Who we are
QueryInbox (“we”) operates the QueryInbox web app (the “Service”). For anything in this policy, write to support@queryinbox.com.
What we read from your Google account
Signing in with Google asks you for read-only access. Concretely, we receive:
- Your basic profile — name, email address and profile picture (
openid,email,profile), so we can show who is signed in. - Search Console — the sites you can access and their performance data: clicks, impressions, average CTR, average position, queries and pages (
webmasters.readonly). - Google Analytics — the properties you can access and their reports: users, sessions, bounce rate, conversions, landing pages and traffic sources (
analytics.readonly).
The Service is read-only. It cannot create, change or delete anything in your Google account, and it has no access to Gmail, Drive or any other Google product.
What we store
| What | Where | Why | How long |
|---|---|---|---|
| Your account profile — email address, name and profile picture | Cloudflare D1 | To identify your account and, if we ever need to, write to you about it | Until you ask us to delete your account records |
| Google OAuth tokens (access and refresh) | Cloudflare D1, encrypted | So the wall — and any agent key you created — loads without asking you to sign in again | Until you disconnect Google, or ask us to delete them |
| Agent access keys — only a hash; the key itself is shown once and never stored | Cloudflare D1 | So the MCP clients and other agents you configure can read your Search Console and Analytics data | Until you revoke the key, or disconnect Google |
| The sites and properties you picked (your working set) | Cloudflare D1, encrypted | So the wall knows what to show, and what to leave out | Until you change it or ask us to delete it |
| A short-lived cache of report results | Cloudflare D1 | So repeat views are instant instead of re-reading Google | Re-read from Google after 5 minutes for the 24-hour view and the site list, 15 minutes for the other ranges, or 1 minute for realtime; a cached copy is deleted within 24 hours (a site's public rating may stay for a week) |
| A session cookie | Your browser | To keep you signed in | 30 days, or until you log out |
We do not keep a copy of your Search Console or Analytics history. There is no data warehouse, and nothing is ever written back to Google.
What we never do
- We do not sell your data, or your Google data.
- We do not use your Google data, or the contents of your reports, for advertising, ad targeting, or profiling.
- We do not use it to train machine-learning models.
- We do not let people read it — except when you ask us for support and explicitly allow it, or when the law requires it.
- We do not share it with anyone other than the providers below.
QueryInbox’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
- Cloudflare hosts the app and stores the D1 data described above, acting on our instructions.
- Google provides sign-in, the Search Console and Analytics APIs, and the website analytics described below.
- To draw a site’s icon, your browser requests it from Google’s public favicon service, which tells Google that domain. Nothing else about your session is sent with that request.
Website analytics
The public pages and the app itself use Google Analytics 4 to count visits and see which pages are useful. It sets first-party cookies —_ga plus a second cookie scoped to our measurement stream — and records the page you visited, an approximate location derived from your IP address, your browser and device, and how you arrived.
It is never told which sites you monitor or what your reports contain: report URLs are shortened to /dash/report before anything is reported. Google processes this data on our behalf, it is not used for advertising or profiling, and we do not combine it with anything we read from your Google account.
You can block it with a content blocker or your browser settings, or install Google’s opt-out add-on.
Operational logs
The app runs on Cloudflare, which records standard request metadata — such as time, URL, status code and the connecting IP address — for reliability, capacity and abuse prevention. We do not log the contents of your reports.
Security
Tokens and your working set are encrypted at rest with AES-256-GCM using a key that only the server holds. Your account profile — email, name and picture — is stored as-is, because it is not a credential and the email address is what we would use to contact you. Agent access keys are stored as SHA-256 hashes, so even a database leak cannot replay them. Tokens never reach your browser; the browser only holds a signed, HttpOnly session cookie. All traffic is served over HTTPS.
Your choices
- Change or clear the working set — in Settings.
- Log out — ends this browser session. Your Google connection and working set stay.
- Disconnect Google — in Settings, removes the stored Google tokens and revokes every agent key. Your working set and profile stay.
- Revoke access at Google — remove QueryInbox from your Google account permissions. The app loses access immediately.
- Delete everything — write to support@queryinbox.com and we will remove your account records. Cached report numbers are re-read from Google within 15 minutes and are deleted within 24 hours.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
Changes to this policy
If this policy changes we will update this page and its date. Material changes will be announced in the app.