required for security or legal obligations.

Revocation and deletion

An authorised user can revoke access from their Google Account connections page. To request deletion of stored OAuth state or identifiers, email admin@northwind-lab.com. Northwind Lab will remove the service's stored credentials and OAuth state associated with the account, subject to legal or security retention requirements.

Security and policy changes

Northwind Lab uses account allow-lists, property allow-lists, encrypted transport, access-restricted secrets and least-privilege Google scopes. No online service can be guaranteed completely secure. Material changes to this policy will be published on this page with an updated date.

Contact

Questions or privacy requests: admin@northwind-lab.com.